Privacy Policy
Last updated: July 2, 2026
This Privacy Policy for POSTING2 LLC ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"). Use of the Services is also governed by our Terms of Use and Community Guidelines. The Services include:
- Download and use our mobile application (posting2), or any other application of ours that links to this Privacy Policy
- Use posting2 — a casual, ad-free photo sharing app
- Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@posting2.app.
Summary of key points
This summary provides key points from our Privacy Policy, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? We do not ask you for, and we do not intentionally collect, "special category" or "sensitive" personal information such as your racial or ethnic origin, political opinions, religious beliefs, health, sexual orientation, or biometric identifiers. However, because you can upload photographs, the images you post — and the automated safety scan we run on them before they appear — may incidentally involve such information (for example, a photo may reveal apparent ethnicity or religious dress). We process this only to keep the Services safe and lawful, and we explain the legal basis for it below. Learn more about how we handle photos and content moderation.
Do we transfer your information internationally? Yes. We are a United States company and all of our servers and service providers are located in the United States. If you use the Services from the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal information is transferred to and processed in the United States — a country whose data-protection laws may differ from your own. We rely on recognized safeguards (the EU–U.S. Data Privacy Framework where a provider is certified, and Standard Contractual Clauses otherwise). Learn more about international transfers.
Do we collect any information from third parties? We do not collect any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which types of parties do we share personal information? We may share information in specific situations and with specific categories of third parties. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We have adequate organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way to exercise your rights is by visiting posting2.app/privacy-requests, or by contacting us. If you are in the EEA, the UK, or Switzerland, you may also contact our EU representative — see How can you contact us. We will consider and act upon any request in accordance with applicable data protection laws.
Want to learn more about what we do with any information we collect? Review the Privacy Policy in full.
1. What information do we collect?
Personal information you disclose to us
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
- email address
- password (stored as a salted hash; we do not see your plaintext password)
- username
- date of birth
- phone number (optional, used for friend-finding via in-contacts matching)
- profile picture (optional)
- bio (optional)
- posts, photos, captions, comments, and other content you submit through the Services
- friendships, friend requests, blocks, and other relationships you create within the Services
- reports you submit about other users or content
- support and feedback messages you send us
- payment and purchase information when you choose to support posting2 — for web donations, transactions you initiate through Stripe; for in-app purchases and subscriptions, the purchase status, transaction identifiers, and subscription/renewal status we receive from Apple, Google, and our subscription-management provider RevenueCat. In all cases we do not see or store your payment card details.
Sensitive Information. We do not ask you to provide, and we do not intentionally collect, special category (sensitive) personal information. Because the Services let you upload photographs, the images you post may incidentally contain or reveal such information, and we run an automated safety scan on uploaded photos. We describe this — and the legal basis we rely on — in "How we handle photos and content moderation" below.
Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
- Mobile Device Access. We may request access or permission to certain features of your mobile device, including your camera (to take and upload photos), photo library (to upload existing photos), and contacts (to help you find friends who already use posting2). If you wish to change our access or permissions, you may do so in your device's settings.
- Contact-based friend matching. If you grant contacts access, we read your device's contacts locally on your device and send only normalized phone numbers (last 10 digits, with non-digits removed) to our server to look up matches with existing posting2 accounts. Contact names, email addresses, and any other contact metadata never leave your device. We do not store the phone numbers we receive for matching; they are used only to compute the lookup result.
- Mobile Device Data. We automatically collect device information (such as your mobile device ID, model, and manufacturer), operating system, version information and system configuration information, device and application identification numbers, browser type and version, hardware model Internet service provider and/or mobile carrier, and Internet Protocol (IP) address (or proxy server). If you are using our application(s), we may also collect information about the phone network associated with your mobile device, your mobile device's operating system or platform, the type of mobile device you use, your mobile device's unique device ID, and information about the features of our application(s) you accessed.
- Push Notifications. We may request to send you push notifications regarding your account or certain features of the application(s). If you wish to opt out from receiving these types of communications, you may turn them off in your device's settings.
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
The information we collect includes:
- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, and settings and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called "crash dumps"), and hardware settings).
- Device Data. We collect device data such as information about your computer, phone, tablet, or other device you use to access the Services. Depending on the device used, this device data may include information such as your IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information.
