Privacy

Privacy Policy

Understand what information CrerPost processes, why it is used, and the choices available when you use our social media management services.

Page content

Last Updated: July 28, 2026

This Privacy Policy explains how Crer Group LLC, doing business as CrerPost (“CrerPost,” “we,” “us,” or “our”), collects, uses, discloses, and protects information when you visit https://crerpost.com, create or use a CrerPost account, participate in a workspace, connect a third-party service, use our content, publishing, analytics, artificial intelligence, billing, partner, or white-label features, or otherwise communicate with us. Together, these websites, applications, features, and services are the “Platform.”

1. Scope

This Policy applies to personal information processed through the complete CrerPost Platform. It covers information supplied directly by account owners, team members, workspace administrators, partners, and visitors; information generated through use of the Platform; and information received from connected services at a user’s direction.

This Policy does not govern a third-party website, social network, payment service, artificial intelligence provider, or other service that maintains its own privacy practices. When you connect or use one of those services, its terms and privacy policy also apply.

2. Company Identity and Contact Details

The Platform is operated by:

Crer Group LLC
Doing business as CrerPost
1021 E Lincolnway, Suite #7195
Cheyenne, Wyoming 82001
United States

Email: support@crerpost.com
Website: https://crerpost.com

3. Our Roles as Controller and Processor

CrerPost generally acts as a controller of information used to operate the Platform, administer accounts and subscriptions, prevent abuse, communicate with users, meet legal obligations, and improve user-facing service functionality.

When an organization uses CrerPost to manage content, files, team activity, Business Profiles, or connected accounts on behalf of its customers, personnel, or other individuals, the organization may determine the purposes and means of that processing. In those circumstances, the organization is normally the controller or business, and CrerPost processes the information on its behalf as a processor or service provider. Workspace owners and administrators are responsible for providing required notices, obtaining permissions, and responding to requests relating to information they control.

4. Information We Process

4.1 Account and identity information

We may process your name, username, email address, profile image, password authentication record, account status, language and preference settings, login method, referral information, and information needed to authenticate or recover an account. If you use a supported social login, we may receive basic identity information from that provider, such as an account identifier, name, email address, or profile image, according to the permissions you approve.

4.2 Business Profiles, teams, and workspaces

We may process Business Profile names, descriptions, brand information, websites, contact details, logos, audience or business settings, and related configuration. For teams and workspaces, we may process membership, invitations, roles, permissions, ownership, assignments, approval status, activity, and collaboration records. Workspace administrators may be able to view and manage information and activity associated with workspace members.

4.3 Connected social media and other accounts

When you connect an account, we may process the provider name, external account or channel identifier, username, display name, profile or page details, connection status, granted permissions, and information needed to perform actions you request. Depending on the provider and permissions, this may include pages, profiles, channels, posts, media, comments or engagement information, publishing status, and account or content analytics.

Supported or future user-selected integrations may involve services operated by Google, YouTube, Meta, Facebook, Instagram, LinkedIn, TikTok, X, and other providers made available through the Platform. Availability and accessible information depend on the integration, provider rules, user authorization, and the features enabled for an account.

4.4 OAuth credentials and connection data

To keep a connection working, CrerPost may receive and store OAuth access tokens, refresh tokens, token expiration information, provider account identifiers, authorized scopes, state-validation records, and related connection metadata. These credentials allow CrerPost to communicate with the provider only within the permissions granted by the user and the provider. We do not ask users to provide their third-party account passwords for standard OAuth connections.

4.5 User-generated content and files

We process content you submit to the Platform, including text, captions, prompts, instructions, hashtags, links, drafts, templates, notes, uploaded files, documents, images, audio, videos, thumbnails, and related metadata. We also process content created or transformed through Platform features, including AI-generated text, images, or videos that you choose to save.

4.6 Drafts, scheduled posts, and publishing records

We may process draft content, selected destinations, scheduling dates and times, time zones, approval and workflow status, publishing instructions, delivery status, provider responses, error information, and publishing history. These records help users manage upcoming work, confirm what was sent, diagnose failures, and review prior activity.

4.7 Analytics and reporting information

Where a connected provider makes data available and the user authorizes access, CrerPost may process account, audience, content, reach, impression, engagement, view, click, and similar performance metrics. We may organize or display this information in dashboards and reports requested by the user. Metrics remain subject to the definitions, availability, and adjustments of the source provider.

