Privacy Policy
Last updated: 7 July 2026
1. Who we are
Crystal Spotlight ("we", "us", or "our") operates Crystal Spotlight Social (https://social.cspt.io), an internal social media management platform used to manage artist and client social channels. This Privacy Policy explains how we collect, use, store, and share information when you use Crystal Spotlight Social.
For data protection enquiries, contact rob@crystalspotlight.com.
2. Scope
This policy applies to:
- Authorised administrators and staff who sign in to Crystal Spotlight Social
- Data processed on behalf of artist/client workspaces managed in the platform
- Recipients of shareable post approval preview links (limited data—see Section 9)
Crystal Spotlight Social is not offered to the general public. Public-facing approval preview pages collect only the information described in Section 9.
3. Information we collect
Account and authentication data. When you are invited to Crystal Spotlight Social, we store your user ID, email address, display name, profile avatar (if set), and authentication records in Better Auth on Neon Postgres. Multi-factor authentication factors are managed by Better Auth.
Workspace and operational data. We store workspace names, connected social account metadata (platform, handle, display name, avatar URL, token expiry status), posts (captions, media references, schedules, labels, platform-specific options), publish results, analytics snapshots, inbox events, activity logs, in-app notifications, caption templates, workspace labels, and media library metadata.
OAuth and API credentials. When social accounts are connected, we store encrypted OAuth access tokens, refresh tokens, and encrypted platform application credentials (API client IDs, secrets, and webhook verification tokens). These are encrypted at rest using AES-256-GCM before storage in our database.
Media files. Images and videos uploaded through the composer or media library are stored in Cloudflare R2 object storage. Public URLs may be used when publishing to social platforms or displaying previews.
Known accounts. We maintain an app-wide database of display names and per-platform handles for mention autocomplete. Entries may be added manually, imported via CSV, saved when you select a SocialCrawl suggestion, or derived from published mention usage.
Usage and technical data. Standard server and hosting logs may include IP addresses, request timestamps, and error information via Vercel. We do not use third-party advertising trackers within Crystal Spotlight Social.
4. How we use information
We use collected information to:
- Authenticate users and enforce access controls
- Schedule, validate, and publish posts to connected social platforms
- Retrieve and display analytics from platform APIs
- Receive and display inbox events via platform webhooks
- Store and serve media assets
- Provide mention autocomplete (locally and via SocialCrawl when needed)
- Generate and validate client approval preview links
- Send transactional email alerts for publish failures and token expiry warnings via Postmark
- Maintain activity logs and in-app notifications for your team
- Operate scheduled background jobs (publishing, token refresh, analytics sync)
We process personal data on the basis of legitimate interests in operating our agency services, contractual necessity where we manage client social accounts, and consent where required (for example, where platform OAuth permissions are granted by an authorised user).
5. Third-party platform APIs
Crystal Spotlight Social exchanges data with third-party social platforms when you connect accounts and use publishing, analytics, and inbox features. Data sent to and received from these platforms is governed by their respective privacy policies and API terms.
Meta (Instagram, Facebook, Threads). We use the Meta Graph API for publishing, insights, account discovery during OAuth, and webhook-driven inbox events. Meta may process data according to Meta's Privacy Policy.
X (Twitter). We use the X API v2 for posting, limited analytics, and inbox-related events where available. See X Privacy Policy.
LinkedIn. We use LinkedIn APIs for personal and company page publishing and analytics. See LinkedIn Privacy Policy.
TikTok. Where approved, we use TikTok developer APIs for content posting. See TikTok Privacy Policy.
When you connect an account, the platform provides tokens and account identifiers to Crystal Spotlight Social. We do not sell this data. We use it only to provide the features you request.
6. Other service providers (sub-processors)
We use the following categories of infrastructure and service providers:
- Neon — managed PostgreSQL database hosting
- Cloudflare — media object storage, public asset delivery, and Durable Object realtime connections
- Better Auth — self-hosted authentication within our application and Neon database
- Vercel — application hosting, serverless functions, and scheduled cron jobs
- Postmark — transactional email delivery, including account setup, publish failure alerts, and OAuth token expiry warnings
- SocialCrawl — optional mention/user search API for composer autocomplete when local data is insufficient
Each provider processes data only as needed to deliver their service to us. We select providers with appropriate security practices and contractual safeguards where applicable.
7. Webhooks and inbox data
Connected platforms may send webhook events to Crystal Spotlight Social (for example, new comments, mentions, or direct messages). Incoming requests are verified using platform-specific signature validation (such as Meta's X-Hub-Signature-256 HMAC, or equivalent mechanisms for other platforms where implemented).
Normalised inbox events are stored in our database and associated with the relevant workspace. This may include author handles, display names, avatars, message content, and platform event identifiers.
8. Data retention and security
We retain data for as long as needed to operate Crystal Spotlight Social, fulfil agency contracts, and comply with legal obligations. OAuth tokens are refreshed or invalidated according to platform rules. Approval link tokens expire after fourteen (14) days.
Security measures include encrypted storage of OAuth tokens and API secrets, authenticated access only, multi-factor authentication support, cron route protection via shared secrets, webhook signature verification, and HTTPS for data in transit.
No system is completely secure. Report suspected security issues to rob@crystalspotlight.com.
9. Approval preview links (public visitors)
Shareable approval links allow individuals to view a post preview without an account. Visitors can review the preview and optionally edit the caption. When confirming approval, they enter their name. That name is stored on the post as the approver, recorded in our activity log, and may appear in in-app notifications to your team (for example, "Jane Smith approved this post").
Opening a preview link does not require a name. No advertising cookies are set for this purpose.
10. International transfers
Our service providers may process data in the United Kingdom, European Economic Area, United States, or other countries. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or provider certifications where applicable.
11. Your rights
Depending on applicable law (including UK GDPR), you may have rights to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability. You may also lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
To exercise rights relating to your administrator account, contact rob@crystalspotlight.com. Requests relating to end-audience data on social platforms may need to be directed to the relevant platform or handled through our client relationship.
12. Children
Crystal Spotlight Social is intended for professional use by adults. It is not directed at children under 16, and we do not knowingly collect their data through this platform.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in the service or legal requirements. The "Last updated" date at the top of this page will change when we do. Material changes may also be communicated to administrators through the platform or email where appropriate.
14. Contact
Crystal Spotlight
Email: rob@crystalspotlight.com
Web: https://social.cspt.io
