Privacy Policy
Last updated: 3 October 2026
1. Controller and scope
Dreambig Brand EOOD is the controller of personal data processed through Postlocal. This policy explains how we handle personal data when you visit Postlocal, create an account, use our publishing service, or contact us.
Dreambig Brand EOODSliven, Bulgaria
UIC / VAT ID: BG207940011
Email: hello@postlocal.io
2. Data we collect
- Account data: your name or brand name, email address, password authentication data and legal-acceptance record.
- Service data: selected markets, requested usernames, account setup details, captions, uploaded videos, publishing schedule and publication URLs.
- Support and operational data: messages you send us, device and browser information needed to secure the service, and records of account or support actions.
- Billing data: subscription and payment status, invoices and payment identifiers. Card details are handled by Stripe and are not stored by Postlocal.
3. Why we use data and our legal bases
- To create and run your account, publish your submitted content, provide support and process payments: performance of our contract with you.
- To secure the service, prevent fraud or misuse, enforce our Content Policy, and protect platform accounts: our legitimate interests and those of our customers.
- To keep tax, accounting and other legally required records: compliance with legal obligations.
- For optional marketing only where we separately ask for and receive your consent. You may withdraw that consent at any time.
We do not sell personal data or use your uploaded content to train advertising or AI models.
4. Who receives data
Access is limited to authorised Postlocal personnel and service providers that help us operate the service, including Supabase for authentication, database and file storage, and Stripe for payments. We may disclose information where required by law, to protect legal rights or safety, or in connection with a corporate transaction. When a provider processes data outside the EEA, we use an appropriate transfer mechanism where required by law.
5. Retention and security
We retain account and service data while your account is active and for as long as reasonably necessary to provide the service, resolve disputes, enforce agreements and meet legal obligations. Billing, tax and audit records may be retained for longer where law requires. We use access controls, encrypted connections and other reasonable technical and organisational measures, but no system can be guaranteed completely secure.
6. Your rights
Subject to applicable law, you can request access, correction, deletion, restriction, objection, or portability of your personal data. You can also withdraw consent where processing is based on consent. Contact us at hello@postlocal.io. We may need to verify your identity and will respond within the period required by law. You may also complain to the Bulgarian Commission for Personal Data Protection or your local data-protection authority.
7. Changes
We may update this policy when our processing changes or the law requires it. The current version and effective date are always posted on this page.