4.8 AI prompts, output, providers, and usage records

When you use an AI feature, we may process the prompt, instructions, uploaded reference material, selected settings, generated or edited output, provider response, safety or error response, and operational metadata. Depending on the feature selected, information may be sent to an AI text, image, audio, or video provider that performs the requested generation or analysis.

We may maintain AI usage logs such as the feature used, provider or model selected, processing status, timestamps, request or job identifiers, credit reservation and consumption, error category, and other records needed to deliver the feature, prevent duplicate charges, troubleshoot requests, enforce limits, and maintain billing accuracy. The providers available can change over time. A provider’s handling of information is also governed by its applicable terms, privacy commitments, and configuration.

4.9 Credits, billing, subscriptions, and trials

We may process plan selection, plan limits, trial status, subscription status, billing cycle, renewal or cancellation status, credit balances, credit purchases, credit usage and ledger entries, transaction identifiers, amounts, currency, taxes, invoices or receipts, payment status, refund status, and payment-provider responses. Payment card or account details are generally submitted directly to the selected payment provider rather than stored in full by CrerPost.

Payment processing may involve providers such as Stripe, PayPal, or another gateway displayed at checkout. Those providers process payment information under their own terms and privacy policies.

4.10 Partner and white-label information

If you participate in a referral, affiliate, partner, reseller, or white-label arrangement, we may process referral codes and links, referred account relationships, clicks, conversions, commission or balance records, withdrawal requests, payment instructions, business contact information, brand configuration, custom domain or presentation settings, and communications relating to the arrangement. Program-specific commercial terms, where applicable, are provided separately from this Policy.

4.11 Support and other communications

We process messages sent to support, contact requests, account or billing questions, attachments, troubleshooting information, feedback, survey responses, and records of our response. Please do not send passwords, access tokens, payment card numbers, or other secrets in support messages.

4.12 Device, log, and technical information

When the Platform is used, we may automatically receive IP address, browser and device type, operating system, language, referring page, requested URL, timestamps, session and authentication events, diagnostic data, security events, feature interactions, and application or server logs. We use this information to deliver requests, maintain sessions, secure the Platform, diagnose errors, understand service use, and prevent abuse.

4.13 Cookies and similar technologies

CrerPost uses cookies and similar browser storage where needed for authentication, sessions, security, preferences, theme or language settings, referral attribution, and core Platform operation. We may also use measurement technologies to understand public-site and product use where configured and permitted by law. Browser controls can block or delete cookies, but disabling required cookies may prevent login or other Platform features from working.

5. How We Use Information

We use information to:

  • create, authenticate, secure, administer, and support accounts, teams, workspaces, and Business Profiles;
  • connect user-authorized accounts and maintain OAuth sessions;
  • create, edit, organize, store, schedule, approve, publish, and analyze content at the user’s direction;
  • process selected files, images, videos, drafts, campaigns, and publishing history;
  • provide analytics, reporting, collaboration, AI, billing, credit, partner, and white-label functionality;
  • process transactions, subscriptions, trials, renewals, cancellations, credits, invoices, and related records;
  • communicate service, security, support, billing, and administrative information;
  • send marketing communications where permitted and manage opt-out choices;
  • detect, investigate, and prevent fraud, abuse, security threats, prohibited conduct, and technical failures;
  • maintain, troubleshoot, and improve the reliability, usability, and user-facing functionality of the Platform;
  • enforce agreements, resolve disputes, establish or defend legal claims, and comply with law; and
  • create aggregated or de-identified operational insights that do not reasonably identify an individual.

6. Legal Bases for Processing

Where the General Data Protection Regulation, United Kingdom data protection law, or similar law applies, our legal bases may include:

  • Contract: processing needed to provide the Platform, administer an account, complete a transaction, or perform a user-requested integration.
  • Legitimate interests: securing and improving the Platform, supporting users, preventing abuse, administering the business, and understanding service performance, balanced against individual rights.
  • Consent: processing based on an optional choice, such as authorizing an OAuth connection or receiving certain marketing communications. Consent can be withdrawn, although prior processing remains lawful.
  • Legal obligation: processing required for tax, accounting, sanctions, law-enforcement response, consumer protection, or other applicable duties.
  • Legal claims and vital interests: processing needed to protect rights, safety, or property, or to establish, exercise, or defend claims.

If we process information for a customer as its processor, the customer determines the applicable legal basis for that processing.

7. Service Providers and Integrations

We use service providers to operate the Platform and fulfill user requests. Their functions may include hosting and infrastructure, content storage and delivery, email and communications, security, monitoring, customer support, analytics, payment processing, and AI generation. We provide them only the information reasonably needed for their assigned function and subject their access to applicable contractual or technical restrictions.

