Legal
Privacy policy
This policy explains how Greenlit collects, uses, stores, and shares personal information when you use our content approval and publishing platform.
Last updated: 24 June 2026
1. Introduction
Greenlit (“Greenlit”, “we”, “us”, or “our”) is operated by Tell It All Communications (Pty) Ltd, based in South Africa. We provide a workspace platform that helps marketing agencies and their clients draft, review, approve, and publish social media content—primarily on LinkedIn, Facebook, Instagram, and TikTok.
We respect your privacy and process personal information in accordance with the Protection of Personal Information Act, 2013 (“POPIA”) and, where applicable, the General Data Protection Regulation (“GDPR”) and UK GDPR.
This policy applies to visitors of our website, registered workspace users, and individuals who interact with content through review links we send on behalf of an agency workspace.
2. Data controller and contact
For the purposes of POPIA and the GDPR, Tell It All Communications (Pty) Ltd is the responsible party (data controller) for personal information processed through Greenlit, except where an agency workspace processes client content on its own instructions—in which case the agency may act as an independent controller for that content and we act as a processor.
- Privacy enquiries: legal@tellitall.co.za
- POPIA Information Officer: legal@tellitall.co.za
3. Personal information we collect
We collect only the information needed to operate Greenlit. Depending on how you use the service, this may include:
Account and identity data
- Email address and password (stored and authenticated by Supabase Auth)
- Name or display name associated with your account
- Organisation membership, role (administrator, agency, or client), and workspace identifiers
- Denormalised email and name snapshots stored for workspace roster display
Content and workflow data
- Post drafts, captions, feedback, approval decisions, and revision history
- Campaign and organisation names
- Media files you upload for posts (stored in Supabase Storage)
- Scheduling metadata, publish status, platform post identifiers, and error messages
- Audit events relating to post workflow (created, submitted, approved, declined, published, and similar)
Social platform connection data
If you choose the fully managed posting model and connect a social account, we store OAuth access tokens (and refresh tokens where issued) encrypted at rest using AES-256-GCM. We may also store platform-specific identifiers such as LinkedIn member IDs, Facebook Page IDs, Instagram Business account IDs, TikTok open IDs, connected page names, granted OAuth scopes, token expiry dates, and integration health status.
We never receive or store your LinkedIn, Meta, or TikTok passwords. Authorisation always occurs on the platform's own login page.
Review link data
When an agency generates a time-limited review link, we store a cryptographic hash of the link token (not the raw token), an expiry timestamp, and optional usage metadata. Anyone with the link can view the associated draft content until the link expires.
Engagement metrics
For published posts, we may store aggregated engagement metrics (such as impressions, likes, comments, and shares) retrieved from connected platforms, along with raw API responses where needed for troubleshooting.
Technical and usage data
- Session and authentication cookies managed by Supabase
- Theme preference cookie
- Temporary OAuth state cookies during social account connection flows
- Server logs, IP addresses, browser type, and request metadata generated by our hosting provider
- Notification deduplication keys to prevent duplicate review emails
Workspace OAuth configuration
Organisation administrators may store platform OAuth application credentials (client IDs, encrypted client secrets, redirect URIs, and API version settings) so their workspace can connect client accounts. These credentials are controlled by the workspace administrator.
4. How and why we use personal information
We use personal information for the following purposes:
- Creating and managing user accounts and workspace memberships
- Operating the content drafting, review, approval, and publishing workflow
- Sending transactional notifications (for example, when a post awaits your review)
- Connecting and maintaining social platform integrations you authorise
- Publishing approved content on your behalf when you use the fully managed model
- Generating self-post guidance links when you use the self-post model
- Displaying post performance metrics after publication
- Securing the service, preventing abuse, and troubleshooting errors
- Complying with legal obligations
5. Legal bases for processing
Under POPIA, we process personal information where a lawful condition applies, including processing that is necessary to perform a contract, required by law, protects a legitimate interest (balanced against your rights), or based on your consent where consent is required.
