Terms of Service

Effective Date: July 24, 2026

1. Acceptance of Terms

These Terms of Service ("Terms") constitute a legally binding agreement between you ("Client", "you") and Tap & Swipe ("we", "us", "our") regarding your use of Postback ("Service"). By creating an account, integrating our SDK, or otherwise accessing the Service, you agree to be bound by these Terms. If you do not agree, do not use the Service.

2. Description of Service

Postback is mobile measurement infrastructure for app developers. We provide SDK, dashboard, API, signal link, and integration tools that you control and configure for your own apps. Postback is not an ad network, data broker, or cross-app advertising network.

  • Attribution SDK: A lightweight mobile SDK that processes app install, device, event, and attribution data for your app under your configuration
  • Attribution Dashboard: A web-based dashboard for viewing attribution data, Signal Campaign performance, and conversion analytics
  • Attribution API: RESTful API endpoints for programmatic access to attribution data
  • Ad Network Integrations: Client-configured integrations with ad networks (Apple Search Ads, TikTok, Meta, Google) and revenue platforms (RevenueCat, Superwall)
  • Signal Links: Customizable signal links for Signal Campaign measurement

3. Eligibility

You must be at least 18 years of age and have the legal capacity to enter into these Terms. If you are using the Service on behalf of a company or organization, you represent and warrant that you have authority to bind that entity to these Terms.

4. Account & Access

4.1 Account Creation

Access to the Postback dashboard requires authentication via Google OAuth. You are responsible for maintaining the security of your Google account and for all activity that occurs under your account.

4.2 API Keys

Upon creating an App within the dashboard, you will receive API keys for SDK integration. You must keep your API keys confidential and must not share them publicly. You are responsible for all API calls made with your keys.

4.3 Account Security

You agree to notify us immediately at hello@postback.sh if you become aware of any unauthorized use of your account or API keys.

5. Service Plans

5.1 Trial and Event Allowances

Postback may offer no free trial, a 7-day free trial, or a 14-day free trial on standard paid plans. The checkout page states the trial length and amount due before purchase, and those displayed terms control your subscription. Each plan includes a fixed organization-wide monthly Event allowance. Unless a different written agreement applies, allowances reset at the beginning of each UTC calendar month, including for annually billed plans. Unused Events do not roll over.

For billing purposes, one "Event" means one of the following newly persisted production records:

  • An app install, whether attributed to a paid source or classified as organic
  • An accepted SDK event, including a session, custom event, trial, purchase, or subscription event
  • An accepted normalized event from a connected revenue provider such as RevenueCat or Superwall

Each accepted item in a batch counts separately. A retry or duplicate delivery that does not create a new record does not count again.

Test events, customer identity updates, signal-link clicks, invalid or unsupported webhook payloads, sandbox webhook payloads, webhooks for unknown installs, data lookups, configuration requests, and outbound delivery attempts do not count as Events.

5.2 Paid Plans

Standard Starter plans begin at $9 per month for 10,000 Events and include 1 app. Standard Growth plans begin at $19 per month for 10,000 Events and include up to 10 apps. Higher fixed Event allowances are available on the pricing page. Annual plans are charged at ten times the corresponding monthly price and retain a monthly Event allowance. Plans above 20 million Events per month require a custom agreement. Pricing, features, and limits are subject to change with 30 days' notice.

5.3 Allowance Handling

Postback does not automatically charge usage overages on standard plans. When you reach your monthly Event allowance, Postback may continue accepting Events and processing configured outbound deliveries so that your data is not silently lost. Access to analytics and reporting may be restricted until you move to a plan with a higher allowance or the next UTC calendar month begins. Billing, settings, and integration configuration remain available. We may notify you as you approach or reach your allowance.

5.4 Billing

All payments are processed through Whop. Paid subscriptions renew automatically unless cancelled. You may upgrade, downgrade, cancel renewal, or restore renewal from the Postback dashboard. A cancellation takes effect at the end of the current paid period unless we clearly state otherwise. Subscription changes become effective after Whop confirms them to Postback.

6. Client Obligations

6.1 Privacy Law Compliance

You are the data controller, business, or equivalent responsible party for End-User Data processed through your app and your Postback workspace. We process End-User Data as your processor or service provider, under your instructions. You are solely responsible for complying with all applicable privacy laws and regulations (including GDPR, ePrivacy Directive, CCPA/CPRA, and any other local laws) in the jurisdictions where your app operates. This includes but is not limited to:

  • Providing clear and accurate privacy disclosures to your end users
  • Obtaining all necessary consents, permissions, and legal bases for data collection and processing
  • Honoring opt-out requests and privacy preferences
  • Maintaining a compliant privacy policy in your app
  • Correctly completing Apple App Store privacy details, Google Play Data safety answers, and any other platform privacy disclosures
  • Ensuring your use of Postback and any enabled integrations complies with applicable app store, ad network, and platform policies

6.2 End-User Consent

You must obtain appropriate consent from your end users before the Postback SDK collects and transmits data when required by applicable law and platform rules. The iOS SDK does not request App Tracking Transparency permission. It accesses IDFA only when the host app already has authorized ATT status, and otherwise omits it; other app-scoped identifiers and device context may still be processed as described in our Privacy Policy. You must respect platform settings, consent management choices, opt-out signals, and any privacy controls that apply to your complete app and integrations.

