Last updated: August 2026. This is a placeholder draft. Replace with the text your lawyer reviewed before launch.
The short version
- Postiba stores the minimum: email, password hash, subscription plan, marketplace connection status.
- Photos never leave your PC unless you publish a listing. All the cleanup and cropping happens on your PC.
- Marketplace login cookies stay on your PC, encrypted, in the Postiba local data folder. Our servers never hold them.
- Payments are processed by Stripe. We do not see your card.
- We use zero analytics cookies and zero third-party trackers on the website.
Data controller
Postiba, Replace this in Config/site.json with the registered business address.. Contact: support@postiba.com.
What we store on our servers
Account data: email, hashed password, display name, subscription plan, subscription status, billing period. Company profile: name, billing email, VAT number if you provided one. Audit log: identifier of actions you performed inside the desktop app, timestamp, error messages. No listing content, no photos, no marketplace credentials.
What stays on your PC
Your photos and processed variants. Your listing drafts. The cookies your browser saved when you logged into a marketplace inside Postiba, encrypted with a key derived from your Windows account. The local database of active listings and their sync status.
Where your data goes when you publish
When you publish a listing, the photos and text you selected are sent from Postiba directly to the marketplace API you targeted (Vinted, Depop, Poshmark, Mercari, eBay). Postiba servers are not in the middle. From that point on, the marketplace privacy policy governs how they handle the data.
Payments
Subscription payments are processed by Stripe Payments Europe Ltd (Ireland). Postiba receives a customer identifier, a subscription identifier, and the plan you are on. We do not see or store credit card numbers. Stripe privacy notice: stripe.com/privacy.
Emails we send
Sign-up verification (one-time code), password reset (one-time code), receipts and payment failure alerts (through Stripe). Zero marketing emails without your explicit opt-in.
Your rights (GDPR)
You can request access, correction, or deletion of your personal data at any time. Write to support@postiba.com. We reply within thirty days.
Data retention
Account data is kept while your account is active. When you delete your account, your data is erased within thirty days from our production database. Backups roll off within sixty days. Audit log entries are kept twenty-four months for security investigation, then erased.
Changes to this policy
Substantive changes are announced by email to the address on your account, at least thirty days before they take effect. The current version is always visible on this page with the last-updated date at the top.