Privacy Policy

Effective date: May 5, 2026  |  Postplan — Social Media Scheduling Platform

This Privacy Policy explains how Postplan ("the Platform", "we", "us", "our") collects, uses, stores, and protects information when you use our content scheduling and publishing service. Postplan is a social media automation platform that enables tourism businesses, travel agencies, tour operators, and content creators to automatically publish scheduled content to TikTok, VKontakte (VK), and Telegram.

By connecting your social media accounts to Postplan, you acknowledge that you have read and agree to this Privacy Policy.

1. Information We Collect

We collect only the data strictly necessary to provide the scheduling and publishing service. This includes:

We do not collect: passwords, payment information, contacts, private messages, browsing history, precise location data, biometric data, or information about third parties.

2. How We Use Your Information

The information we collect is used exclusively for the following purposes:

We do not sell, rent, trade, or otherwise share your data with any third party. Data is not used for advertising, profiling, or any purpose beyond operating the service.

3. Legal Basis for Processing

The Platform processes your social media account data on the basis of your explicit consent, granted when you authorize access through TikTok's OAuth flow. You may withdraw this consent at any time by revoking the Platform's access to your account (see Section 6).

4. Data Storage and Security

OAuth tokens and configuration data are stored in an encrypted database on a dedicated server. Access to the server is strictly controlled and limited to authorized personnel only.

No token or credential is ever logged in plaintext, included in error messages, or transmitted to any service other than TikTok's official API endpoints (open.tiktokapis.com). All communication with TikTok's API is performed over HTTPS with TLS encryption.

5. Data Retention

OAuth tokens are retained until you disconnect your account from the Platform or request deletion of your data. Publishing logs are retained for 90 days for operational monitoring purposes, after which they are automatically purged.

You may request deletion of all stored data at any time by contacting us (see Section 7). Upon receiving a valid request, we will delete all associated data within 30 days.

6. Revoking Access

You can revoke the Platform's access to your TikTok account at any time:

  1. Log in to TikTok and go to Settings → Privacy → Connected Apps .
  2. Find Postplan in the list and tap Remove access.
  3. Revocation takes effect immediately. All stored tokens become invalid and the Platform will cease all publishing activity for that account.

7. Your Rights

You have the right to:

To exercise any of these rights, contact us at bolotin.energy@gmail.com.

8. Third-Party Services

The Platform interacts with the following third-party services solely to perform its function:

We do not integrate any analytics, advertising, or tracking services.

9. Children's Privacy

The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided data to us, contact us immediately and we will delete it.

10. International Data Transfers

Your data may be processed on servers located outside your country of residence. By using the Platform, you consent to this transfer. We apply appropriate safeguards to ensure your data remains protected in accordance with this Privacy Policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we will update the effective date at the top of this page. Continued use of the Platform after changes are posted constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:
Email: bolotin.energy@gmail.com