Privacy Policy — PostLane
PostLane PostLane
The story Pricing Contact
On this page Information we collect How we use it AI features Information we share Google user data Your storage, your masters Cookies and DNT Data retention and deletion Security Updating your information Access, rectification, erasure California residents Nevada residents International users; GDPR Opt-out Children's privacy Business transfers Changes to this policy Dispute resolution Contact us

Privacy Policy

Last updated: 8/11/2026 · Effective: 8/12/2026

PostLane LLC ("PostLane," "we," "us," or "our") operates postlane.studio and the PostLane application (together, the "Site"). "Service" or "Services" means use of the Site, including registering a studio workspace and using PostLane's post-production, production and social operations software. PostLane recognizes and respects the importance of keeping your personal information secure, and we believe it is important for our customers to know and understand how we handle it.

This Privacy Policy (the "Policy") describes, in plain English, how we collect, use, disclose, and retain information when you use our Services. Please read this Policy carefully. By using, accessing, or licensing our Services, you agree to be bound by this Policy and our Terms of Service. If you do not agree with this Policy or our Terms of Service, you must immediately stop using our Services.

One thing worth understanding up front: PostLane is a business tool. Our customer is the studio that opens a workspace, and the studio decides what goes into it. For the content in a studio's workspace (projects, media, comments, crew details), we act as the studio's service provider and process that content on the studio's instructions. If your personal information appears inside a studio's workspace (for example, you are a crew member or a client of a studio that uses PostLane), the studio is the right first stop for requests about that information; we support studios in honoring them, and if you contact us directly we will route your request to the studio and help resolve it.

Information We Collect

Account data. Your name, email address, and profile details (such as title, phone, city/state, pronouns, avatar, and working preferences) when you or your studio create an account.

Crew and production details. Studios use PostLane to staff and run productions, so profiles can include booking and logistics details. Two are worth calling out. First, crew members may choose to add dietary-restriction and allergy information to their own profiles; it is used for shoot-day catering and on-set safety (call sheets), it is visible only within productions that crew member is booked on (not studio-wide, and not to clients), it can be edited or deleted by the crew member at any time, and it is never included in any AI processing. Second, a private-details section (mailing address and emergency contacts) is visible only to a studio's owners, admins, and managers. Where a studio collects them, professional credentials and tax documents are stored for the studio's onboarding and payment records.

Studio content. The work product your studio puts into PostLane: projects and productions, documents (call sheets, shot lists, checklists, SOWs, and contracts), uploaded media and files, comments and review notes (including comments authored by a studio's clients), tasks, bookings, time entries, and invoices. This content belongs to your studio, and we process it only to provide the Services.

Media and transcripts. Review video is streamed through our video infrastructure; master files live in our managed storage or, if your studio connects its own storage, in the studio's storage (see "Your Storage, Your Masters" below). Eligible video is transcribed automatically so it can be searched and captioned; transcripts are stored with your studio's content.

Payment data. Billing is handled by Stripe. Card numbers go directly to Stripe and are never stored on PostLane's servers; we keep invoice and payment-status records (amounts, dates, invoice numbers). Time-entry descriptions and hours can cross into Stripe when they become invoice line items.

Log Data and diagnostics. When the application errors or behaves unexpectedly, we capture error context and a reference ID through our monitoring tools (Sentry and Axiom) so we can diagnose and fix problems. Sentry is configured not to send default personal information, and our structured logs pass through a redaction list (passwords, tokens, authorization headers, cookies, emails) before storage. We also use Sentry session replay for debugging: replay records an anonymized reconstruction of the interface during a session, with text and media masked, for a sample of sessions (currently about 10%, and sessions where an error occurs). Replay is used solely to diagnose problems, not for advertising or profiling. If you have questions or objections about session replay, contact us at info@postlane.studio.

How We Use The Information We Collect

Information that is collected may be used for the following:

To provide, secure, support, and improve the Services;

To process transactions and bill for the Services;

For customer support and to communicate with you about the Services;

To investigate, prevent, or respond to violations of this Policy or our Terms of Service, suspected fraud, security incidents, or potential illegal activity; and

To comply with legal obligations, resolve disputes, and enforce agreements.

We do not sell personal data, we do not use your data for advertising, and we do not use your content to train AI models (see "AI Features" below). We do not use any third-party analytics SDK.

AI Features

AI features are off by default for every studio. They are enabled only when a studio deliberately turns them on after signing PostLane's AI addendum (the product enforces this), and a studio can turn them off at any time. When enabled, here is what they do and who processes what:

Text features (Anthropic). Document analysis and term extraction, change-note drafting, review-comment summaries, and internal digests are processed by Anthropic (Claude). These features present their output for review by studio staff before it is used.

