posto

Privacy & Terms

Privacy, service terms, role requirements, and technical data-handling terms for Posto are collected here in one place.

PostoX, Inc · Archived document · Version archive

Published September 7, 2026. Customer acceptance is affirmative and prospective; this release does not rewrite earlier acceptance records.

On this page Data Processing Addendum

Data Processing Addendum

Contractual requirements governing personal information that Posto processes on a Customer's behalf. Processing roles and mandatory rights are determined by the actual activities and applicable law.

Effective 2026-09-07 · Version 2026-09-07 · Permanent version

1. Parties, incorporation, and precedence

This Data Processing Addendum ('DPA') forms part of the Agreement between PostoX, Inc ('Posto') and the business entity or sole proprietor accepting the Terms of Service or an applicable Order ('Customer'). It applies to Customer Personal Data processed by Posto on Customer's behalf in providing the contracted Service.

This DPA controls an express conflict with other provisions of the Agreement concerning the regulated processing obligations it addresses. The Terms of Service continue to govern commercial matters, including their aggregate liability limit, indemnity procedure, governing law, and dispute resolution, except to the extent an expressly agreed provision or mandatory law requires otherwise. Nothing in the Agreement limits a data subject's nonwaivable rights, a regulator's powers, or mandatory terms of a separately completed transfer mechanism.

2. Definitions and activity-specific roles

Personal data or personal information means information regulated as such by applicable data-protection law. Processing, controller, processor, business, service provider, contractor, data subject, personal-data breach, and supervisory authority have the meanings assigned by the law applicable to the relevant activity. Customer Personal Data means personal information processed by Posto on Customer's behalf under the Agreement, including information described in Annex I when used in that capacity.

Customer acts as controller or business, or as a processor acting with its controller's authority, for Customer Personal Data it instructs Posto to process. Posto acts as processor, service provider, contractor, or subprocessor only to the extent its actual processing and the applicable legal requirements support that role. Customer shall have authority to appoint Posto when acting for another controller.

Posto may determine separate purposes for account administration, independently determined security and fraud prevention, billing, legal compliance, and its business records where permitted by law. The Privacy Policy describes those activities. Labeling an activity 'security,' 'improvement,' or 'measurement' does not by itself remove it from this DPA or permit use beyond a lawful service-provider or processor role.

3. Documented instructions and use restrictions

Customer instructs Posto to process Customer Personal Data to perform the contracted activities described in the Agreement, the applicable service notices, and Customer's lawful configurations and confirmed instructions. Instructions shall be specific enough to identify the permitted purpose and shall not authorize unrelated profiling, publication of confidential materials, or a restricted transfer without the required arrangement. Posto shall process Customer Personal Data only on those instructions, unless applicable law requires otherwise; Posto shall inform Customer of such a requirement before processing unless legally prohibited.

Where Posto acts as a service provider or contractor under the California Consumer Privacy Act, Posto shall not sell or share Customer Personal Data; retain, use, or disclose it for a purpose other than the specified business purposes permitted by the Agreement and applicable law; or retain, use, or disclose it outside the direct business relationship except as the law permits. Posto shall not combine it with information received from another person or collected through its own interaction with an individual except where applicable law expressly permits the combination for the specified service purposes. Posto certifies that it understands and shall comply with these restrictions.

Posto shall not use Customer Personal Data to create another Customer's advertising profile or train an unrelated model. Security, fraud prevention, service integrity, permitted service improvement, and aggregate or deidentified measurement remain subject to the applicable instructions, confidentiality duties, and legal restrictions. Information is deidentified only if the applicable legal standard and required safeguards are met; hashes and filtered text do not qualify automatically.

Posto shall notify Customer if it determines that it can no longer meet its applicable data-protection obligations. If Posto reasonably believes an instruction violates applicable law, Posto shall inform Customer unless prohibited and may suspend the affected processing while the parties resolve the issue. Customer may take reasonable and appropriate steps to verify permitted use and, on notice, stop and remediate unauthorized use, including through the assistance and audit process below.

4. Customer instructions, lawful basis, and minimization

Customer shall supply lawful instructions, accurate notices, a valid legal basis, and any specific consent required for collection and disclosure to Posto, including browser storage or access where applicable. Customer shall respect applicable choices and binding privacy signals and maintain authority for the information it submits. Contract acceptance does not replace an End User's legally required consent.

Customer shall minimize submissions, maintain the accuracy required for the processing, configure audience and retention choices lawfully, and refrain from submitting unnecessary or prohibited sensitive information. Customer shall promptly notify Posto of unlawful submissions or material changes affecting the processing and cooperate on correction, deletion, and rights requests. These duties do not excuse Posto's own statutory or contractual obligations.

5. Confidentiality and security obligations

Posto shall ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only as needed for authorized work. Posto shall maintain technical and organizational safeguards appropriate to the nature, scope, context, and risk of the processing, including the applicable measures described in Annex II.

Posto may update safeguards as technology and risk change while maintaining an appropriate level of protection. A technical control applies to the interface or environment for which it is designed; no statement in this DPA represents that filtering removes all sensitive information, that hashing anonymizes records, or that every integration uses an identical security mechanism.

