GuestPost reference

Privacy Policy

Last updated: July 27, 2026

The operating legal entity, registered address, applicable privacy representative, and regulator details must be added when the production business entity and supported jurisdictions are finalized.

1. Scope and roles

This Policy covers the public website and GuestPost customer, publisher, support, administrative, marketplace, payment, and integration workflows. GuestPost acts as controller for account administration, marketplace operations, security, fraud prevention, support, and its own financial records. Customers and publishers may separately control personal data they include in content or instructions.

2. Information we process

  • Account data: name, email, role, organization, publisher relationship, verification state, and preferences.
  • Authentication and security data: sessions, IP address, device and browser signals, access events, recovery activity, rate-limit events, and security findings.
  • Marketplace data: websites, listings, services, metrics, moderation decisions, orders, briefs, articles, evidence, messages, cancellations, disputes, and support history.
  • Financial operations data: prices, wallet entries, funding attempts, provider references, reservations, settlements, refunds, withdrawals, payout states, reconciliation findings, and audit evidence.
  • Integration data: connection identifiers, permissions, selected properties, synchronization status, and the marketplace metrics produced by an authorized integration.
  • Communications: support requests, policy notices, security reports, and other correspondence.

Payment providers process card or bank information under their own terms. GuestPost does not intentionally store raw card numbers.

3. Purposes and legal bases

  • Perform the service and administer the user agreement.
  • Protect legitimate interests in platform security, fraud prevention, service reliability, support, moderation, and legal claims.
  • Meet accounting, tax, sanctions, payment-provider, court, and other legal obligations.
  • Use consent where applicable law requires it, including for non-essential tracking if introduced.

4. Service providers and recipients

Data may be processed by infrastructure, database, authentication, email, monitoring, customer-support, payment, payout, analytics, and integration providers where required to operate the service. Stripe, eligible payout providers, Sentry, and authorized Google integrations are examples depending on the enabled workflow.

Data may also be disclosed to professional advisers, insurers, processors, financial institutions, counterparties where required for an order, and authorities where lawfully required. GuestPost does not sell personal data as an independent product.

5. International processing

Providers and marketplace participants may operate in different countries. Where required, GuestPost will use an approved transfer mechanism and contractual or organizational safeguards. The final production policy must identify the operating entity's primary location and jurisdiction-specific transfer mechanism.

6. Cookies and local storage

Essential cookies or similar storage may support authentication, security, session continuity, CSRF protection, and account recovery. The separate Cookie Policy describes the current categories and how future non-essential tracking must be handled.

7. Security

GuestPost uses role-based authorization, session controls, transport encryption, restricted administrative access, audit events, provider verification, and additional controls appropriate to the affected data. No internet service can guarantee absolute security.

8. Retention

Retention depends on purpose rather than one universal period:

  • Account and organization data is retained while the account is active and for a reasonable closure and claims period.
  • Financial, tax, settlement, payout, and audit records are retained for applicable accounting, provider, fraud, and legal obligations.
  • Security and fraud evidence is retained for investigation, enforcement, chargeback defense, and recurrence prevention.
  • Support and order content is retained while needed to operate the order, resolve disputes, and meet legal obligations.

The production retention schedule must supply jurisdiction-specific periods once the legal entity and launch regions are approved.

9. Automated tools

Automated signals can prioritize review, apply rate limits, or hold a risky workflow. Material enforcement and sensitive financial exceptions can be routed to authorized human review. Contact support to challenge an account-specific outcome.

10. Individual rights

Depending on location, you may have rights to access, correct, delete, restrict, object, receive a portable copy, withdraw consent, or complain to a regulator. These rights can be limited by identity verification, another person's rights, legal privilege, fraud prevention, and mandatory retention.

Submit a request to privacy@guestpost.cc. Do not send passwords, payment credentials, or unnecessary identity documents by email.

11. Children

GuestPost is a business marketplace and is not directed to children. Users must have legal capacity to enter the applicable agreement. Report suspected child data to the privacy contact.

12. Changes and contact

Material changes will update the date and may require notice or renewed consent where law requires it. Contact privacy@guestpost.cc with privacy questions or requests.