Privacy Policy
Last updated: 16 June 2026
This Privacy Policy explains how Straw Social (“Straw Social”, “we”, “us”), a product operated by Soracle Media, collects, uses, shares and protects your personal information when you use our website and application at www.strawsocial.com (the “Service”).
Soracle Media is the data controller. You can contact us at any time at r.sorrell@soraclemedia.com or by post at Soracle Media, 8 Gerard Avenue, Hounslow, TW4 5NB, United Kingdom.
1. Information we collect
We collect the following categories of information:
- Account information — your name, email address and password (stored hashed) when you create an account.
- Brand information — the brands you create, including names, logos, timezones and accent colours.
- Connected social accounts — when you connect a social network (Facebook, Instagram, TikTok, YouTube, LinkedIn or Pinterest), we receive and securely store the access tokens and basic account details (such as the connected account name and id) needed to publish on your behalf and to retrieve analytics you ask for.
- Content you create — the posts, captions, schedules and media (images and videos) you upload to compose and schedule.
- Analytics data — performance metrics (such as reach, impressions and engagement) that we fetch from connected networks for posts you have published through the Service.
- Usage and technical data — basic logs, device and browser information, and cookies needed to keep you signed in and to operate and secure the Service.
2. How we use your information
- To provide, operate and maintain the Service.
- To publish content to the social networks you connect, at the times you schedule.
- To retrieve and display analytics for the content you publish through us.
- To authenticate you and keep your account secure.
- To respond to your support requests and communicate with you.
- To comply with our legal obligations.
Our lawful bases for processing under UK/EU GDPR are the performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), and your consent (for example, when you connect a social account and authorise specific permissions).
3. Connected social networks & platform data
When you connect an account, you authorise Straw Social to act on your behalf for the specific permissions you grant. We use this access only to provide the features you request — namely publishing your scheduled content and retrieving its analytics.
- Access and refresh tokens are stored encrypted, server-side only, and are never exposed to your browser or shared with other customers.
- We do not sell platform data, and we do not use it for advertising or for any purpose other than operating the Service for you.
- Our use of information received from Meta (Facebook and Instagram), Google (YouTube), TikTok, LinkedIn and Pinterest complies with each platform’s developer terms and policies, including the Meta Platform Terms and Developer Policies.
- You can disconnect any network at any time in the Service, which revokes our stored tokens for that account.
4. How we share information
We do not sell your personal information. We share it only with:
- Social networks you connect — to publish the content you schedule, in line with your instructions.
- Service providers (sub-processors) who help us run the Service, under contract and only as needed:
- Supabase — database, authentication and file storage (hosted in the EU).
- Vercel — application hosting and content delivery.
- Authorities — where required by law, or to protect our rights, users or the public.
5. Storage, security & location
Your data is stored with Supabase in the European Union. We protect it with encryption in transit, row-level security so each customer can only access their own data, and encrypted vault storage for social access tokens. No method of transmission or storage is completely secure, but we take reasonable measures to safeguard your information.
6. Data retention
We keep your information for as long as your account is active. If you delete a brand, a connection, or your account, we delete the associated data (including stored tokens and uploaded media) within 30 days, except where we must retain limited records to meet legal obligations.
7. Your rights
Under UK/EU GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. You can exercise most of these directly in the Service, or by emailing r.sorrell@soraclemedia.com. You also have the right to complain to the UK Information Commissioner’s Office (ICO) or your local data protection authority.
8. Deleting your data
You can delete your data at any time by disconnecting a network, deleting a brand, or deleting your account in the Service. To request deletion of all your data, see our Data Deletion instructions or email r.sorrell@soraclemedia.com.
9. Cookies
We use only essential cookies required to authenticate you and keep you signed in, and to remember your light/dark theme preference. We do not use third-party advertising or tracking cookies.
10. Children
The Service is intended for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date above. Significant changes will be communicated where appropriate.
12. Contact us
Questions about this policy or your data? Contact Soracle Media at r.sorrell@soraclemedia.com, or Soracle Media, 8 Gerard Avenue, Hounslow, TW4 5NB, United Kingdom.
