Skip to content

Privacy policy

How PoundPost uses information when you browse, post, message or ask for help on our website and apps.

Updated 7 September 2026

Information we use

Your account

We use your email address and sign-in details to create and protect your account. If you choose Apple or Google sign-in, we receive the account information that provider shares with us. You can choose a username, display name, profile photo and bio. We do not ask for your date of birth.

Posts and conversations

We store the posts, photos, approximate listing locations, messages, offers, saved searches and favourites you create. Your posts and public profile can be seen by other people. Messages are available to the people in the conversation. Authorised staff can review reported conversations and supporting evidence.

Location and photos

If you allow location access, we use your device location to find nearby places. You can choose a place yourself instead. Listing maps show an approximate location. Camera and photo access is used when you choose to add a photo. Check your photos and text for personal details before posting.

Payments

Stripe processes payments for PoundPost posts, boosts and credits. We keep payment references, amounts, currencies, outcomes and receipt details. Card details are entered into Stripe payment fields. PoundPost does not process the payment between a buyer and seller.

Support and safety

We store support requests, replies, attachments, reports, blocks and moderation records so we can investigate problems and protect people using PoundPost. Requests also produce technical information such as IP addresses, timestamps and error records. We use request counters to limit abuse.

Notifications

If you enable notifications, we store the delivery address or device token needed to reach your browser or phone. Notification services can receive a title, message preview and link. Email alerts can also include message or listing details. You can change optional alerts in Settings and revoke notification permission on your device.

Services that help us run PoundPost

Hosting, delivery and security

PoundPost uses Supabase for accounts, databases and uploaded files, Stripe for payments, and Resend for email delivery when configured. Website hosting handles page requests and technical logs. Where enabled, Cloudflare checks requests with Turnstile for automated abuse. Maps request tiles and fonts from OpenFreeMap. These services receive the information needed to provide their part of the service, including connection details.

Phone and browser services

Apple or Google handles sign-in when you choose that option. Push delivery uses the services supplied by your browser or phone, and the mobile app uses Expo notification services. Your device may show notification previews on its lock screen. Shared links and anything you copy out of PoundPost are handled by the service you share them with.

Access to private information

Account data is protected by sign-in and access permissions. Staff access depends on their role, and support and moderation actions are recorded. Messages are not end-to-end encrypted. Do not send information that is not needed to arrange your trade or resolve your request.

Keeping and deleting information

Account closure

Deleting your account takes its posts offline immediately. If you choose the seven-day window, you can cancel before deletion begins. Once deletion starts, PoundPost deletes your profile, posts, sent message content, support content and attachments, notification registrations, saved activity and sign-in identity. Payment, credit, store purchase and moderation records may stay when they are needed for refunds, accounting, fraud prevention or safety. Those records are separated from your sign-in and linked to a random internal record.

Your choices and rights

Ask about your information

You can edit your profile and notification settings, and download a portable copy of your information from Account settings. You can also ask for access, correction, deletion or restriction, and object to some uses. Which rights apply depends on the information and why it is used. Contact support with a privacy request. We may need to verify that the account is yours.

A concern about your privacy

You can raise a concern with the UK Information Commissioner’s Office. You do not have to contact us first.