Privacy Policy
Last updated: October 1, 2026
1. Introduction
PayPosts ("we", "us", or "the Company") values the privacy and protection of our users' personal data. This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you use our platform, in accordance with the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018) and other applicable regulations.
By using the PayPosts platform, available at payposts.paywallo.com.br, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller Identification
The controller of the personal data processed by the platform is:
| Legal Name | Virex Tech LLC |
| Trade Name | PayPosts |
| Company registration (New Mexico, USA) | 0008078201 |
| Address | 412 W 7th St, STE 1164, Clovis, NM 88101, USA |
| Website | https://payposts.paywallo.com.br |
| Privacy / DPO E-mail | contato@virextech.com.br |
The Data Protection Officer (DPO) is responsible for receiving and responding to requests from data subjects and from the National Data Protection Authority (ANPD).
3. What Personal Data We Collect
3.1. Data provided directly by the User
| Data | Purpose | Legal Basis (LGPD) |
|---|---|---|
| Account creation, authentication, service communications | Contract performance (Art. 7, V) | |
| Password (stored as hash) | Account authentication and security | Contract performance (Art. 7, V) |
| Name / Company name | Identifying the User on the Platform | Contract performance (Art. 7, V) |
| Payment data | Billing processing | Contract performance (Art. 7, V) |
3.2. Data collected automatically
| Data | Purpose | Legal Basis (LGPD) |
|---|---|---|
| IP address | Security, fraud prevention, audit logs | Legitimate interest (Art. 7, IX) |
| Browsing data (pages visited, clicks, time on site) | Improving the Platform and User experience | Legitimate interest (Art. 7, IX) |
| Device information (browser, operating system) | Technical compatibility and support | Legitimate interest (Art. 7, IX) |
| Session cookies (HttpOnly JWT) | Maintaining the authenticated session | Contract performance (Art. 7, V) |
3.3. Data obtained from third parties
| Data | Purpose | Legal Basis (LGPD) |
|---|---|---|
| TikTok access token (via OAuth) | Content publishing authorized by the User | Consent (Art. 7, I) and Contract performance (Art. 7, V) |
| Instagram professional account data, when the User connects their own account through Instagram Login (see Section 3.4) | Publishing, first comment and performance metrics of the User's own account | Consent (Art. 7, I) and Contract performance (Art. 7, V) |
| Public data from TikTok and Instagram accounts (metrics, posts, engagement) | Monitoring and analysis requested by the User | Legitimate interest (Art. 7, IX) |
Important note:the data of third-party TikTok and Instagram accounts that the User chooses to monitor (for example, competitors or references) is exclusively publicly available data. Non-public data is only accessed for the User's own Instagram account, after the User connects it and authorizes it on Instagram, as described in Section 3.4. We never access direct messages, private accounts, or passwords.
3.4. Instagram data (Meta Platform)
When the User clicks "Connect Instagram", they are taken to Instagram's official login page (Instagram API with Instagram Login, provided by Meta Platforms, Inc.). PayPosts never sees or stores the Instagram password. After the User authorizes it, Instagram gives PayPosts an access token limited to the permissions below, and only for that professional account (Business or Creator):
| Permission | Data accessed | What we use it for |
|---|---|---|
| instagram_business_basic | Account ID, username, profile picture, follower and media counts, list of the account's own posts | Identifying which account is connected and showing it in the User's workspace |
| instagram_business_content_publish | Media and captions created by the User in PayPosts | Publishing posts, carousels, reels and stories to the account, when the User publishes or schedules them |
| instagram_business_manage_comments | Comments on the account's own posts | Posting the first comment the User wrote for a post (for example, hashtags or a link) right after it is published |
| instagram_business_manage_insights | Metrics of the account and of its own posts (views, reach, likes, comments, saves, shares, follower changes) | Showing the User how their posts perform and suggesting better posting times and formats |
- Instagram data is used only to provide these features to the User who connected the account. We do not sell it, do not use it for advertising, and do not share it with third parties other than the infrastructure providers needed to run PayPosts.
- The access token is stored encrypted and is never shown to other users.
