Privacy Policy
Last updated
Get Posting is a service operated by We Coast (ABN 11 722 302 546), an Australian sole trader business based in Western Australia (“Get Posting”, “we”, “us”, or “our”). This Privacy Policy explains how we handle personal information when you use getposting.com, the Get Posting application, our APIs, Model Context Protocol (“MCP”) access, and related services (the “Service”).
1. Contact us
We are established in Western Australia, Australia. Contact support@getposting.com for privacy questions, requests, or complaints.
2. Our role
We decide why and how Account, billing, support, security, and website-analytics information is handled.
When a customer connects a social account and uses Get Posting to process posts, media, analytics, comments, or direct messages, the customer generally decides the purpose of that processing. We process that information to provide the Service on the customer’s instructions. Customers are responsible for their own notices, permissions, lawful basis, and audience requests.
3. Information we collect
Depending on the features you use, we may collect:
- Account and team information: name, email address, password hash, profile details, workspace name, role, invitations, timezone, and authentication records.
- Billing information: customer, subscription, checkout, payment, invoice, currency, and payment-status information received from our payment provider. Stripe handles full card details; we do not store full card numbers.
- Connected-account information: platform and account identifiers, usernames, profile details, permissions, connection status, and related metadata. A specialist social-connection provider manages the platform credentials needed to maintain these connections on our behalf.
- Customer Content: captions, posts, threads, comments, direct messages, automation rules and templates, schedules, media, publishing settings, validation results, and publishing history.
- Social and audience information: account and post analytics, follower and engagement metrics, and, where enabled, identifiers and content belonging to commenters or message participants.
- API and MCP information: API keys or OAuth grants, approved workspace, tool or endpoint calls, timestamps, and request and response information needed to provide, secure, and debug those features. We receive the information an authorised client sends to our tools, not the rest of a conversation held by that client.
- Support and communications: messages, attachments, feedback, and other information you send us.
- Device and usage information: IP address, browser and device information, referral source, pages viewed, feature use, conversion events, cookies or similar identifiers, and security and error logs.
Do not submit full payment-card numbers, government identifiers, health records, information about children, or other sensitive information the Service is not designed to hold.
4. How we collect and use information
We collect information from you, your workspace members, authorised API or MCP clients, connected platforms, payment and service providers, and automatically when the Service is used.
We use it to:
- provide, maintain, secure, and support the Service;
- authenticate users and administer workspaces;
- connect accounts and publish, schedule, validate, and report on Content;
- provide analytics, inbox, automation, API, and MCP features that customers enable;
- process subscriptions, payments, tax records, and account access;
- send service, security, billing, and support communications;
- send marketing communications where permitted, with an unsubscribe option;
- understand use of the Service and measure advertising and conversions;
- prevent fraud, spam, abuse, and violations of our Terms of Service;
- comply with law and connected-platform requirements; and
- establish, exercise, or defend legal claims.
We do not sell social-platform credentials or Customer Content for money, and we do not use unpublished post content to advertise third-party products.
5. Legal bases
Where a law such as the EU or UK GDPR requires a legal basis, we rely on one or more of:
- contract, where processing is needed to provide the Service you requested;
- legitimate interests, including operating, securing, supporting, and improving the Service, preventing abuse, and understanding business performance, where those interests are not overridden by individual rights;
- legal obligations, including tax, accounting, law-enforcement, and regulatory requirements; and
- consent, where required for particular marketing, tracking, or other processing. Consent can be withdrawn, without affecting processing already carried out lawfully.
6. Who receives information
We disclose information only as reasonably needed for the purposes above, including to:
- Connected Platforms selected by the customer;
- our specialist social-connection and publishing provider, which handles platform connections and delivery on our behalf;
- hosting, database, storage, content-delivery, authentication, email, security, and support providers;
- Stripe for checkout, subscriptions, payments, invoices, and fraud prevention;
- DataFast for website and conversion analytics;
- Meta when Meta Pixel is enabled for advertising measurement, including page, registration, and trial events;
- workspace owners and members according to their permissions;
- professional advisers and insurers under appropriate duties of confidentiality;
- authorities where required by law or reasonably necessary to protect rights, safety, and security; and
- a buyer or successor in connection with a merger, financing, restructure, or sale of the business, subject to applicable law.
