Legal

Privacy Policy

Last updated: 2 August 2026 · Effective: 31 July 2026

This Privacy Policy explains how Isaac Lindsay Whitbread, an individual sole trader in Australia ("we", "us", or "our"), collects, uses, stores, shares, and deletes information when you use our website at postairport.com and our application at app.postairport.com (together, the "Service"). Isaac Lindsay Whitbread operates and is the controller of the personal data described in this Policy. PostAirport is the name of the Service. It is a scheduling, analytics, and manual community-management tool for Instagram professional accounts on behalf of the account owner who connects them.

PostAirport accesses Instagram data through Meta's official APIs. Our use of that data is limited to the purposes described below and is subject to the Meta Platform Terms, the Meta Developer Policies, and applicable data-protection law. By using the Service, you agree to this Policy.

1. Information we collect

We collect only what we need to run the Service:

Account information

Billing information

Content you provide

Instagram account data

When you connect an Instagram professional account, we access the data described in Section 2 below.

Technical & operational data

2. Instagram / Meta Platform Data

PostAirport uses the Instagram API with Instagram Login. When you connect an Instagram professional (Business or Creator) account, you grant PostAirport a limited set of permissions and we access the following "Platform Data" strictly to provide the Service to you:

DataWhy we access it
Instagram user ID, username & account typeIdentify the connected account ("terminal") and show it in your dashboard.
Access tokens (short- and long-lived)Authenticate API requests to publish posts and read insights on your behalf. Stored encrypted; a scheduled maintenance job attempts renewal before expiry.
Media you publish (photo, video, cover, caption)Create the media container and publish the post or Reel to your account at its scheduled time.
Media & account insights (views, reach, watch time, likes, comments, saves, shares, engagement, follower metrics/demographics)Render your Control Tower analytics for the connected account and its posts.
Comments, reply/moderation state, commenter identifiers and usernamesShow comments for the connected account's media so an authorized user can manually reply, hide, unhide, delete, or send one eligible private reply.
Instagram conversations, message text, message identifiers, timestamps, participants, and attachment metadataShow an inbox for conversations started by Instagram users and let an authorized user manually reply within Meta's allowed window.
Messaging preference records (opt-out status, participant identifier, time, source, recording manager, and optional note)Immediately stop message and private-comment replies after an on- or off-platform opt-out, and allow them again only after an authorized manager records renewed consent.
Webhook event and delivery identifiersReceive, validate, deduplicate, and securely process comment, message, and message-reaction updates for the connected account.
Content publishing limit / usageRead the API-reported publishing quota when available and avoid knowingly submitting over the reported quota.

We request only the minimum permissions required: instagram_business_basic, instagram_business_content_publish, instagram_business_manage_insights, instagram_business_manage_comments, and instagram_business_manage_messages. We do not request any permission we don't use.

Comment and message management is available only when Meta has granted the required access for the connected account. It remains manual: we do not automate or bulk-trigger engagement.

Purpose limitation. We process Platform Data only to provide scheduling, analytics, and manual community-management features to the account owner or authorized manager who connected the account, and for no unrelated purpose.

3. How and why we use data

We use the information above to:

Where data-protection law (such as the GDPR or the Australian Privacy Act) applies, we rely on: performance of a contract (to deliver the Service you sign up for), consent (which you give when you connect an Instagram account, and can withdraw at any time by disconnecting), legitimate interests (to secure and improve the Service), and legal obligation (to meet our compliance duties).

5. How we store & secure data

6. Data retention

7. Third parties & sub-processors

We do not sell your data. We share it only with the service providers we rely on to run PostAirport, each acting under contract and only as needed:

ProviderPurpose
Cloudflare, Inc.Hosting, application infrastructure, database, media staging, queues, transactional email delivery, and network security.
GitHub, Inc.Source-code hosting, change management, and restricted development artifacts used to maintain and secure the Service.
OpenAI OpCo, LLCAI-assisted software development and security review. This is not an end-user product integration; diagnostic material is limited and should be redacted before use.
StripeSubscription billing and payment processing.
Meta Platforms, Inc. (Instagram)The Instagram APIs we call to publish your posts, read your insights, and provide manual comment and message management for a connected account.

We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a business transfer, subject to this Policy.

8. Your rights & data deletion

You are always in control of your data. Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to withdraw consent. To exercise any of these, contact us at privacy@postairport.com.

You can delete your data at any time using any of these paths:

  • Disconnect or delete in-app. Open PostAirport, go to your Terminals, and choose Disconnect terminal to remove one Instagram connection and its associated Platform Data. Use Delete my data in Settings to request removal of your PostAirport account and associated data.
  • Email us. Write to privacy@postairport.com and we will delete your data.
  • Data deletion page. Follow the instructions at postairport.com/data-deletion.

If you remove PostAirport from your Instagram/Meta settings, Meta may send us a signed deauthorization or data-deletion request. After validating the request, we initiate removal of the relevant tokens and Platform Data. For a data-deletion request, we return a confirmation code and a status URL; the status changes to completed only after the applicable deletion is confirmed.

9. What we never do

10. Children

PostAirport is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. Instagram professional accounts are intended for creators and businesses.

11. International transfers

The Service is operated from Australia. Cloudflare runs the application on a global network and Cloudflare and its subprocessors may process or remotely access data in other countries as described in their current data-processing and subprocessor disclosures. Other providers may also process data outside Australia. Where required, we rely on appropriate safeguards for cross-border transfers.

12. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Continued use of the Service after changes take effect means you accept the updated Policy.

13. Contact us

Questions or privacy requests? Reach us at:

PostAirport is not affiliated with, endorsed, or sponsored by Instagram or Meta Platforms, Inc. Instagram is a trademark of Meta Platforms, Inc.