Privacy Policy
This Privacy Policy explains how ТОВ «Смарт Інфосервіс» (the “Company”, “we”, “us”) processes personal data when you visit or use SocialPro / Social Publisher, our WordPress-based social media publishing workspace.
Effective date: September 16, 2026
Service operator and privacy contact: ТОВ «Смарт Інфосервіс» · smartsitepro@gmail.com
1. Scope and responsibility
This policy covers this website, the publishing workspace and its connections to Facebook, Instagram, TikTok and, when used, YouTube. The Company is responsible for the processing described here. Account holders and authorized administrators must have the necessary rights to provide content and authorize publishing on each connected account.
Social networks operate independently and apply their own privacy policies to their services and to content published there. This policy does not replace those policies or imply that any platform has endorsed or approved our service.
2. Information we process
- Workspace and client information: WordPress administrator account information, client names, notes and associations between clients and connected social accounts.
- Connected account information: platform account identifiers, account or Page names, usernames where provided, channel identifiers, available publishing permissions and account-specific publishing restrictions.
- Authorization information: access tokens, refresh tokens where issued, expiry information and authorization grants. We receive these through the platform's authorization flow; the publishing integration does not request or store your Facebook, Instagram, TikTok or Google account password.
- Content and publication records: uploaded images and videos, captions, descriptions, hashtags, selected destinations, publication times, visibility choices, audience choices, commercial and AI-content disclosures, immutable scheduled content snapshots, processing status, returned publication identifiers and error or activity records.
- Technical and support information: authentication cookies and information you send in privacy or support correspondence. WordPress and hosting infrastructure may process IP addresses, browser and request information, security events and server logs to deliver and protect the website.
The installed publishing modules do not request private messages, contact lists, advertising campaign data or follower lists. Information available to an integration depends on the permissions you authorize and the platform's response.
3. How social platform data is used
Facebook and Instagram: Meta permissions are used to discover Pages the authorizing user can manage, identify the professional Instagram account linked to a Page, obtain the account identifiers needed for publishing, and publish approved content to the selected Facebook Page or Instagram account. Page and account information is used for account selection, authorization checks and publication delivery.
TikTok: the TikTok integration uses authorized account identity and current creator publishing settings to identify the destination and respect its publication limits. Approved video files, captions, interaction choices and required disclosures are submitted to the selected account. The service tracks the existing publication operation until the platform reports its result. TikTok Business Organic API and TikTok Direct Post are separate integrations, each subject to its own permissions and availability.
YouTube, when connected: Google authorization is used to identify the authorized channel and upload approved videos with their title, description, visibility and audience settings. The service stores and checks the resulting upload and processing status.
We use platform data to provide the authorized publishing functions and their necessary security, troubleshooting and support. We do not sell platform data, use it for targeted advertising, or use it to train artificial intelligence models.
4. Purposes and grounds for processing
We process data to operate the workspace, connect accounts you choose, prepare and schedule content, deliver authorized publications, refresh supported account authorization, prevent duplicate delivery, maintain security, resolve failures and respond to data requests.
Where applicable law requires a legal basis, processing relies on providing the service requested by you or your organization, your consent where required, our legitimate interests in securely operating and supporting the service, or a legal obligation. Platform authorization allows the requested API access; it is not a substitute for any separate consent required by law. You may withdraw consent or revoke account access, subject to processing that remains necessary on another lawful basis.
5. Disclosure and publicly accessible media
Content, publication settings, account identifiers and the credentials needed for an authorized request are transmitted to the social platform you select. Administrators with workspace access can view client records, prepared content and publication history. Hosting and backup providers process the installation's data as needed to provide their infrastructure. We may disclose information when legally required or when necessary to protect lawful rights and security.
Uploaded media is stored at publicly accessible URLs so platforms can retrieve it. Anyone who obtains such a URL may be able to access the file, even before the scheduled publication. A private workspace or private destination choice does not make the original uploaded media URL private. Do not upload confidential material that must remain inaccessible on the public web.
