Legal Documents

Privacy Policy

Effective DateJuly 21, 2026
Last UpdatedJuly 21, 2026
Version1.0
Contactprivacy@socialscheduler.co
Website: https://socialscheduler.co

🏛️ GRIEVANCE OFFICER (MANDATORY UNDER INDIAN IT ACT & SPDI RULES 2011)

In accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the details of the Grievance Officer are:

Name: Jay Rathod

Designation: Founder & Grievance Officer

Company: SocialScheduler

Address: Ahmedabad, Gujarat, India

Email: grievance@socialscheduler.co

Availability: Monday to Friday, 10:00 AM – 6:00 PM IST

Any grievance or complaint regarding the processing of your personal data must be addressed to the Grievance Officer above. We will acknowledge your complaint within 24 hours and resolve it within 30 days of receipt.

1. WHO WE ARE

SocialScheduler ("we", "us", "our") is a social media scheduling and management platform operated from Ahmedabad, Gujarat, India. Our platform allows creators, businesses, and agencies to connect their social media accounts, schedule and publish content, view analytics, manage team workspaces, and access creative tools.

Our services are available at:

  • Production: https://socialscheduler.co
  • API: https://api.socialscheduler.co

This Privacy Policy applies to all users of SocialScheduler, including visitors, registered users, workspace members, and agency clients accessing the platform through any of the above domains.

2. LAWS THAT GOVERN THIS POLICY

This Privacy Policy is written to comply with:

  • (a)The Information Technology Act, 2000 (India)
  • (b)The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules)
  • (c)The Digital Personal Data Protection Act, 2023 (DPDP Act) — provisions as applicable from the date of enforcement by the Government of India
  • (d)Meta Platforms' Platform Policy and Data Policy requirements for applications using Facebook and Instagram APIs
  • (e)Pinterest's Developer Policy for applications using Pinterest APIs
  • (f)Google's API Services User Data Policy for applications using YouTube APIs

3. WHAT DATA WE COLLECT AND WHY

3.1 Account Registration Data

When you create a SocialScheduler account, we collect:

FieldWhat We StorePurpose
First NamePlain textDisplay in your account profile
Last NamePlain textDisplay in your account profile
Email AddressPlain textLogin, notifications, billing
PasswordBCrypt one-way hash (raw password NEVER stored)Authentication (raw password is never stored anywhere)
Phone NumberAES-256-GCM encryptedAccount verification, support
Profile PictureCDN URL (if provided)Display in dashboard
Google OAuth IDPlain text (Google subject ID)If you sign in with Google — links your Google account

Legal basis: Consent (you provide this data voluntarily during registration).

3.2 Connected Social Media Account Data

When you connect a social media account (Instagram, Facebook, YouTube, Pinterest), we collect and store:

FieldStoragePurpose
Platform account IDPlain textIdentify your connected account
Platform usernamePlain textDisplay in your dashboard
OAuth access tokenAES-256-GCM encryptedPost content on your behalf at scheduled times
OAuth refresh tokenAES-256-GCM encryptedRenew access without re-login
Token expiry timePlain textManage token refresh scheduling
Granted OAuth scopesPlain textTrack what permissions exist

We do NOT store your social media passwords. We use the OAuth 2.0 protocol, which means social platforms issue us a temporary token — your password never passes through our servers.

Legal basis: Contract performance (without these tokens, we cannot provide the scheduling service you signed up for).

3.3 Content You Create and Schedule

FieldStoragePurpose
Post captionsPlain textSchedule and publish your content
Scheduled publish timeTimestampTrigger publishing at your time
Platform-specific settingsPlain textYouTube title/description/tags, Pinterest pin details, Instagram hashtags, Facebook link preview
Post status and historyPlain textShow your post history and retries
Error messagesPlain textDebug failed post attempts
Media files (images, videos)Cloudflare R2 StorageAttach media to your posts, content library

Legal basis: Contract performance.

3.4 Analytics Data

When you use our analytics dashboard, we fetch and store aggregated metrics from the social platform APIs you have connected:

  • Instagram: Reach, impressions, profile views, follower count, website clicks, per-post likes/comments/shares/saves/plays
  • Facebook: Page reach, fan count, impressions, post-level metrics
  • YouTube: Views, watch time, subscribers gained/lost, impressions, CTR

IMPORTANT: We store only aggregated metrics, not individual user identities. We do not store the names, profiles, or personal information of your followers, fans, or viewers. We never access private messages or DMs.

