OPost Privacy Policy
Effective date: 3 June 2026
Last updated: 3 June 2026
This Privacy Policy explains how OPost collects, uses, stores, shares, and protects personal information when you use our website, mobile applications, APIs, location tools, submission flows, media upload features, social media Highlights, connected social account features, staff review tools, and related services.
OPost is operated by [OPost Operator Legal Name], registered in [country/jurisdiction] with company number [company number, if applicable], with registered address at [registered address].
For privacy questions or data rights requests, contact us at:
Email: privacy@opost.ng
Address: [registered address]
1. Who this policy applies to
This policy applies to:
- visitors to OPost websites;
- users of OPost mobile apps;
- people who create OPost accounts;
- users who submit, suggest, claim, edit, save, or review places/entities;
- businesses, institutions, representatives, staff, contributors, and administrators;
- users who upload media or documents;
- users who add social links or connect TikTok, Instagram, Facebook, or other social accounts;
- people whose information appears in submitted or reviewed OPost records.
2. What OPost does
OPost is a location and entity discovery platform. We help users register, verify, review, manage, and discover places, services, institutions, businesses, facilities, public-facing entities, and location-based records.
Because OPost is a spatial and review-based platform, we may process location information, submission data, verification data, uploaded files, social media references, staff review decisions, and public entity information.
3. Personal information we collect
We may collect the following types of information.
A. Account information
- name;
- username or display name;
- email address;
- phone number;
- password or authentication information;
- verification level;
- account status;
- profile photo;
- user role, such as user, contributor, staff, institution, or superadmin.
B. Submission and entity information
- place/entity name;
- category and subcategory;
- description, headline, alias/common names, service information, tags, attributes, and public access details;
- ownership or claim type;
- submitted contact information;
- submitted business, institution, or service details;
- draft progress and submission state;
- review status, correction history, staff decisions, and publication status.
C. Location information
- map pins;
- GPS coordinates;
- manually entered coordinates;
- address details;
- administrative area selections;
- OPost code or resolved location identifiers;
- location capture mode;
- location confidence and resolution metadata;
- walk-to-map or route/path data, where used.
D. Media and document uploads
- photos;
- videos;
- thumbnails or previews;
- documents, licences, permits, ownership proof, authorization letters, correction evidence, or identity/institution verification files;
- file names, file size, file type, file hash, storage key, scan status, review status, and upload metadata.
OPost does not intend to publicly display private verification documents unless a document is clearly submitted and approved for public use.
E. Social media links and Highlights
If you add social links or Highlights, we may collect:
- platform name, such as TikTok, Instagram, Facebook, YouTube, X, website, or other;
- profile URL;
- post, reel, video, short, or page URL;
- normalized URL;
- public username or author name;
- thumbnail URL;
- embed URL or embed HTML;
- caption, title, or public metadata;
- selected display order;
- review status;
- availability or preview status.
F. Connected social account information
If you connect a TikTok, Instagram, Facebook, or other provider account, we may collect information provided by that platform after your consent, such as:
- provider account ID;
- username;
- display name;
- profile URL;
- avatar URL;
- account type, such as creator, business, page, or professional account;
- granted scopes/permissions;
- access token and refresh token, encrypted before storage;
- token expiry information;
- selected media metadata;
- public or authorized media references you choose to display.
OPost uses connected social account access only for the permissions you grant. We do not sell social account tokens. We do not post to your social account unless you separately grant posting permissions for a future feature.
G. Device, usage, and security information
- device type;
- operating system;
- app version;
- IP address;
- browser or device identifiers;
- log data;
- crash reports;
- API request logs;
- security events;
- fraud prevention signals;
- approximate location from device/network where required for security or service operation.
H. Communications
- support messages;
- correction responses;
- complaints;
- review disputes;
- emails or notifications sent to you;
- records of your preferences and consent choices.
4. How we collect information
We collect information when:
- you create or update an account;
- you use the app or website;
- you submit, save, edit, claim, or review a place/entity;
- you upload media or documents;
- you connect a social account;
- you paste a social media link;
- you interact with OPost staff or support;
- your device sends technical information;
- third-party providers send authorized data after you consent.
We may also receive information from staff, institutions, service providers, public sources, or users who submit entity information.