- Approximate Location. We collect approximate (city-level) location associated with your account for the purpose of an active-user heatmap that helps us understand where the Services are being used. We do not request or use precise GPS location, and we do not use your location to track your real-time movements. Separately, our service providers (e.g., Supabase, Sentry, our hosting and email providers) log IP addresses for security, debugging, and abuse-prevention purposes; an IP address can typically be associated with approximate (city-level) location, but we do not use IP addresses as a precise locator.
2. How do we process your information?
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
- To respond to user inquiries and offer support. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
- To send administrative information to you. We may process your information to send you details about our products and services, changes to our terms and policies, and other similar information.
- To enable interactions between users. We may process your information if you choose to use features that let you interact with other users' content or profiles, such as commenting on or liking a post, or sending and accepting friend requests. posting2 does not offer private messaging between users.
- To request feedback. We may process your information when necessary to request feedback and to contact you about your use of our Services.
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.
- To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual's vital interest, such as to prevent harm.
- To moderate user-generated content and enforce community guidelines. We review content posted on the Services and take action on content or accounts that violate our Terms of Use, our Community Guidelines, or applicable law, including illegal content, harassment, and content that is harmful to other users. Photos you upload are also sent to a third-party automated moderation provider (Sightengine — see When and with whom do we share) to scan for nudity, violence, and other content that violates our policies before they appear in the Services.
- To improve and develop our Services. We analyze how users interact with the Services, review feedback and support requests, and study aggregated usage patterns to identify bugs, prioritize improvements, and develop new features.
- To enforce our legal terms and protect our legal rights. We use personal information to investigate suspected violations of our Terms of Use, enforce our agreements, respond to legal claims or requests from authorities, and establish, exercise, or defend legal claims.
3. What legal bases do we rely on to process your information?
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
- Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
- Analyze how our Services are used so we can improve them to engage and retain users
- Diagnose problems and/or prevent fraudulent activities
- Understand how our users use our products and services so we can improve user experience
- Maintain a safe platform for our users, prevent harm, respond to reports of abuse, and comply with our obligations as a hosting provider under applicable law
- Ensure our Services function reliably, meet user needs, and remain competitive
- Protect our business, our users, and our legal rights, and to comply with legal processes
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
- For identifying injured, ill, or deceased persons and communicating with next of kin
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
- If the collection is solely for journalistic, artistic, or literary purposes
- If the information is publicly available and is specified by the regulations
- We may disclose de-identified information for approved research or statistics projects, subject to ethics oversight and confidentiality commitments
4. When and with whom do we share your personal information?
The third parties we may share personal information with — and the purpose of each — are as follows:
- Supabase (database, authentication, file storage, and backend hosting). Our primary backend provider. Stores account data, posts, comments, friendships, profile pictures, and related records.
- Cloudflare (post-image storage and content delivery). The photos you attach to posts are stored in and served from Cloudflare's R2 object storage and global delivery network. Cloudflare also provides network-level security and content delivery for our Services. See Cloudflare's privacy policy.
- Stripe (web donation payment processing). When you make a voluntary donation through our website, Stripe handles the payment transaction. We do not see, collect, or store your payment card details. See Stripe's privacy policy.
- Apple In-App Purchase / Google Play Billing (in-app payment processing). When you make a purchase or start a subscription inside the iOS or Android app, the platform (Apple or Google) processes the payment as merchant of record and provides your receipt. We do not see, collect, or store your payment card details; we receive only your purchase and subscription status.
- RevenueCat (subscription and purchase management). We use RevenueCat to validate in-app purchase receipts and track subscription/entitlement status. RevenueCat receives an app-specific user identifier, purchase events, and limited device and transaction metadata. See RevenueCat's privacy policy.
- Sentry (crash and error reporting). When the app encounters an error, a stack trace and limited device/runtime metadata may be sent to Sentry to help us diagnose and fix bugs. May incidentally include your IP address. See Sentry's privacy policy.
- Sightengine (automated image moderation). Photos you upload are transmitted to Sightengine, which scans them for nudity, violence, and other policy-violating content before they appear in the Services. Sightengine receives the photo for the purpose of returning a classification result; we do not authorize Sightengine to use your photos to train models or for any purpose other than performing the moderation analysis we request. See Sightengine's privacy policy.
