This policy describes what we actually do with your data - not what a template says a platform might do. If you find something here that does not match how the service behaves, that is a bug and we want to hear about it.
1 Who is responsible for your data
The data controller for the personal data described here is:
We have not appointed a Data Protection Officer, because the scale and nature of our processing does not require one. Privacy questions go to the address above and are answered by us directly.
2 What we collect, and why
Every category below is something the application genuinely stores. Nothing is listed speculatively.
| Data | Why we hold it | Legal basis |
|---|---|---|
| Name, email address, password hash, username | Creating your account, signing you in, verifying your address, resetting your password | Performance of our contract with you |
| Profile photo, biography, location, phone number | Showing you to other people on the platform, as much or as little as you choose | Performance of our contract with you |
| Business profile: trading name, description, address, contact details, logo, opening hours | Publishing your public business page | Performance of our contract with you |
| Posts, articles, images, product and service listings, gallery uploads | Publishing what you create, and delivering it to the people who follow you | Performance of our contract with you |
| Comments, reactions, saved posts, follows, direct messages | Operating the social features you chose to use | Performance of our contract with you |
| Blocked and muted accounts | Honouring your choice not to see someone | Performance of our contract with you |
| Orders and bookings you place | Passing your request to the business you placed it with, and keeping a record of it | Performance of our contract with you |
| Subscription plan, status, dates; Stripe customer and subscription identifiers | Running your subscription and taking payment for it | Performance of our contract with you |
| Invoices: amount, tax, billing name and address | Issuing receipts and keeping accounting records | Legal obligation |
| IP address, browser, operating system, pages visited | Security, fraud prevention, keeping the service running and diagnosing faults | Our legitimate interest in a service that works and is not abused |
| Login attempts, sessions, security events, administrator action logs | Detecting and investigating unauthorised access | Our legitimate interest in securing the service |
| Reports you file, moderation decisions about you, appeals | Running a moderation process that can be explained and challenged | Legal obligation and our legitimate interest in a safe platform |
| Record of which policy version you accepted, and when | Demonstrating that you agreed to our terms | Legal obligation |
| Cookie and marketing preferences | Honouring your choices and proving we asked | Consent, and our legal obligation to record it |
| Support and contact messages | Answering you | Our legitimate interest in supporting our users |
| Google or Apple account identifier, if you use single sign-on | Letting you sign in with that provider | Performance of our contract with you |
We do not run behavioural advertising, we do not sell personal data, and we do not make automated decisions that produce legal effects for you.
3 What is public and what is not
Some of what you give us is meant to be seen. The rest never is.
Visible to others
- · Your name and username
- · Profile photo and biography
- · Your business page and its contact details
- · Posts, articles and images you publish
- · Products and services you list
- · Reviews and comments you write
- · Who you follow
Never shown to other users
- · Your email address and phone number
- · Your password
- · Billing details and invoices
- · IP addresses and login history
- · Direct messages, other than to the person you sent them to
- · Who you blocked or muted
- · Reports you file - these are confidential
Anything published on a public page can be read by anyone and indexed by search engines. Your visibility settings and your business page privacy options control how much of this applies to you.
4 Who we share it with
We use the following processors. Each one only receives what it needs, and each is bound by a contract to protect it.
Stripe Payments Europe, Ltd.
Subscription payments and invoicing
Receives: Name, email address, billing address, payment card details (collected by Stripe, never by us)
Processed in: Ireland, with onward transfer to the United States
Safeguard: EU Standard Contractual Clauses and the EU-US Data Privacy Framework
Hosting provider
Running the application and storing its database and uploads
Receives: All account, content and technical data
Processed in: European Union
Safeguard: Processing within the EEA
Email delivery provider
Sending account, security, subscription and notification email
Receives: Name, email address, message content
Processed in: European Union
Safeguard: Processing within the EEA
Google LLC / Apple Inc.
Optional single sign-on, only if you choose to use it
Receives: Name, email address, provider account identifier
Processed in: United States
Safeguard: EU Standard Contractual Clauses and the EU-US Data Privacy Framework
We also disclose data where the law requires it, or where it is necessary to establish or defend a legal claim, or to protect someone from serious harm.
5 Transfers outside your country
We operate from North Macedonia. Some of our processors are in the European Economic Area, and some are in the United States.
Where data leaves the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses, and where the recipient is certified under the EU-US Data Privacy Framework we rely on that as well. You can ask us for a copy of the safeguards that apply to a particular transfer.
6 How long we keep it
Specific periods, not "as long as necessary". These are the same numbers the application enforces automatically.
| Data | Retention |
|---|---|
| Your account and profile | Until you close it |
| A closed account | 30 days, during which signing back in restores it, then permanently anonymised |
| Posts, listings, images and articles | Until you delete them, or your account is closed |
| Direct messages | Until the conversation is deleted, or your account is closed |
| Invoices and payment records | 10 years, as accounting law requires |
| Orders and bookings you placed | Kept by the business you placed them with, with your account unlinked once you close it |
| Security and administrator logs | 365 days |
| Reports and moderation decisions | 730 days after the case is closed |
| Support and contact messages | 730 days |
| Record of policy acceptance | For as long as your account exists, as evidence of your agreement |
| Cookie and marketing consent | Current choice kept until you change it; superseded history removed after 365 days |
| Backups | Overwritten on a rolling 30-day cycle |
Deleting your account does not reach into backups immediately. Backups are encrypted, are not used to serve the site, and roll over within the period above, at which point the deletion is complete there too.
7 Your rights
You can exercise all of these from your account. Most of them take effect immediately rather than becoming a support ticket.
- Access - download everything we hold about you as a single file, from Settings.
- Rectification - edit your profile directly, or ask us to correct anything you cannot reach.
- Erasure - close your account from Settings. What is deleted, kept or anonymised is set out above.
- Portability - the same download is structured JSON, which another service can read.
- Restriction and objection - tell us through the privacy screen and we will stop the processing in question unless we have compelling grounds not to.
- Withdraw consent - turn off marketing email or optional cookies at any time. Withdrawing does not undo what was lawful before it.
We answer requests within 30 days. There is no charge unless a request is repetitive or excessive.
If you think we have handled your data badly, please tell us first - but you are also entitled to complain directly to Agency for Personal Data Protection of the Republic of North Macedonia, or to the data protection authority where you live.
8 Keeping it safe
Passwords are hashed and never stored in a form we could read. Traffic is encrypted in transit. Backups are encrypted at rest. Administrative access is restricted, requires a second factor, and every administrative action is logged.
Card details never reach our servers - Stripe collects and stores them, and we only ever hold an identifier that points at your record with them.
If a breach ever puts your rights at risk, we will notify the supervisory authority within 72 hours and tell you directly without undue delay.
9 Children
BoothPost is not intended for anyone under 16, and we do not knowingly collect data from them. If you believe a child has an account, tell us and we will remove it.
10 Changes to this policy
This page carries a version number and an effective date. Minor clarifications are published here. If we change something material about how we use your data, we will tell you and, where the law requires it, ask you to agree again before you carry on using the service.