Transcription and captions. Transcription is not processed by Anthropic. Captions are generated in our media infrastructure (Cloudflare), which converts speech to text as part of video processing, and transcription is performed by a dedicated speech-to-text provider. Unlike the review-gated text features above, transcription runs automatically on eligible video, without a human review step, so search and captions work out of the box.

No training. We do not use your content to train or fine-tune AI models, whether ours or anyone else's. AI features send content to our providers for processing only (inference), under agreements that do not permit the provider to train on it.

What never reaches AI. Rates and financial records, crew personal data (including addresses, emergency contacts, and dietary/allergy details), stored credentials, and client contact records are not included in any AI processing.

Information We Share with Others (Service Providers)

We do not sell, rent, trade, or otherwise transfer your personally identifiable information to outside parties. This does not include the service providers who assist us in operating the Services, so long as those parties process data only to provide their function under binding confidentiality and data-protection obligations. Our service providers are: Supabase (database, authentication, and file storage); Netlify (application hosting and content delivery); Cloudflare (video streaming, media file storage, and caption generation, which converts speech to text as part of video processing); Stripe (billing and payment processing); Resend (transactional email: sign-in links, booking and notification emails); Sentry (error monitoring and masked session replay); Axiom (application log management); Upstash (rate limiting and abuse prevention, processing IP addresses and request metadata); and Anthropic (AI processing for text features, described under "AI Features" above).

Some providers only process data when your studio connects or triggers them: Google (Drive archiving and Calendar sync, only if you connect a Google account) and Slack (notifications, only if your studio adds a Slack webhook.

On rare occasions, we may disclose specific information upon governmental request, in response to a court order, or when required by law to do so, and, where legally permissible, we will provide advance notice to the affected studio before doing so.

Google User Data

If you connect a Google account, PostLane accesses only the Google data needed for the feature you enable. For Google Drive, PostLane uses the narrow "drive.file" scope: PostLane can see and manage only files PostLane itself creates in your Drive. The Drive connection is used to archive approved masters to a destination your studio selects through the Google picker: PostLane pushes copies to your Drive; it does not browse, read, or import your existing Drive files. For Google Calendar, PostLane syncs calendar events to keep your production schedule and your calendar aligned.

We use this data solely to provide those features. We do not sell Google user data, we do not use it for advertising, and we do not transfer it to third parties except as necessary to provide the feature you asked for or as required by law. PostLane's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google access at any time from your studio's integration settings (or by revoking PostLane's access at myaccount.google.com/permissions). Disconnecting deletes the stored connection tokens and stops archiving and sync; copies already archived to your Drive are your studio's and remain in your Drive under your control.

Your Storage, Your Masters

Studios can bring their own storage for master files: an S3-compatible bucket a studio controls, plus push-only archiving of approved masters to the studio's own Google Drive. When your masters live in your storage, the bytes are yours: they sit in your account, under your provider agreement, and you can keep or delete them on your terms. To make the Services work, PostLane still holds the connection credential (encrypted as described under "Security"), file metadata, and the working copies the platform generates (review proxies, thumbnails, and transcripts), which live in PostLane-managed infrastructure even when masters are customer-stored. Your studio is responsible for its own storage accounts, including their security, sharing settings, and costs.

Cookies and Do Not Track ("DNT") Settings

"Cookies" are files with a small amount of data, which may include an anonymous unique identifier, sent to your browser from a website and stored on your computer. PostLane uses only essential cookies: the session cookies that keep you signed in. We do not use advertising cookies, third-party analytics cookies, or any analytics SDK, which is why you don't see a cookie banner. You can instruct your browser to refuse cookies, but without the session cookie you will not be able to stay signed in. Our diagnostic tools described above (error monitoring and masked session replay) run as part of operating the Services.

"Do Not Track" or "DNT" is a privacy preference that users can set in certain web browsers. While we are committed to providing clear, transparent, and meaningful choices about the information collected on our Site, we do not currently recognize or respond to browser-initiated DNT signals.

Data Retention and Deletion

Your studio's content stays in your workspace for as long as your account is active, with one deliberate exception to automatic cleanup: deliverable versions formally submitted for client review ("cuts") are kept while in service, even if soft-deleted, so the record of what was reviewed and approved stays intact. Here is how deletion actually works:

Deleting media. Deleted media follows a soft-delete, grace-period, scheduled-destruction cycle: items are recoverable during a 90-day grace window, after which a daily process permanently destroys the streams, the bytes, and the records.

Deleting a studio. Studio deletion is a soft delete with a 30-day grace period, followed by permanent purge processing. Workspace owners also have a hard-delete control for content, with byte purge behind a separate confirmation.