Publishing makes content available according to the destination platform's settings and moderation. Published material may be viewed, copied or shared by others. The service does not control a platform's independent processing or other people's copies.
6. Retention and backups
Authorization credentials are kept while needed for the connected account. Disconnecting removes the locally stored credentials and cancels waiting publication jobs. A revoked grant may also need to be removed in the platform's account settings.
Publication activity logs are automatically cleaned according to the workspace retention setting, currently 90 days. Client records, prepared content, uploaded media, connected account records, scheduled job snapshots, publication history and encrypted operation records do not all have an automatic expiry. They remain until the Company removes them or acts on an authorized deletion request. We retain them only as needed for the service, resolving publication outcomes and any applicable legal requirements, and remove data that is no longer required.
Hosting backups and server logs have separate retention arrangements and are not erased immediately by disconnecting an account or deleting a live record. For a deletion request, we also address copies with the relevant infrastructure provider; backup copies are removed or expire under its applicable retention cycle. If a backup must be restored, applicable deletion requests must be reapplied. Contact us for details of the hosting arrangements in effect for this installation.
7. Security
The workspace is restricted to authorized WordPress administrators. Social authorization credentials, app secrets and sensitive publication operation state are encrypted in the database. Production access and platform transfers must use HTTPS. Administrators are responsible for protecting their login access, hosting access, backups and encryption configuration.
These measures reduce risk but cannot guarantee absolute security. Public media URLs, published content, hosting infrastructure and the social platforms have their own security characteristics.
8. Cookies and international processing
WordPress uses necessary authentication and session cookies for administrator access. The publishing modules do not add advertising cookies or analytics trackers. A social platform may use its own cookies when you visit its authorization screen; its policy applies there.
Hosting providers and social platforms may process data in countries different from your own. We use the safeguards required by applicable law for transfers for which the Company is responsible. Platform-operated transfers are described in each platform's privacy policy.
9. Your choices and rights
You may choose whether to connect an account, revoke its platform authorization, and ask us about personal data related to you. Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent and complain to the competent data protection authority. These rights may be subject to identity verification and lawful exceptions.
Send requests to smartsitepro@gmail.com. Include the relevant platform, account identifier or username and what you want us to do. We may request proportionate information to verify that you control the account or are authorized to act for its owner. Do not send passwords, app secrets or access tokens. We respond within the period required by applicable law and explain any lawful reason preventing full completion.
10. Revoking access and requesting deletion
- In the workspace, open Social Accounts and disconnect the relevant account, or ask its authorized administrator to do so. This clears local credentials and cancels waiting jobs.
- To revoke the grant at the platform, remove the application in Facebook's Business integrations / Apps and websites, TikTok's connected app permissions, or your Google Account's third-party connections, as appropriate. Platform menu names may change.
- For removal of stored service data, email smartsitepro@gmail.com with the subject Social Publisher data deletion, the platform and account identifier, and the requested scope. We verify authorization and arrange deletion of associated account information and applicable stored content, media and publication records, subject to lawful retention exceptions and shared records belonging to other account holders.
Disconnecting or revoking access alone does not erase all client records, media, historical job snapshots or previously published content. Remove published posts through the destination social network. Content already accepted by a platform may finish processing after local access is disconnected. See our Data Deletion Instructions.
11. Children and policy changes
This workspace is intended for authorized business administrators and is not directed to children. Do not submit children's personal information unless you have the necessary authority and lawful grounds. If you believe information has been provided improperly, contact us so we can assess and address it.
We update this policy when our processing or service changes and display the revised effective date here. Where required, we provide additional notice or obtain consent before applying a material change.
12. Contact and platform policies
ТОВ «Смарт Інфосервіс»
Privacy, account data and deletion requests: smartsitepro@gmail.com.
Independent platform policies: Meta / Facebook, Instagram, TikTok, and Google / YouTube.