posto

Privacy & Terms

Privacy, service terms, role requirements, and technical data-handling terms for Posto are collected here in one place.

PostoX, Inc · Archived document · Version archive

Release of October 2, 2026: shopping cards and affiliate networks. The Privacy Policy and Subprocessors describe affiliate tracking links and the networks as independent recipients; the Developer Terms add Section 5 on shopping cards and affiliate programs (later sections renumbered). Substantive change: renewed acceptance is required. Historical documents and acceptance evidence are unchanged.

On this page Subprocessors

Subprocessors

A public summary of provider categories and selected recipients involved in Posto's enabled services. Current subprocessor identities and processing details required for Customer agreements are available through the account or privacy-contact process.

Effective 2026-10-02 · Version 2026-10-02 · Permanent version

Scope, provider roles, and change notices

This public disclosure summarizes provider categories and selected recipients; it is not an exhaustive named subprocessor register. A provider receives information only when the corresponding enabled feature or operational flow calls for it. A provider may act as a subprocessor for one function and independently for another, particularly payment compliance, banking, or a selected advertising destination. Actual activities, applicable law, and the provider agreement determine the role.

Posto shall update this disclosure before a new subprocessor begins relevant processing and provide individual advance notice where required by the Agreement or law. Affected Customers may send reasonable data-protection objections to legal@postoconnect.com before the stated effective date. The DPA governs authorization, objections, and appropriate contractual safeguards.

Processing and support locations depend on the provider service, configuration, and agreement. The regional descriptions below do not constitute a blanket United States-only commitment. Provider retention, abuse monitoring, training settings, and transfer safeguards also depend on the applicable service terms and account configuration; Posto does not represent that every provider offers zero retention or that a public statement establishes a restriction for every workflow.

Amazon Web Services, Inc. (AWS)

Functions: cloud compute and networking, database hosting, object storage, backups, keys and secrets, operational logs, and Amazon SES transactional email.

Information: account and business records, contextual request content, delivery and measurement events, security and financial records, stored reports and backups, recipient email addresses, and transactional message content. Contextual records can remain personal information after filtering.

Locations and role: the configured infrastructure and provider agreement govern the hosting region and any support, email-delivery, or security processing elsewhere. AWS ordinarily supplies infrastructure on Posto's behalf for these functions. An actual region commitment shall be established through the applicable service or transfer arrangement rather than inferred from this disclosure.

Stripe, Inc.

Functions: Advertiser checkout, payment confirmation, disputes, and payment-risk operations.

Information: account and business contact details, transaction identifiers and amounts, payment and dispute status, and card or bank-payment details submitted directly to Stripe Checkout. Posto does not store full card or bank-account numbers through this flow.

Locations and role: Stripe and its service providers may process information in the United States and other locations under the applicable Stripe terms and transfer safeguards. Stripe may act independently for certain payment, compliance, and fraud functions and is not characterized as Posto's processor for every activity.

Mercury and its banking and payment partners

Functions: recipient onboarding for eligible Developers, collection of ACH and tax-document details through the provider, supplier-payment requests and approval, and approved payments from Posto's business account.

Information: Developer legal or business name, work email, recipient and payment identifiers, amounts, status, and payment memos; banking details and tax documentation are submitted directly to the provider. Posto does not store full bank-account numbers or tax-form copies from this flow.

Locations and role: Mercury, its partner banks, and disclosed service providers use locations and safeguards governed by their applicable services. Banking and legally required compliance activities may be independent of Posto's instructions; the description of the payment flow does not make every participant a Posto subprocessor.

Third-party AI service providers

Functions: enabled advertising, product and campaign assistance, content generation, and Customer support services. The applicable feature determines the permitted purpose and information submitted.

Information: permitted interaction text; product, campaign, creative, and performance information; Customer questions; and relevant account context. Submitted information may remain personal information, and some inputs are not filtered for identifiers before reaching a provider. Customer shall not include prohibited sensitive information. The use of a provider does not authorize unrelated disclosure, profiling, or model training by Posto.

Provider details and terms: current identities, relevant processing locations, and the information needed for an applicable DPA or transfer assessment are made available to affected Customers through the account process or legal@postoconnect.com before relevant processing where required. The applicable provider agreement and actual service configuration govern retention, support access, onward transfers, and any restrictions on provider use. This public category summary does not establish zero retention, exclusive United States processing, or a blanket restriction applicable to every provider account.

Google LLC

Functions: Google Play Integrity verification for supported Android requests. Any separate AI service falls within the third-party AI provider category above.

Information: integrity tokens, request hashes, registered application identity, and verification verdicts needed for the integrity function.

Locations and terms: the applicable verification-service terms and infrastructure govern processing, support, and any transfer safeguards.

Apple Inc.

Functions: Apple App Attest proof and verification for supported iOS application and device-integrity checks.

Information: App Attest key identifiers, challenges, assertions, counters, and registered Team ID and Bundle ID, together with applicable request-verification information. Posto's ad-request interface does not require a Customer-supplied advertising identifier or hardware serial number.

Locations and role: the applicable Apple service terms and infrastructure govern verification and related processing, including any processing outside the United States. Technical proofs and installation-linked information may remain personal information even though an advertising identifier is not required.

Advertisers, destinations, and affiliate partners

The Advertiser and destination selected after an End User's intentional click are data recipients for that activity, rather than Posto subprocessors solely because they receive the click. Posto may send the selected destination a pseudonymous click identifier needed for redirect and attribution. The destination may collect subsequent browsing and transaction information under its own privacy notice and applicable obligations.

Affiliate networks that carry shopping-card links to retailers, such as Awin, CJ, FlexOffers, impact.com, or Rakuten Advertising, are independent recipients of the tap, the publishing app, placement, and content identifiers in their tracking links, and resulting commission information, once Posto participates in the network's program. They are not Posto subprocessors; each processes that information under its own terms and notice.

Affiliate integrations, including Trip.com, are production-disabled unless expressly enabled and disclosed for the applicable campaign. An enabled affiliate relationship requires the advertising and material-connection disclosures applicable to that experience. Posto does not disclose ad-request transcripts to Advertisers through ordinary campaign reporting.

Contact and due-diligence information

Legal notices and questions about enabled providers, processing locations, relevant safeguards, change notices, or data-protection objections may be sent to legal@postoconnect.com. Posto shall provide information required for an applicable processor or transfer assessment through the DPA process; a Customer shall arrange any required restricted-transfer terms before introducing the affected processing.

© PostoX, Inclegal@postoconnect.com