Privacy Policy
Effective: 4 August 2026
PostQueueHD schedules and publishes posts to the social accounts you connect. To do that we hold your account details, the content you give us to publish, and access tokens for the platforms you connect. This policy sets out exactly what we hold, why, how long for, and how to make us delete it.
Who is responsible for your data
Simão Coutinho, sole trader, taxpayer number 223695815, of Rua da Guiné, 4785-112 Trofa, Portugal, is the controller of the personal data described here.
For privacy questions, including any request under the sections below, write to info@postqueuehd.com.
What we collect
Data you give us
| Data | Why we have it |
|---|---|
| Name and email address | To create your account and sign you in |
| Password (hashed, never stored in readable form) | To sign you in |
| Two-factor secret or passkey, if you enable one | To sign you in more securely |
| Team name and the members you invite | To let more than one person share a queue |
| Posts, captions, images and videos you upload | Because publishing them is the service |
| Billing contact details and payment references | To take payment and issue invoices |
| Support messages you send us | To answer them |
Data we receive from the platforms you connect
When you connect a channel, that platform gives us data about the account you chose. We ask for the narrowest set that lets us publish on your behalf.
Facebook and Instagram (Meta)
| Permission we request | What it gives us |
|---|---|
pages_show_list |
The list of Facebook Pages you administer, so you can choose which to connect |
pages_read_engagement |
The name, category and profile picture of the Pages you connected |
pages_manage_posts |
The ability to publish the posts you schedule to those Pages |
instagram_basic |
The Instagram Business account linked to a connected Page, and its username and profile picture |
instagram_content_publish |
The ability to publish the posts you schedule to that Instagram account |
From Meta we store: your app-scoped user ID, the ID of each Page or Instagram Business account you connected, its name, username and profile picture URL, and the access tokens needed to publish. We do not request, receive or store your Facebook friends, your personal profile, your messages, your followers' data, or the content of anyone else's posts.
TikTok — your open ID, display name, avatar and the posting options your account allows, plus access and refresh tokens.
YouTube — your channel ID, title and thumbnail, plus access and refresh tokens.
Data we generate
Publishing results and error messages, timestamps, plan and usage counters, and ordinary server logs including IP address, which we keep for security and debugging.
How we use it
- To publish what you schedule, at the time you schedule it.
- To show you your queue, your history and what failed.
- To sign you in and keep your account secure.
- To take payment and enforce plan limits.
- To answer your support messages.
- To detect and investigate abuse and technical faults.
Under the GDPR our legal bases are: performance of our contract with you (all of the publishing, account and billing purposes), our legitimate interest in a secure and working service (logs, abuse prevention), and your consent where you have given it (optional emails).
We do not sell your data, and we do not use it to train machine learning models. We do not use Platform Data received from Meta, TikTok or Google for advertising, profiling, or any purpose other than delivering the features you asked for.
Who else sees it
We use these processors, each only for the purpose given:
| Processor | Purpose |
|---|---|
| PTisp | Application hosting, database, storage of the media files you upload, and transactional email — all on one managed server in Portugal |
| ifthenpay | Payment processing (Multibanco, MB WAY, card) |
| Meta Platforms, TikTok, Google | The platforms you chose to publish to |
We disclose data to anyone else only where the law requires it.
Where your data is held
Our servers and databases are in Portugal, hosted by PTisp. Where a processor transfers data outside the EU, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
How long we keep it
| Data | Retention |
|---|---|
| Account and team data | Until you delete your account |
| Access tokens for a connected channel | Until you disconnect it, the platform revokes it, or you delete your account |
| Posts and uploaded media | Until you delete them, or 90 days after account deletion |
| Publishing history | 24 months, then deleted |
| Invoices and payment records | 10 years, because Portuguese tax law requires it |
| Server logs | 90 days |
Deleting your data
There are three routes, and all of them work.
1. Disconnect one channel. In the app, go to Channels and disconnect it. We delete that channel's access token and platform identifiers and cancel anything still queued for it. We also ask the platform to revoke our access.
2. Delete your whole account. In the app, go to Settings and choose Delete account. This removes your account, your teams where you are the only member, your posts, your uploaded media and every connected channel.
3. Ask the platform, or ask us. If you remove PostQueueHD from your Facebook settings, Meta notifies us and we mark those channels disconnected. If you ask Meta to delete your data, Meta sends us a deletion request, we erase everything we received from Meta about that login — tokens, Page and account identifiers, profile pictures and usernames — and we return a confirmation code you can check on our site. Your PostQueueHD account and any TikTok or YouTube channels are not affected by a Meta deletion request, because Meta did not give us those.
You can also simply email info@postqueuehd.com and ask. We answer within 30 days.
Your rights
You have the right to access your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent at any time. Write to info@postqueuehd.com.
If you are not satisfied with our answer, you may complain to the Comissão Nacional de Proteção de Dados (cnpd.pt), or to the supervisory authority in your own country.
Security
Passwords are hashed. Access tokens are encrypted at rest. Traffic is served over TLS. Access to production data is limited to the people who need it to operate the service. No system is perfect: if a breach affects your data, we will notify you and the supervisory authority as the law requires.
Children
PostQueueHD is not for anyone under 16. We do not knowingly collect data about children. If you believe a child has given us data, write to info@postqueuehd.com and we will delete it.
Changes
If we change this policy in a way that matters, we will email you before it takes effect. The date at the top always reflects the current version.
Contact
Simão Coutinho Rua da Guiné, 4785-112 Trofa, Portugal info@postqueuehd.com