Privacy Policy for SendFinch

Last updated: 19/10/2025

1. Introduction

Welcome to SendFinch (“we”, “us”, “our”). SendFinch is a social media autoposter platform that lets you schedule posts (including text content, images and optional links) to social networks you connect such as Bluesky, Mastodon, LinkedIn and Pinterest. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you use our services. By accessing or using SendFinch, you agree to this policy.

2. Data Controller

SendFinch

Registered address: 134 St. Mary’s Road, Garston, Liverpool, L19 2JG

Contact email: info@sendfinch.com

For UK & EEA users, we are the data controller of your personal data in this policy.

3. Information We Collect

3.1 Account Information

When you sign up for SendFinch we collect:

Name (optional)

Email address

Username

Encrypted password

We store this to create and manage your SendFinch account and for login/authentication purposes.

3.2 Social Account Connections

When you connect a social network account (e.g., Bluesky, Pinterest) we collect and store:

The network name (e.g., “bluesky”, “pinterest”)

The base URL of the service (for federated/alternative servers)

External account identifier (e.g., DID, Pinterest user ID)

Your handle / username on that service

Access token (encrypted at rest) and optionally refresh token (encrypted at rest)

Display name, profile handle (optional)

We use these tokens only to publish posts on your behalf. We do not read your private messages or reuse the tokens for other purposes.

3.3 Scheduled Posts & Media

When you compose a post via SendFinch we collect:

Text content of the post

Optional scheduling time

Selected social accounts you want to post to

Uploaded image files (or image URLs) for the scheduled posts

We store references to the uploaded image files (path, mime type, alt text) and schedule metadata.

We do not attempt to repurpose your media beyond posting it to the selected social networks.

3.4 Log Data

When you use SendFinch, we automatically collect certain usage and log data including:

IP address

Browser/user-agent information

Date/time stamps of when you log in or publish a post

System events (e.g., failed login, status of scheduled job)

We use this data for analytics, security, troubleshooting and fraud prevention.

3.5 Cookies & Tracking

SendFinch uses cookies and similar technologies for authentication, analytics (e.g., Google Analytics / Matomo), and improving user experience. You may manage cookie preferences via your web browser or our settings page.

4. How We Use Your Data

We use your personal data for the following purposes:

To provide, maintain and operate the SendFinch service

To authenticate you and secure your account

To let you schedule and publish posts on connected social networks

To send you transactional emails (e.g., password resets, account changes) and relevant service notifications

For analytics, monitoring, system security and optimisation of our service

To respond to your support requests and enforce our terms of service

To comply with legal obligations (e.g., fraud investigation, data deletion requests)

5. Sharing & Disclosure

We do not sell your personal data for marketing or advertising purposes.

We may share your data in the following circumstances:

Service providers: We use third-party vendors (hosting, mail, analytics) who have access to data strictly on a “need-to-know” basis and must protect it under contract.

Legal & safety: If required by law, court order or regulation to disclose data; or to defend our rights, investigate fraud or ensure the safety of our service.

Business transfer: If SendFinch merges or is acquired, data may be transferred subject to standard privacy protections.

6. International Transfers

SendFinch may store your data on servers located in the UK or European Economic Area (EEA). If data is transferred outside the EEA (for example cloud hosting in the US), we ensure appropriate safeguards such as EU Standard Contractual Clauses or equivalent.

7. Your Rights (UK/EEA)

If you are in the UK or EEA, you have the following rights:

Right to access the personal data we hold about you

Right to rectify incorrect or incomplete data

Right to erase (“right to be forgotten”) your personal data, subject to certain legal and legitimate-interest limitations

Right to restrict or object to processing of your data (e.g., direct marketing, profiling)

Right to data portability (receive your data in a commonly used machine-readable format)

Right to withdraw consent (where processing is based on consent)

To exercise any of these rights, contact us at info@sendfinch.com. We will respond within one month or as required by applicable law.

8. Data Retention

We retain your personal data only as long as it is necessary for our services or to comply with legal obligations.

Account data: retained while your account is active; after account deletion we may retain anonymised or aggregate logs.

Social account tokens: retained while your connection is active and you continue to use our scheduled posting service; if you disconnect a social account we will delete the related tokens and unlink the account.

Scheduled posts & media: retained until they are published or deleted — you may delete drafts or scheduled items manually; after publication we keep a record for audit/troubleshooting (but we do not retain the raw uploaded images beyond what is needed for posting).

Logs: retained for a maximum of 12 months unless longer retention is required for legal or security reasons.

9. Security

We implement appropriate technical and organisational measures to protect your data:

Access tokens encrypted at rest

HTTPS (TLS) for all data in transit

Regular security reviews and updates

Least privilege access for internal and external systems

However, no system is perfect; if you suspect a security breach, contact us immediately at info@sendfinch.com.

10. Third-party Links & Social Networks

When you connect a social network account (Bluesky, Pinterest, etc.), you permit SendFinch to act on your behalf for post creation only — we do not ingest your posts, read your direct messages or manage your connections unless explicitly authorised. Each network’s own privacy policies remain in force once the content is published there.

Also, our site may include links to third-party websites or services. We are not responsible for their privacy practices; please review their privacy policies separately.

11. Children

SendFinch is not intended for children under the age of 16. We do not knowingly collect personal data from minors. If you believe we have inadvertently done so, please contact us and we will delete the data.

12. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised version on our site with a new “Last updated” date. If the changes are material, we may send you a notice (e.g., via email or dashboard alert).

13. Contact Us

If you have any questions, requests or concerns about this Privacy Policy or our data practices, please contact us:

SendFinch

Email: info@sendfinch.com

Address: 134 St. Mary’s Road, Garston, Liverpool, L19 2JG

We will endeavour to respond within 30 days or as required by applicable law.