Last updated: 2026-07-20
- 1. What this Policy covers
- 2. Definitions
- 3. What information we collect
- 4. How we use your information
- 5. How the extension interacts with Facebook Marketplace
- 6. How we share information with third parties
- 7. About Sentinel Holdings Group
- 8. Managing or deleting your information
- 9. Retention
- 10. Security
- 11. International transfers
- 12. Legal requests and harm prevention
- 13. Changes to this Policy
- 14. Chrome Web Store certified disclosures
- 15. Notice for United States residents
- 16. Why and how we process your information
- 17. Contact
This Privacy Policy describes what information Postwise collects, how we use and share it, and the choices and rights you have over that information. It applies to the Postwise browser extension, the usepostwise.com website, and the Partners portal, all operated by Sentinel Holdings Group, Inc.
Postwise is a browser extension for tradespeople that automates posting to Facebook Marketplace and, on the Postwise Software tier, adds Facebook Groups posting, a message inbox, auto-relist, and a health monitor. The extension runs inside your own browser, using your own Facebook session. Most of what happens when you use Postwise never leaves your computer.
1. What this Policy covers
This Policy covers your use of:
- The Postwise browser extension for Chrome, Microsoft Edge, and Brave on Windows, macOS, and ChromeOS. The extension is distributed off-store: after you purchase, we email you your activation key and a magic sign-in link. Your extension download and a short install video live on your /account page, under the Install and Learn tabs. You side-load the unpacked extension into your browser yourself.
- The usepostwise.com website, including marketing pages, the FAQ, the sign-up and checkout flow, and the support form.
- The Partners portal, where approved affiliate partners apply, sign in, view their referral code and promo code, and track their referrals and payouts.
The extension does not run on iOS or Android. Facebook Messenger notifications on your phone are handled by Facebook, not by Postwise.
This Policy does not cover Facebook, Meta, or any of Meta's products. When you use Postwise inside Facebook Marketplace, your relationship with Facebook is governed by Facebook's own terms and privacy policy. Postwise is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.
2. Definitions
In this Policy:
- Postwise, we, us, or our refers to Sentinel Holdings Group, Inc., a North Carolina C-Corporation, doing business as Postwise.
- Extension refers to the Postwise browser extension for Chrome, Edge, or Brave.
- Site refers to the marketing site and Partners portal at usepostwise.com.
- Personal information means information that identifies you or can reasonably be linked to you, such as your name, email, IP address, or payment identifiers. Aggregated or de-identified data is not personal information.
- Customer means a tradesperson or business that has purchased Postwise.
- Partner means an individual or business enrolled in the Postwise Partners program.
- Visitor means anyone who visits the Site or contacts us without being a Customer or Partner.
- Postwise Software means the $99/month subscription that adds Facebook Groups posting, the message inbox, auto-relist, the health monitor, and access to new features.
- Onboarding fee means the $299 one-time fee charged at purchase, which includes a 30-minute onboarding call.
3. What information we collect
Information you provide to us
Checkout and account information. When you buy Postwise, Stripe forwards us the billing email you gave them so we can send you your activation key and a magic sign-in link; the extension download and install video live on your /account page under the Install and Learn tabs. We also receive from Stripe the customer identifier and payment intent identifier for your order, which we use to look up your record if you contact support, request a refund, or cancel the Postwise Software subscription.
Support conversations. When you email support@usepostwise.com, or when you submit the support form on usepostwise.com, we collect the email address you send from, your phone number if you choose to include it, and the content of your message (up to 5,000 characters). Support form submissions also include the IP address and timestamp of the submission so we can enforce a rate limit of five submissions per ten minutes per IP against automated abuse. Submissions are delivered to us by Postmark, with the reply-to header set so we can respond directly. If our email service is temporarily unavailable, your submission fails and we ask you to email support@usepostwise.com directly.
Partners program applications. If you apply to the Postwise Partners program at /partners/apply, we collect your name, email address, password (stored only as a salted hash — we never see the plaintext), phone number if you choose to include it, website if you choose to include it, a short description of your audience if you choose to include it, and your free-text description of how you plan to promote Postwise. We also collect the IP address and timestamp of your application to enforce a rate limit of three applications per hour per IP. Approved partner status is activated instantly on submission, and your unique referral code and promo code are issued at that time so you can start sharing them right away.
