Privacy Policy
This page explains what data Brandhackers Post stores, why, for how long, and how to have it deleted.
Contents
About the service and the provider
Brandhackers is the brand name. Brandhackers Post is operated by Business Horizon v/ Daniel Petersen. The details below are given under the Spanish Information Society Services Act (LSSI-CE, Art. 10).
| Provider and data controller | Business Horizon v/ Daniel Petersen |
|---|---|
| NIF/NIE | Y6878690W |
| Address | Calle de Río Danubio 16A, 63, 6, 29660 Marbella, Spain |
| infobrandhackers@gmail.com |
Brandhackers Post is an internal tool at post.brandhackers.dk. It is used to schedule and publish posts on the social channels of Brandhackers' own brands. For now it is used internally only. The provider is the data controller. Write to the contact email with questions about personal data, access or deletion.
Brandhackers Post is a self-hosted installation of the open source software Postiz v2.25.0 (AGPL-3.0). The source code is at https://github.com/gitroomhq/postiz-app. We run the server ourselves.
What data we collect
We collect only the data the tool needs to publish posts.
Login to the tool
You sign in with Google. We receive only your basic profile: name, email address and profile picture.
TikTok
- user.info.basic: we fetch your TikTok account name and avatar so you can see which account is connected.
- user.info.profile: we fetch the profile details shown next to the account in the tool, such as username and profile link.
- video.upload: we upload the videos you have chosen yourself to your TikTok account as a draft.
- video.publish: we publish the videos you have chosen and approved yourself on your TikTok account.
We do not read your private messages, your follower list, or videos you did not send through the tool.
Facebook and Instagram
We store the name, ID and profile picture of the Facebook Pages and Instagram accounts you connect, and the access token Meta issues. We use them to publish and schedule the posts you create.
YouTube
We store the channel name, channel ID and profile picture of the YouTube channel you connect, and the access token Google issues. We use them to upload videos you have chosen to your channel.
Google Business Profile
We store the name and ID of the business profiles you connect, and the access token from Google. We use them to publish posts on the profile.
Content you create
Post text, images, videos, scheduled times and the status of each post.
Technical data
Server logs with IP address, time and error messages, so we can run and secure the tool.
Purpose and legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Connecting your accounts and publishing posts you created | Consent (Art. 6(1)(a)). You give consent at TikTok, Meta or Google when you connect the account. |
| Login and operation of the tool | Performance of the agreement to use the tool (Art. 6(1)(b)) |
| Security, troubleshooting and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
You can withdraw consent at any time by disconnecting the account. Withdrawal does not affect the lawfulness of processing before it.
We do not sell personal data. We do not use it for advertising or to train AI models.
Where data is stored
Accounts, connections and posts are stored in a PostgreSQL database on Brandhackers' own server in Denmark. Images and videos you upload are stored in Cloudflare R2, Cloudflare's object storage. Traffic to and from the tool runs through Cloudflare (tunnel and DNS).
The provider is established in Spain and the database is located in Denmark. Cloudflare may process data outside the EU/EEA, including the media files stored in R2. This happens under Cloudflare's data processing agreement with the EU Standard Contractual Clauses. The platforms you connect yourself (TikTok, Meta and Google) process data under their own policies.
Third parties
When you connect an account, the tool exchanges data with that platform. The platform's own privacy policy governs its processing.
- TikTok (TikTok Login Kit and Content Posting API).
- Meta (Facebook and Instagram).
- Google (Google sign-in, YouTube Data API and Google Business Profile).
- Cloudflare (tunnel, DNS and object storage for media files). Cloudflare is a data processor for us.
The tool does not send data to other services, such as email providers, payment providers or AI services.
Retention
- Access tokens for TikTok, Meta and Google: deleted when you disconnect the account in the tool.
- Account details, posts and media: kept while you use the tool. When you delete them or your access is closed, we remove them within 30 days.
- Server logs: kept for up to 30 days.
Data deletion
You can have all data we hold about you deleted in two ways.
1. Disconnect the account in the tool
Sign in at post.brandhackers.dk, open the connected channel and disconnect it. Our access tokens for TikTok, Facebook, Instagram, YouTube and Google Business Profile are deleted when the account is disconnected. Posts you already published stay on the platform. You delete those at the platform.
2. Email us
Send an email to infobrandhackers@gmail.com with the subject "Delete my data" and the email address you use to sign in. We confirm receipt and delete your data within 30 days.
Revoke access at the platform
- TikTok: Settings and privacy, Security and permissions, Apps and services.
- Facebook and Instagram: Settings, Apps and Websites (Facebook) or Apps and Websites (Instagram).
- Google: https://security.google.com/settings/security/permissions.
Your rights and complaints
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent at any time. Write to infobrandhackers@gmail.com and we reply within 30 days.
You can complain to the supervisory authority in Spain, the Agencia Española de Protección de Datos (AEPD): aepd.es. You can also complain to the supervisory authority in your own country of residence. In Denmark that is Datatilsynet: datatilsynet.dk.
Cookies
Brandhackers Post uses only necessary session cookies for login. The tool has no marketing or tracking cookies.
This website, brandhackers.dk, uses Google Analytics for visit statistics.
Google API Services User Data Policy
Brandhackers Post's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means:
- We use Google data (YouTube and Google Business Profile) only to provide the features you see in the tool: uploading and publishing the posts you created.
- We do not transfer Google data to others, except when necessary to provide the feature, to comply with law, or in a merger or acquisition with your prior consent.
- We do not use Google data for advertising and do not sell it.
- Humans do not read your Google data unless you gave consent for specific data, it is necessary for security purposes, or it is required by law.
- We do not use Google data to develop, improve or train generalized AI or machine learning models.
The YouTube features use YouTube API Services. By using them you agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke access at any time at https://security.google.com/settings/security/permissions.
Changes and last updated
We update this policy when the tool or the rules change. Changes appear here with a new date. Last updated: 5 October 2026.