- We never sell your data: We do not sell, rent, monetize, or trade your personal data, content, or social media tokens to data brokers, advertisers, or third parties.
- Strict Google Limited Use compliance: Our use of Google and YouTube user data strictly complies with the Google API Services User Data Policy, including Limited Use requirements.
- Full user control & easy deletion: You can disconnect social accounts and delete all synchronized data at any time through your dashboard or our User Data Deletion Portal.
1. Overview and Scope
WP Bulk Publishing operates WBP Social Command Center (accessible at our web applications, client portals, and related services). WBP Social Command Center provides businesses, marketing agencies, and creators with tools to strategize, generate, review, schedule, and publish content across multiple social media platforms, as well as analyze cross-channel publishing metrics.
This Privacy Policy applies to all registered users, workspace collaborators, and visitors who access our application or connect their social media accounts via OAuth APIs.
2. Information We Collect
We collect information in three main categories:
A. Account & Workspace Information
When you create an account or are invited to a workspace, we collect your name, email address, password hash (securely encrypted via Supabase Auth), workspace preferences, brand guidelines, and organizational roles (e.g., owner, admin, creator, reviewer).
B. Social Media Platform Information (Via Authorized OAuth APIs)
When you connect your social media channels to WBP Social Command Center, you grant us permission to interact with those platforms on your behalf using official, platform-approved OAuth 2.0 protocols. Depending on the platform you link, we collect and process:
- Meta (Facebook Pages & Instagram Graph API): Page names, Page IDs, Instagram Business/Creator Account IDs, connected account handles, profile avatars, permissions granted, and scoped access tokens. We use this to schedule posts, publish photos/videos/Reels, and retrieve page/post-level engagement metrics.
- LinkedIn (LinkedIn Marketing & Community Management APIs): Member profile ID, name, email address, Organization/Company Page IDs, organizational administrator roles, and access tokens for publishing updates, articles, images, and videos to your company pages or personal profile.
- Google & YouTube (YouTube Data API v3): Channel IDs, channel names, thumbnails, video upload permissions, and scoped OAuth tokens. We use this to upload videos, schedule Shorts, manage metadata (titles, descriptions, tags, playlists), and view video performance metrics.
- TikTok (TikTok for Developers & Content Posting API): Creator Open ID, display name, avatar URL, video posting permissions, and access tokens for uploading and publishing video content.
- Pinterest (Pinterest API v5): Username, profile details, board names, board IDs, and access tokens to publish pins, manage boards, and track pin impressions.
- X (formerly Twitter API v2): User ID, username/handle, profile information, and scoped tokens to compose, schedule, and publish posts, threads, and media.
- Reddit (Reddit Data API): Reddit username, moderator status for subreddits you manage, and access tokens to submit approved posts to designated communities.
C. Content & Media Assets
We store drafts, text copy, hooks, hashtags, links, images, and video assets that you upload to the Media Library or generate in Content Studio for the purpose of scheduling and publishing to your connected platforms.
3. How We Use Your Information
We process your personal and social platform information solely for the following legitimate business and service purposes:
- To authenticate your identity and safeguard access to your workspaces.
- To facilitate OAuth connections and maintain active API tokens with connected social platforms.
- To schedule and automatically publish your content and media to the platforms you designate.
- To display aggregated publishing history, health statuses, and engagement metrics.
- To provide collaborative workflow features (approvals, internal comments, version control, brand compliance rules).
- To provide customer support, troubleshoot API integration issues, and deliver security notices.
WBP Social Command Center's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In adherence to Google's Limited Use requirements:
- We only request access to Google/YouTube user data scopes necessary to provide social media publishing, scheduling, and analytics features.
- We do not transfer Google user data to any third party, unless necessary to provide or improve our user-facing social publishing functionality, to comply with applicable law, or as part of a merger/acquisition with user notification.
- We never use or transfer Google user data for serving advertisements, including personalized, re-targeted, or interest-based advertising.
- We do not allow humans to read Google user data, unless we have obtained your affirmative agreement for specific messages, it is necessary for security purposes (such as investigating a bug or abuse), to comply with applicable law, or our use is limited to internal operations where the data has been aggregated and anonymized.
For more information on Google's privacy standards, please review the Google Privacy Policy and the YouTube Terms of Service.
5. Meta & Third-Party Social Platform Policies
When utilizing WBP Social Command Center to manage accounts on third-party social networks, your use is also subject to the privacy policies and developer terms of each respective platform:
- Meta (Facebook & Instagram): Data is handled in accordance with the Meta Privacy Policy and the Meta Platform Terms.
- LinkedIn: Governed by the LinkedIn Privacy Policy.
- TikTok: Governed by the TikTok Privacy Policy.
- Pinterest: Governed by the Pinterest Privacy Policy.
- X (Twitter): Governed by the X Privacy Policy.
- Reddit: Governed by the Reddit Privacy Policy.
6. Data Sharing and Disclosure
We strictly limit who has access to your data. We disclose information only under the following circumstances:
- To Connected Social Platforms: To execute your scheduling and publishing commands, we transmit your content, media, and authorization tokens to the respective platform APIs.
- Infrastructure Service Providers: We employ trusted infrastructure providers (such as Supabase for database and authentication hosting, Cloudflare for CDN and edge routing) who process data under strict confidentiality and security agreements.
- Workspace Collaborators: Team members whom you explicitly invite to your workspace will have role-governed access to drafts, media, and campaign plans.
- Legal Compliance: If required by law, subpoena, or government authority, we may disclose information to the extent strictly necessary to comply with legal obligations.
7. Data Retention and Security
We implement industry-standard administrative, physical, and technical safeguards to protect your personal information and API tokens against unauthorized access, destruction, loss, or alteration.
- Encryption: All data in transit is encrypted using Transport Layer Security (TLS 1.3). Sensitive credentials and OAuth tokens are encrypted at rest using industry-standard AES-256 encryption.
- Row-Level Security (RLS): Our database isolates tenant data via workspace-scoped access control rules enforced at the database layer.
- Token Retention: OAuth access and refresh tokens are retained only as long as your account connection remains active. When you disconnect a platform or request data deletion, associated tokens are immediately invalidated and purged.
8. Your Privacy Rights and Data Deletion
Depending on your location (including the European Economic Area under GDPR, the United Kingdom under UK GDPR, and California under CCPA/CPRA), you possess distinct privacy rights:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can update or correct inaccurate profile or workspace information at any time.
- Right to Erasure ('Right to be Forgotten'): You can request that we delete your account, workspace data, and social media tokens.
- Right to Restrict or Object to Processing: You may revoke social media OAuth permissions at any time directly through WBP Social Command Center or within the third-party platform's application settings.
Need to delete your data or revoke app permissions?
Please visit our dedicated User Data Deletion Portal for step-by-step instructions for Meta, Google, LinkedIn, and all connected platforms, or submit a request directly to Wpbulkpublishing@gmail.com.
9. Children's Privacy
WBP Social Command Center is intended for professional use and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our services, platform API updates, or relevant legal requirements. When changes are made, we will revise the "Last Updated" date at the top of this policy and notify registered users via in-app notification or email when appropriate.
11. Contact Information
If you have questions, feedback, or requests regarding this Privacy Policy or our data handling practices, please contact our Data Protection Officer: