Privacy Policy

Last updated: August 2026
📋 This is a placeholder Privacy Policy. The information below describes our intended practices in general terms. A final, legally-reviewed policy will replace this before PleaseRepost launches publicly.

PleaseRepost ("we," "us," or "our") operates pleaserepost.com. This policy explains what data we collect, how we use it, and your rights regarding that data.

What we collect

Company admin accounts

When a company signs up, we collect the company name, a URL slug, and the admin's email address and password (stored as a secure hash — we never store plain-text passwords).

Employee data

Admins add employees by entering their name and email address. Each employee receives a unique personal link. We store the name and email the admin provided, along with the unique token that powers the employee's personal link.

LinkedIn OAuth tokens

When an employee connects their LinkedIn account, LinkedIn provides us with an OAuth access token. We store this token so we can post on their behalf when they click "Repost." We also store their LinkedIn profile ID and display name. We do not store LinkedIn passwords — ever.

Reshare activity

We log when each employee reshares a post (or schedules one) so admins can see participation data in their dashboard.

Usage data

Standard web server logs (IP addresses, browser type, pages visited) are retained briefly for security and debugging. We do not use third-party analytics trackers on employee-facing pages.

How we use your data

  • To operate the service: authenticate accounts, display repost pages, record reshares, generate participation reports.
  • To send Slack reports if you've configured a webhook.
  • To contact admins with important service updates (not marketing spam).

What we don't do

  • We do not sell, rent, or share your data with third parties for marketing purposes.
  • We do not post to LinkedIn without an explicit click from the employee.
  • We do not read your LinkedIn messages, connections, or anything beyond what's needed for posting.

LinkedIn API data

Our use of LinkedIn's API is limited to posting on behalf of employees who have explicitly authorized us to do so. We request only the OAuth scopes necessary for this purpose. Employees may revoke our access at any time through their LinkedIn account settings.

Data retention

We retain account data for as long as the account is active. When an account is deleted, we remove all associated data within 30 days. LinkedIn OAuth tokens are deleted immediately when an employee disconnects their account or when the account is closed.

Security

Passwords are hashed using bcrypt. LinkedIn tokens are stored encrypted at rest. We use HTTPS for all communications. We do not store payment card data (payments are handled by our payment processor).

Your rights

Employees may request deletion of their data at any time by contacting us or asking their company admin. Admins may export or delete all company data from the admin dashboard.

Contact

Questions about this policy: hi@pleaserepost.com

Back to home