Privacy Policy
Effective Date: August 31, 2026
1. Introduction
This Privacy Policy describes how Tap & Swipe ("we", "us", "our") collects, uses, and protects information when you use Postback ("Service"), including our SDK, dashboard, API, signal links, and integrations.
Postback is mobile measurement infrastructure for app developers. For End-User Data, Postback acts as a data processor or service provider on behalf of our clients. Our clients (app developers) are the data controllers or businesses that decide why and how End-User Data is collected, which Postback features are enabled, which events are sent, and which integrations are configured.
Postback is not an ad network, data broker, or cross-app advertising network. We do not sell End-User Data, build cross-client end-user profiles, use End-User Data for Postback's own advertising or retargeting, or independently decide to share End-User Data with ad networks.
For clarity, this Policy distinguishes between Client Data (information about account holders and their apps) and End-User Data (device, click, install, event, and attribution data processed on behalf of our clients).
2. Data We Collect
2.1 Client Data (Account Holders)
When you create an account and use the dashboard, we collect:
- Account information: Name, email address, and profile image when provided through Google OAuth or GitHub OAuth
- Company information: App name, bundle identifiers, and platform details
- Billing information: Payment details are processed and stored by Whop. We store the Whop membership and plan identifiers, subscription and renewal state, billing-period dates, and receipt metadata needed to show and manage billing in the Postback dashboard
- Dashboard usage data: Pages visited, features used, and session data for improving the Service
2.2 End-User Data (Collected via SDK)
When a client integrates our SDK or API, Postback processes End-User Data on that client's behalf. Depending on the platform, operating-system availability, device state, client configuration, and applicable permission status, this may include:
- Device and install identifiers: A random Postback install identifier; IP address and user agent; IDFV on iOS; IDFA only when iOS already reports ATT authorization; and GAID or other platform advertising identifiers on Android when available under platform settings
- Device and app context: Device model and hardware family, operating-system and app versions, SDK version, screen dimensions and scale, processor and memory class, touch capability, battery and low-power state, preferred languages, locale, timezone, graphics renderer, color scheme, connection and radio category, and diagnostic network state such as VPN, Low Data Mode, or an expensive connection
- Attribution context: Signal-link and referrer data, ad click identifiers, campaign and UTM parameters, Apple AdServices attribution when enabled, install and event timestamps, and conservative install lifecycle classification
- App activity: Sessions and client-defined in-app events, including revenue and currency when the client chooses to send them
- Request and security metadata: Network request headers, HTTP and TLS characteristics, Cloudflare request context, and approximate geographic context derived from IP address. Postback does not collect precise GPS location through its SDK
The iOS SDK does not display or initiate an ATT prompt. If a host app has not already obtained authorized ATT status, IDFA is omitted. Other app-scoped identifiers and device context may still be processed for client-directed attribution, analytics, diagnostics, and fraud prevention. Postback deliberately does not collect iOS carrier name, carrier country, MCC, MNC, or SIM identity.
The SDK does not access end-user contacts, photos, microphone, camera, health data, messages, or other personal content. Clients should not send raw names, email addresses, phone numbers, or other direct identifiers through event parameters or customer identifiers.
2.3 Signal Link Click Data
When an end user clicks a signal link or TikTok App Profile, we collect request metadata and browser-side context such as screen size, locale, timezone, and graphics renderer when available. We use this information for link analytics and probabilistic click-to-install attribution on supported platforms, including iOS and Android.
2.4 Google User Data
This section explains specifically how Postback accesses, uses, stores, protects, shares, retains, and deletes data received through Google Sign-In. Google Sign-In data is Client Data about the Postback account holder; it is not End-User Data collected through a client's mobile app.
Data Accessed
When a client chooses Continue with Google, Postback requests only openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile. These scopes allow Postback to access:
- The client's unique Google Account identifier
- The client's name
- The client's email address and whether Google reports it as verified
- The client's Google profile image, when available
- OAuth tokens and related metadata returned by Google to complete sign-in, such as token type, authorized scopes, and expiration time
Postback does not use Google Sign-In to access Gmail, Google Drive, Google Contacts, Google Calendar, Google Ads, or any other Google product data. The Google Sign-In OAuth client is limited to dashboard authentication and does not request the Google Ads adwords scope.
Data Usage
Postback uses Google user data only to:
- Authenticate the client and create, link, or access the correct Postback account
- Maintain and secure the client's Postback session, prevent account confusion, and record the authentication provider and last sign-in time
- Display the client's name and profile image in the dashboard
- Send welcome, onboarding, service, billing, and security messages about the client's Postback account
- Respond to account and support requests
Postback does not use Google user data for advertising, retargeting, interest-based profiling, data brokerage, credit or lending decisions, or training generalized artificial intelligence or machine-learning models. We do not sell Google user data or use Google OAuth tokens to access Google services beyond the authentication described above. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Data Sharing
We disclose Google user data only to the following service-provider categories, and only as needed to operate Postback:
- Cloudflare processes sign-in requests and provides hosting, network security, and application infrastructure
- Neon hosts the database where the Postback account record and OAuth account data are stored
- Self-hosted Plunk and Amazon SES process the client's email address and name, but not OAuth tokens or the Google profile image, to deliver welcome, onboarding, and account-related email
These providers process data for us under their applicable contractual and data-protection obligations. We do not share Google user data with ad networks, revenue platforms, data brokers, other Postback clients, or other third parties for their own purposes. We may disclose data when legally required, as described in Section 4.6. A business transfer involving Google user data will be handled as described in Section 4.7 and with explicit prior user consent where required by Google policy.