- Expo / Apple Push Notification service / Firebase Cloud Messaging (push notifications). If you enable push notifications, we send a push token to Expo and the platform-native push service so the app can deliver notifications to your device.
- Apple App Store / Google Play / TestFlight (app distribution). The platforms you download posting2 through have their own privacy practices; we receive limited install/usage analytics from them.
- Resend (transactional email delivery). We use Resend to send account-related emails such as confirmation links, password-reset codes, and administrative notices — including emails sent on our behalf through our authentication provider. Resend processes recipient email addresses and email delivery metadata, and may incidentally log IP addresses associated with delivery. See Resend's privacy policy.
We do not sell your personal information, and we do not share your personal information with third parties for advertising, analytics-for-marketing, or behavioral profiling purposes.
We also may need to share your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Other Users. When you share personal information (for example, by posting comments, contributions, or other content to the Services) or otherwise interact with public areas of the Services, such personal information may be viewed by all users and may be publicly made available outside the Services in perpetuity. Similarly, other users will be able to view descriptions of your activity (such as likes, comments, and friend connections) and view your profile. posting2 does not offer private messaging between users.
5. Is your information transferred internationally?
We are a United States company, and all of our servers and the third-party service providers we rely on are located in the United States. This means that if you use the Services from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, your personal information — including the content you post — is transferred to, stored in, and processed in the United States. This is true for every EEA/UK/Swiss user, not only in special situations. The service providers involved are listed in "When and with whom do we share your personal information?" above.
The United States may not provide a level of data protection equivalent to that of your home country. To protect your information when it is transferred to the United States, we rely on the safeguards required by Chapter V of the GDPR (and the equivalent UK and Swiss rules), as follows:
- EU–U.S. Data Privacy Framework (DPF) and its UK Extension and Swiss–U.S. framework. Where a service provider is certified under the relevant Data Privacy Framework, we rely on that certification as an adequacy mechanism for transfers to that provider.
- Standard Contractual Clauses (SCCs). Where a provider is not DPF-certified, we put in place the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum / Swiss equivalent), supported by a transfer impact assessment and supplementary measures where appropriate.
You can ask us which mechanism applies to a particular provider, and request a copy of the relevant safeguards, by contacting us using the details in "How can you contact us about this notice?" Our backend provider's data processing agreement and Standard Contractual Clauses are available at https://supabase.com/legal/dpa; we maintain comparable agreements with our other providers and can provide further details on request.
6. How long do we keep your information?
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
In practice:
- When you delete your account, we immediately remove your profile, your posts and their photos, your likes, comments, and friendships, your push-notification tokens, your authentication record (email, phone, password hash), and any in-app reports you submitted or received.
- Encrypted database backups that may contain your information roll off automatically within 30 days of deletion.
- Aggregate analytics with no personal identifiers (for example, active-user counts by country or total posts per day) are retained indefinitely.
- Where an account is removed for violations of our Terms of Use, we retain an opaque banned-device identifier to help prevent ban evasion. This applies only to a small minority of deletions and does not include your profile or content.
You can request deletion at any time — see our Privacy requests page.
How we handle photos and content moderation
What we do. When you upload a photo, it is sent to our automated moderation provider, Sightengine, which classifies it for nudity, sexual content, violence, and other content that violates our Terms of Use and Community Guidelines or applicable law, before the photo becomes visible to other users. Sightengine returns a classification only. We do not authorize Sightengine to use your photos to train its models or for any purpose other than performing the moderation analysis we request, and Sightengine does not perform facial recognition or otherwise attempt to identify you from your photos.
Special category (sensitive) information. A photograph can incidentally reveal information that data-protection law treats as "special category" — for example, apparent racial or ethnic origin, religious belief, or health. We do not collect such information deliberately and we do not use it to profile you. Where our safety scanning involves special-category information, we rely on the condition in Article 9(2)(g) of the GDPR (processing necessary for reasons of substantial public interest) — namely keeping our users safe and protecting against the sexual exploitation of others and other serious harms — proportionate to the aim pursued and with safeguards for your rights.
