← Back to automrktr

Privacy Policy

Effective date: April 9, 2026

1. Introduction

automrktr ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard information when you use our platform. By using automrktr, you agree to the practices described here.

2. Information We Collect

Information you provide

  • Account details: name, email address, password, business name, and website.
  • Billing information: processed by Stripe. We do not store card numbers.
  • Content you create or upload: social media posts, images, campaign settings.
  • Social media account credentials (stored encrypted) when you connect platforms.
  • Communications you send to our support team.

Information collected automatically

  • Usage data: pages visited, features used, actions taken within the platform.
  • Log data: IP address, browser type, device information, timestamps.
  • Cookies and similar tracking technologies (see Section 7).
  • Conversion pixel data when our tracking script is installed on your website.

Information from third parties

  • Social media analytics (impressions, reach, engagement) from connected platforms.
  • Payment and subscription status from Stripe.
  • Error and performance data from Sentry.

3. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To generate and schedule social media content on your behalf.
  • To process payments and manage subscriptions.
  • To send transactional emails (receipts, account alerts, weekly reports).
  • To detect and prevent fraud, abuse, and security incidents.
  • To analyse usage trends and improve the platform.
  • To comply with legal obligations.

We do not sell your personal information to third parties. We do not use your content to train AI models without your explicit consent.

We may send you product updates, feature announcements, and other promotional communications by email. You can opt out of marketing emails at any time by clicking the unsubscribe link in any such email or by emailing privacy@automrktr.io with "Unsubscribe" in the subject line. Opting out of marketing emails does not affect transactional emails (receipts, security alerts, account notices), which are necessary to provide the Service.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, we process your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you have subscribed to, including account management, content scheduling, and billing.
  • Legitimate interests: Security monitoring, fraud prevention, product analytics, and service improvement. Our legitimate interests are: operating a secure and reliable platform, understanding how the Service is used so we can improve it, and protecting automrktr and its users from abuse and fraud. We have assessed that these interests are not overridden by your rights and freedoms, taking into account the limited intrusiveness of the processing and the reasonable expectations of business users of a SaaS platform.
  • Legal obligation: Retaining billing and tax records as required by applicable law.
  • Consent: Marketing communications and any processing not covered above. You may withdraw consent at any time without affecting prior processing.

Our Data Processing Agreement is available for business subscribers who require one for GDPR compliance purposes.

5. International Data Transfers

automrktr is headquartered in the United States (Utah). If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the EU Standard Contractual Clauses ("SCCs") and, where applicable, the UK International Data Transfer Agreement. By using the Service, you acknowledge that your data may be transferred to and processed in the United States and other countries where our service providers operate.

To obtain a copy of the applicable transfer mechanism or request a DPA, contact us at privacy@automrktr.io.

6. How We Share Your Information

We share information only in the following circumstances:

  • Service providers: Supabase (database), Stripe (payments), Cloudinary (media storage), Resend (email), Upstash (queuing), Sentry (error monitoring), Anthropic and Replicate (AI generation). These providers process data only as necessary to perform services for us.
  • Social platforms: When you connect accounts, we share post content and credentials with Meta, LinkedIn, and other connected platforms to publish on your behalf.
  • Legal requirements: We may disclose information if required by law, court order, or government authority.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before this occurs.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. After cancellation or termination, we retain account data (content, campaign history, analytics) for up to 30 days, during which you may request an export. After this period, data is permanently deleted. You may request earlier deletion by contacting us (see Section 11).

Billing records and transaction logs may be retained for up to 7 years to comply with financial, tax, and legal obligations regardless of account status.

8. Security

We use industry-standard security measures including AES-256-GCM encryption at rest, TLS encryption in transit, role-based access controls, and audit logging. Social media access tokens are stored encrypted and accessed only server-side. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

If you suspect unauthorised access to your account, contact us immediately at privacy@automrktr.io.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where required by applicable law (including within 72 hours for GDPR purposes), notify the relevant supervisory authority. Notification to you will be sent to the email address on your account and will describe the nature of the breach, the data affected, likely consequences, and the measures we are taking to address it.

