Privacy Policy
Effective Date: 14.11.2025
1. Scope
This Privacy Policy explains how SnapPoster, operated by CityShop OÜ, collects, uses, and protects data submitted by business clients. This policy applies to users in the European Union, United States, and other supported jurisdictions. We do not provide services to users located in the Russian Federation, Belarus, or any region engaged in or supporting armed aggression.
2. What Data We Collect
- Business contact information (e.g., company name, email)
- Facebook Page ID and access token (encrypted)
- Feed URLs and scheduling preferences
- Stripe billing metadata (we do not store payment details)
- Usage logs, AI prompts, and posting behavior
3. How We Use Your Data
- To deliver the SnapPoster service and AI-based feed generation
- To communicate onboarding and operational messages
- To track service usage, detect abuse, and ensure uptime
- To analyze patterns, optimize product decisions, and inform our marketing
- To train AI systems or recommendation engines using anonymized content
4. Legal Basis (GDPR)
SnapPoster is intended for businesses. If personal data (e.g. contact name or email) is submitted, we rely on:
- Contractual necessity – to deliver what you subscribed to
- Legitimate interest – to improve the service and prevent abuse
5. Storage and Security
All data is stored securely in the EU (via DigitalOcean infrastructure). Facebook tokens are encrypted at rest. Traffic is encrypted (HTTPS). Only authorized personnel have access to client data.
6. Data Use and Processors
You agree that we may collect, use, and analyze all submitted and generated data for business purposes, including:
- AI training and prompt optimization
- Internal analytics, diagnostics, and commercial research
- Sales, marketing, and communication improvements
We do not resell or publish identifiable customer data.
We use the following processors/service providers under GDPR-compliant agreements:
- DigitalOcean – hosting and data storage (infrastructure provider)
- SMTP2GO – transactional email delivery (uses your business contact email)
- Stripe – payment processing and billing (customer email and invoice metadata)
- Optional (when enabled): OpenAI/Google GenAI – text/image enhancement (no use by default)
We publish content to Meta (Facebook/Instagram) on your behalf. Meta acts as a separate controller; beyond tokens and the content you choose to publish, we do not share your personal details with Meta.
Government Data Requests
CityShop OÜ’s policy for requests from public authorities:
- Legality review: We review every request for legal sufficiency, scope, and jurisdiction, and consider only written requests citing valid authority.
- Challenge process: We challenge or seek to narrow unlawful or overbroad requests.
- Data minimization: We disclose only the minimum information necessary to comply with a valid request; where feasible we use aggregated, anonymized, or redacted data.
- Documentation: We document each request, the legal basis, reviewer, decision, any disclosures, and timestamps for audit and compliance.
- Notification: Where permitted by law, we notify affected customers prior to disclosure.
7. Your Rights
If personal data has been submitted (e.g. contact person details), you may request:
- Access to your personal data
- Correction or deletion (if applicable)
- Export or restriction of that data
Contact: support@cityshop.ee. We will respond within 30 days as required by law.
8. Data Retention
We retain business usage data and logs for as long as your subscription is active. After termination, data may be retained for up to 12 months for security, billing, or analytics purposes unless otherwise requested.
9. Jurisdiction Limits
We do not permit use of our service from or by residents of the Russian Federation, Belarus, or other territories actively involved in armed aggression or sanctioned by the EU or US. Detection may result in account suspension or termination.
10. Contact
CityShop OÜKesakanni 40, 51011 Tartu, Estonia
Email: support@cityshop.ee
Registry Code: 14196231
11. Changes
We reserve the right to update this Privacy Policy at any time. Significant changes will be communicated through the dashboard or email. Continued use of SnapPoster constitutes acceptance of the revised terms.
Data Deletion
To request deletion of Facebook-related data, follow the instructions here: Data Deletion.