Legal basis. For the safety scan and for our moderation and enforcement activity generally, we rely on our legitimate interests (Article 6(1)(f)) in operating a safe platform and protecting our users and third parties from harm, and on our legal obligations (Article 6(1)(c)) as a hosting service under applicable law, including the EU Digital Services Act. We have weighed these interests against your interests and rights in a legitimate-interests assessment, which we can summarize on request.
Automated decision-making. The initial safety scan of your photos is automated. Automated scanning can result in a photo being blocked or held for review before it is published. Where a removal, restriction, or account action would produce legal or similarly significant effects, a member of our team reviews the case before or promptly after the action, so the decision is not based solely on automated processing. If you believe an automated outcome was wrong, you can ask us to review it — see the statement-of-reasons and objection process described in our Terms of Use ("Content Moderation, Enforcement & Appeals"), and you may also exercise your right under Article 22 GDPR not to be subject to a solely automated decision by contacting us.
7. How do we keep your information safe?
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
8. Do we collect information from minors?
We do not knowingly collect, solicit data from, or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or the equivalent age as specified by law in your jurisdiction, or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age or the equivalent age as specified by law in your jurisdiction has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18 or the equivalent age as specified by law in your jurisdiction, please contact us at info@posting2.app.
9. What are your privacy rights?
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22 GDPR). We use automated scanning to detect unsafe and illegal photos — see "How we handle photos and content moderation" — and where an action would have a significant effect on you, a human reviews it and you can request human review of an automated outcome. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us by using the contact details provided in the section "How can you contact us about this notice?" below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent
If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section "How can you contact us about this notice?" below.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
- Log in to your account settings and update your user account.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms, and/or comply with applicable legal requirements.
If you have questions or comments about your privacy rights, you may email us at info@posting2.app.
10. Controls for do-not-track features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.
California law requires us to let you know how we respond to web browser DNT signals. Because there currently is not an industry or legal standard for recognizing or honoring DNT signals, we do not respond to them at this time.
11. Do United States residents have specific privacy rights?
Categories of personal information we collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you. For a comprehensive inventory of all personal information we process, please refer to the section "What information do we collect?"
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name | YES |
| B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information | YES |
| C. Protected classification characteristics under state or federal law | Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | YES |
| D. Commercial information | Transaction information, purchase history, financial details, and payment information | NO |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or other similar network activity | Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements | NO |
| G. Geolocation data | Device location | YES |
| H. Audio, electronic, sensory, or similar information | Images and audio, video or call recordings created in connection with our business activities | YES |
| I. Professional or employment-related information | Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us | NO |
| J. Education information | Student records and directory information | NO |
| K. Inferences drawn from collected personal information | Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual's preferences and characteristics | NO |
| L. Sensitive personal information | — | NO |
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
- Receiving help through our customer support channels;
- Participation in customer surveys or contests; and
- Facilitation in the delivery of our Services and to respond to your inquiries.
We will use and retain the collected personal information as needed to provide the Services or for:
- Category A — As long as the user has an account with us
- Category B — As long as the user has an account with us
- Category C — As long as the user has an account with us
- Category G — As long as the user has an account with us
- Category H — As long as the user has an account with us
Sources of personal information
Learn more about the sources of personal information we collect in "What information do we collect?"
How we use and share personal information
Learn more about how we use your personal information in the section "How do we process your information?"
Will your information be shared with anyone else?
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Learn more about how we disclose personal information in the section "When and with whom do we share your personal information?"
We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" of your personal information.
We have not sold or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. We have disclosed the following categories of personal information to third parties for a business or commercial purpose in the preceding twelve (12) months:
- Category A. Identifiers
- Category B. Personal information as defined in the California Customer Records law
- Category C. Characteristics of protected classifications under state or federal law
- Category G. Geolocation data
- Category H. Audio, electronic, visual, and similar information
The categories of third parties to whom we disclosed personal information for a business or commercial purpose can be found under "When and with whom do we share your personal information?"
