Operator and contact
TrackPost is operated by MarkenGroup SAS · Calle 5SUR #25-233 · Medellín, Antioquia · Colombia · NIT 902 003 798-4. Privacy, access and deletion requests can be sent to office@marken-group.com.
Data we process
Account data includes the signed-in user's email address, name, organization, project, roles and security metadata needed to provide the service.
When an authorized administrator connects a provider, TrackPost receives an OAuth grant and reads the accounts the user may manage, such as Facebook Pages, Instagram Professional accounts, Threads profiles, Google Business Profile accounts and locations, and LinkedIn profiles or organizations. Stored connection metadata can include provider IDs, display names, usernames, location names, granted scopes and token expiry.
Publishing data includes drafts, text, links, public media URLs, schedules, selected destinations, delivery attempts, provider post IDs, status and error categories. OAuth credentials are encrypted server-side and are not exposed to customer websites.
Why we use the data
We use this data to authenticate users, enforce organization and project permissions, list destinations the user may manage, publish or schedule requested content, report delivery status, support safe retries and provide support. TrackPost does not use connected provider data for unrelated advertising or sell it.
Provider access
Meta permissions are requested only for the selected Facebook, Instagram or Threads publishing functions. Google Business Profile uses https://www.googleapis.com/auth/business.manage to list authorized accounts and locations and to create requested Local Posts. LinkedIn access is limited to the authorized member or organization publishing functions.
Google user data obtained through Google APIs is used only for the user-facing TrackPost functions described here. Its use and transfer are intended to comply with the Google API Services User Data Policy, including the Limited Use requirements.
Sharing and infrastructure
Data is processed by the infrastructure and subprocessors needed to operate TrackPost, including Google Cloud and Firebase. The current backend is hosted in the United States. Meta, Google and LinkedIn receive authorization, account-discovery and publishing requests when a connected user invokes those functions.
Retention and security
Connections, drafts and delivery records are retained while needed to provide the service and for limited security, support, backup or legal purposes. Access is tenant- and project-bound, credentials are encrypted, and raw credential collections are not directly readable by browser clients.
Publishing queues can retry a request after a temporary provider or network failure. Because providers do not offer one universal idempotency guarantee, a rare lost success response can result in a duplicate post. Delivery records are retained long enough to detect and reconcile that condition.
Your choices and rights
You can disconnect an integration in TrackPost and revoke its grant in the provider account. For access, correction, export, objection or deletion, contact office@marken-group.com from the account email and identify the organization, project and connection. We verify authority before disclosing or deleting tenant data. The data-deletion page describes the exact process.