After termination. Studios can export their content (a self-serve export is available, delivered as a time-limited download) for 30 days after termination; PostLane then deletes studio content from PostLane-controlled storage through the machinery above. Copies your studio holds in its own storage (connected buckets and Drive archives) are your studio's, and stay put.

Practical carve-outs. Invoice and payment records are retained where financial record-keeping requires it, and deleted data can persist in encrypted backups for a limited window before those backups age out on our infrastructure providers' cycle.

Security

Data is encrypted in transit (TLS) and at rest. Every studio's data is isolated by row-level security enforced in the database itself (queries are scoped to your studio at the data layer, not just in application code), and we run automated cross-tenant denial tests against that isolation. Stored integration credentials are envelope-encrypted with per-secret keys. Every code change passes security gates before merge (static analysis, secret scanning, dependency audit, and build checks), security headers and input validation are enforced at the application boundary, AI flows carry prompt-injection controls (untrusted content is delimited as data, output is re-validated, and no privileged action happens without a human gate), two-factor authentication is available, and access-lifecycle events are logged.

We are honest about scope: PostLane does not currently hold formal certifications such as SOC 2; we claim only the controls we actually run. And while we strive to use commercially acceptable means to protect your personal information, "perfect security" does not exist on the Internet, and we cannot promise or guarantee its absolute security.

Updating or Reviewing Your Information

If you are a registered user, we provide you with tools and account settings to access or modify the profile information you provided to us and associated with your account, and studios can self-serve a full export of their workspace data for portability.

Rights of Access, Rectification, and Erasure

You can request access to, a copy of, correction of, or deletion of your personal data by emailing info@postlane.studio. We will confirm and complete deletion through the machinery described under "Data Retention and Deletion." If your data lives inside a studio's workspace, we will coordinate with the studio as described at the top of this Policy.

California Residents

We do not sell or share personal information for cross-context behavioral advertising, and we do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to opt out of. California residents may exercise the rights provided by the California Consumer Privacy Act, including access, correction, deletion, portability, and non-discrimination for exercising your rights, by contacting us as provided in the Contact Us section below. We reserve the right to request further information to verify your identity and residency.

Nevada Residents

We do not sell covered information as defined under Nevada law. If you are a Nevada resident and wish to register your preference regarding any future sale, please contact us with the subject line "Nevada Do Not Sell Request," including your name and the email address connected to your account.

International Users; EU General Data Protection Regulation (GDPR)

The Services are provided from the United States. By using the Site, you agree to the transfer of your information to the United States and to processing of your data as described in this Policy. If you are in the European Economic Area or another region with laws governing data collection and use: for account and billing data, PostLane acts as a controller; for content in a studio's workspace, PostLane processes data on the studio's instructions as a processor, and the studio is the controller. Where the GDPR applies, you are entitled to the rights of access, rectification, erasure, restriction of processing, objection to processing, and data portability, under the conditions the GDPR provides. If you would like to exercise any of these rights, please contact us as provided in the Contact Us section below; we may ask you to verify your identity, and where your request concerns a studio's content we will route it to the studio as described above. You also have the right to complain to your local data protection authority.

Opt-Out (Right to Restrict Processing)

You have the right to unsubscribe from any marketing emails from us by using the "unsubscribe" link at the bottom of such emails, and to withdraw any consent you have given to processing by contacting us. Note that you will continue to receive transaction-related emails regarding your account and non-promotional communications regarding the Services, such as updates to our Terms of Service or this Policy.

Protecting Children's Privacy Online

PostLane is a business tool and is not directed to anyone under 16 years of age. We do not knowingly collect personal information from children. If you believe we have received information from an individual under 16, please contact us at the email address listed in the Contact Us section below, and we will take reasonable efforts to remove the information.

Business Transfers

In the event that PostLane is involved in a bankruptcy, merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. The promises in this Privacy Policy will apply to your information as transferred to the new entity.

Changes To This Privacy Policy

This Policy is effective as of the date first set forth above. We may update this Policy from time to time; when we do, we will update the "Last updated" date at the top of this page. If we make material changes, we will notify studio owners by email or an in-app notice before the change takes effect. Your continued use of the Services after a change takes effect constitutes your acceptance of the modified Policy.

Dispute Resolution

Your use of our Services, and any disputes arising from your use, are governed by the dispute resolution provisions of our Terms of Service. Please read the Terms of Service carefully and review them periodically to be informed of the most current revisions.

Your Consent

By continuing to use our Services, you consent to the collection and use of your personal information as detailed in this Policy.

Contact Us

We always welcome your questions and feedback. For anything in this Policy, including questions, access requests, deletion requests, and complaints, please contact us at info@postlane.studio.

PostLane PostLane
The story Pricing Contact Sign in Terms © 2026 PostLane