Data Storage and Protection
Postback stores the Google Account identifier, name, email address, profile image URL, OAuth tokens returned by Google, and related OAuth metadata in its managed Neon database. OAuth data is handled server-side and is not exposed through the Postback dashboard. Dashboard sessions use signed, secure, HTTP-only cookies.
Google user data is encrypted in transit using HTTPS/TLS and is protected at rest by provider-managed database and storage encryption. Access to production systems is limited to authorized personnel, protected with multi-factor authentication, and subject to the security controls described in Section 9.
Data Retention and Deletion
We retain Google user data while the client's Postback account remains active. If the account is terminated without an immediate deletion request, we retain Client Data for a 90-day grace period and then delete the Google profile data, OAuth account association, and stored OAuth tokens. Limited billing or legal records may be kept for the periods described in Section 6 when required by law; Google OAuth tokens and the Google profile image are not retained as billing records.
A client may request deletion at any time by emailing hello@postback.sh with the subject "Google Data Deletion" and the email address used for the Postback account. After verifying the request, we will delete the client's Google user data from active systems within 30 days, except for records we must retain by law. Residual copies may remain temporarily in encrypted backups or security logs until their normal rotation and are not used for any other purpose.
A client may also revoke Postback's Google access from the Google Account permissions page. Revocation prevents future Google access but does not by itself delete data already stored in the Postback account; the client must use the deletion process above to request that deletion.
2.5 Support Chat
We use Crisp for support chat on Postback dashboard pages. Crisp processes messages, attachments, and contact details you choose to share, together with technical information such as your IP address, browser and device details, pages visited, and a session cookie that keeps your conversation available. While you are signed in, we automatically share your internal Postback user and organization identifiers, plus the identifier of the app you are viewing, so our support team can locate the correct account and app records. The app identifier updates as you navigate and is cleared on account-level pages. These account identifiers are not attached to chat on the login page, and signing out resets the chat session in your browser.
This integration does not automatically send your Postback account name or email address to Crisp. The chat widget is not included in the Postback mobile SDKs. You can also contact us by email at hello@postback.sh.
3. How We Use Data
We use data only to provide, secure, maintain, and improve the Service for our clients. For End-User Data, we process data under the client's instructions for the following purposes:
- Attribution matching: Matching ad clicks to app installs and in-app events to marketing Signal Campaigns
- Analytics dashboards: Displaying attribution data, Signal Campaign performance, and conversion metrics to clients in the dashboard
- Client-configured integrations: Sending selected attribution, event, or conversion data to ad networks and revenue platforms only when configured by the client
- Billing: Processing payments and managing subscriptions via Whop
- Security and reliability: Preventing abuse, debugging issues, maintaining uptime, and protecting the Service
- Service improvement: Analyzing aggregated or anonymized usage patterns to improve the Service
- Communication: Sending account-related notifications (billing, service updates, security alerts) and responding to support requests
We do not sell End-User Data to third parties. We do not combine End-User Data from one client with End-User Data from another client to create cross-client profiles. We do not use End-User Data for Postback's own advertising, retargeting, lookalike modeling, or interest-based profiling.
4. Data Sharing
4.1 Ad Networks (Client-Configured)
Ad network integrations are disabled unless a client explicitly sets up and enables them. When a client configures an ad network integration, Postback sends selected attribution, install, event, or conversion data to the respective ad network at the client's direction, for the client's own advertising account or campaign measurement. Supported networks include:
- Apple Search Ads
- TikTok Ads
- Meta Ads
No End-User Data is sent to ad networks unless the client explicitly configures the integration. The client is responsible for ensuring that their use of each ad network integration is allowed by applicable law, their own privacy disclosures, app store rules, and the ad network's terms.
4.2 Revenue Platforms (Client-Configured)
When configured by the client, we exchange data with revenue platforms such as RevenueCat and Superwall for revenue attribution. These integrations operate only for the client's app and only under the client's configuration.
4.3 Infrastructure Providers
We use Cloudflare for hosting, security, and infrastructure services. We use Neon Postgres as our managed database provider for Postback product, account, attribution, and analytics data. These providers process data on our behalf under their respective data processing terms.
4.4 Payment Processor
Whop processes all payment information. See Whop's privacy policy.
