PostSquare

Privacy Policy

Effective Date: August 31, 2026

1. Introduction

This Privacy Policy explains how mindknoll ("PostSquare," "we," "us," or "our") collects, uses, stores, and shares your personal information when you use the PostSquare service ("Service").

We are committed to protecting your privacy and handling your data in a transparent, secure, and lawful manner. Please read this policy carefully. By using PostSquare, you agree to the practices described here.

If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and the UK GDPR. If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA/CPRA).

2. Data Controller

The data controller responsible for your personal information is:

mindknoll
Republic of Korea
Email: mindknoll@mindknoll.com

If you are located in the EU/EEA, our EU representative is: [EU Representative — to be designated before EU launch]

3. Information We Collect

3.1 Information You Provide Directly

  • Account information: Email address (used for authentication via Google OAuth or email/password).
  • Profile information: Nickname, avatar image, short bio, country of residence, language preference, and interests.
  • Postcard content: The text, design selection, and metadata of postcards and replies you create and send.
  • Communications: Messages you send to our support team.

3.2 Information Collected Automatically

  • Usage data: Pages visited, features used, postcards viewed or collected, interaction timestamps.
  • Device and connection data: IP address, browser type, operating system, device identifiers, referring URL.
  • Cookies and similar technologies: Session authentication tokens (Supabase), language preference cookie (ps_locale). See our Cookie Policy for details.

3.3 Location Information

To issue country stamps when you publish a postcard, we request access to your device location and read a single set of coordinates using your device's standard geolocation API. These coordinates are sent one time to a reverse-geocoding service (BigDataCloud) via our own server and translated into a two-letter country code and a coarse city name. We do not store or log the raw coordinates in our database, and we do not track your location over time. Only the resulting country code (and, where applicable, city name for display) is retained on your postcard.

If you deny location permission, you cannot publish postcards until permission is granted; this is required because country stamps are the app's core collection mechanic. You can revoke location permission at any time from your device settings.

3.4 Advertising

PostSquare shows advertisements provided by Google AdMob. AdMob may access your device's advertising identifier (AAID on Android) to serve, cap, and measure ads. You can reset or opt out of ad personalization through your device settings (Settings → Google → Ads on Android). PostSquare does not sell your personal information and does not share your postcard content or profile data with advertisers.

3.5 Information We Do Not Collect

  • We do not track your location over time or maintain a location history.
  • We do not integrate third-party analytics or tracking SDKs beyond Google AdMob (see §3.4).
  • We do not access your device contacts, camera, or microphone without your explicit action (e.g., uploading an avatar).

4. How We Use Your Information

We use your information for the following purposes:

  • Providing the Service: Creating and managing your account, displaying the Square, enabling postcard creation, collection, and reply threads, and personalizing your stamp collection.
  • Communication: Sending service notifications (e.g., replies received), account security alerts, and product updates. You can opt out of non-essential communications.
  • Safety and moderation: Detecting and preventing abuse, spam, harassment, and violations of our Terms of Service.
  • Analytics and improvement: Understanding how users interact with PostSquare to fix bugs and improve features. We use anonymized or aggregated data where possible.
  • Legal compliance: Meeting our obligations under applicable laws and regulations, responding to lawful requests from authorities, and enforcing our Terms.

Legal Bases for Processing (GDPR)

For users in the EEA and UK, we process your data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service as described in our Terms.
  • Legitimate interests: Analytics, fraud prevention, and service security — where these do not override your rights.
  • Legal obligation: Complying with applicable law.
  • Consent: Where required by law, we will ask for your consent (e.g., optional marketing emails).

5. Information Sharing

We do not sell your personal information. We share your information only in the following limited circumstances:

  • Service providers: We share data with trusted third parties who help us operate PostSquare, including:
    • Supabase Inc. (authentication, database, storage) — servers in the United States and/or EU.
    • Vercel Inc. (web hosting and content delivery) — global CDN infrastructure.
  • Legal requirements: We may disclose your information if required by law, court order, or governmental authority, or where disclosure is necessary to protect the rights, property, or safety of PostSquare, our users, or the public.
  • Business transfers: If PostSquare is acquired or merges with another company, your data may be transferred to the successor entity, subject to the same privacy protections.
  • With your consent: In any other circumstance with your explicit consent.

All service providers are bound by Data Processing Agreements (DPAs) and are prohibited from using your data for their own purposes.

6. International Data Transfers

PostSquare is operated from the Republic of Korea, and our infrastructure providers are based in the United States and/or European Union. By using PostSquare, your information may be transferred to and processed in countries outside your country of residence.

For transfers of personal data from the EEA or UK to countries not recognized as providing an adequate level of data protection, we rely on appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions where applicable.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service.

  • Active account: Data is retained for the duration of your account.
  • After account deletion: We retain your data for 30 days to allow for account recovery, after which it is permanently and irreversibly deleted from our systems.
  • Legal obligations: Certain data may be retained longer where required by law (e.g., financial records).
  • Anonymized data: Aggregated, anonymized analytics data may be retained indefinitely.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

Rights for All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and personal data.
  • Opt-out: Unsubscribe from non-essential communications at any time.

Additional Rights for EEA/UK Residents (GDPR)

  • Data portability: Receive your data in a structured, machine-readable format.
  • Restriction of processing: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.
  • Lodge a complaint: File a complaint with your local data protection authority (e.g., your national DPA in the EU, or the ICO in the UK).

We will respond to all verifiable requests within 30 days.

Additional Rights for California Residents (CCPA/CPRA)

  • Know what personal information we collect, use, disclose, or sell.
  • Request deletion of your personal information.
  • Opt out of the sale or sharing of your personal information. PostSquare does not sell your personal information.
  • Non-discrimination: You will not receive different service for exercising your CCPA rights.

To exercise your rights, contact us at mindknoll@mindknoll.com or use the data management tools in your account settings (My Page → My Data).

9. Children's Privacy

PostSquare is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA) and equivalent regulations.

If you believe we have inadvertently collected data from a child under 13, please contact us immediately at mindknoll@mindknoll.com and we will promptly delete such data and close the account.

Users between 13 and 18 should have parental or guardian consent to use PostSquare. In certain EU member states, the minimum age for consent is 16; please consult your local laws.

10. Security

We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction, including:

  • Encryption of data in transit using TLS (HTTPS).
  • Encryption of data at rest in our database infrastructure.
  • Access controls limiting data access to authorized personnel only.
  • Regular security reviews and monitoring.

Important: PostSquare does not currently support end-to-end encryption. Postcard content and reply threads are readable by PostSquare for moderation and legal compliance purposes. Please do not share highly sensitive personal information through the Service.

In the event of a data breach affecting your rights, we will notify you and the relevant authorities as required by law.

11. Third-Party Links

Our Service may contain links to external websites or services not operated by PostSquare. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any external sites you visit.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you through the app or by email at least 14 days before the changes take effect.

We encourage you to review this policy periodically. The "Effective Date" at the top indicates when the policy was last revised.

13. Contact Us

For privacy-related inquiries, data access requests, or to report concerns, please contact:

mindknoll
Email: mindknoll@mindknoll.com
Website: postsquare.net