Privacy Policy

Last updated: July 22, 2026

1.Introduction

Welcome to PosteAhora ("we," "our," or "us"). PosteAhora is operated by Aleksandr Borisov (CUIT: 27-96484697-4), Monotributo - Régimen Simplificado para Pequeños Contribuyentes, Categoría A. We are committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information. This Privacy Policy explains our practices regarding data collection, usage, and your rights when using our social media management platform.

By using PosteAhora, you agree to the collection and use of information in accordance with this policy. We process your data in compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Argentina's Personal Data Protection Law (Ley 25.326), and other relevant regulations.

2.Information We Collect

2.1 Account Information

When you create an account with PosteAhora, we collect:

  • Email address (required for account creation and authentication)
  • Full name (as provided during registration)
  • Profile picture/avatar URL (if provided)
  • Account creation and last login timestamps

2.2 Social Media Platform Data

To provide our services, we collect and store data from connected social media accounts:

  • OAuth Tokens: Encrypted access tokens and refresh tokens for platforms including Facebook, Instagram, TikTok, YouTube, X (Twitter), LinkedIn, and Threads. These tokens are stored in an encrypted format and are necessary to post content on your behalf.
  • Platform Account Information: Username, display name, and account connection status for each platform you connect.
  • Platform-Specific Data: When you grant permissions, we may access profile information, page/account IDs, and basic account statistics. We only access data necessary to provide our services.

2.3 Content Data

We store content you create or upload to our platform:

  • Post captions and text content
  • Media files (images and videos) you upload for posting
  • Hashtags and metadata associated with your posts
  • Scheduling information (date, time, timezone)
  • Post status (draft, scheduled, published)

2.4 Analytics and Performance Data

We collect engagement metrics from your published posts:

  • Views, likes, comments, shares, and other engagement metrics
  • Post publication timestamps
  • Platform-specific performance data

2.5 Payment Information

PosteAhora uses Polar.sh as our Merchant of Record for payment processing. When you make a purchase:

  • Payment processing is handled entirely by Polar.sh. We do not collect, store, or process credit card information directly.
  • We receive payment confirmation, subscription status, and billing information (name, email, billing address) from Polar.sh for account management purposes.
  • Polar.sh's privacy policy applies to payment data: polar.sh/legal/privacy

2.6 Technical Data and Web Analytics

Automatically collected technical information:

  • IP address and approximate location (country/region)
  • Browser type and version
  • Device information and operating system
  • Usage patterns and feature interactions
  • Error logs and performance data

We use Datafa.st, a privacy-friendly web analytics service, on our public landing pages to measure aggregated traffic (pageviews, referrers, country, device/browser type) and conversion events. Datafa.st does not use tracking cookies on our site and does not collect personally identifiable information. IP addresses are not stored. Datafa.st's privacy practices are described at datafa.st/privacy-policy.

3.How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our social media management services.
  • Authentication: To authenticate your identity and secure access to your account.
  • Platform Integration: To connect with and interact with third-party social media platforms via their APIs on your behalf.
  • Analytics and Insights: To provide you with performance analytics and insights about your content.
  • Communication: To send you service-related notifications, updates, security alerts, and support communications.
  • Account Management: To manage your subscription, process payments (via Polar.sh), and handle billing inquiries.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
  • Security: To detect, prevent, and address technical issues, fraud, security breaches, and other harmful activities.

4.Third-Party Services and API Integration

4.1 Social Media Platforms

PosteAhora integrates with the following social media platforms and their APIs:

  • Meta (Facebook, Instagram): We use Facebook Graph API and Instagram Graph API. By connecting your accounts, you authorize us to access and manage your content as specified in Meta's Platform Terms.
  • TikTok: We use TikTok for Developers API. Your use is subject to TikTok's Terms of Service.
  • YouTube: We use YouTube Data API v3. Usage is subject to YouTube's Terms of Service.
  • X (Twitter): We use X API. Usage is subject to X's Terms of Service.
  • LinkedIn: We use LinkedIn API. Usage is subject to LinkedIn's User Agreement.
  • Threads: We use Threads API through Meta's platform integration.

