Privacy Policy
Last updated: April 6, 2026
1. Introduction
This Privacy Policy explains how Montadecs Co., Ltd. ("Company," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use the Postiz social media scheduling and management platform ("Service"), accessible at postiz.imseankim.com.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, password
- Profile information: display name, avatar
- Payment information: processed securely by third-party payment processors (we do not store card details)
- User Content: posts, media, captions, and scheduling data you create
- Communications: messages you send to us (e.g., support requests)
2.2 Information from Third-Party Platforms
When you connect your social media accounts (e.g., TikTok, Instagram, Facebook, X/Twitter, YouTube, LinkedIn), we collect information authorized by those platforms, which may include:
- Your public profile information (username, display name, profile picture)
- Account identifiers and access tokens
- Content you authorize us to publish on your behalf
- Basic analytics data (likes, views, engagement metrics) where available
- Video and image content you upload for scheduling and publishing
We only request permissions necessary to provide the Service. You can review and revoke platform permissions at any time through the respective platform's settings.
2.3 Information Collected Automatically
- Device information: browser type, operating system, device identifiers
- Usage data: pages visited, features used, actions taken
- Log data: IP address, access times, referring URLs
- Cookies: session and preference cookies
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Schedule and publish content to your connected social media accounts
- Authenticate your identity and manage your account
- Process transactions and send related notifications
- Provide analytics and insights about your social media performance
- Respond to your inquiries and provide customer support
- Send service-related communications (e.g., updates, security alerts)
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
We do not sell your personal information. We do not use your data for advertising purposes unrelated to the Service.
4. How We Share Your Information
We may share your information only in the following circumstances:
4.1 Third-Party Social Media Platforms
When you use the Service to schedule or publish content, we transmit your User Content and necessary account data to the connected platforms (e.g., TikTok, Meta, Google) via their official APIs. This sharing is initiated by you and required to provide the core functionality of the Service.
4.2 Service Providers
We may share data with trusted third-party service providers who assist us in operating the Service, including hosting (Vercel), database (Supabase), and payment processing. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
4.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of our Company, users, or the public.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: retained until you delete your account
- User Content: retained until you delete it or close your account
- Access tokens: retained until you disconnect the platform or delete your account
- Usage logs: retained for up to 12 months
- Payment records: retained as required by applicable tax and accounting laws
After account deletion, we will delete or anonymize your data within 30 days, except where retention is required by law.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure storage of access tokens and credentials
- Regular security assessments and monitoring
- Access controls limiting employee access to personal data
While we strive to protect your data, no method of electronic transmission or storage is 100% secure.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate or incomplete data
- Deletion: request deletion of your personal data
- Portability: request a portable copy of your data
- Restriction: request restriction of processing
- Objection: object to processing for certain purposes
- Withdrawal of Consent: withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at hello@greitstudios.com. We will respond within 30 days.
8. Data Deletion
You may request deletion of your personal data at any time by:
- Deleting your account through the Service settings
- Emailing us at hello@greitstudios.com
Upon receiving a deletion request, we will delete your personal data, including any data obtained from third-party platforms, within 30 days. We will also revoke any active API tokens associated with your connected social media accounts. Some data may be retained where required by law.
9. Third-Party APIs and Services
The Service uses official APIs provided by third-party platforms including but not limited to:
- TikTok: TikTok API for content publishing and account management
- Meta (Facebook/Instagram): Meta Graph API for content scheduling and publishing
- Google (YouTube): YouTube Data API for video publishing
- X/Twitter: X API for post scheduling and publishing
- LinkedIn: LinkedIn API for content publishing
Data obtained through these APIs is used solely to provide the Service's scheduling and publishing functionality. We do not sell, lease, or otherwise monetize data obtained from third-party platform APIs. We comply with each platform's developer terms and data use policies.
10. Cookies
We use cookies and similar technologies to maintain your session, remember your preferences, and analyze usage. You can control cookies through your browser settings, though disabling cookies may limit functionality.
11. Children's Privacy
The Service is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such data, we will take steps to delete it promptly.
12. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the Republic of Korea and the United States. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. We encourage you to review this policy periodically.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Montadecs Co., Ltd.
Email: hello@greitstudios.com