JTC
JTC Tech
  • Home
  • About
  • Guides
  • Services
  • Tools
  • Contact
Home / Privacy / Social Post

Social Post Privacy

Social Post is a web app for writing, scheduling and tracking LinkedIn posts. To do that it needs your account details, access to your LinkedIn account, and the posts and images you create. This notice explains what we hold, why, who else sees it, and how to have it deleted, including your rights under South Africa's POPIA.

Last updated: 24 September 2026

Who we are

JTC Technologies Group ("JTC", "we", "us") builds and operates Social Post. We are based in Johannesburg, South Africa, and we are the responsible party for the personal information described here.

Information Officer: Jon Boyle: hello@jtctech.co.za. Send any privacy question, request or complaint about Social Post to that address.

This notice covers the Social Post app only. Our main website has its own privacy notice.

What we collect

  • Your account. Your email address, a password (stored only as a one-way hash by our authentication provider, never readable by us), your name and your time zone. If you sign in with LinkedIn instead, we receive your name, email address, profile photo and LinkedIn member ID from LinkedIn.
  • Your connected LinkedIn account. When you connect LinkedIn so the app can post for you, LinkedIn gives us an access token plus your name, profile photo and member ID. The token is what lets Social Post publish on your behalf. It is encrypted at rest, is only ever used by our servers, and is never sent to your browser.
  • Your content. The posts you write (drafts, scheduled and published), the images you upload to your library and their tags, and when each post is scheduled or was published.
  • Post statistics. Where LinkedIn makes them available to us, the view, reaction, comment and reshare counts for posts you published through Social Post. These are totals only; they do not identify who viewed or reacted.
  • Technical records. Error reports and server logs (for example, which request failed and when), which can include your IP address and browser type. We use these only to keep the service working.

We only request the LinkedIn permissions each feature needs. Today that is signing in and posting to your own profile. Company-page posting and statistics will need further permissions, and LinkedIn will ask you to approve them before we receive anything new.

We do not sell, rent or trade your information, we do not use it for advertising, and we do not use your LinkedIn data for anything except the features you use in Social Post. We never post anything you have not written and scheduled or published yourself.

How we use it

  • To sign you in and keep your account secure.
  • To publish your posts to LinkedIn at the time you chose, and to retry if LinkedIn is temporarily unavailable.
  • To show you your posts, your image library and your post statistics.
  • To email you about your account: confirming your address, resetting your password, telling you when a scheduled post fails, and warning you before your LinkedIn connection expires. We send no marketing email.
  • To find and fix faults.

Cookies and browser storage

Social Post keeps your sign-in session in your browser's local storage so you stay signed in. That is its only purpose. We use no advertising cookies, no cross-site tracking and no analytics that identify you.

Who else processes it

We use a small number of service providers (operators, in POPIA's terms). Each processes data only to provide its service to us:

  • Supabase provides our database, sign-in, image storage and server functions. Your account, posts, images, statistics and encrypted LinkedIn token are stored with Supabase in the European Union (Ireland, AWS region eu-west-1).
  • Cloudflare hosts the Social Post web app and so processes the technical details of each request (including your IP address) to deliver it.
  • Resend delivers our account and alert emails, so it processes your email address and the content of those emails.
  • Sentry receives error reports so we can fix faults. These can include your user ID, IP address and browser details, but not your password or LinkedIn token.
  • Google Fonts serves the app's typefaces, so Google's CDN receives your IP address and browser details when the fonts load. No cookie is set.
  • LinkedIn receives the posts and images you publish, and returns the account details and statistics described above. What LinkedIn does with your content once it is posted is governed by LinkedIn's own privacy policy.

Data stored outside South Africa

Some of these providers store or process data outside South Africa. Where they do, we rely on POPIA's provisions for cross-border transfers: each provider is bound by terms that require it to protect personal information to a standard substantially similar to POPIA, and the transfer is needed to provide the service you signed up for.

How long we keep it

  • Account, posts and images: for as long as you have an account. You can delete individual posts and images at any time.
  • LinkedIn token: until you disconnect LinkedIn or delete your account, when we delete it from our systems. LinkedIn tokens also expire on their own after about 60 days; Social Post will ask you to reconnect.
  • Post statistics: collected for up to 90 days after a post is published, then kept with the post until you delete it or your account.
  • Error reports and logs: kept for a limited period (typically no more than 90 days) and then deleted.

Deleting your account removes your profile, posts, images, statistics and LinkedIn token. Copies may remain in our providers' encrypted backups for a short period until those backups are overwritten. Posts already published to LinkedIn stay on LinkedIn: delete them there if you want them gone.

Revoking LinkedIn access

You can disconnect LinkedIn inside Social Post at any time. You can also remove Social Post's access from LinkedIn itself, under Settings > Data privacy > Permitted services. Either way, Social Post can no longer post for you, and any posts still scheduled will not be published.

Security

All traffic is encrypted in transit (HTTPS). LinkedIn tokens are encrypted at rest and handled only by our servers. Database access rules make sure each account can only reach its own data. No system is perfectly secure, but if a breach affects your information we will tell you and the Information Regulator as POPIA requires.

Children

Social Post is not intended for anyone under 18, and we do not knowingly collect information from children.

Legal basis (POPIA)

We process your information because it is needed to provide the service you signed up for, with your consent for the LinkedIn permissions you grant (which you can withdraw by disconnecting), and in our legitimate interest in keeping the service secure and working.

Your rights

Under the Protection of Personal Information Act you may ask us to confirm what personal information we hold about you and to send you a copy, to correct or delete it, or to object to how we process it. You may also complain to the Information Regulator of South Africa. To exercise any of these rights, email hello@jtctech.co.za and we will respond within a reasonable period.

Changes

If this notice changes materially we will update the date at the top of this page and tell account holders by email before the change takes effect.

Contact

JTC Technologies Group, Johannesburg, South Africa: hello@jtctech.co.za.

JTC
JTC Tech

AI and Agile enablement — hands-on product and delivery management that makes adoption stick. Built in South Africa.

The Toolkit

  • All checks & guides
  • AI Enablement
  • Agile & Delivery
  • Product Management
  • Team Cognitive Health
  • Vibe Coding
  • Tools Readiness

Tools

  • Guardian AI
  • PromptForge
  • Dark Pattern Detector
  • Scrum Toolkit

Company

  • Founder
  • About
  • FAQ
  • Contact
  • Privacy
  • Terms
  • LinkedIn

© 2026 JTC Technologies Group. All rights reserved. Built in 🇿🇦