5. Why we use your information
We use information to:
- create and manage user accounts;
- verify email, phone, identity, ownership, institution, or staff status;
- process POI / Data / Entity submissions;
- save drafts and restore progress;
- resolve locations, map pins, coordinates, addresses, and OPost codes;
- review, approve, reject, correct, archive, or publish submissions;
- store and review media/document evidence;
- display approved public place/entity information;
- display selected public social Highlights;
- connect social accounts through official provider authorization;
- fetch authorized social media metadata for user-selected Highlights;
- provide saved places, notifications, user activity, and settings;
- prevent fraud, misuse, impersonation, spam, and unsafe submissions;
- protect OPost, users, staff, and the public;
- provide customer support;
- comply with law, platform rules, court orders, and regulatory duties;
- improve OPost features, performance, security, and reliability.
6. Lawful basis for using personal information
Depending on the situation and applicable law, we may rely on:
- Contract: to provide OPost services you request;
- Consent: where you connect a social account, allow location access, receive optional communications, or grant optional permissions;
- Legitimate interests: to operate, secure, improve, moderate, review, and protect OPost;
- Legal obligation: where we must comply with applicable laws, regulators, court orders, tax, security, or reporting requirements;
- Public interest or vital interests: where applicable for safety, emergency, or public-risk scenarios.
Where we rely on consent, you may withdraw consent at any time. Withdrawal will not affect processing already carried out before withdrawal.
7. Social media integrations
OPost supports social media features in two main ways.
A. Pasted social links
You may paste a TikTok, Instagram, Facebook, YouTube, website, or other supported link. OPost may fetch or store a preview, thumbnail, embed reference, caption, author name, public URL, or availability status.
B. Connected social accounts
You may connect your TikTok, Instagram, Facebook, or other account through that provider’s official login or OAuth flow. If you approve the connection, the provider may send OPost an authorization code, access token, refresh token, account information, and authorized media metadata.
OPost stores social access and refresh tokens in encrypted form. We use them only for the connected-account features you approve, such as fetching media metadata so you can select Highlights.
You may disconnect your social account from OPost. You may also revoke access directly through the relevant platform’s account settings.
If a selected social post is deleted, made private, removed, restricted, or unavailable through the provider, it may stop appearing in OPost.
OPost does not scrape private social accounts and does not copy TikTok, Instagram, or Facebook video/media files into OPost storage unless we separately ask for permission and you upload or authorize such content.
8. Uploaded documents and sensitive evidence
Some OPost workflows may require verification documents, ownership proof, licences, permits, institution evidence, representative authorization, or identity-related materials.
We use these materials for review, verification, moderation, dispute handling, safety, compliance, and support.
We restrict access to authorized staff, reviewers, administrators, or trusted service providers who need access for their role.
We do not intend to make private verification documents public. Public display is limited to approved public information and approved public media.
9. Location data
OPost processes location data because the service is built around places, entities, maps, coordinates, and spatial verification.
Location data may be used to:
- place an entity on the map;
- resolve an address or administrative area;
- generate or verify an OPost code;
- detect location mismatch;
- support staff review;
- support public discovery;
- support safety and fraud prevention;
- improve map/search accuracy.
You can control some device location permissions through your mobile operating system. Some OPost features may not work properly without location access.
10. What information may become public
If a submission is approved, OPost may publicly display approved information such as:
- place/entity name;
- category and subcategory;
- public description;
- alias/common names;
- public tags and attributes;
- public contact or service details submitted for public use;
- address, map position, coordinates, OPost code, or approximate location;
- approved photos/media;
- approved social Highlights;
- verification or review indicators.
Private account data, private verification documents, internal staff notes, private tokens, and private review evidence are not intended for public display.
11. Who we share information with
We may share information with:
- OPost staff, reviewers, administrators, and support personnel;
- institutions, where relevant to institutional submissions or review;
- cloud hosting and storage providers;
- database, infrastructure, and security providers;
- email, SMS, notification, and communication providers;
- map, geocoding, and location providers;
- social media providers when you connect accounts or request previews;
- payment processors where paid services are used;
- professional advisers, auditors, insurers, or legal representatives;
- courts, regulators, law enforcement, or authorities where required by law or necessary for safety, fraud prevention, or legal claims.
We do not sell your personal information.
12. International transfers
OPost may use service providers or infrastructure located outside your country. Where personal information is transferred internationally, we take reasonable steps to protect it according to applicable data protection requirements, such as contractual safeguards, access controls, encryption, and provider due diligence.