Retention: Analytics data is retained for 12 months on a rolling basis.

Legal basis: Contract performance (you activated the analytics feature).

3.5 Billing and Payment Data

We use Razorpay to process all subscription payments (India). We store:

FieldStoragePurpose
Razorpay customer IDPlain textLink your account to Razorpay
Razorpay subscription IDPlain textManage your subscription
Razorpay order/payment IDPlain textTransaction reference
Amount (in paise)Plain textBilling records
CurrencyPlain textBilling records
Payment statusPlain textConfirm successful payment
Invoice URLPlain textProvide you invoice access
Refund reference (if any)Plain textProcess refunds

We do NOT store any card numbers, CVV codes, bank account details, or UPI credentials. All card and payment credential processing is handled exclusively by Razorpay, which is PCI-DSS compliant. We never see or touch your payment credentials.

Legal basis: Contract performance, Legal obligation (Indian accounting law requires transaction records for 7 years).

3.6 Workspace and Team Data

If you use workspace features (agency/team functionality):

  • Workspace name, description, and brand logo
  • Team member email addresses (for invitations)
  • Workspace invite tokens (SHA-256 hashed in database)
  • Member roles (OWNER, MANAGER, CLIENT, VIEWER)
  • Post approval records and reviewer comments
  • Member join/leave timestamps

Team members invited to a workspace consent to this data being stored when they accept the invitation.

3.7 Referral Program Data

If you participate in our referral program:

  • Your referral code
  • The referral code used during your registration (if any)
  • Referral earnings amounts and payout status
  • Payout method and reference (for processing referral payouts)

3.8 Technical and Operational Data

  • Session refresh tokens (SHA-256 hashed — raw token never stored)
  • Email verification OTP codes (SHA-256 hashed — raw OTP sent to email only)
  • Password reset tokens (SHA-256 hashed)
  • Notification preferences (which email notifications you have enabled)
  • API rate limit tracking per platform (to respect platform quotas)
  • Post preset templates you create

4. SOCIAL PLATFORM DATA — SPECIFIC DISCLOSURES (META & PINTEREST)

This section provides explicit detail about data received from Facebook, Instagram, YouTube, and Pinterest APIs, as required by Meta's Platform Policy and Pinterest's Developer Policy.

4.1 Facebook Data

Permissions we request:

  • public_profile: Your name and Facebook user ID, used to identify your connected account in our dashboard.
  • pages_show_list: List of Facebook Pages you manage, so you can select which page to connect and post to.
  • pages_read_engagement: Page analytics (reach, fan count, impressions, post metrics), displayed in your SocialScheduler analytics dashboard.
  • pages_manage_posts: Publish posts to your Facebook Page at your scheduled times.

What we do with Facebook data:

  • We use it solely to provide the scheduling and analytics service.
  • We do not use Facebook data for advertising or to build advertising profiles.
  • We do not sell Facebook user data to any third party.
  • We do not access your personal Facebook timeline, friends list, or private messages.
  • Analytics data is aggregated page metrics — we do not store individual fan identities.

4.2 Instagram Data

Permissions we request:

  • instagram_business_basic: Your Instagram username and account ID, used to display your connected account and fetch your profile picture.
  • instagram_business_content_publish: Publish photos, videos, reels, and carousels to your Instagram Business or Creator account at your scheduled times.
  • instagram_manage_insights: Account-level and post-level analytics (reach, impressions, profile views, follower count, website clicks, per-post engagement), displayed in your analytics dashboard.

What we do with Instagram data:

  • We use it solely to provide scheduling and analytics features.
  • We do not read, store, or process your Instagram direct messages.
  • We do not read, store, or process comments on your posts beyond aggregate count metrics.
  • We do not access your followers' personal information.
  • We do not use Instagram data for advertising purposes.
  • We do not sell Instagram data to any third party.

4.3 YouTube Data

Permissions we request:

  • youtube.upload: Upload videos to your YouTube channel.
  • youtube.force-ssl: Set video metadata (title, description, tags, visibility, category), upload thumbnails, and add videos to playlists.
  • yt-analytics.readonly: Read your channel analytics (views, watch time, subscribers, impressions, CTR), displayed in your analytics dashboard.

