Privacy Policy
How Postlyo handles personal data, and the rights you have over it.
1. Who we are
This Privacy Policy is issued by Postlyo (“we”, “us”, “our”), and covers the Postlyo website, dashboard and publishing service (the Service).
| Purpose | Contact |
|---|---|
| Privacy enquiries and rights requests | privacy@postlyo.com |
| General support | support@postlyo.com |
| Legal notices | legal@postlyo.com |
| Registered address | Available on request — email legal@postlyo.com and we will provide our registered postal address. |
| Grievance Officer (India) | To be completed by the website owner. |
| EU / UK representative | To be assessed — required under GDPR Art. 27 in some cases. |
2. The two roles we play — please read this
Postlyo lets our customers build and run their own websites. Personal data therefore flows through the Service in two very different ways, and your rights depend on which one applies to you.
2.1 When we are the controller
If you sign up for an account, visit our marketing website, or contact our support or sales teams, we decide why and how your personal data is used. This Policy governs that relationship, and you should send your requests to us.
2.2 When we are only the processor
If you are a visitor, reader or commenter on a website that someone else built using Postlyo, then that site’s operator decides why and how your data is used. They are the controller; we act only on their instructions.
- The site operator’s own privacy policy governs your data — not this one.
- Requests to access, correct or delete your data should go to the site operator, whose contact details appear on their site.
- If you contact us instead and we can identify the site, we will forward your request to the operator and tell you we have done so. We generally cannot action it ourselves, because the data is not ours to decide about.
We do not use content or audience data from customer sites for our own marketing, and we do not sell it.
3. Personal data we collect
3.1 Data you give us (we are controller)
| Category | Data | Why | Lawful basis |
|---|---|---|---|
| Account identity | Email address, username, display name, password (stored only as a hash — never in readable form) | Create and secure your account, authenticate you, contact you about the Service | Contract |
| Profile | Biography, profile picture, social media links | Author attribution on content you publish, where you choose to provide it | Contract / consent |
| Organisation | Site name, subdomain, any custom domain you connect, team invitations | Provision and operate your site | Contract |
| Billing | Billing name, plan, transaction and invoice history, and — where you save a card — its brand, last four digits, expiry, and issuing bank | Take payment, prevent fraud, meet tax obligations | Contract / legal obligation |
| Support | Ticket contents, contact-form messages, correspondence | Answer you and improve the Service | Legitimate interests / contract |
| Content | Posts, drafts, revision history, categories, media, site settings | Store, render and publish what you create | Contract |
| Imports | Connection details you supply to import from an existing site — stored encrypted and used only for the import you requested | Perform the import you asked for | Contract |
We never see your card number
Full card numbers, CVV and PIN are entered directly into our payment provider’s own secure interface and never reach our systems. All we hold is a provider-issued token and the non-sensitive details above, so you can recognise a saved card.
3.2 Data collected automatically (we are controller)
- Technical data — IP address, browser type and version, device and operating system, language, timezone, referring URL.
- Usage data — pages viewed in the dashboard, features used, actions taken, timestamps, and measurements used to apply your plan’s limits.
- Security and reliability data — authentication events, request logs, rate-limiting records and error diagnostics, used to detect abuse and keep the Service running.
3.3 Data we process for our customers (we are processor)
When someone interacts with a customer’s site, we may process, on that customer’s instructions: comment content and the account that posted it; contact-form submissions (name, email, subject, message); reader accounts registered on that site; and technical data associated with page requests. See section 2.2.
3.4 What we do not collect
We do not intentionally collect special category data — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — and we ask you not to submit it. We do not collect government identifiers, precise location, or financial account data beyond what section 3.1 describes.
4. How we use personal data
- Create, authenticate and secure your account.
- Provide and maintain the Service, including storing and publishing your content.
- Take payment, manage subscriptions and renewals, issue invoices and process refunds.
- Apply your plan's usage limits and notify you as you approach them.
- Provide support and answer your enquiries.
