PAGES BY POSTPADDY — PRIVACY POLICY
Last updated: February 17, 2026
This Privacy Policy explains how PostPaddy LLC (“PostPaddy”, “we”, “us”) collects, uses, discloses, and protects information in connection with Pages by PostPaddy (the “Service”).
Not offered to EU/UK. The Service is not offered to residents of the European Union or the United Kingdom at this time. Do not use the Service if you are located in the EU/UK. If we unintentionally receive such data, we will delete it once identified.
1. Scope and Roles
1.1 Controller vs processor
Controller processing (PostPaddy decides why/how): account management, subscriptions/billing, security, fraud prevention, product analytics, and service improvement.
Processor processing (you decide why/how): visitor and lead data you collect through your Pages (for example Submissions). In that context, you are typically the controller and PostPaddy processes on your instructions.
If you publish Pages that collect Submissions or use tracking, you are responsible for providing required notices and obtaining consent from your visitors where required.
1.2 Who this policy applies to
This Policy covers:
users of the Service (account owners and teammates),
visitors to Pages published via the Service,
people who submit forms on your Pages,
visitors to our websites.
2. Information we collect
2.1 Account and profile information
Name, email, password hashes, brand/workspace information, team member data, settings, and support communications.
2.2 Billing and payment data
Subscription tier, invoices, billing address, and tax details (if required). Payments may be processed by third party processors (for example Stripe, Paystack). We do not store full payment card numbers.
2.3 Page content and configuration (Customer Content)
Page layouts, sections, text, media, templates, connected domains, DNS related configuration, and Page settings.
2.4 Submissions (lead data)
If your Page has forms, we collect the information visitors submit, which may include:
name, email, phone number,
free text responses,
selected product/service fields,
timestamps and metadata.
2.5 Visitor Data and analytics
Depending on your setup, we may collect:
page views and timestamps,
referrers and UTM parameters,
clicks, scroll depth, and conversion events,
device and browser information,
IP address (for security, integrity, rate limiting, and analytics).
2.6 Experiment and optimization data
When you run Experiments, we may collect:
Variant assignment,
conversion outcomes,
aggregated performance results per Variant,
logs related to Experiment operation.
2.7 Cookies and similar technologies
We use cookies/SDKs for:
authentication and security,
session management,
analytics and performance,
(where enabled) Experiment variant assignment.
If you add third party pixels or scripts (for example Meta Pixel, Google Analytics), those third parties may collect data directly from your visitors. You are responsible for disclosures and consent where required.
2.8 AI inputs and outputs
If you use AI Features:
inputs: prompts and page context you submit to the AI feature,
outputs: generated suggestions and drafts,
acceptance signals and credit usage.
We recommend you avoid submitting sensitive personal data unless necessary.
2.9 Derived and aggregated data
We may create aggregated and/or de identified statistics derived from Service operation (for example, overall conversion benchmarks). We do not attempt to re identify individuals from de identified aggregates.
3. How we use information
We use information to:
provide, operate, and maintain the Service,
publish Pages and serve Page content to visitors,
deliver Submissions to you and show them in your dashboard,
run Experiments and calculate results,
secure the Service, prevent fraud, and reduce abuse,
troubleshoot errors and improve performance,
communicate with you about updates, security alerts, and support,
enforce our Terms and comply with legal obligations.
No sale/share (CPRA style). We do not sell personal information. We do not share personal information for cross context behavioral advertising.
Disclosures to third parties
We share information with vendors and service providers (“sub processors”) only as needed to operate the Service, such as:
hosting, CDN, storage, and infrastructure,
database providers,
email delivery/notification providers,
analytics providers (for example GA4, Mixpanel),
monitoring and logging tools (for example Sentry),
AI model providers (when AI Features are used),
payment processors.
We may also disclose information:
to comply with law or lawful requests,
to protect rights, safety, and security,
in connection with a merger, acquisition, financing, or sale of assets.
We do not permit service providers to use Customer Data for their own marketing.
Data Retention
We retain personal data for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
Account and billing records may be retained for legal and accounting requirements.
Submissions are retained until you delete them or close your account, subject to backup rotation.
Visitor Data and Experiment logs may be retained for a limited time to support analytics, security, and audits.
When you delete data or close your account, we delete or de identify within a reasonable period (commonly 30 to 90 days), subject to lawful retention and backup cycles.
Security
We implement reasonable administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, role based access controls, logging, and monitoring. No method of transmission or storage is fully secure.
If we become aware of a material breach affecting Customer Data, we will notify affected users without undue delay.
Your choices and rights
Subject to applicable law, you may request to:
access and obtain a copy of your personal information,
correct inaccurate information,
delete information,
object to or restrict certain processing,
export information (data portability).
To exercise rights, email [email protected].
If you are a Customer collecting visitor data and Submissions, you are responsible for handling visitor requests related to that data. We support you as required under our DPA.
Children
The Service is not intended for anyone under 18. We do not knowingly collect personal information from children.
International transfers
The Service is not offered to EU/UK account holders. Data may be processed in the United States and other locations where we or our providers operate.
10. Changes
We may update this Policy. For material changes, we will provide notice (for example, in app or by email). Continued use after the effective date means you accept the updated Policy.
CONTACT
PostPaddy LLC
11900 Commerce Street, Apt 1307
Farmers Branch, Texas 75234, United States
Nigeria office: 24 Ibikunle Ave, off Awolowo Avenue, Bodija, Ibadan, Oyo State 200212, Nigeria
Email: [email protected] | [email protected]
Appendix A: Data Processing Addendum (summary)
If we process Customer Data (including Submissions) on your behalf, our Data Processing Addendum (DPA) applies. For a copy, contact [email protected].