posto

Privacy & Terms

Privacy, service terms, role requirements, and technical data-handling terms for Posto are collected here in one place.

PostoX, Inc · Archived document · Version archive

Published September 7, 2026. Customer acceptance is affirmative and prospective; this release does not rewrite earlier acceptance records.

On this page Developer Terms

Developer Terms

Additional contractual terms for business entities and sole proprietors that supply advertising inventory or integrate Posto into an application, service, or placement. These Terms supplement the Terms of Service.

Effective 2026-09-07 · Version 2026-09-07 · Permanent version

1. Authorized properties and integrations

Developer shall use supported Posto SDKs, APIs, credentials, and documented test paths and shall register each application and placement accurately. Developer shall own each registered property or hold written authority from its owner, provide an official app-store listing or verified domain when requested, disclose material resellers or supply intermediaries, and keep package, bundle, domain, placement, and traffic-source declarations current.

Web applications shall use a Developer-controlled backend relay with server HMAC authentication. Supported native integrations shall use the required Apple App Attest or Google Play Integrity proof. Developer shall not embed server secrets in browser code or mobile binaries, circumvent integrity checks, or use a non-billable test path as production inventory.

2. End User experience and advertising disclosures

Developer controls its property and shall provide the notices, permissions, and lawful basis required to transmit context and display advertisements. Every advertisement shall be visually distinguishable from organic content and shall display the SDK-prescribed 'Sponsored' or 'Ad' label clearly and conspicuously, as close as reasonably possible to the headline or other primary focal point, on every supported device.

Developer shall not remove, obscure, minimize, misplace, or delay that disclosure; materially alter an advertisement without authority; force a click; or create a deceptive placement. A format in which the required disclosure cannot remain clear and conspicuous shall not serve Posto advertisements. Where necessary to prevent deception, an affiliate destination shall also be accompanied by a disclosure that Posto or the relevant party may earn a commission.

3. Data minimization and privacy notices

Developer shall submit only the bounded recent messages and optional coarse demographic fields allowed by the SDK Data Handling Notice, run the supplied filtering, and refrain from disabling or bypassing server filtering. Developer shall not submit names, contact details, authentication secrets, payment information, precise location, street addresses, protected health information, biometric or government identifiers, children's personal information, or other prohibited sensitive data. Filtering has limitations and does not authorize otherwise prohibited submissions.

Developer shall maintain an accurate, publicly accessible privacy notice identifying Posto as an advertising and measurement provider, linking to Posto's legal notices, and describing the categories, purposes, recipients, retention, and choices relevant to its integration. Developer shall obtain any required specific consent, including for storage or access technologies, and honor applicable platform and legally binding universal privacy signals. Posto does not currently approve child-directed production integrations.

4. Event validity and invalid traffic

Developer shall record an impression only after the advertisement is rendered and viewable under the applicable documentation and shall record a click only after an intentional human action. Developer shall take reasonable measures to detect and stop invalid activity and shall cooperate with a reasonable investigation.

Developer shall not cause or authorize bots, device farms, click injection or spamming, undisclosed incentives, forced redirects, deceptive pop-ups, self-clicks, replayed tokens, concealed traffic sources, manipulated context, spoofed SDK or location information, emulators outside documented test paths, or other inflation or fabrication of requests, impressions, clicks, installs, or conversions.

Posto may classify traffic as valid, observe, held, or invalid and may withhold, adjust, offset, or reverse affected earnings and restrict related payments while evidence is reviewed. Such action shall relate to the applicable invalid activity, credible risk, or lawful obligation; confirmed invalid activity does not become payable merely because an account is restored.

5. Earnings, supplier payments, and taxes

Developer supplies valid advertising inventory and related integration services as an independent business and controls operation of its property. The Agreement does not create employment, agency, partnership, or representative authority, and does not override a classification required by applicable law.

Valid Publisher earnings are calculated from finalized billable impressions after the applicable Posto fee. A minimum CPM applies only when expressly stated in an executed Order or eligible placement setting and only to finalized valid impressions. It does not guarantee payment for test, observe, held, invalid, unsupported, or no-fill traffic. Simulation balances have no cash value.

Finalized eligible earnings are an accounts-payable obligation of Posto, rather than a deposit, stored-value account, escrow balance, or segregated advertiser fund. There is no contractual right to an instant or automatic withdrawal. When the payment-request feature is enabled, Developer may request ACH payment after finalized available earnings reach the displayed minimum. Each request remains subject to Posto review, approval through the payment provider, fraud and compliance holds, and lawful withholding, adjustment, offset, or reversal. These controls do not extinguish an otherwise valid payment obligation.

A payment statement generated by Posto may serve as a self-billing record. Developer shall report a good-faith amount dispute promptly through support with the relevant statement and evidence; this request for prompt reporting does not shorten a nonwaivable statutory period.

Developer shall provide accurate legal name, address, banking details, taxpayer status, and any requested Form W-9, Form W-8, or other required documentation through the designated secure channel and shall promptly report changes. Developer is responsible for its income, employment, sales, use, value-added, and similar taxes, excluding taxes imposed on Posto. Posto may validate information, withhold payment or tax when legally required, and file and deliver required information returns. Payment-provider setup or acceptance does not establish that a tax authority has accepted a tax form or taxpayer identification number.

6. Security and supported versions

Developer shall protect credentials, signing keys, app identifiers, and administrative access; promptly install security-critical SDK updates; and maintain supported application versions. Developer shall notify security@postoconnect.com promptly after discovering compromise, an integrity-verification failure, or suspected invalid traffic and shall cooperate in containment. Posto may rotate credentials or suspend an unsafe integration to address the risk.

7. Property content, compliance, and rights requests

Developer represents that it owns or has the necessary rights to its property and submitted content and that the integration complies with applicable platform, privacy, consumer-protection, advertising, commerce, intellectual-property, and product requirements and Developer's published notices. A property shall provide substantive, authentic functionality and shall not exist primarily to display advertisements.

Prohibited properties include child-directed services, services soliciting protected health information for ad matching, malware, deceptive or infringing services, and properties whose principal traffic source is undisclosed or invalid. Developer shall respond to End User requests within its responsibilities and forward requests requiring Posto's processor assistance. An End User remains free to contact Posto directly and exercise applicable statutory rights.

8. Review, suspension, appeal, and termination

Posto may use integrity checks, traffic analysis, and manual review to verify property ownership, integration, content, disclosures, and traffic quality. To investigate credible risk, Posto may pause a property or placement, delay a payment, hold affected earnings, rotate credentials, or suspend access as reasonably necessary.

Where practicable, Posto shall identify the relevant policy category and permit Developer to submit ownership records, implementation evidence, or a traffic explanation through support. Security-sensitive information and third-party data may be withheld. Confirmed invalid activity remains ineligible after restoration. On termination, Developer shall remove or disable affected Posto SDKs and credentials as directed; valid accrued earnings and permitted adjustments remain governed by the Agreement.

9. Developer indemnity

Subject to Sections 13 and 14 of the Terms of Service, Developer shall defend and indemnify Posto and participating Advertisers against third-party claims and resulting covered losses to the extent arising from Developer's property, placements, data collection, disclosures, invalid traffic, unauthorized modifications to advertisements, or breach of these Developer Terms. The defense procedure, exclusions, aggregate liability limit, and prohibition on duplicate recovery in the Terms of Service apply. This provision does not impose liability for an indemnified party's own breach or unlawful conduct beyond what the Agreement and applicable law permit.

© PostoX, Inclegal@postoconnect.com