Under the GDPR, we rely on the following legal bases (Article 6):
- Contract (Art. 6(1)(b)): to provide the service you or your organisation signed up for, including account management, content workflows, and publishing you approve
- Legitimate interests (Art. 6(1)(f)): to secure our platform, prevent fraud, maintain service reliability, and improve functionality—provided those interests are not overridden by your rights
- Consent (Art. 6(1)(a)): where you connect a social account via OAuth or opt in to optional communications; you may withdraw consent for OAuth by disconnecting the integration or revoking access on the platform
- Legal obligation (Art. 6(1)(c)): where we must retain or disclose information to comply with applicable law
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
6. Sharing and third parties
We do not sell personal information. We share information only as needed to operate Greenlit:
- Within your workspace: agency members and assigned clients can see posts, approvals, and roster information relevant to their role
- Social platforms: when you approve managed publishing, post content and media are transmitted to the platform you selected (LinkedIn, Meta, or TikTok) using your authorised connection
- Service providers: we use subprocessors listed below under contractual safeguards
- Legal requirements: where required by court order, regulator, or applicable law
Subprocessors
- Supabase — Authentication, PostgreSQL database hosting, and media file storage. Typical processing location: United States and/or European Union (region-dependent).
- Vercel — Application hosting and content delivery. Typical processing location: United States and global edge network.
- Resend — Transactional email delivery (when configured). Typical processing location: United States.
- LinkedIn — OAuth authorisation and managed publishing (when you connect an account). Typical processing location: United States and global.
- Meta (Facebook / Instagram) — OAuth authorisation and managed publishing (when you connect an account). Typical processing location: United States and global.
- TikTok — OAuth authorisation and managed publishing (when you connect an account). Typical processing location: United States and global.
Each social platform processes data under its own privacy policy when you connect an account or publish content. You should review the relevant platform policy before connecting.
7. International transfers
Tell It All Communications (Pty) Ltd is established in South Africa. Our infrastructure providers may process personal information in countries outside South Africa and, for EEA/UK users, outside the EEA/UK—including the United States.
Where POPIA applies, we take reasonably practicable steps to ensure that foreign recipients protect personal information to a standard comparable to POPIA, including contractual protections and provider security commitments.
Where the GDPR applies, we implement appropriate safeguards for transfers—such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms offered by our providers—unless a specific derogation applies.
8. Retention
We retain personal information only for as long as necessary for the purposes described in this policy, unless a longer period is required by law.
- Account data: retained while your account is active and for a reasonable period thereafter to resolve disputes and meet legal obligations
- Post and campaign data: retained while the workspace exists and as needed for audit trails; archived campaigns may be retained according to workspace policy
- OAuth tokens: retained while a connection remains active; deleted or invalidated when you disconnect or revoke access
- Review links: expire automatically; associated token hashes may be retained briefly for security logging
- Server logs: typically retained for a limited rolling period
Workspace administrators may request deletion of organisation data subject to contractual and legal constraints.
9. Security
We implement technical and organisational measures appropriate to the risk, including encrypted storage of OAuth tokens and platform secrets, role-based workspace access, hashed review-link tokens, HTTPS transport, and access controls on database and storage infrastructure.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at legal@tellitall.co.za.
10. Cookies and similar technologies
We use a limited set of cookies:
- Authentication cookies (essential): maintain your signed-in session via Supabase
- Theme preference cookie (functional): remembers light or dark mode
- OAuth state cookies (essential, temporary): protect social connection flows against cross-site request forgery; deleted after authorisation completes
We do not use advertising or third-party tracking cookies on Greenlit. You can control cookies through your browser settings, but disabling essential cookies may prevent sign-in or integrations from working.
11. Your rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Access to personal information we hold about you
- Correction of inaccurate or incomplete information
- Deletion, subject to legal and contractual exceptions
- Restriction or objection to certain processing
- Data portability (GDPR), where processing is based on consent or contract and carried out by automated means
- Withdrawal of consent where processing is consent-based
- Lodging a complaint with a supervisory authority
Under POPIA, you may also request details of third parties who have received your information. To exercise your rights, email legal@tellitall.co.za. We may need to verify your identity before responding. We aim to respond within one month (GDPR) or a reasonable period under POPIA.
If you are a client user managed by an agency workspace, your agency may also hold information about you. Contact them directly where they act as an independent controller.
12. Complaints and supervisory authorities
If you are in South Africa, you may contact the Information Regulator (South Africa) at inforegulator.org.za.
If you are in the EEA or UK, you may lodge a complaint with your local data protection authority. We encourage you to contact us first so we can try to resolve your concern.
13. Children
Greenlit is a business service not directed at children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with an updated “Last updated” date. Continued use of Greenlit after changes take effect constitutes acceptance of the revised policy where permitted by law.
15. Contact
Questions about this privacy policy or our processing practices may be sent to legal@tellitall.co.za.