13. How long we keep information
We keep information only for as long as reasonably needed for the purpose collected, unless a longer period is required for legal, safety, dispute, audit, fraud prevention, or compliance reasons.
Typical retention may include:
- account data: while your account is active and for a reasonable period after closure;
- drafts: until deleted, discarded, expired, or archived according to OPost settings;
- published entity records: while the entity remains active or relevant;
- review records: as needed for audit, safety, fraud prevention, and dispute handling;
- uploaded public media: while approved and linked to an active entity or submission;
- private verification documents: only as long as needed for verification, audit, legal, or dispute purposes;
- social tokens: until disconnected, expired, revoked, or no longer needed;
- logs and security records: for a limited period needed for security, troubleshooting, legal, or operational purposes.
We may anonymize or aggregate information so it no longer identifies you.
14. Security
We use technical and organizational measures designed to protect personal information, including:
- account authentication;
- role-based access control;
- encryption in transit;
- encrypted storage for sensitive tokens;
- restricted access to private documents;
- file metadata and review tracking;
- malware/security checks where available;
- audit and security logs;
- separation of public content and private review evidence;
- staff access controls.
No system is completely secure. You are responsible for keeping your login details safe and notifying us if you suspect unauthorized access.
15. Your rights
Depending on where you live and which law applies, you may have rights to:
- be informed about how your data is used;
- access your personal information;
- correct inaccurate or incomplete information;
- delete your information;
- restrict processing;
- object to processing;
- withdraw consent;
- request data portability;
- complain to a supervisory authority;
- not be subject to solely automated decisions that have legal or similarly significant effects, where applicable.
To exercise your rights, contact privacy@opost.ng.
We may need to verify your identity before responding. Some rights may be limited where we need to keep information for legal, security, fraud prevention, review, dispute, or public-interest reasons.
16. Account deletion and social data deletion
You may request deletion of your OPost account and personal information by contacting privacy@opost.ng or using any in-app deletion feature we provide.
You may also request deletion of social data collected through TikTok, Instagram, Facebook, or other connected providers.
When you request deletion, we will take reasonable steps to:
- delete or deactivate your account where applicable;
- remove or anonymize personal profile data;
- disconnect linked social accounts;
- delete encrypted access and refresh tokens;
- remove connected media cache where it identifies you;
- remove or archive private documents according to legal and review requirements;
- stop future provider API syncs.
Some information may be retained where needed for legal compliance, fraud prevention, security, audit trails, dispute resolution, enforcement of Terms, or protection of public records and safety.
If your information appears in a public entity record because it relates to a business, institution, place, or public-facing service, we may review whether to remove, anonymize, correct, or keep the record depending on the nature of the information and applicable law.
17. Children
OPost is not intended for children under [13/16/18 depending on your chosen policy and jurisdiction]. Users under the required age must not create accounts or submit information without appropriate consent.
If you believe a child has provided personal information to OPost, contact us at privacy@opost.ng.
18. Cookies and similar technologies
OPost websites may use cookies, local storage, device identifiers, or similar technologies to:
- keep you signed in;
- remember preferences;
- improve performance;
- measure usage;
- protect security;
- support analytics;
- diagnose errors.
Where required, we will ask for consent before using non-essential cookies.
19. Automated checks and AI-assisted review
OPost may use automated or AI-assisted tools to help with:
- duplicate detection;
- location mismatch detection;
- category suggestions;
- media/document checks;
- fraud signals;
- moderation flags;
- search and recommendation improvements;
- staff review support.
These tools support review but do not replace all human judgment. Where a decision significantly affects you, you may contact us to request review or correction.
20. Third-party links and platforms
OPost may contain links, embeds, previews, or integrations from third-party platforms such as TikTok, Instagram, Facebook, YouTube, X, map providers, websites, and payment providers.
Those third parties have their own privacy policies and terms. OPost is not responsible for their independent processing of your data.
21. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as by email, in-app notice, or posting the updated policy.
The updated policy will apply from the effective date shown at the top.
22. Contact and complaints
For privacy questions, requests, or complaints, contact:
[OPost Operator Legal Name]
Email: privacy@opost.ng
Address: [registered address]
If you are in the United Kingdom, you may complain to the Information Commissioner’s Office.
If you are in Nigeria, you may complain to the Nigeria Data Protection Commission.
We encourage you to contact us first so we can try to resolve your concern.