6. Subprocessor authorization and changes

Customer grants general authorization for Posto to engage the current subprocessors whose identities and relevant processing details are made available to Customer for the applicable enabled Service, subject to this Section. The public provider-category summary is not an exhaustive named register or a substitute for information required by applicable law. Posto shall make the current details available through the account or privacy-contact process before relevant processing where required. Before a subprocessor processes Customer Personal Data, Posto shall impose written data-protection obligations appropriate to the activity and providing the protection required by applicable law. Posto remains responsible for the subprocessor's performance of those obligations to the extent required by the Agreement and law.

Posto shall maintain current subprocessor details and make updated information available before a new subprocessor begins the relevant processing. Where the Agreement or law requires individual advance notice, Posto shall send it to the affected account contact and state the proposed effective date. Customer may object before that date on reasonable data-protection grounds, identifying the concern and affected processing.

The parties shall work in good faith to address a reasonable objection through information, safeguards, an alternative provider, or a change to the affected feature where feasible. If no reasonable resolution is available, either party may terminate the affected processing or feature without requiring Customer to authorize an unlawful transfer; accrued payment duties and applicable refund rights remain governed by the Agreement. Independent payment providers and selected destinations are not subprocessors merely because they appear in the provider disclosure.

7. Individual requests and assistance

Taking account of the nature of processing, Posto shall provide reasonable technical and organizational assistance needed for Customer to fulfill applicable access, correction, deletion, portability, restriction, objection, opt-out, consent-withdrawal, and appeal obligations. Customer shall provide information reasonably needed to identify the relevant records without requiring unnecessary additional personal information.

If Posto receives a request relating to processing on Customer's behalf, Posto shall promptly inform or coordinate with Customer and assist the response, unless the law requires or permits Posto to respond directly. Posto may explain which business is responsible, but shall not require an individual to contact that business first as a condition of contacting Posto or exercising a statutory right. Verification, exceptions, and response periods shall follow the applicable law.

8. Personal-data breaches and incident cooperation

Posto shall notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed under this DPA. Posto shall not delay initial notice solely because an investigation is incomplete. Taking account of available information, the notice shall describe the nature and scope of the breach, affected categories and approximate quantities where known, likely consequences, protective measures taken or proposed, and a contact for further information; details may be supplied in phases without undue delay.

Posto shall take reasonable steps to contain, investigate, mitigate, and remediate the breach and provide information reasonably necessary for Customer's applicable notification duties. Notification is not an admission of fault. Each party remains responsible for notices concerning its own systems, role, and legal obligations and shall coordinate where appropriate without unlawfully delaying a required notice.

9. Assessments and regulatory consultation

Taking account of the nature of processing and information available to it, Posto shall provide information and reasonable assistance needed for Customer's applicable data-protection impact assessments, security assessments, and prior consultation with a competent authority concerning the contracted processing. Assistance shall be proportionate to the relevant risk and shall protect other Customers' information, privileged material, and sensitive security details through appropriate means rather than withholding information the law requires.

10. Return, deletion, and restricted retention

At termination of the relevant processing or on Customer's lawful request, Posto shall, at Customer's choice, return or delete Customer Personal Data through the applicable documented process, unless law requires retention. Posto shall provide available export mechanisms and, on reasonable request, confirm completion of the applicable deletion process. Deletion of one record type, shopper erasure, store disconnection, and account closure have different scopes and shall not be represented as interchangeable.

Posto may preserve information only where continued retention is permitted or required for an identified financial, acceptance-evidence, security, fraud, backup, dispute, or legal purpose. Such records shall be protected, access restricted, and use limited to that purpose. Pseudonymization is not a substitute for legally required deletion and does not make a retained record anonymous. Backup copies shall be protected from ordinary use and deleted through the applicable rotation or required deletion process.

The current retention rules are described in the Privacy Policy and applicable integration notice, including the 30-day account-closure grace period, the 30-day retention schedule for ad-request text, related delivery or diagnostic text copies, and raw measurement-event content, and longer necessary financial or legal retention. A required legal hold may suspend deletion for the affected records, but does not authorize unrelated use or unlimited retention.

11. Compliance evidence, audits, and remediation

Posto shall maintain information sufficient to demonstrate compliance with its obligations under this DPA and make appropriate current security documentation, relevant independent reports where available, or other compliance evidence available under confidentiality. Where legally required and reasonably necessary, Customer or a qualified independent auditor may assess the relevant processing on reasonable notice, during business hours, and with safeguards against disruption or access to another Customer's data.

Routine Customer audits are limited to one in a 12-month period where applicable law permits that limit. The limit does not restrict an additional assessment reasonably necessary following a material personal-data breach, credible evidence of material noncompliance, a regulator's request, or an applicable statutory requirement. The parties shall use existing evidence where it reasonably addresses the issue and agree on a proportionate scope and method.