Partners portal use. Once approved, when you sign in to the Partners portal we create a session record that includes your partner identifier, a refresh token, a device name derived from your browser, your IP address, your user agent, and the session expiry. Access tokens are re-verified against these session rows on every mutating request, so any session can be revoked on demand. We keep a lastLoginAt timestamp against your partner record.
Partner payouts. If we owe you a payout under the Partners program, we collect the details needed to send it — the method you asked us to use (PayPal, ACH, Stripe Connect, or check) and a reference for the transaction (transaction identifier, batch identifier, or check number). We keep a record of the amount and the date it was paid.
Referral records. When someone buys Postwise using your referral code, your promo code, or a matching Stripe promotion code, our webhook writes a Referral record tying your partner account to the buyer's Stripe checkout session, the buyer's email as Stripe passed it to us, the amount of your commission, and its status (pending, paid, or reversed). Attribution priority is: ref_code metadata on the Stripe checkout, then promo_code metadata, then a matching Stripe Promotion Code on the session.
Information about payments
We do not collect or store your credit card number, card expiration, CVV, or bank account details. Stripe processes your payment and holds those details on its own infrastructure. We receive from Stripe only what is described above.
Information collected automatically on the Site
Cookies and session storage. usepostwise.com sets cookies and uses browser session storage to keep you signed in to the Partners portal, to remember Stripe Checkout state during a purchase, and to keep the Site functional. We do not use third-party advertising cookies, retargeting pixels, cross-context behavioral advertising trackers, or session-replay tools on the marketing site. Stripe sets its own cookies on its checkout pages to complete the payment and to detect fraud; those cookies are governed by Stripe's privacy policy, not ours.
Server logs. Our hosting provider records standard request metadata — IP address, user agent, request path, timestamp, response status — so we can operate the Site, debug problems, and defend against abuse. These logs are retained for a limited period and are not tied to a marketing profile of you.
Announcement and feature-vote endpoints. The extension periodically fetches two small JSON files from api.postwise.com — one that describes the dashboard announcement card and one that lists the current feature-vote options. These requests carry no personal information. If you submit feedback or a feature vote, we receive the free-text content along with a stable per-install identifier generated by your copy of the extension, the extension version, and your browser's user-agent string. If you enter an email address in the feedback form, that email is transmitted as well. Feature votes use the per-install identifier as their primary key so each install's most recent vote replaces the previous one.
Device fingerprint (hashed). When you activate the Postwise extension on a computer, we store a hash of your browser and hardware fingerprint (deviceIdHash) plus the timestamp of that first activation (deviceLockedAt) so the license binds to that machine and cannot be reused on unlimited computers. The extension also pings our server about every 30 minutes while it is running so we can show "is this install still alive?" in the admin UI (lastHeartbeatAt). None of these values are the raw device fingerprint — only a one-way hash — and none of them include the contents of any Facebook page, listing, or message.
Information stored on your computer that we do not receive
The extension keeps working data in your browser's local storage and IndexedDB on your own machine. This includes:
- Marketplace leads and message threads shown in the Postwise message inbox.
- Your listing catalog, drafts, and photo variants.
- Your quick replies and any custom quick replies you author.
- Your reminders and reminder schedule.
- Your custom overlay labels and any renamed fields (sq ft, stage names, custom chips).
- The active-tab pointer that keeps the overlay from running on multiple Facebook tabs at once.
Nothing about your contacts leaves your device unless you export the CSV yourself, or you choose to include specific details in a message to our support team.
Information from third parties
The only third party that regularly sends us information about you is Stripe, and only in the ways described above (checkout email, customer identifier, payment intent identifier, webhook events for checkout completion, refunds, and expired sessions). If someone else buys Postwise using your referral code or promo code, we learn that a purchase attributed to you occurred and store the Referral record described above.
We do not buy personal information from data brokers, and we do not receive personal information from advertising networks, social graphs, or public-records vendors.
Information about children
Postwise is a tool for adult tradespeople running a business. The service is not directed to children, and we do not knowingly collect information from anyone under 16. If we learn we have collected information from a child under 16, we will delete it without undue delay.
