Privacy Policy
Last updated: August 23, 2026
This Privacy Policy explains how Hookpost ("Hookpost", "we", "us", or "our"), operated by JR Consulting Co., collects, uses, shares, and protects personal data in connection with the Hookpost social-media scheduling, publishing, analytics, and team-collaboration platform (the "Service"), the website at hookpost.hookstep.in and related sub-domains (the "Site"). It applies to visitors to the Site, account holders, members of customer workspaces, and anyone else who interacts with us. By using the Site or the Service, you acknowledge this Policy. For our contractual terms, see our Terms of Service.
1. Who We Are (Data Controllers)
Hookpost is owned and operated by JR Consulting Co. JR Consulting Co. is the contracting party for paid subscriptions, the recipient of subscription revenue, and the primary data controller for account, billing, customer-support, marketing, and Service-usage data.
JR Consulting Co. also holds the developer accounts, OAuth integrations, and platform-side approvals with third-party social media platforms whose APIs the Service uses (including X / Twitter, Meta / Facebook / Instagram / Threads, LinkedIn, YouTube, TikTok, Pinterest, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram, and GitHub).
For all privacy questions, requests, and data inquiries, you can reach us at jatinder1901243@gmail.com.
2. The Service in Brief
Hookpost lets you connect multiple social-media and chat channels to centrally schedule, publish, analyze, and collaborate on content. The platform includes a visual content calendar, media storage engine, publishing queue, analytics dashboards, AI-assisted content optimization, team permissions, and third-party integrations.
3. The Data We Collect
3.1 Account & Identity Data
- Name, email address, password (stored solely as a cryptographically salted one-way hash), profile picture, workspace name, role, language, and timezone preferences.
- If you sign in via a social-login provider (e.g., Google or GitHub), the basic profile fields and email address returned by that provider.
- Workspace membership, invitations sent/accepted, and permissions granted within an organization.
3.2 Connected Platform Data
When you connect a third-party social or messaging account to Hookpost, we receive and store via authorized APIs:
- OAuth access & refresh tokens (encrypted at rest using AES-256), the scopes granted, platform username, user IDs, page IDs, channel IDs, and profile avatars.
- Content and engagement data needed to provide the Service: scheduled posts, published posts, comments, post-level analytics (impressions, reach, clicks, engagement metrics), and aggregate audience data exposed by platform APIs.
- For YouTube specifically: The Service uses YouTube API Services. Your use of those features is subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke Hookpost's access to your Google data at any time via Google Security Settings.
- For Pinterest specifically: We access your Pinterest user boards and profile solely to create Pins on your behalf in compliance with Pinterest Developer Policies.
3.3 Content You Upload
Text, images, video, audio, captions, links, hashtags, schedules, prompts, notes, and calendar metadata you upload to or generate within the Service.
3.4 Billing Data
Plan tier, subscription status, invoice history, billing email, and transaction IDs. Card numbers and banking details are processed directly by our PCI-compliant payment gateways (including Razorpay); Hookpost never stores your raw card credentials.
3.5 Logs, Usage & Device Data
- IP address, browser user-agent, operating system, referrer URL, and approximate geographic location derived from IP.
- Application telemetry: pages visited, features used, post dispatch logs, error reports, and performance metrics.
4. How We Use the Data & Legal Bases
- Provide the Service: Authenticate users, manage workspaces, store media, publish content across connected social channels, and generate analytics dashboards. (Performance of contract)
- Billing & Subscriptions: Process subscriptions, issue invoices, prevent payment fraud, and fulfill tax requirements. (Performance of contract; legal obligation)
- Security & Abuse Prevention: Detect and mitigate unauthorized account access, DDoS attacks, spamming, and platform policy violations. (Legitimate interests)
- Improve the Service: Debug issues, monitor uptime, and optimize application performance. (Legitimate interests)
- Transactional Communications: Send critical notifications regarding failed posts, security alerts, and account changes. (Performance of contract)
We do not use your private posts or messages to serve third-party advertising, and we do not sell your personal data.
5. AI-Assisted Features
The Service offers optional AI tools to generate or refine captions, hashtags, and copywriting. Prompts and drafted text are transmitted securely to sub-processor model providers (such as OpenAI). We enforce contractual terms requiring that your data is not used to train public foundation models. AI outputs are probabilistic; you remain responsible for reviewing content before publishing.
6. Controller vs. Processor
For account, billing, site telemetry, and security data, Hookpost acts as a data controller. For the content you schedule and the audience metrics fetched on your behalf, Hookpost acts as a data processor operating under your instructions.
7. Who We Share Data With
We do not sell personal data. We share data only with:
- Connected Third-Party Platforms: Transmitting scheduled posts and media to the platforms you choose (Pinterest, YouTube, Meta, X, LinkedIn, etc.).
- Infrastructure & Hosting Sub-processors: Secure cloud infrastructure (Google Cloud Platform), Redis, PostgreSQL, and transactional email providers (Resend).
- Workspace Collaborators: Team members assigned to your Hookpost organization based on their designated roles.
- Legal Authorities: When required by valid legal process, court order, or regulatory mandate.
8. Data Retention
- Account & Workspace Data: Retained while your account is active. Upon account deletion, data is purged or anonymized within 30 days.
- OAuth Tokens: Retained while connected. Disconnecting a platform immediately purges active tokens from our database.
- Scheduled Content: Retained until published or manually deleted by the user.
- Billing Invoices: Retained as required under statutory financial and taxation regulations.
9. Security
We implement comprehensive technical and organizational measures: TLS 1.3 encryption in transit, AES-256 encryption for stored tokens, cryptographic password hashing, isolated database networks, and automated intrusion monitoring.
10. Your Rights (GDPR / CCPA / Global)
You have the right to access, rectify, or erase personal data, object to or restrict processing, and export your content. To exercise these rights, email jatinder1901243@gmail.com.
11. Contact Us
For questions or privacy requests, contact: