Legal

Trust & Security

How we protect your account and your content today. We only list measures that are actually in place — anything still to be verified is marked.

Last reviewed: [TO BE COMPLETED]

Account security

  • Passwords are stored only as salted hashes, never in plain text.
  • Sign-in uses signed session tokens with an expiry, and sessions can be ended by logging out.
  • Google sign-in is available so you can rely on your Google account's own protections.
  • Repeated failed login attempts are rate-limited to slow down guessing.
  • You can change your password at any time from Settings, and reset it by email if you forget it.

Encryption

Traffic between your browser and PostMint is served over HTTPS/TLS. Data at rest is stored in our managed database.

Confirm before publishing. Confirm before publishing: state your database encryption-at-rest configuration and TLS versions once verified with your hosting provider.

Access controls

  • Customer data is scoped to the account that owns it; every request is checked against the signed-in user.
  • Administrative screens are restricted to PostMint admin accounts.
  • Access tokens for connected social accounts are stored for publishing and removed when you disconnect the account.

Infrastructure

PostMint runs as a managed cloud application with a managed database.

Confirm before publishing. Confirm before publishing: name your hosting provider, region and data location.

Backups and continuity

Backup frequency, retention and restore testing.

Confirm before publishing. Confirm before publishing: describe your actual backup schedule, retention and whether restores have been tested. Do not claim backups that are not configured.

Incident management

We monitor application errors and investigate reports of security problems. If a personal data breach affects you, we will inform you and, where required, the supervisory authority. Report a suspected vulnerability or incident to mint@postmint.nl — please do not test against other customers' data.

Privacy by design

  • Card details are handled by our payment provider; PostMint never stores them.
  • Non-essential cookies are off until you consent, and analytics is not loaded before that.
  • You can export your data and delete your account yourself from Settings → Privacy & Data.
  • Content is only published after you approve it.

Third-party providers

We rely on providers for hosting, payments, email and AI generation. Each is listed with its role in the Subprocessor List on the DPA page.

What we do not claim

We do not hold ISO 27001 or SOC 2 certification, and we have not published a third-party penetration test. We would rather tell you that plainly than imply a certification we do not have.

Contact

Questions about this document, your data or your subscription can be sent to mint@postmint.nl. Our company details are listed on the Legal Notice page.

PostMint · postmint.nl · mint@postmint.nl · Registered in the Netherlands · KVK 42148900