What if you do not provide certain information
Some information is required for us to do our job. Without a billing email we cannot send you your license key. Without your license key we cannot verify your entitlement to the extension. Without a payout method we cannot pay you Partners commissions. If you leave optional fields (phone, website, audience description) blank on the Partners application, we will still consider the application on its merits.
4. How we use your information
To provide, operate, and support Postwise
We use your purchase record to email you your activation key and a magic sign-in link (the extension download and install video live on your /account page), to verify your license when needed, and to give you access to updates on the tier you paid for. We use your Partners portal credentials and session records to keep you signed in and to give you access to your dashboard. We use your support messages, your account information, and the context you share with us to answer your questions, walk you through your onboarding call, help you resolve issues with Facebook Marketplace, and handle refund and device-transfer requests.
To process payments and manage subscriptions
We use your Stripe records to process your one-time $299 onboarding payment, to set up and manage your optional $99/month Postwise Software subscription, to cancel Postwise Software when you ask, to apply promotion codes you enter at checkout, and to reconcile refunds and disputes.
To operate the Partners program
We use Partners program information to issue your unique referral code and promo code, credit paid signups to the correct partner, calculate and pay commissions, and reverse referral credit when the associated purchase is refunded. Each paid signup earns $99, one-time; after a seven-day cooldown that guards against chargebacks the $99 is paid out — there is no minimum balance threshold to clear.
Under the current design, the affiliate credit only fires on the $299 one-time onboarding checkout. Postwise Software subscription checkouts do not currently trigger a partner payout.
To keep our services secure and prevent abuse
We use IP addresses, user agents, and timestamps to enforce API rate limits (thirty checkouts per IP per fifteen minutes; five support submissions per IP per ten minutes; three Partners applications per IP per hour), to detect and block automated abuse (including honeypot fields on our forms), to investigate and respond to fraud, and to protect the integrity of licenses and referral credit. We use session records so we can revoke a session if you tell us your account has been compromised. We use the hashed device fingerprint, first-activation timestamp, and heartbeat timestamps described in Section 3 to bind an activation key to a single machine, to detect installs that appear to have gone offline, and to support device-transfer requests when you legitimately move to a new computer.
To communicate with you
We use your email address to send you transactional messages: your license and install materials after purchase, receipts and refund confirmations from Stripe, responses to your support tickets, notifications when your Partners application has been activated, notifications when a referral you generated is paid or reversed, and notices about material changes to this Policy or our Terms.
We do not send marketing emails. We do not run a newsletter. We do not drip-campaign you. The only time you will hear from us is if you or someone acting on your behalf contacts us first, if we need to complete a transaction you started, or if there is a security, licensing, or terms issue we need to flag.
To comply with the law
We use your information to meet our tax, accounting, and other legal obligations, to respond to lawful government requests, and to defend legal claims. See Section 12.
Legal bases where required
Where the law requires us to name a legal basis for processing, ours are:
- Performance of the contract with you — delivering the product, running your onboarding call, billing Postwise Software, running your Partner dashboard, and calculating and paying earnings.
- Legitimate interests — securing the Site and extension, preventing fraud and abuse, running rate limits and honeypots, answering support requests, and understanding aggregate product usage.
- Consent — where we ask for it explicitly. You may withdraw consent at any time; withdrawal does not affect processing that was lawful before you withdrew it.
- Legal obligation — meeting tax, accounting, anti-fraud, and other legal requirements, and responding to lawful requests from authorities.
We do not use solely automated decision-making that produces legal or similarly significant effects about you.
5. How the extension interacts with Facebook Marketplace
The extension runs inside your own logged-in Facebook session, in your own browser, on your own machine. It reads only the parts of Facebook it needs to do its job, and nothing it reads on Facebook is sent to our servers.
What the extension reads on your machine
To operate the features you turn on, the extension reads:
- Your Facebook Marketplace listing catalog and its dashboard counts.
- Your Facebook Marketplace buyer/seller message threads, including sender names and message text needed to populate the message inbox.
- The Facebook UI state necessary to fill in the Marketplace listing form, drive Facebook's native renew/relist and location dialogs, and detect account health flags.
- On the Postwise Software tier, the Facebook Groups posting UI necessary to submit your ad to the groups you have selected.