Important: When you connect a social media account, you grant us permission to act on your behalf according to the permissions you grant. We only access and use data necessary to provide our services. You can revoke access at any time through your account settings or directly through the platform's settings.

4.2 Data Processing with Third Parties

We share data with third parties only in these circumstances:

  • Social Media Platforms: To post content and retrieve analytics data as authorized by you.
  • Polar.sh: For payment processing and subscription management. Polar.sh operates as an independent data controller for payment data.
  • Hosting Providers: We use Supabase (hosted on cloud infrastructure) for data storage and processing. Data is stored in secure, encrypted databases.
  • Datafa.st: Cookieless web analytics for our public landing pages. Datafa.st receives anonymized pageview and event data; it does not store IP addresses and does not collect personally identifiable information. See datafa.st/privacy-policy.
  • Service Providers: We may use additional third-party services for error monitoring and customer support. These providers are contractually obligated to protect your data.

We do not sell your personal information to third parties.

5.Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: OAuth tokens and sensitive credentials are encrypted at rest and in transit using industry-standard encryption algorithms.
  • Authentication: Secure authentication using Supabase Auth with password hashing and secure session management.
  • Access Controls: Row-level security policies ensure users can only access their own data.
  • Secure APIs: All API communications use HTTPS/TLS encryption.
  • Regular Audits: We conduct regular security assessments and updates.
  • Data Minimization: We only collect and store data necessary for service functionality.

Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

6.Your Rights and Choices

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update or correct inaccurate personal information through your account settings.
  • Deletion: Request deletion of your account and associated data.
  • Data Portability: Request a machine-readable copy of your data in a structured format.
  • Opt-Out: Unsubscribe from marketing communications (service-related communications are required).
  • Revoke Access: Disconnect social media accounts at any time through your account settings or directly through the platform.
  • Withdraw Consent: Withdraw consent for data processing where consent is the legal basis.

To exercise these rights, contact us at privacy@posteahora.com or through your account settings. We will respond within 30 days.

California Residents (CCPA): You have the right to know what personal information we collect, sell, or disclose, and the right to opt-out of the sale of personal information (we do not sell personal information). You also have the right to non-discrimination for exercising your privacy rights.

EU/UK Residents (GDPR): You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

7.Children's Privacy

PosteAhora is not intended for users under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children under 13. If we discover that we have collected information from a child under 13, we will delete it immediately. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@posteahora.com.

In compliance with Meta's policies, we do not share information about children under 13 with Facebook or any third party.

8.Data Retention

We retain your personal data for as long as necessary to provide our services and fulfill the purposes described in this policy:

  • Account Data: Retained while your account is active and for 30 days after account deletion (unless longer retention is required by law).
  • Content Data: Retained until you delete the content or your account.
  • OAuth Tokens: Retained while accounts are connected and deleted immediately upon disconnection.
  • Analytics Data: Retained for 24 months from the date of collection for historical analysis.
  • Payment Records: Retained for 7 years as required by tax and accounting laws (managed by Polar.sh).

9.International Data Transfers

Your data may be stored and processed in countries other than your country of residence. Data transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) for EU/UK data transfers, and we ensure that data processors meet our security and privacy standards.

10.Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. We may also notify you via email or in-app notification for significant changes. Your continued use of PosteAhora after changes become effective constitutes acceptance of the updated policy.

11.Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

PosteAhora

PosteAhora

Operated by: Aleksandr Borisov

CUIT: 27-96484697-4

Tax Regime: Monotributo · Categoría A

Address: LAPRIDA 1283 Piso:2 Dpto:C, 1425-Ciudad Autónoma de Buenos Aires, Argentina

This Privacy Policy complies with GDPR, CCPA, Argentina's Personal Data Protection Law (Ley 25.326), Meta Platform Terms, TikTok Developer Guidelines, and Polar.sh Merchant Requirements.