Privacy Policy

Last updated: 12 February 2026

1. Introduction

Phos ("we", "us", "our") operates the marketing automation platform at phos.nz. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our services.

We are committed to protecting your privacy and complying with the New Zealand Privacy Act 2020.

2. Information We Collect

Account information: When you create a Phos account, we collect your name, email address, and business name.

Connected social accounts: When you connect a social media account (such as Instagram or Facebook), we receive and store:

  • Your account name and profile information
  • An access token that allows us to publish content and read engagement metrics on your behalf
  • Page and account identifiers

Content and analytics data: Posts you create or schedule through Phos, and engagement metrics (likes, comments, shares, impressions, reach) from your connected accounts.

Usage data: Basic information about how you use the platform, including login timestamps and feature usage.

3. How We Use Your Information

We use the information we collect to:

  • Publish and schedule content to your connected social media accounts on your behalf
  • Display engagement analytics and performance metrics for your posts
  • Provide AI-powered content suggestions based on your brand profile
  • Manage your subscription and process payments
  • Send you service-related notifications (such as publishing confirmations or account alerts)
  • Improve our platform based on aggregated, anonymised usage patterns

4. Data Storage and Security

Your data is stored in PostgreSQL databases hosted in the Australia/New Zealand region (Sydney, AU). Social media access tokens are stored encrypted at rest.

We use industry-standard security measures including HTTPS encryption for all data in transit, encrypted database connections, and role-based access controls.

5. Third-Party Services

We integrate with the following third-party services to provide our platform:

  • Meta (Facebook/Instagram): We use the Meta Graph API to publish content and retrieve engagement metrics from your connected Instagram Business and Facebook Page accounts. Meta's use of data is governed by Meta's Privacy Policy.
  • Stripe: We use Stripe to process payments. Stripe handles all payment card data directly—we never see or store your card details.
  • Supabase: We use Supabase for authentication and database hosting.

We do not sell, rent, or share your personal information with any other third parties for their marketing purposes.

6. Data Retention

Access tokens: Social media access tokens are valid for approximately 60 days and are automatically refreshed while your account is connected. When you disconnect a social account, the associated tokens are deleted immediately.

Account data: If you cancel your subscription and delete your account, all associated data (content, analytics, tokens, and profile information) is permanently deleted within 30 days.

Analytics data: Engagement metrics are retained for the duration of your subscription to provide historical reporting.

7. Your Rights

Under the New Zealand Privacy Act 2020, you have the right to:

  • Access the personal information we hold about you
  • Correct any inaccurate or incomplete information
  • Delete your data by disconnecting your social accounts and/or deleting your Phos account
  • Withdraw consent for social media access at any time by disconnecting the platform from your Phos dashboard or removing Phos from your Facebook/Instagram app settings

To exercise any of these rights, contact us at the address below.

8. Cookies

We use minimal cookies strictly necessary for the operation of our platform:

  • Authentication cookies: To keep you signed in to your Phos account

We do not use advertising cookies, tracking pixels, or any third-party analytics cookies.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on our platform. Your continued use of Phos after changes are posted constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

Email: support@phos.nz

Website: phos.nz