- Send service messages — security alerts, billing notices, changes to terms, outage notifications. These are not marketing, and you cannot opt out while you hold an account.
- Send marketing messages, where you have consented or the law otherwise permits it. You can opt out at any time.
- Detect, investigate and prevent fraud, abuse and spam.
- Monitor availability, diagnose faults and improve the Service.
- Comply with legal, tax and regulatory obligations, and defend legal claims.
What we do not do
- We do not sell personal data.
- We do not share personal data for cross-context behavioural advertising.
- We do not use your content to train machine-learning models, and we do not send it to any AI provider. See our AI Usage & Disclosure Policy.
5. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Some routine operations are automated — applying plan usage limits, restricting a site that exceeds its allowance, retrying a failed payment, and filtering spam. These follow fixed, published rules rather than profiling. If an automated restriction affects your account, you may email support@postlyo.com and ask a person to review it.
6. Who we share personal data with
6.1 Service providers
We use a small number of vendors to run the Service — for payments, transactional email, hosting and content delivery, storage, databases and internal operational alerting. Each is bound by contract to process data only on our instructions.
The complete, current list is published at Third-Party Services & Sub-processors. Please treat that page as part of this Policy.
6.2 Integrations you choose to connect
You may connect optional third-party services to your site — web analytics, advertising, or search-console reporting. These are off by default. Enabling one instructs us to make that connection, and the third party’s own privacy policy then governs what they do with the data. You are responsible for disclosing these to your visitors and, where the law requires it, obtaining their consent first — see our Cookie Policy.
6.3 Legal and protective disclosures
We may disclose personal data where we believe in good faith it is necessary to comply with a law or enforceable governmental request; enforce our terms; detect or address fraud or security issues; or protect against harm to the rights, property or safety of Postlyo, our users, or the public.
Where we are legally permitted to do so, we will notify you before disclosing your data in response to a legal demand, so you have an opportunity to challenge it.
6.4 Content you publish is public
Content you publish is public by design. Author names, biographies and profile pictures are displayed on your site, and comments are visible to anyone who can see the post. Do not put anything in these fields that you do not want the world to see.
6.5 Business transfers
If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction. We will give you notice before your data becomes subject to a materially different privacy policy, and you will be able to close your account.
7. International transfers
The Service uses providers located in several countries — see Sub-processors for the current list and locations. Your personal data may therefore be transferred to, stored in, and processed in countries other than your own, which may not provide the same level of data protection.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), an adequacy decision, or another lawful mechanism. You may request a copy of the relevant safeguard from privacy@postlyo.com.
8. How long we keep personal data
In summary: account and content data for as long as your account is open plus a short window afterwards; billing records for the period tax law requires; security logs for a short operational window.
The full schedule, by category, is in our Data Retention Policy.
9. Security
We apply technical and organisational measures appropriate to the risk — encryption in transit, hashing of passwords with an industry-standard adaptive algorithm, encryption of stored third-party credentials, tenant isolation, access controls, rate limiting and monitoring.
No system is perfectly secure and we cannot guarantee absolute security. Details, and how to report a vulnerability, are in our Security Policy.
10. Your rights
| Right | What it means |
|---|---|
| Access | Confirmation of whether we process your data, and a copy of it |
| Rectification | Correction of inaccurate data and completion of incomplete data |
| Erasure | Deletion of your data, where no overriding legal ground requires us to keep it |
| Restriction | Limiting how we process your data in certain circumstances |
| Portability | Receiving your data in a structured, machine-readable format |
| Objection | Objecting to processing based on legitimate interests, and to direct marketing at any time |
| Withdraw consent | Withdrawing consent at any time, without affecting prior processing |
| Non-discrimination | Not being treated worse for exercising your privacy rights |
| Complain | Lodging a complaint with your data protection authority |
10.1 How to exercise them
Email privacy@postlyo.com with the subject line “Privacy Request”, telling us which right you wish to exercise. You may also use the controls in your account settings where available.