What the extension does not do
- It does not collect your Facebook password. The extension uses the Facebook session that already exists in your browser. Your password stays with Facebook.
- It does not read your personal Messenger inbox, your notifications, or non-Marketplace conversations.
- It does not read your timeline, your friends list, your photos outside the ones you upload to a listing, or your other Facebook activity.
- It does not send Facebook credentials, cookies, session tokens, or the content of Facebook screens to our servers.
- It does not track your browsing on any other site.
Facebook's role
Facebook is a third party. Your use of Facebook Marketplace, including any listings you post through Postwise, is governed by Facebook's own terms and policies, and Facebook's handling of your data is governed by Facebook's privacy policy. Postwise cannot control how Facebook treats your account or your data. To exercise rights against Facebook itself, contact Meta directly.
Your responsibility as the account holder
You are the Facebook account holder. You are the seller of record for your listings and the sender of record for any message the extension sends on your behalf, including auto-sent quick replies you have enabled. Automating actions on Facebook may violate Facebook's Terms of Service and can result in listing removal, account throttling, checkpoints, or permanent bans. You use automation at your own risk. The extension throttles operations (for example, batching fan-out operations in groups of four) to reduce that risk; you should not attempt to disable those throttles.
6. How we share information with third parties
We use a small number of vendors to run Postwise, and each one only sees the data it needs to do its job.
Service providers
- Stripe — payment processing for the $299 one-time onboarding and the $99/month Postwise Software subscription, promotion-code redemption, and webhook delivery for checkout completion, asynchronous payment success, refunds, and expired sessions. Stripe holds your card and billing details on its own infrastructure. We never see your card number.
- Postmark — transactional email. Postmark delivers our purchase emails, support replies, and admin notifications about new Partners applications. Postmark sees the email address and the message body of anything it delivers.
- Vercel — hosting and serverless runtime for the usepostwise.com marketing site and the Partners portal, plus Vercel Analytics and Vercel Speed Insights, which run on every page of the Site to record aggregate page-view counts and Core Web Vitals performance measurements (load time, interaction latency, layout shift) so we can monitor and improve site performance.
- Google — Sign-in with Google. If you use the "Continue with Google" button on the sign-in screen, Google authenticates you and returns to us your email address and, when present, your name, which we use to create or match your Postwise account. If you sign in with an email and password instead, Google is not involved in your session.
- Upstash — Redis-backed rate limiting. Upstash briefly receives IP addresses to enforce per-IP request limits (checkouts, support submissions, Partners applications, and other sensitive endpoints) so we can prevent abuse. Purpose: rate limiting to prevent abuse; stores IP addresses briefly.
- Managed Postgres provider — the database that holds our server-side records (Partners accounts, sessions, referrals, payouts, staff accounts, and Partners application submissions). Neon is our documented default; a comparable managed Postgres provider (for example Railway or Supabase) may be substituted without changing the substance of this Policy.
Each of these vendors is contractually limited to processing your data on our behalf, for the purpose we hired them for, and nothing else.
Meta / Facebook
The extension operates inside your own logged-in Facebook session on facebook.com. We do not transmit Facebook credentials or personal Messenger data to our servers. Any interaction with Facebook happens in your browser and is subject to Facebook's own terms and policies.
Partners in our affiliate program
If your purchase is attributed to a Postwise partner, we share with that partner only the fact that a paid signup credited to their code occurred and the commission amount owed. We do not share your name, email, phone, or any other identifying details with the partner.
Payout providers
If we owe a partner a payout, we share with the chosen payout provider — PayPal, an ACH-processing bank, Stripe Connect, or the party issuing a check — only the information the chosen method requires to send the payment.
Legal and safety disclosures
We may share information when we believe in good faith that disclosure is required to comply with a valid legal process, to respond to a lawful government request, to enforce our Terms, to detect and prevent fraud or abuse, or to protect the rights, property, or safety of Postwise, our users, or others. See Section 12 for how we handle legal requests.
If our business changes hands
If Sentinel Holdings Group, Inc. is involved in a merger, acquisition, financing, or sale of assets, we may transfer information to the successor entity, subject to protections that are at least as strong as those in this Policy. We will notify you in advance of any such transfer that changes how your information is handled.
