Privacy Policy
Last updated: 2 August 2026 · Effective: 31 July 2026
This Privacy Policy explains how Isaac Lindsay Whitbread, an individual sole trader in Australia ("we", "us", or "our"), collects, uses, stores, shares, and deletes information when you use our website at postairport.com and our application at app.postairport.com (together, the "Service"). Isaac Lindsay Whitbread operates and is the controller of the personal data described in this Policy. PostAirport is the name of the Service. It is a scheduling, analytics, and manual community-management tool for Instagram professional accounts on behalf of the account owner who connects them.
PostAirport accesses Instagram data through Meta's official APIs. Our use of that data is limited to the purposes described below and is subject to the Meta Platform Terms, the Meta Developer Policies, and applicable data-protection law. By using the Service, you agree to this Policy.
- 1. Information we collect
- 2. Instagram / Meta Platform Data
- 3. How and why we use data
- 4. Legal bases
- 5. How we store & secure data
- 6. Data retention
- 7. Third parties & sub-processors
- 8. Your rights & data deletion
- 9. What we never do
- 10. Children
- 11. International transfers
- 12. Changes
- 13. Contact us
1. Information we collect
We collect only what we need to run the Service:
Account information
- Email address — used to create your account and sign you in with a passwordless magic link.
- Authentication & session data — a random opaque identifier in a Secure, HTTP-only cookie and a corresponding session record in our database so you stay logged in.
Billing information
- Subscription & plan data — your cabin plan, status, and account/post limits.
- Payment details are collected and processed by Stripe. We do not store your full card number; we retain only a Stripe customer/subscription identifier.
Content you provide
- Media you upload — the photos, video files and cover images for the posts and Reels you schedule.
- Post details — captions, cover selections, scheduled ("departure") times, and share settings.
Instagram account data
When you connect an Instagram professional account, we access the data described in Section 2 below.
Technical & operational data
- Application audit records — event type, timestamp, result, and relevant internal user, account, post, or subscription identifiers; some events include an Instagram username or a hashed email address. We use these records to operate, secure, and debug the Service. Access tokens are never written to audit records in cleartext.
- Standard request metadata (e.g., IP address, user agent) handled by our infrastructure provider for security and abuse prevention.
2. Instagram / Meta Platform Data
PostAirport uses the Instagram API with Instagram Login. When you connect an Instagram professional (Business or Creator) account, you grant PostAirport a limited set of permissions and we access the following "Platform Data" strictly to provide the Service to you:
| Data | Why we access it |
|---|---|
| Instagram user ID, username & account type | Identify the connected account ("terminal") and show it in your dashboard. |
| Access tokens (short- and long-lived) | Authenticate API requests to publish posts and read insights on your behalf. Stored encrypted; a scheduled maintenance job attempts renewal before expiry. |
| Media you publish (photo, video, cover, caption) | Create the media container and publish the post or Reel to your account at its scheduled time. |
| Media & account insights (views, reach, watch time, likes, comments, saves, shares, engagement, follower metrics/demographics) | Render your Control Tower analytics for the connected account and its posts. |
| Comments, reply/moderation state, commenter identifiers and usernames | Show comments for the connected account's media so an authorized user can manually reply, hide, unhide, delete, or send one eligible private reply. |
| Instagram conversations, message text, message identifiers, timestamps, participants, and attachment metadata | Show an inbox for conversations started by Instagram users and let an authorized user manually reply within Meta's allowed window. |
| Messaging preference records (opt-out status, participant identifier, time, source, recording manager, and optional note) | Immediately stop message and private-comment replies after an on- or off-platform opt-out, and allow them again only after an authorized manager records renewed consent. |
| Webhook event and delivery identifiers | Receive, validate, deduplicate, and securely process comment, message, and message-reaction updates for the connected account. |
| Content publishing limit / usage | Read the API-reported publishing quota when available and avoid knowingly submitting over the reported quota. |
We request only the minimum permissions required: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights, instagram_business_manage_comments, and instagram_business_manage_messages. We do not request any permission we don't use.
Comment and message management is available only when Meta has granted the required access for the connected account. It remains manual: we do not automate or bulk-trigger engagement.
3. How and why we use data
We use the information above to:
- Create and secure your account and keep you signed in.
- Schedule and publish your feed photos and Reels to the Instagram accounts you connect, at the times you choose.
- Provide analytics — read and display account insights and reel-level media insights in your Control Tower dashboard.
- Provide manual community management — show comments and user-initiated conversations in Arrivals so an authorized user can respond or moderate one item at a time. We do not automate replies or send bulk engagement.
- Honor messaging preferences — preserve an explicit opt-out, block both ordinary message replies and private comment replies for that Instagram participant, and require a manager to record renewed consent before replies are available again. A new inbound message does not clear an opt-out.
- Enforce plan limits and process your subscription and payments.
- Operate, secure, monitor, and troubleshoot the Service, and prevent abuse.
- Communicate with you about your account, security, and service changes.
- Comply with legal obligations and the Meta Platform Terms.
4. Legal bases
Where data-protection law (such as the GDPR or the Australian Privacy Act) applies, we rely on: performance of a contract (to deliver the Service you sign up for), consent (which you give when you connect an Instagram account, and can withdraw at any time by disconnecting), legitimate interests (to secure and improve the Service), and legal obligation (to meet our compliance duties).
5. How we store & secure data
- Encryption at rest. Instagram access tokens are field-encrypted using authenticated encryption (AES-256-GCM). Tokens are never stored or logged in cleartext.
- Encryption in transit. Our application, API, and callback URLs are served over HTTPS.