You are responsible for determining whether your specific use of Postback, signal links, attribution matching, or third-party integrations constitutes "tracking", "sharing", "sale", advertising measurement, or any similar regulated activity under applicable law or platform policy. You must not enable or continue using a feature or integration unless you have the required notices, consents, permissions, contractual rights, and platform disclosures.

6.3 No Child-Directed Apps

You must NOT integrate the Postback SDK into any app that is directed at children under the age of 13 (or 16 in the EU). If your app targets a mixed audience, you must ensure the SDK is not activated for users identified as children.

6.4 Accurate Data

You agree to provide accurate information when setting up your account, apps, and integrations. You are responsible for the accuracy of Signal Campaign and signal link configurations.

6.5 Integration Credentials and Permissions

If you connect ad network accounts, revenue platform accounts, or other third-party services to Postback, or if you provide API keys, OAuth tokens, or similar credentials, you represent that you have the authority to grant that access. You authorize and instruct us to use those credentials solely to provide the integrations you enable. You are responsible for maintaining the required third-party permissions and for revoking access when you no longer want an integration to operate.

When you enable a third-party integration, you instruct Postback to send the selected Client Data or End-User Data to that third-party destination for your account and your purposes. You represent that this disclosure is permitted by applicable law, your own privacy disclosures, app store rules, ad network terms, and any consents or permissions you have obtained.

6.6 Third-Party Platform Changes

Ad networks, app stores, revenue platforms, and other third-party services may change their APIs, permission scopes, reporting fields, attribution windows, approval rules, or data availability. We will use commercially reasonable efforts to adapt the Service, but we are not responsible for errors, delays, loss of features, missing reports, or data discrepancies caused by third-party changes or outages.

7. SDK License

7.1 License Grant

Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, revocable license to integrate and use the Postback SDK in your mobile applications solely for the purpose of mobile measurement, attribution, analytics, and the integrations you configure through the Service.

7.2 Restrictions

You agree NOT to:

  • Reverse engineer, decompile, or disassemble the SDK
  • Modify the SDK except as documented in our official documentation
  • Use the SDK to build a competing attribution or analytics product
  • Redistribute the SDK outside of your own applications
  • Use the SDK in a manner that violates any applicable law

8. Data Ownership

8.1 Your Data

As between you and Postback, you retain all rights, title, and interest in data generated by your apps, uploaded to the Service, or collected through the SDK under your configuration ("Client Data"). This includes attribution data, event data, install data, and revenue data.

8.2 Processing License

You grant us a limited license and instruction to process Client Data solely for the purpose of providing the Service, including attribution matching, analytics computation, account support, security, reliability, and client-configured integrations.

8.3 Aggregated Data

We may use anonymized, aggregated data that cannot identify individual end users or clients to improve the Service. This data will never be shared with third parties in a way that could identify you or your end users.

9. Prohibited Data

You must NOT use the Postback SDK or Service to collect, transmit, or process:

  • Health or medical data
  • Social security numbers or government identifiers
  • Financial account numbers (bank accounts, credit card numbers)
  • Data from children under 13 (or 16 in the EU)
  • Any data classified as "sensitive" or "special category" under GDPR Article 9
  • Any data whose collection would violate applicable law

10. Third-Party Integrations

10.1 Ad Network Integrations

Postback supports postback integrations with third-party ad networks including Apple Search Ads, TikTok, Meta, and Google. These integrations are client-configured only. No data is shared with ad networks unless you explicitly set up and enable the integration.

Ad network integrations may involve advertising measurement, conversion uploads, or event postbacks under the rules of the applicable ad network, app store, operating system, or privacy law. You are solely responsible for determining whether and how to enable these integrations, for obtaining any required end-user consent or platform permission, and for ensuring your App Store privacy details, Google Play Data safety answers, privacy policy, and other disclosures accurately describe your use.

10.2 Revenue Platforms

Integration with revenue platforms such as RevenueCat and Superwall is available and operates only when configured by you.

10.3 Third-Party Terms

Your use of third-party integrations is subject to those third parties' own terms of service, privacy policies, API policies, and platform rules. We are not responsible for the data practices of third-party services after data is sent to them at your instruction.