9. Cookies

We use cookies and similar technologies for the following purposes:

  • Essential cookies: Required for authentication and session management. These cannot be disabled.
  • Functional cookies: Remember your preferences and settings.
  • Analytics cookies: Help us understand how the platform is used (e.g. page views, feature usage).

You can control non-essential cookies through your browser settings. Disabling essential cookies will prevent you from logging in.

Do Not Track

Some browsers transmit a "Do Not Track" (DNT) signal. Because there is no industry-standard interpretation of DNT signals, automrktr does not currently alter its data collection practices in response to DNT signals. If a standard is adopted in future, we will revisit this policy.

10. Conversion Pixels and Third-Party Visitor Data

If you install the automrktr tracking pixel on your website, it collects visitor behaviour data (page views, conversions) from visitors to your site and associates it with your automrktr account. This data is used solely to provide conversion analytics to you and is not shared with or sold to any third party.

Your responsibility: When you install the automrktr pixel on your website, you become a data controller in respect of your website visitors' data. You are solely responsible for: (a) disclosing the use of the pixel in your own privacy policy; (b) obtaining any consent required from your website visitors under applicable law (including GDPR, CCPA, and ePrivacy regulations); and (c) ensuring your use of the pixel complies with all applicable laws. automrktr acts as a data processor in respect of this visitor data and processes it only on your instructions.

10A. Automated Decision-Making

automrktr uses AI and algorithmic systems to generate content suggestions, recommend posting schedules, optimise ad targeting parameters, and surface performance insights. These systems analyse your account data and historical performance to produce recommendations.

These automated processes are recommendations and tools only — all final publishing, scheduling, and spend decisions are made by you or your configured automations, not unilaterally by automrktr. If you are located in the EEA or UK and believe you have been subject to a solely automated decision with significant legal or similarly significant effect, you may contact us at privacy@automrktr.io to request human review.

10A-1. Special Category Data

automrktr does not intentionally collect or process special category personal data (as defined under GDPR Article 9) about Data Subjects, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation.

If you use the Service to create or publish content that references, targets, or otherwise involves special category data — for example, advertising for healthcare providers, political organisations, or religious groups — you are solely responsible for ensuring you have the required legal basis under GDPR Article 9 (or equivalent applicable law) to process that data, and for obtaining any necessary explicit consents. automrktr does not review content for special category data and accepts no liability for your processing of such data.

10B. Data Controller and Processor Roles

automrktr operates in different roles depending on the data being processed:

  • Data Controller: automrktr is the data controller for personal data collected directly from subscribers (account holders) — including registration details, billing information, and platform usage data. We determine the purposes and means of processing this data.
  • Data Processor: automrktr acts as a data processor when handling personal data that subscribers upload, configure, or direct us to process on behalf of their own clients or end users — including content for social media accounts, audience data, and pixel-collected visitor data. In this capacity, we process data only on the subscriber's instructions as set out in our Data Processing Agreement.

Business subscribers who process personal data of their own clients through automrktrare themselves data controllers and are responsible for having a lawful basis to share that data with automrktr and for maintaining their own privacy notices.

11. Your Rights

General Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data ("right to be forgotten").
  • Object to or restrict processing of your data.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent where processing is based on consent.

California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"):

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioural advertising as defined by the CPRA.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond the purposes permitted by the CPRA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

To submit a California rights request, email privacy@automrktr.io with "California Privacy Request" in the subject line. We will verify your identity before processing the request and respond within 45 days (extendable by an additional 45 days with notice).

EEA / UK Residents

If you are located in the European Economic Area or United Kingdom, you have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection law.

To exercise any of the rights above, email us at privacy@automrktr.io. We will respond within 30 days unless a longer period is permitted by applicable law.

12. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by email or by displaying a notice within the platform at least 14 days before the changes take effect. Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.

14. Contact Us

Questions or concerns about this Privacy Policy? Contact our privacy team at privacy@automrktr.io. automrktr is incorporated in the State of Utah, United States.