Privacy policy
Who we are
Honey Post is run by eCommerce Boost, an email and social marketing agency in Melbourne, Australia. When this page says “we”, it means eCommerce Boost. Questions go to hello@ecommerceboost.io.
What Honey Post does
Brands and agencies use Honey Post to collect content from creators, plan posts, get them approved and publish them to the brand's own social accounts, then see how they did.
What we collect
- Your account: name, email address and a hashed password.
- Brand content: the photos, videos, captions and notes your team and your creators upload, and the posts you plan.
- Connected social accounts: when you connect Instagram, Facebook, Threads or another platform, we receive the account's id, name, handle, profile picture and follower count, and an access key that lets us publish and read post statistics for that account. We never see or store your password for those platforms: you sign in on the platform's own page.
- Post statistics: reach, likes, comments, saves, shares and views for posts published through Honey Post, and follower counts for connected accounts.
- Usage: basic server logs (time, page, IP address) kept for security and troubleshooting.
How we use it
- To publish the posts your team schedules, to the accounts your team connected, at the time you chose.
- To show your team how posts and accounts are performing.
- To run the product: sign-in, notifications, support.
We don't sell personal information, we don't use it for advertising, and we don't use data from connected social accounts for anything other than the features above. Content from your connected accounts is only shown to members of your brand's workspace.
Who else is involved
We use a small number of service providers to run Honey Post: cloud hosting and database (in Australia or the US), file storage (Cloudflare R2), email delivery (Resend), payments (Stripe), and AI writing and tagging (OpenAI or Anthropic). Depending on how a brand's accounts are connected, posts may be published through a publishing service that holds approved platform apps (such as Post for Me or Ayrshare). Each only receives what it needs to do its job.
How we protect it
Everything travels over HTTPS. Platform access keys are encrypted at rest (AES-256) and are never sent to your browser. Access inside a workspace follows the roles your team sets.
How long we keep it
We keep your data while your workspace is active. If you disconnect a social account, we delete its access key straight away. If you close your workspace, we delete its content and connected-account data within 30 days, apart from billing records the law requires us to keep.
Your choices
- Disconnect any social account in Settings → Social accounts, or remove Honey Post from the platform's own settings (for Facebook and Instagram: Settings → Business integrations).
- Ask for a copy of your data, a correction, or deletion: email hello@ecommerceboost.io. See how to delete your data.
- If you're in Australia you can also contact the Office of the Australian Information Commissioner (oaic.gov.au).
Changes
If we change how we handle personal information, we'll update this page and the date at the top, and tell workspace owners by email when the change matters.