Privacy Policy
Last updated: 1 August 2026
This Privacy Policy describes how Peham Ltd (“Peham,” “we,” “us,” or “our”) collects, uses, stores, and shares information in connection with Peham Social(the “Service”), available at https://socials.manage.peham.agency. Peham Social is a multi-tenant platform for scheduling, generating, approving, and publishing social and local business content across connected channels on behalf of agencies and brands.
By accessing or using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service. Capitalized terms not defined here have the meanings in our Terms & Conditions.
1. Who this policy covers
This policy applies to:
- Workspace users — people who sign in to a tenant workspace (owners, managers, staff, viewers).
- Platform administrators — Peham staff who operate the multi-tenant control plane.
- External participants — people who interact with limited shared surfaces (for example, approval links or shared calendars) without a full account.
If your organization (a “Tenant”) provides you access, that Tenant is typically the controller of workspace data for its brands and clients. Peham processes that data to provide the Service.
2. Information we collect
2.1 Account and workspace information
- Name, email address, password (stored hashed), and role.
- Tenant and project details (names, slugs, timezones, contact emails, limits, and configuration).
- Optional two-factor authentication (TOTP) secrets and verification status.
- Invite tokens, password-reset tokens, and related timestamps.
2.2 Content and publishing data
- Draft and published post copy, captions, hashtags, links, scheduled times, approval status, and publish results.
- Media files you upload or import (images, video, and related metadata).
- Templates, calendars, strategy/growth artifacts, reports, and similar workspace content.
- Activity logs related to create, edit, approve, schedule, and publish actions.
2.3 Connected channel and Google account data
When you connect a third-party channel, we receive credentials and profile/page data needed to manage and publish content. Depending on the integration, this may include:
- OAuth access and refresh tokens (stored encrypted), token expiry, and connection status.
- Account, page, profile, location, or site identifiers and display names.
- Permissions/scopes you grant, and basic connection diagnostics (errors, expiry warnings).
- Post identifiers and delivery status returned by the provider after publish attempts.
- Analytics or insights the provider exposes and that you choose to sync (for example, impressions or engagement metrics), where available.
Supported or planned channel families include Meta (Facebook / Instagram), X, LinkedIn (profiles and pages), TikTok, Pinterest, WordPress, Canva (media import), and Google Business Profile (Google My Business) for local business locations and posts.
For Google integrations specifically, we may access Google user data you authorize — such as Google account identity needed for OAuth, Business Profile location information, and posting-related data — solely to provide the features you request in the Service.
2.4 Technical and usage data
- Session cookies and similar authentication identifiers required to keep you signed in.
- IP address, browser/user-agent, approximate request timing, and server logs used for security, debugging, and reliability.
- Product usage events needed to operate quotas, health checks, and support.
2.5 Communications
- Transactional emails (invites, password resets, approval notices, publish failures, connection expiry alerts, and similar operational messages).
- Support correspondence if you contact us about the Service.
3. How we use information
We use information to:
- Provide, maintain, secure, and improve the Service (authentication, scheduling, publishing, approvals, media storage, analytics sync, and AI-assisted drafting where enabled).
- Connect to and operate third-party APIs on your behalf after you authorize those connections.
- Send operational notifications and respond to support requests.
- Enforce our Terms, prevent abuse, investigate incidents, and comply with law.
- Monitor reliability, diagnose failures, and maintain multi-tenant isolation.
We do not sell personal information. We do not use Google user data for advertising, and we do not sell Google user data to third parties.
4. Google API Services and Limited Use
Peham Social's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, when you connect Google Business Profile:
- We access Google user data only to provide and improve user-facing features that are prominent in the Service (for example, connecting locations and creating or scheduling Business Profile posts).
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless you give affirmative consent for specific support cases, it is necessary for security/compliance investigations, or it is required by law — and then only to the minimum extent needed.
- We do not transfer Google user data to third parties except as needed to provide or improve user-facing features (for example, infrastructure processors), for security, or as required by law — and not for other parties' advertising.
You may revoke Peham Social's access to your Google Account at any time via Google Account permissions and by disconnecting the channel inside the Service.
5. How we share information
We may share information with:
- Third-party platforms you connect — to authenticate, publish, sync insights, or import media as you direct (Meta, X, LinkedIn, TikTok, Pinterest, WordPress, Canva, Google, and others you authorize).
- Service providers / processors — hosting, database, object storage, email delivery, AI providers, and observability tools that process data on our instructions.
- Your Tenant administrators — who manage users, projects, and content within your workspace.
- Professional advisors or authorities — when reasonably necessary for legal compliance, dispute resolution, or protection of rights, safety, and security.
- Successors — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and continuity of privacy commitments.
Tenant content remains isolated by design from other Tenants, except where you intentionally share links (approvals, calendar shares) or Peham platform operators access data under strict operational need.
6. Cookies and similar technologies
We use essential cookies and similar storage primarily for authentication and session integrity. We do not operate a third-party advertising cookie stack on the Service. Disabling essential cookies will prevent sign-in and core use of the product.
7. Data retention
We retain information for as long as needed to provide the Service and meet legitimate operational, security, and legal requirements. Typical practices include:
- Account and workspace data while the Tenant/user remains active, and for a reasonable period after deactivation for recovery and audit.
- OAuth tokens while a connection remains active; tokens are invalidated or deleted when you disconnect a channel or when credentials expire and cannot be refreshed.
- Media and post history according to Tenant configuration and our backup/operational retention windows.
- Server logs for a limited period for security and debugging.
Tenant owners may request deletion of Tenant data subject to technical feasibility, legal holds, and residual backup cycles.
8. Security
We implement administrative, technical, and organizational measures appropriate to the nature of the Service, including encrypted transport (HTTPS), hashed passwords, encrypted storage of channel secrets where applicable, role-based access within Tenants, and multi-tenant data separation. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
9. International processing
Peham Ltd operates the Service for users who may be located in different countries. Data may be processed and stored in the regions where our hosting and subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers.
10. Your choices and rights
Depending on your location and role, you may be able to:
- Access or update profile information in your account settings.
- Disconnect third-party channels and revoke provider OAuth grants.
- Request deletion or export via your Tenant administrator or by contacting us.
- Opt out of non-essential communications (transactional mail required for the Service will continue).
If you are an end user of a Tenant workspace, please contact your Tenant administrator first; they control much of the workspace data. You may also email us at social@peham.agency.
11. Children
The Service is intended for business use by adults. It is not directed to children under 16, and we do not knowingly collect personal information from children.
12. Third-party services
Connected platforms and subprocessors have their own privacy policies. Your use of those services is governed by their terms and policies. We encourage you to review them before connecting accounts.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated through the Service or by email where appropriate. Continued use after the effective date constitutes acceptance of the updated policy.
14. Contact us
For privacy questions, data requests, or concerns about this policy:
- Email: social@peham.agency
- Service: https://socials.manage.peham.agency
- Controller / operator: Peham Ltd
