Privacy policy for Stocker Studio and social media integrations
This document explains what data is processed by Stocker Studio — Goodbax’s internal system for publishing content about the Stocker app on our social media channels — together with the Postiz tool and the connected platforms.
This policy does not cover the Stocker inventory app. The app has its own privacy policy.
1. Controller and contact
The data controller is Goodbax spółka z ograniczoną odpowiedzialnością, ul. Michała Kajki 32, 11-010 Barczewo, Poland, KRS 0000987721, NIP 7393971973, REGON 522888955.
For any personal data matter, including access and deletion requests, write to info@goodbax.com.
2. Whose data we process
- People authorised by Goodbax who connect platform accounts, prepare or approve content, and sign in to Studio or Postiz.
- Accounts and channels run by Goodbax on Facebook, Instagram, Threads, X, YouTube and TikTok — to the extent their data is personal data, e.g. when an account is linked to a specific person.
- People shown or named in content, e.g. in a photo or video.
- People who contact us about their data.
Studio is not used to collect data of people who have not connected their accounts. We do not connect accounts of other companies or customers.
3. What data we process
| Category | Examples | Source |
|---|---|---|
| Account and profile data | account or channel ID, display name, username, profile picture; for a Google account also the account’s email address | the platform, after the account is connected |
| Authorisation data | OAuth access and refresh tokens, their expiry, the granted scopes. We do not receive platform account passwords | the platform, after consent on the OAuth screen |
| Content and media | texts, images, videos, thumbnails, descriptions, schedule, IDs and links of published posts, publishing status, error messages | the Goodbax team; IDs and statuses from the platforms |
| Statistics | data provided by platform APIs, e.g. views, likes, follower or subscriber counts, watch time | the platform |
| Studio and Postiz user data | login, email address, data needed for sign-in and the second factor, a record of approval or rejection decisions | the authorised person; system operation |
| Technical data | IP address, request date and time, browser information, server and error logs | server operation |
4. Permissions we request from platforms
We connect accounts through Postiz. The scopes come from Postiz’s module for each platform, and the platform always shows the final list on its consent screen when the account is connected. Below we describe what we use them for.
YouTube (Google)
Stocker Studio uses YouTube API Services. The integration requests the scopes userinfo.profile, userinfo.email, youtube, youtube.force-ssl, youtube.readonly, youtube.upload, youtubepartner and yt-analytics.readonly. We use them to:
- identify the connected account and channel (ID, name, profile picture, Google account email),
- upload approved videos with title, description and thumbnail to our channel,
- read data and statistics of our channel and our videos.
By using the YouTube integration you use YouTube under the YouTube Terms of Service. Google processes data under the Google Privacy Policy. You can revoke the app’s access to your Google account at any time on the Google security settings page.
TikTok
In TikTok for Developers the integration is registered as the app Stocker.app. It requests the scopes user.info.basic, user.info.profile, user.info.stats, video.list, video.upload and video.publish. We use them to:
- identify the connected account (
open_idandunion_id, display name, username, avatar), - upload approved videos and photos to our account — as a post or as a draft to be finished in the TikTok app,
- read basic account statistics and the list of its videos.
Stocker.app has not passed a TikTok audit and does not have approved Direct Post. While that is the case, TikTok only allows private posts from it, visible to the account owner only. Data processed by TikTok is subject to the TikTok privacy policy.
Facebook, Instagram, Threads (Meta) and X
We request permissions to read basic page or account data, publish content to it and read statistics of those posts. The exact scope is shown on the Meta or X consent screen when the account is connected.
5. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Preparing, approving, scheduling and publishing content about our products on our channels | Art. 6(1)(f) — legitimate interest: promoting our own products and services |
| Assessing post performance from statistics | Art. 6(1)(f) — legitimate interest |
| Access management, system security, abuse detection | Art. 6(1)(f) — legitimate interest |
| Handling data requests, including deletion requests | Art. 6(1)(c) — legal obligation under the GDPR |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) — legitimate interest |
6. AI tools
Content may be prepared with the help of AI tools — currently Claude (Anthropic) and Codex (OpenAI). These tools receive the content being prepared and the information needed to prepare it and pass it on for approval, e.g. the name of the channel it is meant for. Every piece of content requires human approval in Studio before publishing. AI tools make no decisions about anyone that have legal effects.
7. Where data is stored
- Studio and Postiz run on a VPS that Goodbax rents from Hostinger. The databases of both systems are on that server — including the authorisation data (tokens), which Postiz keeps in its database.
- Content uploaded to Studio is stored in Studio. Content handed over to Postiz is stored in the file storage configured in our Postiz installation.
- Working drafts may also be created in tools used by the team, e.g. Google Drive.
- Published content is stored by the platforms, under their own rules.
8. Who receives data
- Hostinger — provider of the server that runs Studio and Postiz.
- Social media platforms — Google (YouTube), TikTok, Meta (Facebook, Instagram, Threads) and X. They receive content to publish and the requests made within the granted permissions. They process data under their own terms and privacy policies.
- AI tool providers — Anthropic and OpenAI — as described in section 6.
- Office tool providers, e.g. Google (Google Drive), if working drafts are stored there.
- Public authorities, where required by law.
Some of these providers are based in or process data outside the European Economic Area, in particular in the USA. Such transfers rely on the GDPR transfer mechanisms that these providers refer to in their terms.
We do not sell data from connected accounts.
9. How long we keep data
We do not apply a single fixed retention period. We keep data while it is still needed:
- account and authorisation data — while the account is connected and used for publishing,
- content and decision records — while needed to run our channels, account for publishing decisions or defend against claims,
- statistics — while used to assess post performance.
Disconnecting a channel in Postiz does not immediately delete all data. Postiz marks the channel as deleted, and its record, including tokens, may remain in the database until we delete it. That is why we describe separately how to revoke access and request deletion.
We make server backups, including within Hostinger’s services. Data deleted from the system may remain in backups until they are replaced by newer backups.
10. Security
- Connections to Studio, Postiz and these pages are encrypted (HTTPS).
- The Studio panel requires a password and a one-time code from an authenticator app.
- Postiz is protected by an additional password and its own login; public sign-up is disabled.
- Access to Studio, Postiz and the server is held by people authorised by Goodbax.
No safeguard is a complete guarantee. If a personal data breach occurs, we will act as required by the GDPR.
11. Your rights
You have the right to access your data, rectify it, erase it, restrict processing, data portability (where applicable) and to object to processing based on legitimate interest. Send requests to info@goodbax.com. We reply without undue delay, within the GDPR time limit — as a rule within one month.
You can also revoke the app’s access to your account in the platform’s settings at any time — see disconnecting accounts and deleting data.
You have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or with the supervisory authority in your EU country.
12. Cookies
The Stocker Studio pages on goodbax.com use no cookies and no analytics scripts. The Studio panel and Postiz, available only to authorised people, may use cookies necessary for sign-in.
13. Changes to this policy
We update this policy when the way Studio works, the list of channels or the platforms’ rules change. The current version is always at this address, dated at the top. If the Polish and English versions differ, the Polish version prevails.