Your rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:
- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the processing of your personal data if it is used for targeted advertising (or sharing as defined under California's privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
Depending upon the state where you live, you may also have the following rights:
- Right to access the categories of personal data being processed (as permitted by applicable law, including the privacy law in Minnesota)
- Right to obtain a list of the categories of third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in California, Delaware, and Maryland)
- Right to obtain a list of specific third parties to which we have disclosed personal data (as permitted by applicable law, including the privacy law in Minnesota and Oregon)
- Right to obtain a list of third parties to which we have sold personal data (as permitted by applicable law, including the privacy law in Connecticut)
- Right to review, understand, question, and depending on where you live, correct how personal data has been profiled (as permitted by applicable law, including the privacy law in Connecticut and Minnesota)
- Right to limit use and disclosure of sensitive personal data (as permitted by applicable law, including the privacy law in California)
- Right to opt out of the collection of sensitive data and personal data collected through the operation of a voice or facial recognition feature (as permitted by applicable law, including the privacy law in Florida)
How to exercise your rights
To exercise these rights, you can contact us by visiting posting2.app/privacy-requests, by emailing us at info@posting2.app, or by referring to the contact details at the bottom of this document.
Under certain US state data protection laws, you can designate an authorized agent to make a request on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with applicable laws.
Request verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.
If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request and the agent will need to provide a written and signed permission from you to submit such request on your behalf.
Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at info@posting2.app. We will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may submit a complaint to your state attorney general.
California "Shine The Light" law
California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us by using the contact details provided in the section "How can you contact us about this notice?"
12. Do other regions have specific privacy rights?
Australia and New Zealand
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020 (Privacy Act).
This Privacy Policy satisfies the notice requirements defined in both Privacy Acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information.
If you do not wish to provide the personal information necessary to fulfill their applicable purpose, it may affect our ability to provide our services, in particular:
- offer you the products or services that you want
- respond to or help with your requests
- manage your account with us
- confirm your identity and protect your account
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "How can you review, update, or delete the data we collect from you?"
If you believe we are unlawfully processing your personal information, you have the right to submit a complaint about a breach of the Australian Privacy Principles to the Office of the Australian Information Commissioner and a breach of New Zealand's Privacy Principles to the Office of New Zealand Privacy Commissioner.
Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "How can you review, update, or delete the data we collect from you?"
If you are unsatisfied with the manner in which we address any complaint with regard to our processing of personal information, you can contact the office of the regulator, the details of which are:
The Information Regulator (South Africa)
General enquiries: enquiries@inforegulator.org.za
Complaints (complete POPIA/PAIA form 5):
13. Do we make updates to this notice?
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.
14. How can you contact us about this notice?
If you have questions or comments about this notice, you may email us at info@posting2.app or contact us by post at:
POSTING2 LLC
2501 Chatham Rd #5907
Springfield, IL 62704
United States
Our EU and UK representative for data protection (GDPR Article 27)
Because we offer the Services to people in the European Economic Area and the United Kingdom, we have appointed a representative under Article 27 of the GDPR and the UK GDPR. If you are in the EEA or UK, you may contact our representative on any matter relating to the processing of your personal information:
Prighter Group
EU and UK GDPR Art. 27 Representative
Data-subject portal: app.prighter.com/portal/17102197270
Email: support@prighter.com
Our EU legal representative under the Digital Services Act (Article 13)
We have appointed a legal representative in the European Union under Article 13 of the Digital Services Act. Our legal representative can be addressed by the authorities of the Member States, the European Commission, and the European Board for Digital Services on all matters relating to the Digital Services Act:
Prighter Group
DSA Art. 13 Legal Representative (registration in progress)
Contact: support@prighter.com
Digital Services Act contact points
Single point of contact for authorities (DSA Article 11). Member State authorities, the European Commission, and the European Board for Digital Services may contact us electronically for matters relating to the Digital Services Act at info@posting2.app (subject line "DSA Authority Contact"), or via our EU legal representative named above.
Contact point for users (DSA Article 12). Recipients of the Services may contact us directly and rapidly, by electronic means, at info@posting2.app.
Languages. Both contact points currently accept communications in English. French will be added ahead of the EU launch.
15. How can you review, update, or delete the data we collect from you?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please visit: posting2.app/privacy-requests.
Getting a copy of your data (data portability). If you are in the EEA, the UK, or Switzerland (or a US state that provides this right), you can request a structured, commonly used, machine-readable copy of the personal information you provided to us — including your profile, posts, photos, comments, likes, and friendships. Submit a request at posting2.app/privacy-requests or email info@posting2.app, and we will provide your data within one month.