Depending on what a user enables, third-party services may include Google, YouTube, Google Login, Google Drive, Meta, Facebook, Instagram, LinkedIn, TikTok, X, Stripe, PayPal, and AI text, image, audio, or video providers. Listing a provider does not mean every integration is available to every user or continuously active.

8. How We Share Information

We may disclose information:

  • At your direction: to a social network, file provider, AI provider, payment provider, workspace, team member, or other destination selected by you.
  • Within a workspace: to owners, administrators, and authorized members according to their roles and permissions.
  • To service providers: for infrastructure, storage, communications, security, support, analytics, payment, or other operational services.
  • For legal and safety reasons: when reasonably necessary to comply with law or valid legal process, enforce agreements, investigate fraud or abuse, or protect users, CrerPost, providers, or the public.
  • For a business transaction: in connection with a merger, financing, reorganization, acquisition, sale of assets, or similar transaction, subject to appropriate confidentiality and legal requirements.
  • With consent: when you authorize another disclosure.

CrerPost does not sell personal information for money. We do not disclose personal information for cross-context behavioral advertising as those concepts are defined by the CCPA/CPRA. The specific commitments governing Google user data are stated below.

9. Google API Services and Google User Data

This section applies when you use Google Login, connect a YouTube channel, select a supported Google Drive file, or otherwise authorize a CrerPost feature that uses Google API Services.

9.1 Google and YouTube data CrerPost may access

According to the feature and permissions you approve, CrerPost may access:

  • basic Google account information used for login, such as your Google account identifier, name, email address, and profile image;
  • YouTube channel identifiers, channel names, profile details, and connection status;
  • YouTube videos, titles, descriptions, thumbnails, privacy or publishing settings, upload or processing status, and other content information needed for a user-requested publishing or management action;
  • YouTube channel or content analytics and performance metrics made available under the permissions you grant;
  • metadata and content for a Google Drive file that you expressly select or make available for import into CrerPost; and
  • OAuth access tokens, refresh tokens, authorized scopes, token expiration information, and technical identifiers needed to maintain the approved connection.

CrerPost’s access is limited by the OAuth scopes presented during authorization, the permissions Google grants, and the features the user chooses to use.

9.2 Why the data is accessed and how it is used

CrerPost uses Google user data only to provide or improve user-facing functionality requested by the user. This may include signing the user in, displaying and managing a connected YouTube channel, preparing or publishing user-approved content, showing publishing results or analytics, importing a user-selected Google Drive file, maintaining the connection, preventing duplicate actions, and troubleshooting the requested feature.

CrerPost does not sell Google user data. CrerPost does not use Google user data for advertising. CrerPost does not use Google user data for credit decisions or data brokerage. CrerPost does not use Google Workspace API data or Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.

9.3 OAuth token storage and protection

CrerPost stores OAuth access and refresh tokens and related connection metadata where needed to keep a user-authorized integration operating. Tokens are treated as confidential application data. We use access controls, limited application permissions, secure transmission, monitoring, and operational safeguards designed to prevent unauthorized access or disclosure. We do not claim that CrerPost holds a particular security certification or that every stored record uses a specific encryption method unless separately confirmed in writing.

9.4 Sharing Google user data

Google user data may be transmitted back to Google or YouTube to perform the action you request. It may also be available to infrastructure or service providers that process data for CrerPost when necessary to host, secure, transmit, store, or support the requested feature. We may disclose information when required by applicable law or valid legal process. We do not allow service providers to use Google user data for their own advertising, data-brokerage, credit-decision, or generalized AI-training purposes.

9.5 Retention

We retain Google user data only for as long as reasonably necessary to provide the connected feature, maintain operational and security records, comply with law, resolve disputes, or protect the Platform. Retention depends on the data type, whether the integration remains connected, user settings and deletion actions, workspace requirements, and legal or backup obligations. We do not state a fixed retention period where the implementation and legal requirements may vary.

9.6 Revoking access, disconnecting, and deletion

You can revoke CrerPost’s Google access from your Google Account permissions page. Where the Platform provides a connection control, you can also disconnect the Google or YouTube integration from CrerPost. When an integration is disconnected, CrerPost stops using that connection for new API requests and removes or disables the active connection credentials through the normal disconnection process. Content already imported into CrerPost, publishing history, security records, or backup copies may remain until deleted or no longer needed under this Policy.