- The User can revoke access at any time: in PayPosts ("Disconnect" on the Instagram profile, which deletes the token) or in Instagram (Settings > Website permissions > Apps and websites > Remove).
- How to delete this data is explained on the Data Deletion page.
- This use complies with the Meta Platform Terms and Developer Policies.
4. How We Use Your Data
We use the personal data collected for the following purposes:
- Service delivery: creating and maintaining your account, authenticating access, processing posts, and generating analytics;
- Communication: sending notifications about the service, feature updates, security alerts, and administrative communications;
- Service improvement: analyzing usage patterns (aggregated and anonymized whenever possible) to improve the Platform;
- Security: detecting and preventing fraud, unauthorized access, and other malicious activity;
- Legal compliance: meeting regulatory, tax, or judicial requirements;
- Marketing (only with prior consent): sending promotional communications about new features or offers. The User may withdraw consent at any time.
5. Sharing Data with Third Parties
PayPosts may share personal data with third parties in the following situations:
5.1. Service providers (data processors)
| Third party | Purpose | Data shared |
|---|---|---|
| Apify (scraping infrastructure) | Collection of public data from TikTok and Instagram | URLs of monitored public profiles (not the User's personal data) |
| TikTok (via official API / OAuth) | Publishing content to the User's account | OAuth token, content to be published |
| Meta Platforms, Inc. (Instagram API) | Publishing content and reading metrics of the User's own Instagram account | Access token, content to be published, first comment |
| Hosting / infrastructure provider | Data storage and processing | All data described in Section 3, encrypted |
| Payment gateway | Billing processing | Payment data |
5.2. Other sharing scenarios
- Legal obligation: when required by law, regulation, court order, or determination by the ANPD;
- Protection of rights: to protect the rights, safety, or property of PayPosts, its Users, or the public;
- Corporate transactions: in the event of a merger, acquisition, or sale of assets, data may be transferred to the new controller, with prior notice to the User.
5.3. International data transfer
Some of our service providers may be located outside Brazil. In such cases, we ensure that the international transfer of personal data is carried out in accordance with Articles 33 to 36 of the LGPD, adopting the following safeguards:
- Standard Contractual Clauses;
- Verification that the destination country provides an adequate level of data protection;
- Adoption of technical security measures (encryption in transit and at rest).
6. Data Retention
We keep your personal data only for as long as necessary to fulfill the purposes described in this Policy, observing the following criteria:
| Data type | Retention period | Justification |
|---|---|---|
| Account data (e-mail, name) | While the account is active + 6 months after closure | Contract performance and reactivation |
| Authentication data (password hash) | While the account is active | Security |
| Access logs (IP, timestamps) | 6 months | Legal obligation (Brazilian Civil Rights Framework for the Internet, Art. 15) |
| Payment data / invoices | 5 years after the transaction | Tax and fiscal obligation |
| Anonymized analytics data | Indefinite | Service improvement (non-personal data) |
| OAuth tokens (TikTok, Instagram) | Until the User disconnects the account or deletes their PayPosts account, when they are deleted immediately | Contract performance |
| Instagram metrics and posts of the connected account | While the account is connected; deleted together with the PayPosts account | Contract performance |
After the retention periods, personal data will be deleted or anonymized, unless there is a legal obligation requiring its retention.
7. Your Rights as a Data Subject (Art. 18, LGPD)
In accordance with Article 18 of the LGPD, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Confirmation | Confirm whether we process your personal data |
| Access | Access the personal data we hold about you |
| Correction | Request correction of incomplete, inaccurate, or outdated data |
| Anonymization, blocking, or deletion | Request the anonymization, blocking, or deletion of unnecessary or excessive data |
| Portability | Request the portability of your data to another provider |
| Deletion | Request the deletion of data processed based on your consent |
| Information about sharing | Know which entities we share your data with |
| Information about consent | Be informed about the possibility of not giving consent and its consequences |
| Withdrawal of consent | Withdraw consent at any time |
How to exercise your rights
You can exercise any of these rights in the following ways:
- E-mail: contato@virextech.com.br
- Platform:Settings > Account > Danger Zone > Delete account (deletes all your data)
- Data deletion instructions: https://payposts.paywallo.com.br/data-deletion
Response time: we will respond to your request within 15 (fifteen) business days, as provided for under the LGPD. If we are unable to meet this deadline, we will explain the reasons.
