Privacy Policy
ApprovePost is a SaaS service operated by Mykyta Vorushylo, an individual entrepreneur registered under the laws of Ukraine (“we,” “us,” or “our”). This Policy explains how personal data is handled in connection with approvepost.app, ApprovePost accounts, client reviews, subscriptions, integrations, and support.
1. Scope and privacy roles
This Policy applies to personal data handled through the ApprovePost public website, application, public review pages, support channels, subscriptions, and integrations. It does not govern the independent privacy practices of Paddle, Google, Telegram, Cloudflare, or other services you use separately.
ApprovePost is a service and brand, not a separate legal entity. The data-controller identity and contact details are provided in Section 14.
We act as an independent controller when we determine the purposes and means of processing account, authentication, billing-administration, website analytics, product communications, support, fraud-prevention, and security data.
When an account holder submits personal data in media, captions, review information, or similar customer content and instructs us to process it solely to provide the approval workflow, the account holder or its organisation ordinarily acts as controller (or processor for its own client) and we act as its processor or subprocessor. Our Data Processing Agreement (“DPA”) governs that processor-scope data.
Technical data that we need independently to secure the Service, prevent abuse, keep audit records, establish legal claims, or administer our own account relationship remains controller data even when it relates to activity involving Customer Personal Data.
2. Personal data we handle
Depending on how you use ApprovePost, we may handle:
- Account and authentication data: email address, display name, internal account identifiers, plan, account dates, legal-document acceptance records, and information supplied by supported sign-in providers.
- Customer and review data: client or review names, captions, media, filenames, branding, review status, decisions, feedback, revision history, and related timestamps.
- Billing-administration data: Paddle customer, transaction, and subscription identifiers, subscription status, billing-period dates, and signed webhook events. We do not receive your full payment-card number or card security code.
- Integration data: information needed to connect and operate optional integrations, such as Telegram chat identifiers and notification content.
- Website and analytics data: consent choices, page and interaction information, approximate location, browser/device information, referrer, and pseudonymous analytics identifiers where optional analytics is enabled.
- Support and request data: name, email, message content, support history, and information reasonably needed to verify and respond to a request.
- Security and technical data: IP address, user agent, request and error logs, timestamps, session/security data, rate-limit information, bot-protection signals, and similar information needed to operate and protect the Service.
ApprovePost is not designed for payment-card data, passwords, government identifiers, medical records, biometric data, precise geolocation, children’s data, criminal-offence data, or special-category data. Do not place such information in User Content or support messages unless we have expressly agreed in writing that the Service supports that processing.
3. How and why we use personal data
We use personal data to provide and administer the Service; authenticate users; deliver reviews and requested integrations; manage subscriptions and entitlements; provide support; prevent fraud, abuse, and security incidents; comply with law and protect legal rights; maintain and improve reliability; and, where permitted, communicate about ApprovePost.
Where the GDPR or UK GDPR applies, the legal basis depends on the processing and may include performance of a contract or pre-contract steps, compliance with legal obligations, our legitimate interests in operating and protecting the Service, and consent where required, including for optional analytics.
Where we rely on legitimate interests, we consider necessity, reasonable expectations, and the impact on individuals. Where we rely on consent, you may withdraw it prospectively. We do not use ApprovePost data to make solely automated decisions that produce legal or similarly significant effects.
If we send direct marketing, you may object or opt out at any time. We will honour direct-marketing objections without requiring special grounds.
4. Customer content and review links
Uploaded media is stored in private object storage and made available through access-controlled or time-limited mechanisms. Review links are bearer capability links: they are not intended to be publicly indexed, but anyone who obtains a valid link may be able to view the associated review and submit feedback while the review is open. Account holders must share links only with intended recipients and revoke or rotate a link if it is exposed.
Reviewer decisions, feedback, and timestamps are disclosed to the account holder. If the account holder enables an optional notification integration such as Telegram, relevant review information may be transmitted to that service at the account holder’s instruction. Account holders are responsible for deciding whether such an integration is appropriate and for providing reviewers with any notices they are legally required to provide.
If you are a reviewer and your request concerns Customer Personal Data supplied by an ApprovePost customer, that customer is ordinarily responsible for determining the purpose and lawful basis of the review processing. We may refer a rights request to the relevant customer where appropriate.