11. Prohibited Use

You agree NOT to:

  • Use the Service for any illegal or unauthorized purpose
  • Attempt to overload, disrupt, or interfere with the Service's infrastructure
  • Attempt to gain unauthorized access to the Service or other users' data
  • Resell, sublicense, or redistribute access to the Service
  • Use automated tools to abuse the API beyond reasonable usage
  • Circumvent rate limits or usage restrictions
  • Transmit malicious code through the SDK or API

12. Intellectual Property

The Service, including all software, code, design, documentation, and trademarks, is owned by Tap & Swipe and is protected by intellectual property laws. These Terms do not grant you any rights to our intellectual property except the limited licenses expressly stated herein.

13. Disclaimer of Warranties

TO THE MAXIMUM EXTENT PERMITTED BY LAW (SUBJECT TO MANDATORY CONSUMER PROTECTION LAWS FOR EU CONSUMERS), THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO:

  • Implied warranties of merchantability, fitness for a particular purpose, and non-infringement
  • Warranties regarding the accuracy or completeness of attribution data
  • Warranties that the Service will be uninterrupted, secure, or error-free
  • Warranties regarding the accuracy of install or event matching

Attribution data is provided on a best-effort basis. Due to the nature of mobile attribution (privacy frameworks, limited identifiers, network conditions), we cannot guarantee 100% accuracy of attribution matching.

Third-party data and integrations are provided on a best-effort basis. Reports and postbacks depend on data made available by app stores, ad networks, revenue platforms, device operating systems, and other third parties. Those sources may be incomplete, delayed, changed, or unavailable.

EU Consumer Notice: If you are an EU consumer, this disclaimer does not affect your statutory rights under applicable consumer protection laws.

14. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW (SUBJECT TO MANDATORY PROVISIONS FOR EU CONSUMERS):

14.1 EU Consumer Notice

For EU Consumers: Nothing in these Terms excludes or limits our liability for:

  • Death or personal injury caused by our negligence
  • Fraud or fraudulent misrepresentation
  • Any liability that cannot be excluded or limited under applicable consumer protection laws

14.2 Maximum Liability

Subject to Section 14.1, our total liability to you for all claims arising out of or relating to these Terms or your use of the Service shall not exceed the total amount you paid to us in the twelve (12) months preceding the claim, or 100 EUR if you have not paid any subscription fees.

14.3 Exclusion of Damages

Subject to Section 14.1, we shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, revenue, data, or business opportunities, even if we have been advised of the possibility of such damages.

14.4 Client Indemnity

To the maximum extent permitted by applicable law, you agree to defend, indemnify, and hold harmless Tap & Swipe from claims, damages, liabilities, costs, and expenses (including reasonable legal fees) arising from: your breach of these Terms; your app, content, or data; your use of the SDK or Service in violation of law, app store rules, ad network terms, or platform policies; inaccurate privacy disclosures; your failure to obtain required end-user consent, platform permission, or other legal basis; third-party integrations enabled by you; or your violation of any third-party rights.

15. Termination

15.1 By You

You may cancel your account at any time by contacting us at hello@postback.sh or through the dashboard.

15.2 By Us

We may terminate or suspend your access immediately, without prior notice, if you breach these Terms.

15.3 Data Retention After Termination

Upon account termination, your data will be retained for a 90-day grace period during which you may request export of your data. After the grace period, Client Data will be deleted or anonymized, except for billing records, security logs, encrypted backups awaiting rotation, or records we are required to retain by law.

15.4 Survival

Provisions that by their nature should survive termination shall survive, including data ownership, warranty disclaimers, limitation of liability, and governing law.

16. Governing Law

These Terms are governed by the laws of France. Any disputes arising from these Terms shall be subject to the exclusive jurisdiction of the courts of France.

EU Consumer Notice: If you are an EU consumer, you may also bring proceedings in the courts of the EU member state in which you reside. Nothing in these Terms affects your rights as a consumer to rely on mandatory provisions of the law of the country in which you live.

17. Changes to Terms

We may revise these Terms from time to time. We will provide at least 30 days' notice of material changes via email or through the dashboard. Your continued use of the Service after changes become effective constitutes acceptance of the revised Terms.

18. General Terms

  • Entire agreement: These Terms, together with any referenced policies or order terms, are the entire agreement between you and Tap & Swipe regarding the Service.
  • Severability: If any provision is held invalid or unenforceable, the remaining provisions remain in effect.
  • No waiver: Failure to enforce a provision does not waive our right to enforce it later.
  • Assignment: You may not assign these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, financing, reorganization, sale of assets, or by operation of law, provided the successor assumes our obligations under these Terms.
  • Independent parties: Nothing in these Terms creates a partnership, joint venture, employment, or agency relationship between you and Tap & Swipe.

19. Contact

For questions, concerns, or notices regarding these Terms, please contact us at:

Email: hello@postback.sh
Entity: Tap & Swipe
Service: Postback
Location: France