Skip to content
SocialPostxr SocialPostxr
  • Home
  • Features
  • Pricing
  • Blog
  • Login
  • Start Free
Login Start Free

Privacy Notice

What personal data we hold about you, why we hold it, who else sees it, and what you can make us do about it.

Last updated: 1 August 2026 · version 2026-08-01

Contents

  1. Who we are
  2. What we collect
  3. People who appear in images our users upload
  4. Why we use it, and our lawful basis
  5. Whether you have to give us your data
  6. Automated processing and AI
  7. Cookies and similar technologies
  8. Who we share it with
  9. Sending data outside the UK
  10. How long we keep it
  11. How we protect it
  12. Your rights
  13. Complaining to the ICO
  14. Children
  15. Changes to this notice
  16. Contact us

1. Who we are

ACEMAN SOFTWARE SOLUTIONS LTD is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are the ones answerable for it. Section 3 covers one situation that works differently — images our users upload that contain other people — and says so there rather than leaving you to notice the difference.

  • Company number: 12928098
  • Registered office: 8 Holtdale Grove, Leeds, England, LS16 7RZ
  • Registered in: England and Wales
  • Trading as: SocialPostxr
  • Privacy contact: privacy@socialpostxr.com

1.1 Our group

SocialPostxr is a service provided by Aceman Software Solutions Ltd (company number 12928098), registered at 8 Holtdale Grove, Leeds, England, LS16 7RZ. SocialPostxr Ltd (company number 17077525) is a related company that carries out our sales and marketing.

To be explicit about which company is which: ACEMAN SOFTWARE SOLUTIONS LTD (company number 12928098, registered at 8 Holtdale Grove, Leeds, England, LS16 7RZ) is the controller and is the company you contract with. SOCIALPOSTXR LTD (company number 17077525, registered at 17 Holt Walk, Leeds, England, LS16 7QB, incorporated 9 March 2026) carries out sales and marketing. It is not the controller, and it is not the company you contract with.

1.2 Data Protection Officer

We have not appointed a Data Protection Officer. We are not required to appoint one under Article 37 of the UK GDPR. Privacy questions and requests to exercise your rights go to the contact below, which is monitored by the people responsible for data protection at Aceman Software Solutions Ltd.

2. What we collect

2.1 Information you give us

  • Account details: your name, email address and a hashed password.
  • Billing details: handled by Stripe. We receive confirmation that a payment succeeded or failed, plus a Stripe customer identifier so we know which account it belongs to. Your card details go directly to Stripe and never reach us.
  • Content you create or upload: post text, images and video, brand descriptions, tone and visual-identity notes, target-audience descriptions, campaign briefs, questionnaire answers, and a website address if you ask us to build a brand profile from one.
  • Anything you put in a support message: including whatever you choose to tell us in it.
  • Social account authorisations: the tokens that let us publish to the accounts you connect.

2.2 Information we collect automatically

  • Device and browser information: browser type, operating system, screen size.
  • Usage data: pages visited, features used, time spent.
  • Log data: IP address, access times, referring URLs.
  • Diagnostics: when something breaks, the error and the code path that produced it, tagged with an account identifier that is not your name or email. Request bodies, cookies and authentication headers are not included.

2.3 Your country, and the two different ways we work it out

  • On this website: your country comes from a header our CDN has already attached to your request, and is used only to pick which currency to show. No IP address is sent to anyone else and nothing is looked up. We do not store the country; the currency it produces is saved in your own browser, as sy-preferred-currency in the table in section 7, so we do not have to work it out again on every page.
  • When you create an account: we offer to detect your country automatically so your currency and settings start out right. This is optional. If you agree, your IP address is sent to Kloudend, Inc. (ipapi.co) to look up the country, and nothing else. If you decline, you pick your country from a list and nothing is sent anywhere. Lawful basis: your consent, Article 6(1)(a) — and you can withdraw it.

2.4 Information we get from others

  • Social media platforms: when you connect an account for publishing, we receive the tokens and account identifiers needed to post on your behalf, plus the analytics, comments and messages that come back for the posts we published.
  • Our payment processor: confirmation that a payment succeeded or failed.