5. Providers and disclosures
We do not sell personal data. We disclose data only as reasonably necessary to provide and protect the Service, follow your instructions, complete a transaction, or comply with law. Recipients may include:
- Cloudflare for object storage and, where enabled, bot and abuse protection;
- Google for optional analytics and supported authentication, subject to the relevant configuration and consent;
- Paddle for checkout, payment, tax, invoicing, subscriptions, refunds, chargebacks, fraud prevention, and purchaser communications as Merchant of Record;
- Telegram when an account holder enables the Telegram integration;
- hosting, database, email, logging, and infrastructure providers used to operate the Service;
- account holders and invited reviewers according to the review workflow and link permissions; and
- professional advisers, authorities, and counterparties where reasonably necessary for legal advice, compliance, security, claims, or a permitted business transfer.
Processor-scope subprocessors for Customer Personal Data are listed in the DPA. Some providers may act as independent controllers for their own transaction, account, security, or service-improvement purposes.
6. Paddle and payments
Paddle is the Merchant of Record and authorised reseller for paid ApprovePost transactions. Paddle is the seller identified at checkout and independently processes checkout, payment, tax, invoicing, subscription, fraud-prevention, refund, chargeback, and buyer-support data under its own legal terms and privacy notice.
ApprovePost sends Paddle information needed to initiate and reconcile the transaction, such as your email or Paddle customer identifier, an internal user identifier, the selected price, and transaction metadata. Paddle returns identifiers, subscription status, billing-period and cancellation information, and signed events needed to provision and administer access. We do not receive full card credentials.
7. International transfers
ApprovePost is operated from Ukraine, and our providers may process data in other countries. Where applicable law requires a safeguard for a restricted international transfer, we use the mechanism appropriate to the transfer.
For Customer Personal Data transferred to us from the EEA or UK where a restricted-transfer mechanism is required, the DPA incorporates the applicable European Commission Standard Contractual Clauses and UK transfer addendum. The parties remain responsible for any transfer assessment or supplementary measures required for their circumstances.
8. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, applying the plan’s content-retention rules, maintaining security and transaction integrity, complying with law, resolving disputes, and establishing or defending claims.
Account and active workflow data are generally retained while the account or relevant review exists. Media may be deleted earlier under the plan or review-retention rules. Account deletion removes or anonymises data from active ApprovePost systems according to the available deletion workflow, subject to lawful retention and temporary residual copies in logs, queues, or provider backups until they are overwritten under applicable schedules.
Deleting an ApprovePost account does not automatically delete records that Paddle, Google, Telegram, or another independent controller retains for its own lawful purposes.
9. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, and loss. Measures include access controls, encrypted transport, private storage where appropriate, limited-lifetime access mechanisms, request validation, abuse prevention, logging, and provider security controls appropriate to the Service.
No online service is completely secure. You are responsible for securing your email and account access, maintaining independent copies of important content, and sharing review links only with intended recipients. Contact [email protected] if you suspect unauthorised access or disclosure.
10. Your choices and rights
Depending on your jurisdiction and our role, you may have rights to access, correct, delete, restrict, or obtain certain personal data; object to processing based on legitimate interests or direct marketing; withdraw consent; receive certain data in a portable format; appeal certain decisions; and complain to a competent data-protection authority.
Account holders can use available profile, export, and deletion tools. You may also submit a request through the contact form or email [email protected]. We may request proportionate verification and may limit or refuse a request where permitted by law.
Where we act only as a processor for Customer Personal Data, we may refer the request to the customer that controls that processing.
11. Children
ApprovePost accounts and paid subscriptions are restricted to people aged 18 or older. Review functionality is not intended for children under 16. Do not submit children’s personal data unless you have all authority and safeguards required by applicable law and we have expressly agreed that the processing is supported.
13. Updates
We may update this Policy to reflect changes in the Service, providers, or law. We will update the date above and provide additional notice where a material change or applicable law requires it. Where new consent is required, we will request it before relying on the new consent-based processing.
14. Data controller and contact information
ApprovePostOperated by Mykyta Vorushylo, an individual entrepreneur (FOP) registered under the laws of Ukraine
Kyiv, Kyiv Region, Ukraine
Privacy email: [email protected]
Online request: Contact form
If applicable law requires us to appoint an EU or UK representative or a data-protection officer for relevant processing, we will publish the required contact details here.