To request deletion of Google user data held by CrerPost, disconnect the integration and email support@crerpost.com from the address associated with your account. Please identify the relevant workspace and connection without sending an access token or password. We may need to verify identity and authority before completing the request.

CrerPost’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

10. International Data Transfers

CrerPost is based in the United States, and the Platform and its service providers may process information in the United States and other countries where they operate. Those countries may have data-protection rules different from those in your location. Where required, we use an appropriate legal mechanism for a restricted international transfer, which may include contractual safeguards, a provider’s approved transfer mechanism, or another method permitted by law. We do not claim participation in a transfer certification unless expressly stated and verified.

11. Security

We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, alteration, disclosure, or misuse. Measures may include authentication and authorization controls, role-based access, secure transmission, secret-management practices, logging, monitoring, backups, provider controls, and review of suspicious activity.

No system or transmission is completely secure. Users are responsible for maintaining strong account credentials, protecting their devices and email accounts, reviewing workspace access, and promptly reporting suspected unauthorized use. Do not send provider credentials or tokens through ordinary support messages.

12. Retention

We retain information for as long as reasonably necessary for the purpose for which it was collected, including to maintain an account or workspace, provide requested features, preserve transaction and publishing records, meet legal or accounting requirements, prevent abuse, resolve disputes, and enforce agreements. Retention varies according to the type and sensitivity of information, user actions, workspace instructions, provider requirements, backup cycles, and applicable law.

Information may remain in backups or restricted records for a limited operational or legally required period after deletion from active systems. We may retain aggregated or de-identified information where it no longer reasonably identifies a person.

13. Account Closure and Data Deletion

Users may use available account controls to close an account or contact support@crerpost.com for assistance. A workspace member may need to direct a request to the workspace owner if the organization controls the relevant information. Before closing an account, users should export any information they need and cancel applicable recurring subscriptions.

Closing an account may remove or restrict access to account information and Platform content. Some records may be retained when reasonably necessary for billing, tax, security, fraud prevention, dispute resolution, legal claims, compliance, or backup integrity. Disconnecting a third-party account does not delete content already published to that third-party service; users must manage that content with the third party.

14. Privacy Rights and Choices

Depending on where you live and subject to legal exceptions, you may have the right to request access to, correction of, deletion of, or a copy of personal information; object to or restrict certain processing; withdraw consent; or request portability. You may also have the right to appeal a decision or complain to a data-protection authority.

Many details can be reviewed or changed through account, workspace, connection, and communication settings. To submit a privacy request, email support@crerpost.com. State the nature of the request and the account or workspace involved. We may verify your identity and authority, and we may direct requests concerning customer-controlled data to the relevant customer.

14.1 GDPR and UK data-protection rights

Individuals covered by the GDPR or UK data-protection law may have rights to access, rectify, erase, restrict, object, and receive portable data, as well as the right to withdraw consent and complain to a supervisory authority. These rights are not absolute and depend on the processing context and applicable exemptions. Where CrerPost acts only as a processor, we will reasonably assist the relevant customer in responding to valid requests as required by contract and law.

14.2 California privacy rights

California residents may have rights under the CCPA/CPRA to know the categories and specific pieces of personal information collected, the sources and purposes of collection, the categories of recipients, and to request correction or deletion. They may also have rights concerning sale, sharing, and sensitive personal information.

CrerPost does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA. We will not discriminate against a user for exercising an applicable privacy right. An authorized agent may submit a request where permitted, subject to verification of the agent’s authority and the consumer’s identity.

15. Marketing Communications

We may send product news, offers, or educational communications where permitted by law. You can opt out through the unsubscribe method in the message or by contacting us. Opting out of marketing does not stop transactional, security, billing, support, or other service communications needed to administer an account.

16. Children’s Privacy

CrerPost is intended for business and professional use and is not directed to children under 13. We do not knowingly collect personal information directly from a child under 13. If you believe a child has provided personal information to CrerPost, contact support@crerpost.com so we can review and take appropriate action. Users must also meet the eligibility requirements in the Terms of Use and the age requirements of any connected provider.

17. Policy Updates

We may update this Policy when the Platform, our practices, provider requirements, or applicable law changes. The “Last Updated” date identifies the current version. If a change materially affects how we handle personal information, we will provide notice through the Platform, by email, or by another reasonable method when required.

18. Contact Us

For a privacy question, rights request, or data-deletion request, contact:

Crer Group LLC, doing business as CrerPost
1021 E Lincolnway, Suite #7195
Cheyenne, Wyoming 82001
United States
Email: support@crerpost.com
Website: https://crerpost.com