3. People who appear in images our users upload

This section is for you if you are in a photo somebody else uploaded. You are probably not a SocialPostxr user, you did not give us anything, and you may never have heard of us. You still have rights, and you are entitled to know what happened.

Our users upload images to turn into social media posts — a photo of a shop, a team, an event, a customer holding a product. Those images sometimes contain other people. When that happens, we hold personal data about someone we have no relationship with, and we did not get it from them.

3.1 What happens to the image

  • It is stored in our database and file storage, hosted by Supabase, Inc.
  • It may be sent to OpenAI to be described, edited or used to generate a variation.
  • If our user schedules a post using it, it is published to the social media accounts they have connected, through Ayrshare LLC.
  • It is deleted from our systems when our user deletes it, or when their account is closed. If it has already been published to a social media platform, deleting it here does not remove it from there — only the account holder or the platform can do that.

3.2 What we do not do

  • We do not try to identify you. No facial recognition, no matching against other images, no attempt to work out who you are or link you to anything else. The image is processed as an image.
  • We do not build a profile of you or use your image for advertising.
  • We do not use it to train AI models, and we instruct our providers not to.

3.3 Who decided to upload it

Our user did. They chose the image, and under our Terms of Service they confirm they have the right to use it. They decide what is uploaded and what gets published; we decide how it is stored and which providers process it. Both of us therefore have obligations to you.

We will not use that split as a reason to send you away. If you contact us we will act on what is ours to act on — deleting the image from our systems, stopping it being processed further — and tell you plainly what only the account holder or the platform can do. If you know who posted the image, asking them as well is usually the fastest route to getting it taken down where it was published.

3.4 Your rights, and how to use them

Most of the rights in section 12 apply to you: you can ask what we hold about you, ask for it to be corrected or deleted, ask us to restrict what we do with it, and object to us holding it at all (Articles 15, 16, 17, 18 and 21). Data portability (Article 20) does not, because it applies only where processing rests on your consent or a contract with you, and neither applies here — you never gave us anything. Email privacy@socialpostxr.com, tell us enough to find the image, and we will act on it.

We do not contact people in this position individually, because we do not know who they are or how to reach them — working it out would mean trying to identify them, which is exactly what we have chosen not to do. Article 14(5)(b) of the UK GDPR allows this notice to serve as the information instead, and that is what it is doing here.

4. Why we use it, and our lawful basis

Under Article 6 of the UK GDPR we need a lawful basis for everything we do with your data. Ours are:

  • To provide the service you signed up for — creating your account, generating and scheduling posts, publishing them, taking payment. Lawful basis: performance of a contract, Article 6(1)(b).
  • To keep the service working, fast and secure — being told when it breaks, seeing where it is slow, blocking attacks and abuse, and replying when you contact us for support. Lawful basis: legitimate interests, Article 6(1)(f).
  • To understand how the site is used — analytics. Lawful basis: your consent, Article 6(1)(a). Nothing analytics-related runs unless you turn it on, and you can turn it off again at any time.
  • To detect your country when you sign up, if you agree to it. Lawful basis: your consent, Article 6(1)(a). Decline and you choose your country from a list instead.
  • To meet legal obligations — keeping accounting records, responding to lawful requests. Lawful basis: legal obligation, Article 6(1)(c).

4.1 Where we rely on legitimate interests

Legitimate interests is the basis we use least, and only where the processing is what you would expect from a service that has to stay up. These are the providers involved and the interest in each case:

  • Cloudflare, Inc. — Hosting this site; CDN, TLS, WAF and bot management in front of the API. Keeping the site and the API available and protected from attack, bots and abuse.
  • Microsoft Ireland Operations Limited — Sending transactional and support email. Replying to you when you contact us for support. We cannot answer a support request without sending you an email.
  • Functional Software, Inc. (Sentry) — Error monitoring and service reliability. Being told when the service breaks, with enough detail to fix it, rather than waiting for someone to report it.
  • Grafana Labs — Performance monitoring. Knowing which parts of the service are slow, so we can keep it usable.

