Privacy Policy
Last updated: September 9, 2026
This is a starter policy for Soft launch. It is not legal advice. We may update these documents; the version on this page is the current one.
1. Who we are
Smooth Social is a trade name of OLBE Creative Consultant (J. Gielen), KvK 88788180, Liebergerweg 734, 1223 PZ Hilversum, The Netherlands (the “controller”).
Contact for privacy requests: support@smooth.social.
2. What we process
Depending on how you use the Service, we may process:
- Account data (email, name/metadata, authentication identifiers)
- Billing data (plan, Stripe customer/subscription IDs; card details are handled by Stripe)
- Workspace and social-set configuration
- Connected social account metadata, tokens, and capabilities (via our processors)
- Post content, media, schedules, drafts, and publish status
- Comments and related inbox data you sync or manage in the product
- Usage and technical logs needed to operate and secure the Service
- Support correspondence
3. Why we process data (purposes & bases)
- Contract — provide the Service, authenticate you, publish/schedule content, sync comments, and bill subscriptions
- Legitimate interests — secure the Service, prevent abuse, improve reliability, and basic product analytics that do not require non-essential cookies
- Legal obligation — where we must retain invoices or respond to lawful requests
- Consent — where required (for example non-essential cookies/marketing if we introduce them later; see our Cookie Policy)
4. Processors and recipients
We use trusted processors to run the Service, including:
- Supabase — authentication, database, file storage
- Stripe — payments and subscriptions
- Resend — transactional email
- Outstand — social network connectivity, publishing, and metrics
- Hosting provider (e.g. Vercel) — application hosting
- Social networks you connect (Meta, TikTok, LinkedIn, X, and others) — per your OAuth grants
These parties process data under their own terms and, where applicable, data processing terms with us. Social networks act as independent controllers for data on their platforms.
5. International transfers
Some processors may process data outside the EEA. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) provided by those vendors.
6. Retention
- Account and workspace data — while your account is active
- Billing records — as required for tax/accounting
- Content and media — until you delete them or your account is closed (subject to backups)
- Logs — for a limited period for security and troubleshooting
After account deletion requests, we delete or anonymize personal data that is no longer needed, unless retention is required by law.
7. Your rights (GDPR)
Subject to applicable law, you may request:
- Access to your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction or objection to certain processing
- Data portability
- Withdrawal of consent where processing is consent-based
Email support@smooth.social with the subject “Privacy request”. We may need to verify your identity. You may also lodge a complaint with your local supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens).
8. Security
We use industry-standard measures appropriate to a SaaS product (encryption in transit, access controls, least-privilege practices). No method of transmission or storage is 100% secure.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children under that age.
10. Changes
We may update this Privacy Policy. The “Last updated” date at the top will change when we do. Material changes may also be communicated in-product or by email.