What we do not do
- We do not sell your personal information for money or other valuable consideration.
- We do not share your personal information for cross-context behavioral advertising.
- We do not use or transfer your data for purposes unrelated to Postwise's stated purpose of helping tradespeople manage Facebook Marketplace listings and inbound leads.
- We do not use or transfer your data to determine creditworthiness or for lending purposes.
- We do not share your information with advertisers, retargeting networks, or data brokers.
7. About Sentinel Holdings Group
Postwise is operated by Sentinel Holdings Group, Inc., a North Carolina C-Corporation with its principal place of business at 485 Spartan Dr, Lexington, NC 27292. Sentinel Holdings Group is the entity responsible for the information handled under this Policy.
Sentinel Holdings Group operates other products under separate brands. Postwise data lives in a database dedicated to Postwise operations and is not commingled with data from those other products.
8. Managing or deleting your information
You can ask for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. You can cancel your Postwise Software subscription from your dashboard at any time. Uninstalling the extension deletes the leads, listings, reminders, and other extension data stored in your browser — that data lives only on your machine.
Accessing your information
You can request a copy of the personal information we hold about you by emailing support@usepostwise.com from the email address tied to your account. We will provide the information in a portable, readable format.
Correcting your information
You can update the profile fields on your Partners account from inside the Partners portal. To correct any other information we hold about you, email us at support@usepostwise.com from the email address tied to your account.
Deleting your information
You can ask us to delete your Postwise account and the personal information tied to it. We will honor the request unless we are required to keep specific records for legal, tax, or fraud-prevention reasons (see Section 9). Deleting your account may deactivate any Postwise licenses issued to you.
If you are a Postwise Partner, deleting your account will not automatically reverse commissions already paid to you, nor will it retroactively remove referrals credited to you before deletion.
Pausing or canceling Postwise Software
You can cancel the $99/month Postwise Software subscription at any time from your dashboard. Cancellation stops future charges. Extension features remain available through the end of the current paid period; when the period ends, the extension stops activating and posting until you resubscribe. Your $299 onboarding is a one-time charge and is not re-billed.
Uninstalling the extension
Uninstalling the Postwise extension from your browser removes the local data the extension stored on your machine, including your leads, threads, listings, quick replies, reminders, and custom overlay configuration. Your Facebook account and any CSV exports you saved separately are unaffected. Because leads live in browser local storage and not on a Postwise server, uninstall equals deletion for that data.
Objecting to processing
You may object to our use of your information for a specific purpose (other than uses we are legally required to perform, such as tax records tied to a completed purchase). Contact us at support@usepostwise.com and describe the processing you object to.
Withdrawing consent
Where we rely on your consent to process information, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before you withdrew.
How to exercise your rights
Email support@usepostwise.com from the email address tied to your account, or write to us at the address in Section 17. We will acknowledge your request within seven days, and complete it within 30 days for straightforward requests. For requests covered by state consumer-privacy laws, we will substantively respond within 45 days, extendable once by an additional 45 days with notice for complex requests.
We may need to verify your identity before honoring a request, especially for access and deletion. Verification typically involves matching the email or account details you provide to what we already have on file.
If you use an authorized agent to submit a request, we will require written proof of the agent's authority to act on your behalf.
We do not charge for these requests, and we do not treat you differently — in price, in features, or in support — for making one.
9. Retention
We keep personal information only as long as we need it for the purposes described in this Policy, or as long as we are required to keep it by law.
- Purchase records (Stripe customer identifier, payment intent identifier, associated email, license entitlement) are retained for as long as we may be required to substantiate the transaction under U.S. tax, accounting, or consumer-protection law — typically at least seven years.
- Partner account records (profile, session history, referrals, payouts) are retained while your account is active and for up to seven years after closure to satisfy financial and payout recordkeeping obligations.
- Partners application records for applications that were rejected or withdrawn are retained for up to one year so we can revisit our decision if you re-apply, and then deleted.
- Support conversations are retained for up to three years after the last message, so we can honor commitments we made to you and resolve any related dispute.
- Server logs are retained for up to 90 days and then rotated or deleted.
- Rate-limit and honeypot state is held in memory only, and discarded when the window expires.