- Per-account segregation. Every connected account, post, and insight is scoped to the owning user. We never mix or cross-use one customer's data with another's.
- Webhook validation. We validate Instagram webhook deliveries before processing them and keep account-scoped delivery records to prevent duplicate handling.
- Publishing-stage media. Uploaded photos, videos and covers are staged in object storage so Instagram can retrieve them for publication. We do not offer a long-term customer media library. Cleanup runs after a post reaches a terminal state and as part of deletion workflows; deletion is reported complete only after the applicable stored objects and database records are confirmed removed.
- Access controls. Administrative and service access is restricted to the access needed to operate and secure the Service.
6. Data retention
- Uploaded media — retained while needed to process a scheduled publication and its short operational cleanup period. Publishing, cancellation, disconnection, deauthorization, and account-deletion workflows initiate cleanup of applicable staged objects.
- Access tokens — kept only while an account remains connected; removal is initiated when you disconnect the account, when Instagram/Meta notifies us that access was revoked, or when you delete your account.
- Post records and publication identifiers — captions, scheduling and status records, Instagram container IDs, and published media IDs are retained while the associated Instagram account remains connected so we can show publication history, status, and available insights. They are removed when that account is disconnected or deauthorized, or when you delete your data.
- Insights — cached to power your dashboard and refreshed periodically; cleared when you disconnect the account or delete your data.
- Comments and inbox messages — comments, message content and attachment metadata, and inactive conversation context are scheduled for bounded cleanup after 90 days. An active opt-out is not erased by that cleanup: while the Instagram account remains connected, we retain the stable participant identifier and the preference status, time, source, recording manager, and optional note needed to keep enforcing it. After 90 days without conversation activity, stale previews, usernames, provider conversation IDs, unread state, and reply-window metadata are scrubbed from that preserved preference record. A new inbound message does not clear the opt-out. Webhook delivery records become eligible for cleanup after 7 days, and succeeded or definitively failed manual-action records after 30 days. Cleanup runs daily in bounded batches, so a backlog may require subsequent runs; a pending or uncertain action keeps its relevant inbox item until it is resolved. These records are removed when the account is disconnected or deauthorized or when you delete your data. On a user-initiated disconnect or full-account deletion, we also attempt to remove that account's webhook subscription before deleting its token. If Instagram or the token is unavailable, later deliveries cannot pass our active-account checks and are discarded.
- Account & billing records — retained while your account is active and, where required, for a limited period afterward to meet legal, tax, and accounting obligations. If Stripe is unavailable during account deletion, we retain only the identifiers needed to finish billing termination; they are durably retried and erased from PostAirport after Stripe confirms the billing relationship is terminal.
- When you request deletion, or when we receive a valid deauthorization or data-deletion signal from Meta, we start removing the associated Platform Data promptly and report completion after the applicable database and staged-media deletions are confirmed (see Section 8).
7. Third parties & sub-processors
We do not sell your data. We share it only with the service providers we rely on to run PostAirport, each acting under contract and only as needed:
| Provider | Purpose |
|---|---|
| Cloudflare, Inc. | Hosting, application infrastructure, database, media staging, queues, transactional email delivery, and network security. |
| GitHub, Inc. | Source-code hosting, change management, and restricted development artifacts used to maintain and secure the Service. |
| OpenAI OpCo, LLC | AI-assisted software development and security review. This is not an end-user product integration; diagnostic material is limited and should be redacted before use. |
| Stripe | Subscription billing and payment processing. |
| Meta Platforms, Inc. (Instagram) | The Instagram APIs we call to publish your posts, read your insights, and provide manual comment and message management for a connected account. |
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer, subject to this Policy.
8. Your rights & data deletion
You are always in control of your data. Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to withdraw consent. To exercise any of these, contact us at privacy@postairport.com.
You can delete your data at any time using any of these paths:
- Disconnect or delete in-app. Open PostAirport, go to your Terminals, and choose Disconnect terminal to remove one Instagram connection and its associated Platform Data. Use Delete my data in Settings to request removal of your PostAirport account and associated data.
- Email us. Write to privacy@postairport.com and we will delete your data.
- Data deletion page. Follow the instructions at postairport.com/data-deletion.
If you remove PostAirport from your Instagram/Meta settings, Meta may send us a signed deauthorization or data-deletion request. After validating the request, we initiate removal of the relevant tokens and Platform Data. For a data-deletion request, we return a confirmation code and a status URL; the status changes to completed only after the applicable deletion is confirmed.
9. What we never do
- We never sell your data or Platform Data.
- We never use your data for advertising, or to build cross-user profiles.
- We never use Platform Data to train machine-learning models or for analytics across customers.
- We never repurpose one account's data for another account or share your insights with anyone but you, the account owner.
- We never automate or bulk-trigger comments, private replies, or direct messages.
10. Children
PostAirport is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. Instagram professional accounts are intended for creators and businesses.
11. International transfers
The Service is operated from Australia. Cloudflare runs the application on a global network and Cloudflare and its subprocessors may process or remotely access data in other countries as described in their current data-processing and subprocessor disclosures. Other providers may also process data outside Australia. Where required, we rely on appropriate safeguards for cross-border transfers.
12. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Continued use of the Service after changes take effect means you accept the updated Policy.
13. Contact us
Questions or privacy requests? Reach us at:
- Controller and operator: Isaac Lindsay Whitbread, Australia
- Privacy: privacy@postairport.com
- General: hello@postairport.com
- Data deletion: postairport.com/data-deletion
PostAirport is not affiliated with, endorsed, or sponsored by Instagram or Meta Platforms, Inc. Instagram is a trademark of Meta Platforms, Inc.