Last updated: 28 June 2026. Postlock is operated by James Howard, trading as Postlock (“Postlock”, “we”, “us”). This is the current policy; we’ll post the date of any future change here.
1. Who we are
James Howard, trading as Postlock is responsible for this Service. For questions or to exercise your rights, contact hello@postlock.co.
2. Our two roles
Postlock handles personal data in two capacities:
- As a controller: for the account and identity data of the people who sign in to Postlock (your name, email, login), and for our own usage/analytics and support records.
- As a processor: for the accounting data we read from your Xero organisation on your instruction (which may contain personal data, e.g. a customer or supplier who is an individual, or the name of whoever posted a transaction). We process that data only to provide the Service to you. If you’re a business or practice, you are the controller of that data; our Data Processing terms govern it.
3. What we collect
- Account & identity: name, email, hashed password, role, and your company/account name.
- Xero accounting data (read-only): your balance sheet and profit & loss reports, and the document/history data needed to show what changed after a period was locked. We request read-only scopes and nothing else.
- Content you create: reconciliation notes, institutional-memory memos, schedules, locked-period snapshots, board figures, and any evidence files you upload.
- Connection tokens: the Xero access/refresh token needed to fetch your data, stored server-side and removed when you disconnect.
- Usage & technical: basic product-usage counts (e.g. logins, locks, packs generated), API-call volume, and standard server logs (IP, timestamps) used for security and to operate the Service.
- Visits to this website: a daily count of which pages were viewed, and the hostname of the site that referred you (for example google.com) - never the search term, the full referring address, or your IP. No cookie is set for this, nothing is sent to a third party, and nothing links one visit to another or to a person. It is a tally, kept for 120 days, so we can tell which pages are worth writing.
- Support: messages you send us.
We do not collect card or payment-card details directly - where billing applies, payments are handled by our payment processor.
4. Why we use it, and our lawful basis
- To provide the Service (read your Xero data, reconcile, lock, detect changes, generate packs); lawful basis: performance of a contract with you.
- To secure and operate the Service (authentication, abuse/rate-limit protection, logging, backups); lawful basis: legitimate interests (running a secure, reliable service). Backups are taken daily and kept on a seven-day rotation; they contain the same data as the live service and are deleted as they rotate out.
- To improve the product (aggregate usage metrics); lawful basis: legitimate interests; we keep this to the minimum needed.
- To bill you, where paid; lawful basis: contract.
- To comply with law (e.g. tax, accounting records about our own business); lawful basis: legal obligation.
5. Who we share it with
We don’t sell your data. We share it only with service providers who help us run Postlock, under contract and only as needed:
- Xero: the source of your accounting data (read-only), at your instruction.
- Hosting / infrastructure: Render, where the application and database run (currently a US region - see section 6).
- Payment processing: Stripe, if/when you subscribe (they receive billing details directly; we don’t store card data).
- Email: Resend (EU region), for transactional and alert emails.
- Network / DNS: Cloudflare, which routes traffic to the application.
That is the complete list. We may also disclose data if required by law.
6. Where your data is held
Plainly: the application and database currently run in a US region on Render, and transactional email is sent from an EU region via Resend. UK GDPR permits this with the standard safeguards, and we rely on appropriate safeguards (the UK International Data Transfer Agreement / Standard Contractual Clauses) for the transfer. A move to a UK/EU region is planned as we grow. We would rather tell you this here than have you find it on our security page after you had signed up.
7. How long we keep it
We keep your account and the content you create for as long as your account is active. When you delete your account (or ask us to), we delete your account data, content and uploads without undue delay, except where we must keep limited records to meet a legal obligation. Server logs are kept for a short period for security. Disconnecting Xero removes the access token immediately.
8. How we protect it
Passwords are hashed (scrypt). Traffic is encrypted in transit (HTTPS), with HSTS enforced in production. Sessions are signed, expire, and can be revoked. Each customer’s data is isolated from every other customer’s. Access tokens are kept server-side and removed on disconnect. We apply security headers and rate-limiting, and we never use your financial data to train AI models.
9. Your rights
Under UK GDPR you have the right to access your data, to rectify it, to erase it, to restrict or object to processing, and to data portability. You can:
- Export your data yourself from your account settings (a machine-readable download).
- Delete your account and all its data yourself from your account settings.
- Or email hello@postlock.co and we’ll action your request, normally within one month.
If we process Xero data as a processor for your business, please raise individual rights requests with that business (the controller); we’ll assist them.
10. Cookies
Postlock uses only strictly-necessary cookies: a signed session cookie to keep you logged in (and, in the demo, a “view as” cookie to switch roles). We don’t use advertising or third-party tracking cookies, so there’s no cookie banner to click through. Because these cookies are essential to provide the Service you asked for, they don’t require consent under PECR.
11. Children
Postlock is a business tool and isn’t intended for anyone under 18. We don’t knowingly collect data from children.
12. Complaints
We’d like the chance to resolve any concern - email hello@postlock.co. You also have the right to complain to the ICO (ico.org.uk, or 0303 123 1113).
13. Changes
We may update this policy; the “last updated” date above shows the current version and we’ll give notice of material changes.