- Extension data on your machine (leads, listings, reminders, quick replies) is retained as long as you keep the extension installed. You can clear it any time using the extension's Clear History control or by uninstalling.
When we no longer need personal information, we delete it or de-identify it so that it can no longer be linked to you.
10. Security
We use commercially reasonable technical and organizational measures to protect personal information. Passwords are stored only as salted hashes. Access tokens are backed by revocable session records so we can end a session on demand. Data in transit uses TLS. Access to production databases is limited to the small number of staff who need it. Public forms are protected by rate limits and honeypot fields. Admin credentials are separated from Partner-scoped access.
No system is completely secure and we cannot guarantee absolute security. We do not disclose the specifics of our security controls, because doing so would help the people we are trying to keep out.
If we become aware of a security incident that affects your personal information and that meets applicable notification thresholds, we will notify affected users and, where required, the appropriate regulators without undue delay.
11. International transfers
Postwise is offered exclusively to residents of the United States. Sentinel Holdings Group, Inc. is a North Carolina corporation, and the servers, vendors, and staff that handle your information are based in the United States. Your information is stored and processed in the United States.
We do not market Postwise in EU or EEA languages, we do not price in EU/EEA currencies, we do not use EU top-level domains, and we do not target advertising or business development at EU/EEA residents. If you access the Site from outside the United States, you are doing so on your own initiative and your information will be transferred to and processed in the United States, whose data-protection laws may differ from those of your country.
We have not appointed an EU Representative under Article 27 of the GDPR because our processing is occasional, does not target EU data subjects, and does not include large-scale special-category or criminal data. If you are located in a jurisdiction with its own data-protection regime and you have a good-faith request about your information, we will consider it on the merits regardless of whether we are legally required to respond.
12. Legal requests and harm prevention
We may access, preserve, and disclose your information if we believe in good faith that doing so is required by:
- A valid subpoena, court order, search warrant, or other lawful process.
- A lawful government request with jurisdiction over Sentinel Holdings Group.
- Our need to enforce our Terms, investigate a violation of them, or defend legal claims.
- Our need to detect, prevent, or address fraud, security, or technical issues, or to protect the rights, property, or safety of Postwise, our users, or others.
We review legal requests case by case and require that they be legally valid and appropriately scoped. Where the law allows, we will attempt to notify you of a request for your information before responding, unless doing so would be unlawful or would create a genuine risk of harm.
13. Changes to this Policy
We may update this Policy over time to reflect changes to our practices, our services, or the law. When we do, we will update the "Last updated" date at the top of this page.
For material changes — changes that reduce your rights or meaningfully expand what we collect, use, or share — we will notify you before the changes take effect by emailing the address tied to your account. Continued use of Postwise after the effective date of the change constitutes acceptance of the updated Policy.
Prior versions of this Policy are available on request from support@usepostwise.com.
14. Chrome Web Store certified disclosures
For clarity, and to satisfy the certifications required of extensions distributed through the Chrome Web Store's developer program (which we align with even though Postwise is distributed off-store):
- We do not sell user data to third parties.
- We do not use or transfer user data for purposes unrelated to Postwise's single purpose, which is helping tradespeople manage Facebook Marketplace listings and inbound leads.
- We do not use or transfer user data to determine creditworthiness or for lending purposes.
Browser permissions the extension requests
Every permission is scoped to what Postwise needs to run inside Facebook Marketplace on your machine. In plain English:
| Manifest permission | Why Postwise needs it |
|---|---|
activeTab / host permissions on facebook.com and messenger.com | To read the Marketplace pages you already have open — your listings, buyer/seller message threads, the composer — so it can post, rotate photos, and organize your message inbox. Never used outside of Facebook. |
storage | To save your Postwise settings, saved templates, and cached Marketplace state (your listings, message threads, follow-up reminders) on your machine. Nothing here is sent to us. |
alarms | To fire your posting schedule at the times you set, and to trigger follow-up reminders. Runs entirely in your browser. |
notifications | To surface follow-up reminders and posting-status alerts as native browser notifications. Only fires locally. |
scripting | To inject Postwise's UI overlay into Facebook pages (side-panel, quick-reply bar, listing composer helpers). Injections are limited to facebook.com and messenger.com. |
tabs | To detect when you're on a Marketplace page and to open the composer or a message thread in the correct tab. |
identity (Chrome) | To read your Chrome profile email once, so we can pre-fill the license activation screen and match your account to your license. Never used to log you in anywhere else. |
The extension does not request webRequest, webNavigation beyond facebook.com, cookies, history, bookmarks, downloads, or any permission that would grant access to your other browsing.