YouTube API Services: SocialScheduler uses YouTube API Services. By using our YouTube integration, you also agree to Google's Privacy Policy (https://policies.google.com/privacy). You can revoke our access to your YouTube data at any time via Google's Security Settings: https://security.google.com/settings/security/permissions

4.4 Pinterest Data

Permissions we request:

  • user_accounts:read: Your Pinterest username and account ID, used to display your connected account.
  • boards:read: List your existing Pinterest boards, so you can select which board to pin to.
  • boards:write: Create new Pinterest boards from within SocialScheduler.
  • pins:write: Create and publish pins to your Pinterest boards at your scheduled times.

What we do with Pinterest data:

  • We use it solely to provide pin scheduling features.
  • We do not access your followers' personal information.
  • We do not use Pinterest data for advertising purposes.
  • We do not sell Pinterest data to any third party.

4.5 Revoking Social Platform Access

You can disconnect any social account from SocialScheduler at any time by:

  • (a)Going to Settings → Social Accounts in your SocialScheduler dashboard and clicking Disconnect, OR
  • (b)Removing SocialScheduler from your platform's app permissions directly:
  • Facebook: Settings → Security → Apps and Websites
  • Instagram: Instagram Settings → Security → Apps and Websites
  • Google/YouTube: https://security.google.com/settings/security/permissions
  • Pinterest: Pinterest Settings → Security → Authorized Apps

When you disconnect a social account, the associated OAuth tokens are deleted from our database immediately and permanently.

5. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data to anyone. We share data only with the following service providers, strictly to operate the platform:

Service ProviderRoleData SharedLocation
SupabasePostgreSQL database hostingAll structured data (accounts, posts, tokens, analytics)Mumbai, India
Cloudflare R2Media file storageUploaded images and videosGlobal CDN (edge)
RazorpayPayment processingSubscription amounts, customer ID, statusIndia
RenderBackend API hostingAPI request processingSingapore
VercelFrontend hostingWeb page deliveryGlobal CDN
Meta PlatformsFacebook/Instagram APIOAuth tokens, post content, analytics requestsUSA
GoogleYouTube APIOAuth tokens, video content, analytics requestsUSA
PinterestPinterest APIOAuth tokens, pin content requestsUSA

All service providers are bound by data processing agreements and are permitted to use your data only for the specific purpose of providing their service to us.

6. HOW WE PROTECT YOUR DATA

We implement the following security measures:

  • (a)PASSWORDS: BCrypt one-way hashing. Your raw password is never stored anywhere in our system. We cannot retrieve your password — only reset it.
  • (b)SOCIAL MEDIA TOKENS: AES-256-GCM encryption at rest. Each token is encrypted with a unique random 12-byte Initialization Vector (IV), producing ciphertext that is always unique. The encryption key is stored separately in secure environment variables, never in the codebase.
  • (c)PHONE NUMBERS: AES-256-GCM encryption at rest (same mechanism as social tokens).
  • (d)OTP CODES: SHA-256 one-way hashed. The raw OTP is sent to your email and is never stored. Only the hash is stored for verification.
  • (e)SESSION TOKENS: SHA-256 one-way hashed. Raw session tokens are never stored.
  • (f)INVITE TOKENS: SHA-256 one-way hashed.
  • (g)DATA IN TRANSIT: All data transmitted between your browser, our servers, and third-party APIs is encrypted using TLS 1.2 or higher.
  • (h)PAYMENT CREDENTIALS: We never store card numbers, CVV codes, bank account numbers, or UPI credentials. Razorpay handles all payment credential processing under their PCI-DSS compliance.
  • (i)ACCESS CONTROLS: OAuth tokens are never exposed in API responses to the frontend. The frontend only receives confirmation that an account is connected.