4.5 Email
We use self-hosted Plunk with Amazon SES for transactional email delivery (account notifications, billing alerts).
4.6 Legal Requirements
We may disclose data when required by law, regulation, legal process, or governmental request, or when necessary to protect the rights, safety, security, or integrity of Postback, our clients, end users, or others.
4.7 Business Transfers
If Tap & Swipe or Postback is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, Client Data and End-User Data may be transferred to the successor or acquiring entity as part of that transaction. We will require any successor to protect the data consistently with this Policy and applicable law, and we will notify clients if a transaction materially changes how data is processed.
4.8 Customer Support
We use Crisp IM SAS to operate support chat and manage support conversations. Crisp processes the support-chat information described in Section 2.5 on our behalf. See Crisp's privacy statement.
5. Data Processor Role
Postback operates as a data processor under GDPR and as a service provider or processor under similar privacy laws:
- Our clients (app developers who integrate the SDK) are the data controllers. They determine the purposes and means of processing End-User Data
- Postback processes End-User Data solely on behalf of and under the instructions of our clients
- Clients are responsible for obtaining appropriate legal basis, consent, notices, platform permissions, and app store disclosures for data collection and integration use
- We process End-User Data only as necessary to provide the measurement, attribution, analytics, and integration features requested by the client
- We do not independently monetize, sell, or repurpose End-User Data outside the client-directed Service
For details on our data processing practices and to request a Data Processing Agreement (DPA), contact us at hello@postback.sh.
6. Data Retention
- Active accounts: Client Data and attribution data are retained for the duration of the active account
- Account termination: Data is retained for a 90-day grace period after termination, during which clients may request data export. After 90 days, all Client Data is permanently deleted
- Billing records: Retained for 5-10 years as required by French tax and accounting regulations
- Click data: Raw click data used for attribution matching is retained for 30 days
- Aggregated analytics: Anonymized, aggregated data may be retained indefinitely
- Backups and logs: Deleted data may remain in encrypted backups or security logs for a limited period until those backups or logs rotate, unless longer retention is required by law
7. Opt-Out Mechanisms
End users can limit data collection through:
- iOS settings: The SDK never displays an ATT prompt. When iOS reports that ATT is not authorized, Postback omits IDFA. Apple Search Ads attribution uses Apple's AdServices framework independently of IDFA
- Android Advertising ID: End users can reset or opt out of their advertising ID in device settings
- SDK Configuration: Clients can configure the SDK to disable specific data collection features
- Client deletion or suppression requests: Clients can ask us to delete, suppress, or export End-User Data when needed to honor a valid privacy request
Clients are responsible for deciding whether their complete app, other SDKs, and client-configured integrations require consent prompts or updated App Store and Google Play privacy disclosures.
8. Children
Postback does not knowingly collect data from children under the age of 13 (or 16 in the EU).
Our clients are prohibited from integrating the Postback SDK into apps that are directed at children (see our Terms of Service). If we become aware that a client is using our SDK in a child-directed app, we will terminate their access and delete the associated data.
If you believe we have inadvertently collected data from a child, please contact us immediately at hello@postback.sh.
9. Data Security
We implement appropriate technical and organizational measures to protect data:
- All data in transit is encrypted using HTTPS/TLS
- Data at rest is protected by provider-managed database and storage encryption where supported
- Infrastructure is hosted on Cloudflare and Neon with industry-standard security controls
- Access to production systems is restricted to authorized personnel with multi-factor authentication
- API keys are hashed before storage. We never store plaintext API keys
- Regular security reviews of our codebase and infrastructure
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we take commercially reasonable steps to protect your data.
10. International Transfers
Data may be processed in the following regions:
- Cloudflare (global network): Hosting, security, and infrastructure services
- Neon (US): Managed Postgres database hosting for Postback product data
Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.
11. Your Rights (GDPR)
For Clients (Account Holders)
As a client, you have the following rights regarding your personal data:
- Right of access (Article 15): Request a copy of the personal data we hold about you
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data
- Right to erasure (Article 17): Request deletion of your personal data
- Right to restriction (Article 18): Request that we limit how we use your data
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format
- Right to object (Article 21): Object to processing based on legitimate interests
- Right to lodge a complaint: File a complaint with the CNIL or your local supervisory authority
To exercise any of these rights, contact us at hello@postback.sh with "GDPR Request" in the subject line.
For End Users
If you are an end user of an app that uses Postback, your data is controlled by the app developer. To exercise your GDPR rights, please contact the app developer directly. As a data processor, we will assist the app developer in fulfilling your request.
Data Protection Authority
For users in France, the supervisory authority is:
CNIL (Commission Nationale de l'Informatique et des Libertés)
- Website: https://www.cnil.fr/fr
- Address: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, France
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the "Effective Date" above
- Notifying clients via email for material changes
Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
13. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: hello@postback.sh
Entity: Tap & Swipe
Service: Postback
Location: France
By using Postback, you acknowledge that you have read and understood this Privacy Policy.