Customer shall bear its audit costs unless material noncompliance is found or applicable law or a written agreement requires otherwise. Posto shall cooperate with a competent supervisory authority as required and take reasonable and appropriate steps to stop and remediate unauthorized processing. No audit condition waives a mandatory verification or oversight right.

12. United States scope and restricted transfers

The current offering is a United States business service. The parties shall identify any applicable international transfer restriction before introducing affected processing. Posto shall not carry out a restricted transfer without a lawful mechanism and the safeguards required for that transfer, including an appropriate onward-transfer arrangement where applicable.

If European Standard Contractual Clauses or a UK transfer addendum are required, the parties shall complete the applicable instrument, modules, party and transfer information, annexes, governing-law and forum selections, and any necessary assessment or supplementary measures before the restricted transfer begins. This DPA does not incorporate incomplete clauses or establish a blanket certification under a data-transfer framework. Mandatory terms of a completed transfer mechanism prevail over an inconsistent commercial governing-law, arbitration, liability, or other provision to the extent required.

13. Annex I — processing details

The following description covers information only to the extent processed on Customer's behalf. The enabled feature and actual instructions determine which categories apply.

  • Subject matter and purposes: contextual advertising delivery, campaign and catalog operations, creative assistance, attribution, measurement, reconciliation, Customer-requested support, and permitted security, fraud prevention, and service improvement within the contracted processing instructions.
  • Nature of processing: receipt, validation, filtering, hashing, organization, storage, retrieval, model-assisted analysis, matching, display of authorized advertising content, transmission to authorized providers, aggregation or legally compliant deidentification, correction, export, and deletion.
  • Data subjects: Customer's account representatives, participating applications' End Users, visitors and shoppers of advertised or connected properties, and individuals whose information is included in authorized support or business materials.
  • Data categories: bounded recent request text and derived context; optional permitted coarse demographics; application, placement, request, integrity-proof, impression, click, event, transaction, and conversion fields; optional hashed identifiers; technical metadata; account and business contact information; campaign, catalog, product, and image content; connected-store order, checkout, refund, and status information; and Customer questions or account context used in enabled support workflows. Filtered text, hashes, and inferred information may remain personal information.
  • Transient and provider inputs: supported store webhooks may deliver customer details or line items before selection of retained fields. Enabled third-party AI services may process permitted interaction text, product or campaign information, or Customer support questions and account context. Some submitted information may reach the relevant provider without identifier filtering and can remain personal information. The Privacy Policy and provider disclosure describe the applicable categories, purposes, and limitations.
  • Prohibited sensitive information: the current Service is not designed or approved for children's personal information, protected health information, health or crisis conversations, precise location, financial credentials, authentication secrets, government or biometric identifiers, or other prohibited sensitive categories. Any separately contemplated use requires express written service approval and an appropriate DPA amendment before it begins; a general account acceptance is insufficient.
  • Frequency and duration: processing occurs as Customer uses the enabled Service during the Agreement and the applicable documented return, deletion, and legally permitted retention periods. Long-term residual records remain limited to their identified purposes.

14. Annex II — technical and organizational safeguards

Posto shall maintain measures appropriate to the actual processing and risk, including the following as applicable to the relevant interface and environment:

  • Transport encryption for supported production communications and appropriate protection of production storage, backups, credentials, and connection secrets using the configured infrastructure and access controls.
  • Access restrictions, least privilege, confidentiality commitments, separation of production and simulation functions, controlled credentials and administrative access, and relevant operational logging.
  • Server HMAC authentication, supported Apple App Attest and Google Play Integrity verification, request hashing, signed event tokens, stable idempotency, and replay controls for the interfaces that use those mechanisms.
  • Strict request schemas, bounded context, pattern-based identifier filtering, input restrictions, configured eligibility controls, and automated cleanup for specified record classes. These controls do not guarantee universal sensitive-context detection or anonymization.
  • Risk monitoring, payment and event reconciliation, incident handling, appropriate vulnerability and dependency management, and backup and recovery procedures proportionate to service risk. Customer remains responsible for its own application, consent gate, domain configuration, and server secrets.

15. Annex III — providers and roles

The public provider disclosure summarizes cloud compute, database, storage, email, payment and payout, app-integrity, support, and third-party AI service providers. It states purposes and data categories and distinguishes subprocessors from independent providers and selected destinations where appropriate. Current identities, locations, and details needed for the applicable DPA are made available to affected Customers through the account or privacy-contact process in accordance with Section 6. A listed optional feature does not transmit information while disabled.

Provider processing locations, access, and onward transfers depend on the service configuration and applicable provider agreement; Posto shall supply information needed for a reasonable DPA or transfer assessment. A provider name or a general regional description does not establish that every service is United States-only, that no provider retains inputs, or that a provider has a contractual model-training restriction applicable to every account.

16. DPA contacts

Privacy, processor-assistance, subprocessor-objection, and DPA notices: privacy@postoconnect.com. Legal notices: legal@postoconnect.com. Security reports: security@postoconnect.com. Contracting entity: PostoX, Inc. Contact address: 131 Continental Drive Suite 305, Newark, DE 19702.

© PostoX, Inclegal@postoconnect.com