Privacy Policy
Effective date: February 2026
This Privacy Policy explains how VZV Ltd (“PostQik”, “we”, “us”), operator of the PostQik web application (the “Service”), collects, uses, stores and shares information when you use the Service. By using the Service you agree to this Policy.
1. Summary
- We collect only what we need to sign you in and publish your content: your name, email, and the OAuth tokens you grant us.
- Files you select from Google Drive are streamed through our backend to the destination platform for the moment of publishing only. We do not store their contents.
- We do not sell your data, ever. We do not use it to train AI models.
- You can disconnect any integration or delete your account at any time to revoke our access.
2. Information We Collect
2.1 Account information
When you register, we collect your name, email address, and a hashed password. If an admin approves your account, we record the approval status and any plan tier assigned to you.
2.2 Third-party integration tokens
When you connect Google Drive, TikTok, or Instagram via our publishing partner (Upload-Post), we receive OAuth tokens that let us act on your behalf. We store these tokens encrypted in our database, associated only with your account.
2.3 File metadata & content (Google Drive)
When you browse the Drive Browser, we request file metadata (names, thumbnails, mime types, sizes, folder structure) from your Google Drive using the drive.readonly scope. When you click Send on a file, we temporarily stream that file's content through our backend to the destination platform.
2.4 Publishing activity
We log each send attempt: which file was sent, to which platform and account, at what time, and whether it succeeded. This is shown to you on the Logs page and is retained for troubleshooting and quota accounting.
2.5 Billing information
If you subscribe to a paid plan, our payment processor (Stripe) collects and stores your payment method. We never see or store your card details; we only receive a customer ID, subscription status, and invoice metadata from Stripe.
2.6 Technical information
Our servers automatically record standard request logs (IP address, user agent, endpoint, timestamp) used for security, abuse prevention, and debugging. We do not use third-party analytics or advertising trackers.
3. Google User Data — Limited Use Disclosure
PostQik's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in relation to the Google Drive data we access:
- What we access. With your consent, we request the
https://www.googleapis.com/auth/drive.readonlyscope. This lets us list, view, and download files you own or have access to in Google Drive. - Why we access it. Solely to (a) show you a browsable file list in the Drive Browser inside PostQik and (b) send files you explicitly select to the social platforms you have connected.
- We do not. Modify, delete, share, or transfer your Drive files to anyone other than the destination platform you selected for that specific send. We do not read, index, or process the contents of your files for any other purpose.
- We do not use Google user data to train, fine-tune or evaluate any AI or machine-learning model.
- We do not sell Google user data. Ever.
- Storage. The content of Drive files is not persisted on our servers; it is streamed through the backend and released from memory as soon as the send completes or fails. File metadata (name, id, thumbnail URL) may be cached briefly to power the Drive Browser and posting logs.
- Access by humans. No PostQik employee, contractor, or admin can view the contents of your Drive files. Debugging is done using logs that never include file contents.
- Revocation. You can disconnect Drive at any time from Integrations, or revoke access directly at myaccount.google.com/permissions. Revocation is immediate.
4. How We Use Your Information
- To authenticate you and maintain your session.
- To fetch and display the files you have in Google Drive so you can select them.
- To send files you explicitly choose to TikTok and/or Instagram via our publishing partner.
- To enforce quotas, billing, and plan limits.
- To show you a history of your posting attempts.
- To detect and prevent abuse, spam, or violations of our Terms of Service.
- To communicate transactional messages (e.g. approval notice, billing receipts).
We do not use your data for advertising, retargeting, or profile-building.
5. How We Share Information
We share information only with the following categories of third parties, and only to the minimum extent needed to run the Service:
- Google (Drive API): we call Google's APIs on your behalf using the OAuth token you granted us.
- Upload-Post (our publishing infrastructure partner): we send the file content and caption to Upload-Post so it can post to TikTok / Instagram on your behalf. See their privacy policy at upload-post.com.
- Stripe (billing): payment processing for subscriptions.
- Cloud hosting providers that host our servers and database.
- Legal disclosure: we may disclose information when required by law, subpoena, or to protect the rights, property, or safety of PostQik, our users, or the public.
6. Data Retention
- Account data: retained while your account is active. Deleted (or anonymised) within 30 days of account deletion.
- OAuth tokens: retained while the integration is connected. Deleted immediately on disconnect or account deletion.
- Drive file contents: never persisted.
- Post logs: retained for up to 12 months for troubleshooting and quota history.
- Billing records: retained as required by applicable tax/accounting law (typically 7 years).
7. Security
We use industry-standard measures to protect your data: encrypted transport (HTTPS), password hashing (bcrypt), encrypted storage of OAuth tokens, principle-of-least-privilege access, and regular dependency patching. No system is 100% secure; you use the Service at your own risk.
8. Your Rights
Depending on where you live (e.g. EU/UK under GDPR, California under CCPA), you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (“right to be forgotten”).
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent (by disconnecting integrations or deleting your account).
To exercise any of these rights, contact us at support@postqik.com. We respond within 30 days.
9. Children
The Service is not directed to children under 13 (or under 16 in the EU/UK). We do not knowingly collect data from children. If you believe a child has provided us with information, contact us and we will delete it.
10. International Transfers
Our servers may be located outside your country of residence. By using the Service you consent to your data being transferred to, stored in, and processed in countries other than your own.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be announced by email or in-app notice at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.
12. Contact
For any privacy question, request, or concern, contact us at support@postqik.com.