Privacy Policy

Brandhackers Post · Last updated 5 October 2026

This page explains what data Brandhackers Post stores, why, for how long, and how to have it deleted.

Contents

  1. About the service and the provider
  2. What data we collect
  3. Purpose and legal basis
  4. Where data is stored
  5. Third parties
  6. Retention
  7. Data deletion
  8. Your rights and complaints
  9. Cookies
  10. Google API Services User Data Policy
  11. Changes and last updated

About the service and the provider

Brandhackers is the brand name. Brandhackers Post is operated by Business Horizon v/ Daniel Petersen. The details below are given under the Spanish Information Society Services Act (LSSI-CE, Art. 10).

Provider and data controllerBusiness Horizon v/ Daniel Petersen
NIF/NIEY6878690W
AddressCalle de Río Danubio 16A, 63, 6, 29660 Marbella, Spain
Emailinfobrandhackers@gmail.com

Brandhackers Post is an internal tool at post.brandhackers.dk. It is used to schedule and publish posts on the social channels of Brandhackers' own brands. For now it is used internally only. The provider is the data controller. Write to the contact email with questions about personal data, access or deletion.

Brandhackers Post is a self-hosted installation of the open source software Postiz v2.25.0 (AGPL-3.0). The source code is at https://github.com/gitroomhq/postiz-app. We run the server ourselves.

What data we collect

We collect only the data the tool needs to publish posts.

Login to the tool

You sign in with Google. We receive only your basic profile: name, email address and profile picture.

TikTok

We do not read your private messages, your follower list, or videos you did not send through the tool.

Facebook and Instagram

We store the name, ID and profile picture of the Facebook Pages and Instagram accounts you connect, and the access token Meta issues. We use them to publish and schedule the posts you create.

YouTube

We store the channel name, channel ID and profile picture of the YouTube channel you connect, and the access token Google issues. We use them to upload videos you have chosen to your channel.

Google Business Profile

We store the name and ID of the business profiles you connect, and the access token from Google. We use them to publish posts on the profile.

Content you create

Post text, images, videos, scheduled times and the status of each post.

Technical data

Server logs with IP address, time and error messages, so we can run and secure the tool.

Purpose and legal basis

PurposeLegal basis (GDPR Art. 6)
Connecting your accounts and publishing posts you createdConsent (Art. 6(1)(a)). You give consent at TikTok, Meta or Google when you connect the account.
Login and operation of the toolPerformance of the agreement to use the tool (Art. 6(1)(b))
Security, troubleshooting and abuse preventionLegitimate interest (Art. 6(1)(f))

You can withdraw consent at any time by disconnecting the account. Withdrawal does not affect the lawfulness of processing before it.

We do not sell personal data. We do not use it for advertising or to train AI models.

Where data is stored

Accounts, connections and posts are stored in a PostgreSQL database on Brandhackers' own server in Denmark. Images and videos you upload are stored in Cloudflare R2, Cloudflare's object storage. Traffic to and from the tool runs through Cloudflare (tunnel and DNS).

The provider is established in Spain and the database is located in Denmark. Cloudflare may process data outside the EU/EEA, including the media files stored in R2. This happens under Cloudflare's data processing agreement with the EU Standard Contractual Clauses. The platforms you connect yourself (TikTok, Meta and Google) process data under their own policies.

Third parties

When you connect an account, the tool exchanges data with that platform. The platform's own privacy policy governs its processing.

The tool does not send data to other services, such as email providers, payment providers or AI services.

Retention

Data deletion

You can have all data we hold about you deleted in two ways.

1. Disconnect the account in the tool

Sign in at post.brandhackers.dk, open the connected channel and disconnect it. Our access tokens for TikTok, Facebook, Instagram, YouTube and Google Business Profile are deleted when the account is disconnected. Posts you already published stay on the platform. You delete those at the platform.

2. Email us

Send an email to infobrandhackers@gmail.com with the subject "Delete my data" and the email address you use to sign in. We confirm receipt and delete your data within 30 days.

Revoke access at the platform

Your rights and complaints

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent at any time. Write to infobrandhackers@gmail.com and we reply within 30 days.

You can complain to the supervisory authority in Spain, the Agencia Española de Protección de Datos (AEPD): aepd.es. You can also complain to the supervisory authority in your own country of residence. In Denmark that is Datatilsynet: datatilsynet.dk.

Cookies

Brandhackers Post uses only necessary session cookies for login. The tool has no marketing or tracking cookies.

This website, brandhackers.dk, uses Google Analytics for visit statistics.

Google API Services User Data Policy

Brandhackers Post's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice this means:

The YouTube features use YouTube API Services. By using them you agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke access at any time at https://security.google.com/settings/security/permissions.

Changes and last updated

We update this policy when the tool or the rules change. Changes appear here with a new date. Last updated: 5 October 2026.