If you believe the processing of your data violates the LGPD, you have the right to file a complaint with the National Data Protection Authority (ANPD) — https://www.gov.br/anpd.
8. Cookies and Tracking Technologies
8.1. What cookies are
Cookies are small text files stored on your browser when you access the Platform. We use cookies to keep you signed in, improve your experience, and ensure security.
8.2. Types of cookies used
| Type | Purpose | Duration | Required? |
|---|---|---|---|
| Session cookie (HttpOnly JWT) | Keeping the User authenticated on the Platform | Session duration (expires when the browser is closed or after a configured time) | Yes — essential for operation |
| Preference cookies | Saving User preferences (language, theme) | Up to 1 year | No |
| Analytics cookies | Aggregated usage metrics for service improvement | Up to 1 year | No |
8.3. Managing cookies
- Essential cookies (session/authentication) are necessary for the Platform to function and cannot be disabled;
- Non-essential cookies (preference, analytics) can be managed in the Platform or browser settings;
- Disabling non-essential cookies does not affect the use of the Platform's core features.
Note: we do not use third-party cookies for behavioral advertising or cross-site tracking.
9. Data Security
We adopt technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or improper alteration. Among the measures adopted:
Technical measures:
- Encryption of data in transit (TLS/HTTPS);
- Passwords stored as hashes using secure algorithms (bcrypt);
- JWT session tokens stored in HttpOnly cookies (inaccessible via JavaScript);
- PostgreSQL database with restricted access and encryption at rest;
- Regular encrypted backups;
- Access monitoring and anomaly detection.
Organizational measures:
- Access to personal data restricted to authorized staff, following the principle of least privilege;
- Periodic staff training on data protection;
- Periodic review of security practices;
- Security incident response plan.
In the event of a security incident that may pose a relevant risk to data subjects, we will notify the ANPD and affected Users within a reasonable time, as required by Art. 48 of the LGPD.
10. Data of Minors
PayPosts is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children or teenagers. If we become aware that data from a minor has been collected, we will proceed with its immediate deletion.
11. Data Protection Officer (DPO)
PayPosts' Data Protection Officer is the point of contact between the Company, data subjects, and the ANPD.
| Responsible | Virex Tech LLC |
| contato@virextech.com.br | |
| Address | 412 W 7th St, STE 1164, Clovis, NM 88101, USA |
The DPO is responsible for:
- Receiving and responding to requests from data subjects;
- Receiving communications from the ANPD and taking the necessary measures;
- Guiding the team on data protection practices;
- Preparing and keeping the Data Protection Impact Report (RIPD) up to date when applicable.
12. Changes to This Policy
This Privacy Policy may be updated periodically to reflect changes in our practices, Platform features, or legal requirements.
When we make material changes:
- We will publish the updated version on the Platform with the new "Last updated" date;
- We will notify Users by e-mail at least 15 (fifteen) days before the changes take effect;
- When changes affect the legal basis for processing, we will request new consent when necessary.
Continued use of the Platform after the effective date of the new version constitutes acceptance of the changes.
13. Applicable Law
This Privacy Policy is governed by Brazilian law, in particular:
- LGPD — Law No. 13,709/2018 (Brazilian General Data Protection Law);
- Brazilian Civil Rights Framework for the Internet — Law No. 12,965/2014;
- Consumer Protection Code — Law No. 8,078/1990, when applicable.
14. Contact
For questions, requests, or complaints related to this Privacy Policy or the processing of your personal data:
- General e-mail: contato@virextech.com.br
- Data deletion: https://payposts.paywallo.com.br/data-deletion
- Website: https://payposts.paywallo.com.br
This Privacy Policy is an integral part of PayPosts' Terms of Use. By using the Platform, you acknowledge that you are aware of and agree to the practices described herein.