You can object to any of this. Article 21 of the UK GDPR gives you the right to object to processing based on legitimate interests, on grounds relating to your situation. If you do, we stop unless we can show compelling legitimate grounds that override your rights — and we will explain our reasoning rather than simply asserting it. Email privacy@socialpostxr.com.

If you object to direct marketing, there is no balancing test at all: we must stop, and we will.

5. Whether you have to give us your data

Account and billing details are a contractual requirement. We cannot open an account, take payment or publish anything on your behalf without them. If you do not provide them, we cannot enter into a contract with you and cannot provide the service. There is no statutory requirement to give us any of it — the requirement comes from the contract, not from the law.

Everything else is optional. Analytics cookies are entirely up to you, and so is automatic country detection at signup: refusing any of them costs you nothing and changes nothing about the service you receive. Content you upload is your choice too, though the service has little to do without it.

6. Automated processing and AI

SocialPostxr generates social media content automatically from material you supply — your brand details, product descriptions, uploaded images and the prompts you write. This is automated processing, and we would rather describe it plainly than leave you to guess.

  • What goes in: brand names and descriptions, tone and visual-identity notes, target-audience descriptions, campaign briefs, questionnaire answers, images you upload, and a website address if you ask us to build a brand profile from one. Your email address is not sent.
  • Where it goes: to OpenAI, acting as our processor, which generates draft text and images. Full details are in the subprocessor register.
  • What comes out: draft posts and images, presented to you for review.
  • You stay in control: nothing is published automatically without your instruction. You can edit or discard anything generated.

No decisions are made about you by a machine. This processing produces marketing content, not judgements about you. We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 of the UK GDPR. Nothing here decides whether you get an account, what you pay, or whether you keep the service.

Your content is not used to train AI models. We instruct our providers not to, and they retain what we send only for abuse monitoring, for a limited period set out in the register. Because model outputs are generated rather than retrieved, we cannot promise that generated text or images will be unique, and you should review them before publishing.

7. Cookies and similar technologies

This is everything we store on your device. Nothing in the optional categories is set until you turn it on, and turning a category off deletes what it stored.

Everything SocialPostxr stores on your device.
Name Purpose Duration Type Provider Category
cc_cookie Stores your cookie choices and the version of the cookie policy you saw, so we do not ask again on every page and can prove what you agreed to. 6 months (182 days) Cookie SocialPostxr (first party) Strictly necessary
sy-preferred-currency Remembers which currency prices are shown in (USD, GBP or EUR) — either the one you picked from the selector, or the one we inferred from the country your network reported, so we do not have to work it out again on every page. Until you clear your browser storage localStorage SocialPostxr (first party) Strictly necessary
__cf_bm Set by Cloudflare, our CDN and security layer, to tell automated traffic from human visitors so that attacks, scraping and abuse can be blocked before they reach us. It carries no account identifier and is not used to track you between sites. 30 minutes Cookie Cloudflare, Inc. Strictly necessary
sy-network-assessment Caches a one-off measurement of your connection speed for the current tab, so we can turn heavy animations down on slow connections instead of re-measuring on every page. Until you close the tab (session only) sessionStorage SocialPostxr (first party) Strictly necessary
_ga Google Analytics. Assigns a random identifier to your browser so repeat visits can be counted as one visitor rather than several. 2 years Cookie Google Ireland Limited Analytics
_ga_ZFVKPDKDKK Google Analytics. Tracks the state of your current visit (when it started, how many pages you viewed). 2 years Cookie Google Ireland Limited Analytics
sy-detected-country retired No longer used. Until August 2026 this cached a country code guessed from your IP address by a third-party lookup service. That lookup has been removed; we now read the country your CDN already reports, and nothing is stored. This entry remains listed only because we actively delete any leftover value on your next visit. Deleted on sight localStorage SocialPostxr (first party) Strictly necessary

You can change your mind at any time using the Cookie settings link in the footer of every page. Our Cookie Policy explains each entry in more detail, and why we do not keep a server-side record of your choice.

If you have analytics turned on, you can also opt out of Google Analytics across all sites with the Google Analytics Opt-out Browser Add-on.

