What we collect, why, your rights, and how to exercise them - under UK GDPR.
Last updated: 28 June 2026. Postlock is operated by James Howard, trading as Postlock (“Postlock”, “we”, “us”). This is the current policy; we’ll post the date of any future change here.
James Howard, trading as Postlock is responsible for this Service. For questions or to exercise your rights, contact hello@postlock.co.
Postlock handles personal data in two capacities:
We do not collect card or payment-card details directly - where billing applies, payments are handled by our payment processor.
We don’t sell your data. We share it only with service providers who help us run Postlock, under contract and only as needed:
A current list of sub-processors is kept in our records and available on request. We may also disclose data if required by law.
We aim to keep and process your data in the UK and/or the EEA. If any provider processes data outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards (e.g. the UK International Data Transfer Agreement / Standard Contractual Clauses).
We keep your account and the content you create for as long as your account is active. When you delete your account (or ask us to), we delete your account data, content and uploads without undue delay, except where we must keep limited records to meet a legal obligation. Server logs are kept for a short period for security. Disconnecting Xero removes the access token immediately.
Passwords are hashed (scrypt). Traffic is encrypted in transit (HTTPS), with HSTS enforced in production. Sessions are signed, expire, and can be revoked. Each customer’s data is isolated from every other customer’s. Access tokens are kept server-side and removed on disconnect. We apply security headers and rate-limiting, and we never use your financial data to train AI models.
Under UK GDPR you have the right to access your data, to rectify it, to erase it, to restrict or object to processing, and to data portability. You can:
If we process Xero data as a processor for your business, please raise individual rights requests with that business (the controller); we’ll assist them.
Postlock uses only strictly-necessary cookies: a signed session cookie to keep you logged in (and, in the demo, a “view as” cookie to switch roles). We don’t use advertising or third-party tracking cookies, so there’s no cookie banner to click through. Because these cookies are essential to provide the Service you asked for, they don’t require consent under PECR.
Postlock is a business tool and isn’t intended for anyone under 18. We don’t knowingly collect data from children.
We’d like the chance to resolve any concern - email hello@postlock.co. You also have the right to complain to the ICO (ico.org.uk, or 0303 123 1113).
We may update this policy; the “last updated” date above shows the current version and we’ll give notice of material changes.