Privacy Policy
Last updated: August 1, 2026
This Privacy Policy explains what data PostTrack (the “Platform”, “we”) collects, how we use it, how long we keep it and how you can have it deleted. It covers both the data you give us directly and the advertising data we receive on your behalf through the official TikTok Marketing API and Facebook Marketing API.
1. Who we are and how to contact us
PostTrack is an advertising management and analytics platform for Meta Ads and TikTok Ads, operated by the PostTrack team.
For any question about this policy, about the data we hold, or to make a privacy request, write to support@posttrack.io. We answer privacy requests within 30 days.
2. Data you provide to PostTrack
- Account data: your email address and, if you choose to provide it, your name.
- Password: stored only as a salted one-way hash. We never store, and cannot read, your plain-text password.
- Settings you create: automation rules, campaign templates, report configurations, notification preferences and your interface language.
- Connection data: which advertising accounts you have connected and the access tokens issued to us by the advertising platform when you authorize the connection.
- Technical data: IP address, browser and device type, and action logs from the interface — used for security, abuse prevention and diagnostics.
3. Data we receive from advertising platforms
We access advertising data only for the ad accounts you have explicitly authorized through the platform’s own OAuth screen, and only for as long as that authorization is active. We never ask for the password of your TikTok or Meta account.
3.1 TikTok Ads — TikTok Marketing API
Through the official TikTok Marketing API we receive:
- the list of advertiser (ad) accounts you have granted access to, together with their name, currency, timezone and status;
- the structure of your campaigns, ad groups and ads, including their settings, budgets, schedules and targeting configuration;
- performance statistics: impressions, clicks, spend, conversions and the derived metrics we display in reports (CPA, CPC, CTR, ROI);
- identifiers and metadata of creatives, pixels and applications used in your campaigns, so we can show them in the interface and attach them to the campaigns you create.
The permissions we request and the reason for each one are listed on the TikTok integration page. TikTok data is used solely to operate the Platform for the account owner who authorized it, in line with the TikTok Advertising API Terms of Service.
3.2 Meta Ads — Facebook Marketing API
Through the official Facebook Marketing API we receive:
- the list of ad accounts and business assets you have granted access to;
- the structure of your campaigns, ad sets and ads, including settings, budgets and targeting configuration;
- performance statistics: impressions, clicks, spend and conversions;
- identifiers and metadata of creatives, pixels and applications.
The permissions we request are listed on the Meta integration page. Use of this data is additionally governed by the Meta Platform Terms and Developer Policies.
4. How we use the data
We use the data listed above only to provide the Platform to the owner of the account that authorized the connection:
- displaying dashboards and the structure of your advertising accounts;
- building the reports and analytics you request;
- executing the automation rules you have configured yourself — for example, pausing an ad group when its cost per conversion goes above the target you set;
- creating and updating campaigns from the templates you build, on your instruction;
- sending the notifications you enable (in the interface, by email or to your Telegram);
- keeping the service secure, diagnosing faults and providing support.
5. Storage and security
Access tokens and other credentials are stored encrypted at rest and are decrypted only in memory, at the moment a request is made to the advertising platform on your behalf. All traffic between your browser, our servers and the advertising platforms runs over HTTPS/TLS.
Advertising data is scoped to the PostTrack account that authorized the connection: it is not visible to other customers, and access by our staff is limited to what is strictly necessary to operate the service or to respond to a support request from you.
6. What we do not do
- We do not sell your data, and we do not share or license it to third parties.
- We do not combine data from different customers into shared datasets.
- We do not build advertising or marketing profiles from it, and we do not use it for our own advertising.
- We do not use it to train machine-learning or AI models.
- We do not transfer or resell access to your advertising accounts.
7. Retention and deletion
- Data is retained for as long as your PostTrack account is active and the corresponding connection is in place.
- When you disconnect an advertising account — in PostTrack, or by revoking access in TikTok Business Center or in your Facebook settings — the associated access tokens are deleted immediately and we stop requesting data for that account.
- Advertising data cached for that connection (campaign structure, statistics, creative metadata) is deleted within 30 days.
- To delete your PostTrack account and all data associated with it, send a request to support@posttrack.io. See the Data Deletion page for the full procedure.
- Anonymized technical logs may be kept for a limited period for security and legal-compliance purposes.
8. Your rights
You can at any time request access to the data we hold about you, ask for it to be corrected, request its deletion, or ask for an export of your account data in a machine-readable format. Send the request to support@posttrack.io from the email address of your PostTrack account.
9. Service providers
We use a small number of providers to run the service. They process data only on our instructions and are bound by confidentiality obligations:
| Purpose | Provider |
|---|---|
| Website hosting and CDN | Vercel Inc. |
| Application and database hosting | VPS hosting (Europe) |
| File and creative storage | Cloudflare R2 |
| Transactional and notification email | Resend |
| Notification delivery to Telegram (only if you enable it) | Telegram Messenger |
We do not use third-party advertising or behavioural analytics trackers on the Platform.
10. Cookies and local storage
We use only what is required for the Platform to work: a session identifier and, in your browser’s local storage, your authentication token and interface preferences (language, theme). We do not set advertising, tracking or third-party analytics cookies.
11. Changes to this policy
We may update this policy. The current version is always published on this page with the date below, and material changes are announced in the interface before they take effect.
Last updated: August 1, 2026. Questions: support@posttrack.io.
