Skip to content
ownpost.
The workspaceHow it worksPricingDocumentationMy purchases
Get the kit
← Back to OwnPost

PURCHASE & WEBSITE POLICIES

Privacy Policy

The information used to run this website, process your purchase, and help with your order.

Last updated September 22, 2026

Policies & support

Terms & ConditionsPrivacy PolicyRefund & CancellationDelivery & ServicesContact

On this page

1. Who and what this policy covers2. Information involved3. How information is used4. Cookies and analytics5. Sharing and service providers6. Retention and security7. Your self-hosted workspace8. Your choices and privacy requests9. Policy updates

1. Who and what this policy covers

This policy describes how OwnPost handles information in connection with this sales website, purchases, and support. Dodo Payments, Resend, GitHub, and your chosen hosting and integration providers also process information under their own policies.

The workspace you deploy from the kit is hosted in accounts you control. Browsing this website does not connect us to your X account or give us access to your private workspace.

2. Information involved

  • Website requests: hosting and security services may process IP addresses, browser/device information, requested pages, timestamps, and technical error logs.
  • Orders: Dodo Payments collects the contact, billing, tax, and payment information needed at checkout. Our website stores the email and optional name you enter, selected products and prices, checkout references, payment status, amounts, and any refunds or disputes in our Cloudflare D1 database. Dodo supplies payment and customer references so we can reconcile and support your order. We do not collect card numbers or security codes in this website’s forms.
  • Historical policy acceptance: we retain policy versions and acceptance times previously recorded with orders. Website checkout no longer collects policy acceptance or sends acceptance metadata to Dodo Payments.
  • Customer account: we use your verified checkout email to provide passwordless access to your purchases. We store hashed sign-in link and session tokens, expiry and usage records, and email-delivery status in our database. Resend receives your email address and message content to send transactional welcome and sign-in emails.
  • Kit access: we store the GitHub username you submit with your customer account and send it to GitHub to request repository access. GitHub handles the invitation and access to the repository.
  • Support and deployment: we receive information you choose to share, such as your email, name, order reference, questions, or setup details. Contact messages and deployment requests are stored in our database for follow-up. Deployment requests include your verified checkout email, relevant order references, name, timezone, and any GitHub username, project URL, or notes you provide. Your latest deployment details are also available in your customer account. Do not send passwords, private keys, or full payment details in support messages.

3. How information is used

We use necessary information to process and verify purchases, provide access and deployment help, answer requests, troubleshoot problems, protect against fraud, and meet legal or accounting obligations.

Where applicable data protection law requires a legal basis, these activities rely on performing our contract with you, complying with legal obligations, and legitimate interests in operating and securing the service. Where consent is required for an optional use, we will request it separately.

4. Cookies and analytics

Starting checkout sets an essential receipt-verification cookie named xpl_checkout_ followed by a random reference. It contains a signed checkout session reference, selected offer, and expiry time. It expires after 24 hours, is inaccessible to page scripts, and is sent only to this website’s payment-status endpoint. It is marked Secure on HTTPS.

Signing in to your customer account sets an essential, HttpOnly cookie named xpl_customer. It contains a random session token and expires after 30 days. It is inaccessible to page scripts and marked Secure on HTTPS. Signing out removes the session and cookie.

Our private admin area also uses an essential, HttpOnly session cookie named xpl_admin, which expires after eight hours. Public visitors do not need an admin cookie.

You can delete or block cookies in your browser. Doing so may prevent this website from verifying your checkout or keeping you signed in. Your Dodo receipt remains your payment record; use email sign-in to reopen your customer account when cookies are enabled. This website’s application does not include advertising cookies or third-party marketing analytics. The hosting platform and external checkout may use their own essential authentication, security, or payment cookies.

5. Sharing and service providers

Information is shared as needed with our payment, hosting, access-delivery, and support providers, or when required by law or to protect lawful rights. We do not sell personal information.

Dodo Payments handles payment processing and merchant-of-record obligations; Resend sends transactional account-access emails; GitHub handles repository access; the website’s host handles serving and securing requests; Cloudflare D1 stores sales, customer-access, GitHub assignment, and contact/deployment records. Administrative access is restricted to the site administrator, and signed-in customers can view their own purchases and saved onboarding details. Providers may process information in countries other than your own under applicable transfer safeguards.

Read the Dodo Payments Privacy Policy, Resend Privacy Policy, and GitHub Privacy Statement for their practices.

6. Retention and security

The receipt cookie expires after 24 hours and customer sessions expire after 30 days. The initial welcome sign-in link expires after 24 hours; a newly requested sign-in link expires after 15 minutes. Each link can be used only once. These access expiry periods do not mean that order or support records are deleted. Order, tax, support, and security information may be retained longer as needed to deliver services, resolve disputes, prevent fraud, or satisfy legal requirements. Provider retention periods depend on their policies and the applicable obligations.

We use safeguards appropriate to the service, including signed receipt references, hashed customer tokens, and server-side payment and account-access verification. No transmission or storage system is completely secure. Avoid sharing more information than is needed for a support request.

7. Your self-hosted workspace

Your posts, media, API credentials, and workspace data are stored and processed by your deployment and any integrations you enable. Your chosen hosting, AI, X, Telegram, and other providers have separate practices and terms. You are responsible for selecting providers, controlling access, and handling any personal information you place in your workspace.

If you request setup assistance and grant us access, we use that access for the agreed work. Revoke temporary access and rotate credentials after the handover.

8. Your choices and privacy requests

Depending on your location, you may have rights to access, correct, delete, or receive a copy of your personal information, restrict or object to processing, and withdraw consent where processing relies on it. You may also raise a concern with your local data protection authority. Certain order records may need to be retained to comply with law.

Use our contact details for requests relating to information we handle. We may need to verify your identity. For information controlled independently by a provider, contact that provider directly. The service is intended for people who can legally enter into a purchase and is not directed at children.

9. Policy updates

We will update this page and its date when our practices change. Where legally required, we will provide additional notice or request consent before a new use of information.

ownpost.

A little space for your next big idea.

DocumentationDeployment guideMy purchasesGet the kit
Terms & ConditionsPrivacy PolicyRefund & CancellationDelivery & ServicesContact
© 2026 OwnPostBuilt for your voice. Hosted on your terms.Independent tool for X