8. Who we share it with

We do not sell your personal data. This section covers everyone else who ends up with any of it, and why.

8.1 Providers who process data for us

Nearly all of these are our processors: each is under a written contract requiring them to act only on our instructions, to keep the data secure, and to delete or return it when we stop using them. There is one exception, Google Fonts, which is a free public service with no contract available — 8.2 explains it. This is the full published register: what each one does, what they receive, the lawful basis, how long they keep it and where. The same table is on our subprocessors page.

Providers and other recipients of personal data.
ProviderPurposeData processedLawful basisRetentionLocation & safeguard
Salesforce, Inc.HerokuApplication hostingEverything the backend processes in transit: account identifiers, email addresses, brand descriptions, uploaded images, post textContract — Art. 6(1)(b)Ephemeral; logs held only in a rolling bufferEUUK→EEA, none required
Supabase, Inc.Database, object storage, authentication, realtimeThe whole user record: identifiers, email, names, brand profiles, uploaded and generated images and video, post content, schedules, credit ledgerContract — Art. 6(1)(b)Controlled by us for live rowsUnited Kingdom (London, eu-west-2)UK/EEA — none required (data at rest is in the UK)
Cloudflare, Inc.Hosting this site; CDN, TLS, WAF and bot management in front of the APISite visitors: IP address, user agent, request URL, bot-management cookieContract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f)Our interest: Keeping the site and the API available and protected from attack, bots and abuse.Bot cookie 30 minutesGlobal edge, nearest locationUK Addendum
Google Ireland LimitedFirebase HostingHosting the web applicationApp visitors: IP address, user agent, requested pathContract — Art. 6(1)(b)—europe-west1, global CDN edgeUK→EEA none required for the backend; UK Addendum for edge
Google LLCGoogle FontsFont delivery for the SocialPostxr app (web and mobile) — not this website. The app loads font stylesheets from fonts.googleapis.com and font files from fonts.gstatic.com. This website serves every font from our own servers and sends nothing to Google.Your device's IP address and technical request data (user agent, which font files were requested), sent directly from your device to Google whenever the app loads fonts. That is every app session, because the app's text engine also loads its fallback fonts from Google — not only when you choose a font in the font picker. No account identifier is sent, and Google states these requests are not linked to a Google account or used for profiling.Contract — Art. 6(1)(b)Google-controlled; per Google's Fonts privacy statement, requests are logged in aggregateUnited States / globalNecessary for the font feature the user operates, disclosed at signup (UK GDPR Art. 49(1)(b)); no contractual safeguard exists for this service
OpenAIGenerating post copy, art direction, campaign strategy, image description and image generationBrand names and descriptions, tone and visual-identity text, target-audience descriptions, campaign briefs, questionnaire answers, uploaded and generated images sent for analysis, the website address given for brand extraction. No account email is sent.Contract — Art. 6(1)(b)Not used for training. Abuse-monitoring logs up to 30 daysUnited StatesUK Addendum
Ayrshare LLCPublishing to the user's connected social accounts and retrieving analyticsPost text, hashtags, media, scheduled times; connected social account authorisations; returned analytics, comments and messagesContract — Art. 6(1)(b)Life of the account; deletion acknowledged within five business daysUnited StatesUK Addendum
StripeSubscription billing and checkoutEmail address, Stripe customer identifier, account identifier in checkout metadata. Card details go directly to Stripe and never reach us.Contract — Art. 6(1)(b)Regulatory retention periodsUnited States / United KingdomUK Addendum
Microsoft Ireland Operations LimitedSending transactional and support emailRecipient email address, and the subject and body of transactional support email — whatever the user typed into the support formLegitimate interests — Art. 6(1)(f)Our interest: Replying to you when you contact us for support. We cannot answer a support request without sending you an email.Controlled by our mailbox settingsEuropean UnionUK/EEA — none required
Functional Software, Inc.SentryError monitoring and service reliabilityException type, message and stack trace; a pseudonymous account identifier. Request bodies, cookies and authentication headers are not sent.Legitimate interests — Art. 6(1)(f)Our interest: Being told when the service breaks, with enough detail to fix it, rather than waiting for someone to report it.90 daysEU — GermanyUK→EEA none required; UK Addendum for onward US processing
Grafana LabsPerformance monitoringPerformance traces of outbound requests: method, URL, status, timing. URLs contain a pseudonymous account identifier. No request or response bodies.Legitimate interests — Art. 6(1)(f)Our interest: Knowing which parts of the service are slow, so we can keep it usable.30 daysUnited KingdomNone required
Google Ireland LimitedGoogle AnalyticsWebsite and product analyticsVisitors who accept analytics cookies: IP address, device and browser data, pages viewed, analytics identifier. Nothing is sent before consentConsent — Art. 6(1)(a)Event-level data: 2 months; user-level data: 14 months (GA4 property 523407750)United States / globalUK Addendum
Google LLCGoogle Tag ManagerDelivery mechanism for analyticsDelivers the analytics script to consenting visitors; receives IP address and user agent as a consequenceConsent — Art. 6(1)(a)Not a storage endpointUnited States / globalUK Addendum
Kloudend, Inc.ipapi.coDetecting country and currency to set up the accountThe user's IP address at signup, if they consent to automatic location detectionConsent — Art. 6(1)(a)Server log files, period not publishedUnited StatesUK Addendum