Executable code and remote configuration
All executable code ships inside the extension package you download. Postwise does not fetch or execute remote JavaScript at runtime. The extension does fetch two small JSON configuration files from api.postwise.com/ext/ (announcement copy for the dashboard card and the current feature-vote options) — these are data only, never code.
Data in transit
All requests the extension makes to Postwise infrastructure (api.usepostwise.com, api.postwise.com) use TLS 1.2 or higher. There are no fallback plaintext endpoints.
15. Notice for United States residents
This section provides additional disclosures for residents of U.S. states with comprehensive consumer privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA"), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and the Montana Consumer Data Privacy Act. It applies alongside the rest of this Policy; where terms differ, the terms of this section govern for the residents of the covered states.
Categories of personal information we collect and disclose
In the past twelve months we have collected the following categories of personal information (using CCPA category names in Cal. Civ. Code §1798.140(v)):
| CCPA category | Examples in Postwise | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email, phone, IP address, Stripe customer identifier, referral code, session identifiers, Google account identifier (when you Continue with Google), deviceIdHash, deviceLockedAt, lastHeartbeatAt | Stripe, Postmark, Vercel, Google, managed Postgres provider |
| Customer records | Billing email, purchase amount, license entitlement, Partners payout method | Stripe, Postmark, Vercel, managed Postgres provider |
| Commercial information | Purchase history, subscription status, refund status, Partners referrals and payouts | Stripe, Vercel, managed Postgres provider |
| Internet or network activity | Server logs, session records, IP and user agent for rate limiting, aggregate page-view counts and Core Web Vitals performance measurements collected by Vercel Analytics and Vercel Speed Insights | Vercel, Upstash, managed Postgres provider |
| Professional information | Free-text audience and promotion plan on Partners applications | Vercel, managed Postgres provider |
| Inferences | Whether an IP has exceeded a rate limit, whether a partner is currently eligible for a payout | Vercel, managed Postgres provider |
We do not knowingly collect sensitive personal information as defined in Cal. Civ. Code §1798.140(ae). We do not collect government identifiers, precise geolocation, racial or ethnic origin, religion, union membership, genetic data, biometric data used to identify a person, health data, or information about sex life or sexual orientation.
Sources of personal information
- Directly from you (checkout, support form, Partners application, Partners portal, direct email).
- From Stripe on your behalf (billing email, customer identifier, payment intent identifier, webhook events).
- From Google, when you choose "Continue with Google" to sign in (your email address and, when present, your name).
- Automatically from your browser (IP address, user agent, standard request metadata, and — via Vercel Analytics and Vercel Speed Insights — aggregate page-view counts and Core Web Vitals performance measurements).
- Automatically from your copy of the Postwise extension (hashed browser + hardware fingerprint at first activation and periodic heartbeat timestamps thereafter, as described in Section 3).
Purposes for collecting and using personal information
The purposes are enumerated in Section 4 above: providing the service, processing payments, operating the Partners program, security and abuse prevention, transactional communication, and legal compliance.
Sale or sharing of personal information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months. Because we do not sell or share, we are not required to (and do not) offer a "Do Not Sell or Share My Personal Information" link, but you may confirm this posture by contacting us.
Sensitive personal information
We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit under Cal. Civ. Code §1798.121.
Profiling
We do not engage in profiling that produces legal or similarly significant effects about you.
Financial incentives
We do not offer financial incentives or price differences in exchange for personal information. Our Partners program pays commissions to approved affiliates based on paid signups; it is a commercial affiliate arrangement, not a data-for-discount program.
Your rights
Subject to verification, residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other U.S. states with comparable laws have the right to:
- Know what personal information we have collected about you, the sources, the purposes, and the categories of recipients.
- Access a copy of your personal information in a portable, readable format.
- Correct inaccurate personal information.
- Delete personal information we have collected from you, subject to legal exceptions.
