Privacy

Privacy & data protection.

What we collect, why, your rights, and how to exercise them - under UK GDPR.

Last updated: 28 June 2026. Postlock is operated by James Howard, trading as Postlock (“Postlock”, “we”, “us”). This is the current policy; we’ll post the date of any future change here.

1. Who we are

James Howard, trading as Postlock is responsible for this Service. For questions or to exercise your rights, contact hello@postlock.co.

2. Our two roles

Postlock handles personal data in two capacities:

  • As a controller: for the account and identity data of the people who sign in to Postlock (your name, email, login), and for our own usage/analytics and support records.
  • As a processor: for the accounting data we read from your Xero organisation on your instruction (which may contain personal data, e.g. a customer or supplier who is an individual, or the name of whoever posted a transaction). We process that data only to provide the Service to you. If you’re a business or practice, you are the controller of that data; our Data Processing terms govern it.

3. What we collect

  • Account & identity: name, email, hashed password, role, and your company/account name.
  • Xero accounting data (read-only): your balance sheet and profit & loss reports, and the document/history data needed to show what changed after a period was locked. We request read-only scopes and nothing else.
  • Content you create: reconciliation notes, institutional-memory memos, schedules, locked-period snapshots, board figures, and any evidence files you upload.
  • Connection tokens: the Xero access/refresh token needed to fetch your data, stored server-side and removed when you disconnect.
  • Usage & technical: basic product-usage counts (e.g. logins, locks, packs generated), API-call volume, and standard server logs (IP, timestamps) used for security and to operate the Service.
  • Support: messages you send us.

We do not collect card or payment-card details directly - where billing applies, payments are handled by our payment processor.

4. Why we use it, and our lawful basis

  • To provide the Service (read your Xero data, reconcile, lock, detect changes, generate packs); lawful basis: performance of a contract with you.
  • To secure and operate the Service (authentication, abuse/rate-limit protection, logging, backups); lawful basis: legitimate interests (running a secure, reliable service).
  • To improve the product (aggregate usage metrics); lawful basis: legitimate interests; we keep this to the minimum needed.
  • To bill you, where paid; lawful basis: contract.
  • To comply with law (e.g. tax, accounting records about our own business); lawful basis: legal obligation.

5. Who we share it with

We don’t sell your data. We share it only with service providers who help us run Postlock, under contract and only as needed:

  • Xero: the source of your accounting data (read-only), at your instruction.
  • Hosting / infrastructure: [HOSTING PROVIDER], where the application and database run (intended UK/EU region).
  • Payment processing: [PAYMENT PROCESSOR], if/when you subscribe (they receive billing details directly; we don’t store card data).
  • Email: [EMAIL PROVIDER], for transactional and alert emails.

A current list of sub-processors is kept in our records and available on request. We may also disclose data if required by law.

6. Where your data is held

We aim to keep and process your data in the UK and/or the EEA. If any provider processes data outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards (e.g. the UK International Data Transfer Agreement / Standard Contractual Clauses).

7. How long we keep it

We keep your account and the content you create for as long as your account is active. When you delete your account (or ask us to), we delete your account data, content and uploads without undue delay, except where we must keep limited records to meet a legal obligation. Server logs are kept for a short period for security. Disconnecting Xero removes the access token immediately.

8. How we protect it

Passwords are hashed (scrypt). Traffic is encrypted in transit (HTTPS), with HSTS enforced in production. Sessions are signed, expire, and can be revoked. Each customer’s data is isolated from every other customer’s. Access tokens are kept server-side and removed on disconnect. We apply security headers and rate-limiting, and we never use your financial data to train AI models.

9. Your rights

Under UK GDPR you have the right to access your data, to rectify it, to erase it, to restrict or object to processing, and to data portability. You can:

  • Export your data yourself from your account settings (a machine-readable download).
  • Delete your account and all its data yourself from your account settings.
  • Or email hello@postlock.co and we’ll action your request, normally within one month.

If we process Xero data as a processor for your business, please raise individual rights requests with that business (the controller); we’ll assist them.

10. Cookies

Postlock uses only strictly-necessary cookies: a signed session cookie to keep you logged in (and, in the demo, a “view as” cookie to switch roles). We don’t use advertising or third-party tracking cookies, so there’s no cookie banner to click through. Because these cookies are essential to provide the Service you asked for, they don’t require consent under PECR.

11. Children

Postlock is a business tool and isn’t intended for anyone under 18. We don’t knowingly collect data from children.

12. Complaints

We’d like the chance to resolve any concern - email hello@postlock.co. You also have the right to complain to the ICO (ico.org.uk, or 0303 123 1113).

13. Changes

We may update this policy; the “last updated” date above shows the current version and we’ll give notice of material changes.