We also maintain a fuller register internally, which includes providers that are configured in our systems but that currently receive no personal data. Only the providers that actually receive personal data are published above. We update this notice whenever that changes.

Register last verified against production: 1 August 2026.

8.2 Fonts in the app

When you use the SocialPostxr app, your device loads fonts from Google Fonts (Google LLC, in the United States), and Google receives your IP address along with basic technical details of the request — your browser or device type, and which font files were asked for.

This happens whenever you use the app, not only when you choose a font: the app's text engine loads its own fallback faces from Google as well. Previewing or applying a brand font in the font picker loads more. Our own two brand faces are built into the app and never reach Google.

The website you are reading now does not do this. It serves every font from our own servers, so no font request from this site ever reaches Google — before or after any choice you make about cookies. If you turn analytics on, the analytics tag itself is loaded from Google; that is the one thing on this site that contacts them, it is listed in the table above, and it stays off until you switch it on.

This is a direct connection from your device to Google. The request does not pass through us and we never see it. Google states that font requests are not associated with a Google account and are not used to build a profile of you. No account identifier of ours is sent. The register above shows the basis we rely on for this transfer, and section 9 explains why it is different from every other row.

8.3 Social media platforms you connect

When you connect an account, we send that platform only the content you have chosen to publish, plus what the platform needs to accept it. We request only the permissions needed to post. What the platform then does with it is governed by that platform's own privacy policy, not ours.

8.4 Partners who referred you

If you signed up through a partner link, we tell that partner you signed up, your plan and whether you're active.

We do not tell them what you create, what you upload, or anything else about how you use the service.

8.5 Legal requirements and business transfers

We may disclose data where we are legally required to, to respond to a lawful request from a public authority, or to establish or defend legal claims. If the business is sold or merged, your data may transfer with it — we will tell you before that happens and explain what choices you have.

9. Sending data outside the UK

Where a recipient is outside the UK and is not covered by UK adequacy regulations, we rely on the UK International Data Transfer Agreement, or on the UK Addendum to the EU Standard Contractual Clauses where that is the instrument the recipient offers. We do not rely on the EU Standard Contractual Clauses on their own, because they are not a valid transfer mechanism for a UK exporter.

In practice that means: UK International Data Transfer Agreement (IDTA) / UK Addendum. Where a provider is in a country the UK has found to provide adequate protection — which includes the EEA — we rely on those adequacy regulations instead and no additional safeguard is needed. The location and the safeguard for each provider is shown in the register in section 8.

One row is different, and we would rather say so than smooth it over. The fonts your device loads from Google in the app (section 8.2) go to the United States, and Google Fonts is a free public service: there is no contract to sign, and Google offers no data transfer agreement for it. So there is no safeguard of the kind described above, and we are not going to name one that does not exist.