- Opt out of sale or sharing of personal information (we do not sell or share).
- Limit the use of sensitive personal information (we do not use sensitive personal information in a way that would trigger this right).
- Not be discriminated against for exercising your rights.
- Appeal a denial of a request, where the applicable state law provides an appeal right.
How to exercise your rights and verify your identity
Send your request to support@usepostwise.com from the email address tied to your account, or write to us at the address in Section 17. We will acknowledge your request within ten business days and respond substantively within 45 calendar days, extendable once by an additional 45 days with notice for complex requests.
To verify your identity, we typically match the email address and account details you provide against what we already hold. For requests that involve deletion or portability of sensitive records, we may ask you to confirm additional details tied to your account.
Authorized agents
You may designate an authorized agent to submit a request on your behalf. We will require written proof of the agent's authority (such as a signed permission or a power of attorney) and may verify the request directly with you.
Appeals
If we deny your request, you may appeal by replying to our response email within a reasonable time and describing why you disagree. If we deny your appeal, you may contact your state Attorney General or other applicable consumer-protection authority.
Metrics disclosure
We do not process the personal information of 10 million or more California residents in a calendar year, so we are not subject to the annual metrics disclosure requirement.
16. Why and how we process your information
The table below summarizes the specific purposes for which we process personal information, the categories of data used, the legal basis where a legal basis is required, and the parties with whom we share for each purpose.
| Purpose | Personal information used | Legal basis | Recipients |
|---|---|---|---|
| Delivering the product you purchased (license key, install materials, updates) | Billing email, Stripe customer identifier, license entitlement | Performance of the contract with you | Postmark, managed Postgres provider |
| Processing payments, refunds, and subscription cancellation | Stripe customer identifier, payment intent identifier, billing email, promotion code entered | Performance of the contract with you; compliance with tax and consumer-protection law | Stripe, managed Postgres provider |
| Providing support | Email address, phone (if provided), message content, purchase context | Performance of the contract with you; our legitimate interest in resolving your issues | Postmark, managed Postgres provider |
| Operating the Partners program (issue codes, credit referrals, pay commissions) | Applicant profile, hashed password, referral records, payout records | Performance of the Partners agreement with you; our legitimate interest in running an affiliate channel | Stripe (where payout via Stripe Connect), managed Postgres provider |
| Binding an activation key to a single computer, detecting whether an install is still alive, and supporting device-transfer requests | Hashed device fingerprint (deviceIdHash), first-activation timestamp (deviceLockedAt), heartbeat timestamps (lastHeartbeatAt) | Performance of the contract with you; our legitimate interest in preventing license reuse and abuse | Managed Postgres provider |
| Preventing abuse, fraud, and security threats | IP address, user agent, request metadata, honeypot signals, session records | Our legitimate interest in the integrity of the service; compliance with law | Vercel, managed Postgres provider |
| Sending transactional messages (receipts, license delivery, application decisions, Policy change notices) | Email address, transaction context | Performance of the contract with you; compliance with law | Postmark |
| Complying with tax, accounting, and other legal obligations | Purchase records, payout records | Compliance with law | As required by law |
| Responding to lawful government requests, defending legal claims | Whatever is responsive to the request or claim | Compliance with law; our legitimate interest in defending our rights | As required by law |
Extension activity that happens on your machine — reading Marketplace listings and threads, drafting posts, storing reminders, sending quick replies through Facebook's own composer — is not processing performed by Sentinel Holdings Group. It is processing you perform yourself, using your own Facebook account, on your own device. Postwise provides the tool that makes it possible.
17. Contact
If you have questions, requests, complaints, or feedback about this Policy or your information, contact us at:
- Email: support@usepostwise.com
- Mail: Sentinel Holdings Group, Inc., Attn: Privacy, 485 Spartan Dr, Lexington, NC 27292, United States
A real person reads support email. We aim to acknowledge within seven days and to complete straightforward requests within 30 days.
We have not appointed a Data Protection Officer, and — because Postwise is a U.S.-only service directed at U.S. residents — we have not appointed an EU representative under Article 27 of the GDPR. If your inquiry relates to a right under a specific state or foreign privacy law, please tell us which law you are relying on so we can route your request appropriately.