We may replace a provider as the Service changes. A replacement must be permitted to process information only for the relevant service or another purpose disclosed to you.
7. Cookies, analytics, and advertising
The Service uses essential cookies and local storage for authentication, security, workspace selection, drafts, and interface preferences. Disabling them may prevent the Service from working.
We also use:
- DataFast to measure visits, referrals, product events, and conversions. When you are signed in, we identify the visitor to DataFast with your account email so those visits can be tied to that account; and
- Meta Pixel to measure advertising performance, including page views, completed registrations, and started trials. For registration matching, an email address may be normalised and SHA-256 hashed in the browser before it is sent to Meta. Hashing does not make the information anonymous to Meta.
These providers may receive device, browser, IP, page, referral, event, cookie, or similar information. Their own privacy terms also apply to their independent handling of information.
You may be able to limit cookies and similar technologies through your browser, device, content-blocking tools, or the advertising controls offered by Meta. Some Service features may not work correctly if required storage is blocked.
8. Overseas processing
We operate from Australia and use providers in other countries. Information is likely to be processed in Australia, the United States, Spain and elsewhere in the European Economic Area, and in countries where a Connected Platform or its providers operate.
Privacy protections can differ between countries. Where applicable law requires a transfer safeguard, the recipient and circumstances determine the mechanism, which may include contractual safeguards, an adequacy decision, consent, or another permitted basis. Contact us for information about safeguards relevant to a particular transfer.
9. Retention and deletion
We keep information while an Account or workspace is active and for as long as reasonably needed to provide and secure the Service, comply with law and platform requirements, maintain tax and accounting records, resolve disputes, and enforce agreements.
When Content is deleted, a connection is removed, or an Account is closed, we delete or de-identify associated information from live systems within a commercially reasonable period unless continued retention is required or permitted. Backups and security logs may remain until they expire through their normal cycles. Payment and legal records may be kept for longer.
A workspace owner can delete that workspace in Settings after cancelling its subscription. Deletion removes the workspace’s Content, media, connected accounts, API keys, and MCP grants from live systems. Content already published remains on the Connected Platform under its rules. If that was the owner’s last workspace, we also close the Account login.
Disconnecting an account stops future use of that connection. Content already published remains on the Connected Platform under its rules. The social-connection provider may retain limited connection or delivery records where needed for security, legal compliance, or platform requirements.
YouTube API data is subject to Google’s retention, refresh, and deletion requirements, including 30-day limits in some circumstances. You can revoke Get Posting’s Google access through your Google account permissions or ask us to delete affected YouTube user data. We may verify your identity and will handle the request within applicable legal and platform timeframes.
To close an Account or request deletion of information you cannot remove in Settings, email support@getposting.com. We may verify your identity and authority over the relevant workspace before acting.
10. Your privacy rights
Depending on where you live and which law applies, you may have rights to:
- access personal information we hold about you;
- correct inaccurate or incomplete information;
- request deletion, restriction, or portability;
- object to particular processing, including direct marketing;
- withdraw consent; and
- complain to a privacy regulator.
Email us to exercise a right. We may verify your identity, ask for enough detail to locate the information, and refuse or limit a request where the law permits. We will respond within the period required by applicable law.
Where the Australian Privacy Act applies, you may complain to the Office of the Australian Information Commissioner. People in the EEA or UK may complain to the data-protection authority where they live or work. Please contact us first if you are comfortable doing so, so we can try to resolve the issue.
11. Security and data breaches
We use reasonable technical and organisational measures appropriate to the Service, including access controls and encrypted transport. No internet service is completely secure. You are responsible for protecting passwords, API keys, connected clients, and devices, and should tell us promptly if you suspect unauthorised access.
We assess and notify eligible data breaches as required by applicable law.
12. Children
The Service is for people aged 18 and over and is not directed to children. If you believe a child has provided personal information, contact us.
13. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will update the date above and provide additional notice of a material change where reasonably practicable or legally required.
14. Contact
- Email: support@getposting.com
- Operator: We Coast (ABN 11 722 302 546)