7. DATA RETENTION

Data TypeRetention Period
Account data (name, email, etc.)Until account permanently anonymized
Social OAuth tokensUntil you disconnect the social account (deleted immediately on disconnect)
Post content and captionsUntil you delete the post, or until your account is anonymized
Media files (Cloudflare R2)Until you delete the file, or until your account is permanently deleted (R2 files deleted before DB anonymization)
Analytics data12 months rolling
Payment and transaction records7 years (Indian accounting law requirement)
Verification OTP recordsDeleted after first use or expiry (whichever comes first)
Session refresh tokensUntil logout, revocation, or 30 days of inactivity
Workspace invite tokensUntil accepted or expired

7.1 Account Deletion and Anonymization Timeline

SocialScheduler offers two account closure options:

OPTION A — DEACTIVATE ACCOUNT (1-Year Grace Period):

When you deactivate your account:

  • Your account is immediately disabled (cannot log in, publishing stops, billing is cancelled).
  • Your personal data is retained for 1 year to allow account recovery.
  • After 1 year, your account is permanently anonymized (see below).
  • You can reactivate within 1 year by contacting us.
OPTION B — PERMANENTLY DELETE ACCOUNT (30-Day Queue):

When you request permanent deletion:

  • Your account is immediately disabled.
  • All your media files are deleted from Cloudflare R2 storage first.
  • Your account is queued for full anonymization within 30 days.
  • After 30 days, all personal data is permanently anonymized (see below).
  • This action cannot be reversed after 30 days.
WHAT "PERMANENTLY ANONYMIZED" MEANS:
  • Your email is replaced with a randomized non-identifying string.
  • Your name is replaced with generic placeholder text.
  • Your phone number is cleared.
  • Your profile picture is cleared.
  • Your password hash is cleared.
  • Your social media OAuth tokens are deleted.
  • Your session tokens are revoked.
  • Your media files are deleted from Cloudflare R2.
  • The database row itself is retained only for referential integrity of financial records (required by Indian accounting law), but it contains no information that can identify you as a natural person.
META-INITIATED DELETION:

If you remove SocialScheduler from your Facebook app settings, Meta sends us an automated deletion request. We process this within 30 days, following the same anonymization procedure as Option B above.

You can track the status of a Meta-initiated deletion at:

https://socialscheduler.co/data-deletion-status

8. YOUR RIGHTS

Under the SPDI Rules 2011 and the forthcoming DPDP Act 2023, you have the following rights regarding your personal data:

  • (a)RIGHT TO ACCESS: You can request a copy of the personal data we hold about you by emailing privacy@socialscheduler.co.
  • (b)RIGHT TO CORRECTION: You can update your name, email, phone, and profile picture directly in your account settings. For corrections you cannot make yourself, contact us.
  • (c)RIGHT TO DATA PORTABILITY: You can request an export of your data (posts, analytics history, account information) by emailing privacy@socialscheduler.co.
  • (d)RIGHT TO DELETION: You can delete your account at any time via Settings → Danger Zone in your dashboard. See Section 7.1 for the timeline.
  • (e)RIGHT TO WITHDRAW CONSENT: You can disconnect any social media account at any time (see Section 4.5). This withdraws consent for us to post to or read analytics from that account. Note that withdrawal of consent for essential services (like the scheduling token) will prevent us from providing the service.
  • (f)RIGHT TO GRIEVANCE REDRESSAL: If you believe your data rights have been violated, contact our Grievance Officer (see top of this policy). You also have the right to file a complaint with the Data Protection Board of India once it is operational.

To exercise any of the above rights, email: privacy@socialscheduler.co

We will respond within 30 days of receiving your request.

9. COOKIES AND TRACKING

SocialScheduler uses only essential cookies required for the platform to function:

  • Authentication session cookies (to keep you logged in)
  • CSRF protection tokens

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not serve advertisements. We do not share data with advertising networks.

10. CHILDREN'S PRIVACY

SocialScheduler is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has registered on our platform, please contact grievance@socialscheduler.co and we will delete the account immediately.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Send an email notification to your registered email address
  • Display a notice in your SocialScheduler dashboard

Continued use of SocialScheduler after a policy update constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you must discontinue use and may request account deletion.

12. CONTACT US

For any privacy-related questions, data requests, or concerns:

Email: privacy@socialscheduler.co

Grievance Officer: grievance@socialscheduler.co

Website: https://socialscheduler.co

Address: Ahmedabad, Gujarat, India

For Meta Data Deletion Status:

https://socialscheduler.co/data-deletion-status

END OF PRIVACY POLICY — VERSION 1.0

© 2026 SocialScheduler. All rights reserved.