We rely instead on Article 49(1)(b) of the UK GDPR — the transfer is necessary to provide the font feature you signed up to use, and it is disclosed to you when you sign up. You should know that this is a narrower footing than the agreements covering everything else in the register, and we are taking further advice on it. If that advice changes our position, we will change what we do and say so here.

None of this affects this website, which loads no fonts from Google at all.

You can ask us for a copy of the safeguards we rely on for any specific transfer — email privacy@socialpostxr.com.

10. How long we keep it

  • Account and content: for as long as your account is open.
  • After you delete your account: we delete or anonymise your personal data. We do this on request, and we do it when we close an account at your instruction — there is no automatic timer running today, so if you want your data gone at a particular point, ask us and we will do it. Anything we are required by law to keep, such as billing records, is kept for the period below and nothing longer.
  • Billing and accounting records: six years from the end of the financial year they relate to, because UK tax law requires it.
  • Support correspondence: two years from the last message, so we have context if you come back to us.
  • Error and performance diagnostics: a limited period set in each provider's configuration, shown per provider in the register in section 8.
  • Your cookie choice: six months, then we ask again.

Provider-specific retention is shown in the register in section 8.

11. How we protect it

  • Encryption in transit (TLS) and at rest.
  • Passwords stored only as salted hashes — we cannot read yours.
  • Access to production data limited to the people who need it, and logged.
  • A web application firewall and bot management in front of this site and our API.
  • Written contracts with every provider that processes personal data on our behalf — with one exception, Google Fonts, explained in 8.2.

No system is perfectly secure, and we will not claim otherwise. If a breach happens that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours and tell you directly where the law requires it.

12. Your rights

Under the UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you (Article 15).
  • Correct anything inaccurate or incomplete (Article 16).
  • Delete it, where we have no overriding reason to keep it (Article 17).
  • Restrict what we do with it while a dispute is resolved (Article 18).
  • Send it elsewhere in a structured, machine-readable format (Article 20).
  • Object to processing based on legitimate interests, including any direct marketing (Article 21). See section 4.1 for what we rely on that basis for.
  • Withdraw consent at any time, where consent is the basis (Article 7(3)). Withdrawing does not make what we did beforehand unlawful. For cookies, use the Cookie settings link in the footer.

Email privacy@socialpostxr.com to exercise any of these. We will respond within one month. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if we do. It is free, unless a request is manifestly unfounded or excessive.

These rights are not only for account holders. If you appear in an image someone uploaded, section 3 explains how they apply to you.

13. Complaining to the ICO

If you think we have mishandled your personal data, please tell us first — we would rather fix it. But you do not have to come to us first, and you can complain to the supervisory authority at any time.

Information Commissioner's Office (ICO) is the UK's supervisory authority for data protection.

  • Complain online: https://ico.org.uk/make-a-complaint/
  • Helpline: 0303 123 1113
  • Post: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

Complaining to the ICO costs nothing and does not affect your right to a legal remedy.

14. Children

SocialPostxr is not for children under 16, and we do not knowingly collect their personal data. If we find that we have, we delete it. If you believe a child has given us their data, tell us at privacy@socialpostxr.com and we will remove it.

15. Changes to this notice

We update this notice when what we do with personal data changes. The version and date at the top of the page tell you which one you are reading. If a change is significant — a new category of data, a new recipient, a new purpose — we will tell you directly by email before it takes effect, and where the change relies on your consent we will ask you for it.

We will not treat your continued use of the site as agreement to anything. If we need your consent, we will ask for it and you can say no.

16. Contact us

  • Controller: ACEMAN SOFTWARE SOLUTIONS LTD
  • Company number: 12928098
  • Registered office: 8 Holtdale Grove, Leeds, England, LS16 7RZ
  • Email: privacy@socialpostxr.com

We aim to respond to privacy enquiries within five working days, and always within one month.

SocialPostxr SocialPostxr
  • Home
  • About
  • Contact
  • Privacy
  • How we got your details
  • Terms
  • Cookies
  • Subprocessors
  • DPA

© 2026 SocialPostxr