- We respond within 30 days, or the shorter period your local law requires. If a request is complex we may extend once, and will tell you why within the initial period.
- We verify your identity in proportion to the sensitivity of the request, and will not ask for more information than necessary.
- Exercising these rights is free. We may charge or decline only where a request is manifestly unfounded or excessive — and we will explain why.
- You may use an authorised agent where your local law provides for it; we will ask for proof of authorisation.
10.2 If your data is on a customer's site
See section 2.2 — send your request to the site’s operator. If you cannot identify them, contact us and we will help route it.
10.3 Supervisory authorities
- EEA: your national data protection authority (list at edpb.europa.eu)
- UK: the Information Commissioner’s Office (ico.org.uk)
- India: the Data Protection Board of India, once constituted under the DPDP Act, 2023
- California: the California Privacy Protection Agency, or the Attorney General
We would appreciate the chance to resolve your concern first, but you are not required to come to us before going to a regulator.
11. Cookies
The Service uses strictly necessary cookies to keep you signed in and protect your session. Customer sites may load additional analytics or advertising technologies, but only where the site operator has switched them on. Full details are in our Cookie Policy.
12. Children's privacy
The Service is not directed to children and we do not knowingly collect personal data from them.
- You must be at least 16 — or the age of digital consent in your country, if higher — to create an account. In the United States the threshold for our purposes is 13, consistent with COPPA.
- If we learn we have collected data from a child below the applicable age, we will delete it promptly. If you believe this has happened, contact privacy@postlyo.com.
If your site is aimed at children
You carry additional obligations under COPPA, the GDPR provisions on children’s data, and India’s DPDP Act — which requires verifiable parental consent and prohibits behavioural advertising to children outright. You must not enable behavioural advertising on such a site. See our Acceptable Use Policy.
13. Region-specific disclosures
13.1 EEA, UK and Switzerland
Our lawful bases are set out in section 3.1 and summarised here:
- Contract — providing the Service, managing your account, taking payment.
- Legal obligation — tax, accounting, and responding to lawful requests.
- Legitimate interests — securing the Service, preventing fraud, improving the product, and limited marketing to existing customers. You may object at any time.
- Consent — optional cookies, optional marketing, and any integration you enable. You may withdraw it at any time.
Providing account and billing data is necessary to enter into a contract with us; without it we cannot provide the Service.
13.2 California (CCPA / CPRA)
In the twelve months before the date of this Policy we collected the categories described in section 3 — identifiers, commercial information, internet activity, and any profile details you supply. We collect them from you and from your use of the Service, for the purposes in section 4, and disclose them to the service providers in section 6.1.
We have not sold personal information, and have not shared it for cross-context behavioural advertising. We do not knowingly sell or share the personal information of consumers under 16.
You have the rights to know, delete, correct, and to opt out of sale or sharing (which does not arise for us). Exercise them per section 10.1. We will not discriminate against you for doing so, and we honour Global Privacy Control signals where transmitted.
13.3 India (DPDP Act, 2023)
- We act as a Data Fiduciary for our own customers, and as a Data Processor for data we handle on a customer's behalf.
- You may access, correct, complete, update and erase your personal data, and nominate another person to exercise your rights in the event of death or incapacity.
- Grievance Officer: To be completed by the website owner — name, designation, email and address must be published under the Act.
- If you are not satisfied with our response you may approach the Data Protection Board of India.
14. Changes to this Policy
We may update this Policy. When we do, we will change the “Last updated” date at the top.
If a change materially affects your rights or how we use your data, we will give you at least 30 days’ notice by email or a prominent notice in the Service before it takes effect. Where a change requires your consent, we will ask for it rather than assume it. We keep prior versions and will provide one on request.
15. Contact us
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | privacy@postlyo.com |
| Legal notices | legal@postlyo.com |
| Support | support@postlyo.com |
| Postal address | Available on request — email legal@postlyo.com and we will provide our registered postal address. |
This document is provided in English. If we publish a translation and there is a conflict, the English version governs unless local law requires otherwise.