Legal
Privacy Policy
This policy explains what personal data Herd CMS collects, why we collect it, who else touches it, and what you can ask us to do about it. We collect only what the product needs to work.
Last updated 27 July 2026
Who we are
Herd CMS is operated by Herd LLC, a Delaware limited liability company.
| Legal entity | Herd LLC, a Delaware limited liability company |
| Address | TODO — registered business address, United States |
| Contact | info@getherd.io |
Herd LLC is the controller of the account data described below. Where we publish content on behalf of a client organisation, that client is the controller of the content and we act as their processor — the terms of that arrangement are in our Data Processing Addendum. Under US state privacy laws the equivalent terms are business and service provider.
What this policy covers
This policy covers the Herd CMS application and its website. It does not cover LinkedIn, or any other third-party service you reach from within the product — those run under their own privacy policies.
What we collect, and why
| Data | What it is, and why we hold it |
|---|---|
| Account details | Your name, email address and a hashed password. Used to sign you in and to show who created or was assigned a post. |
| Organisation membership | Which brands you belong to and your role. Used to decide what you can see and do. |
| LinkedIn connection | Your LinkedIn member ID, display name and profile picture URL, plus access and refresh tokens. Used to publish the posts you are assigned. |
| Content | Posts, captions, schedules and any images or video you upload. This may contain personal data if you choose to put it there. |
| Activity log | A record of actions such as scheduling, publishing and connecting an account, with a timestamp and who did it. Used for troubleshooting and accountability. |
| Technical log data | Our hosting and database providers record standard server data — IP address, browser user agent, request time and outcome — as part of serving and securing the application. Used to keep the service running and to investigate abuse and errors. |
| Messages to us | If you email us for support, we keep the message and our reply so we can answer you and refer back to it. |
We do not use analytics, advertising or third-party tracking. The only cookie we set is the one that keeps you signed in — see the Cookie Notice.
We do not collect sensitive personal information, we do not knowingly collect data about children, and we do not infer characteristics about you.
How we use it
- To create and run your account, and to sign you in.
- To provide the product: drafting, scheduling, assigning and publishing posts.
- To publish to LinkedIn on your instruction, using the connection you grant.
- To keep the service secure and available, and to investigate faults and abuse.
- To keep an activity record so actions inside an organisation are accountable.
- To answer you when you contact us.
- To comply with the law and to establish or defend legal claims.
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not use your content to train machine learning models.
Legal bases (where the GDPR applies)
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these grounds:
| Basis | What we use it for |
|---|---|
| Performance of a contract | Running your account, showing you your organisation’s content, scheduling and publishing posts. |
| Consent | Connecting your LinkedIn account. You give it through LinkedIn’s own consent screen and can withdraw it at any time. |
| Legitimate interests | Keeping the service secure and available, investigating faults and abuse, and keeping an activity log so actions are accountable. We have weighed these against your interests and kept the data to the minimum that serves the purpose. |
| Legal obligation | Responding to lawful requests and meeting accounting and record-keeping duties. |
Providing account data is necessary to use Herd CMS — without it we cannot give you an account. Connecting LinkedIn is optional; if you do not, you simply cannot publish through us.
Your LinkedIn connection
Connecting LinkedIn is optional and always initiated by you. You authorise through LinkedIn’s own consent screen, and we request only these permissions:
| Scope | What it lets us do |
|---|---|
openid | Confirms which LinkedIn account is connected. |
profile | Your name and profile picture, so the connected account is recognisable in Herd CMS. |
email | The email on your LinkedIn account, used to match the connection to your Herd CMS user. |
w_member_social | Publishes the posts you have been assigned. Nothing else. |
These permissions do not let us read your LinkedIn feed, your connections, your messages, or anyone else’s profile. We can publish, and nothing more.
You can revoke access at any time from LinkedIn under Settings → Data privacy → Permitted services, or by disconnecting inside Herd CMS. Revoking stops all publishing immediately. Disconnecting deletes the stored tokens. Anything already published stays on LinkedIn until you delete it there — revoking does not retract past posts.
Once a post is published, LinkedIn holds it under its own privacy policy and as its own controller. We have no control over what LinkedIn does with it.
Where your data is stored
We use the following processors. Each holds data only to run the service, under their own data processing terms.
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Application hosting, content delivery, and storage of uploaded media | United States and European Union |
| Neon Inc. | Managed database hosting | United States and European Union |
| LinkedIn Corporation / LinkedIn Ireland Unlimited Company | The platform posts are published to, at your instruction. LinkedIn decides for itself how it handles what it receives, so it is an independent controller rather than our processor. | Global |
The current list, and how we tell you when it changes, is at Sub-processors. We may also disclose data to professional advisers, or to an authority or court where the law requires it, and to a buyer or successor if the business is sold or reorganised — in which case this policy continues to apply until you are told otherwise.
International transfers
We are based in the United States and your data is processed primarily there. If you are in the European Economic Area, the United Kingdom or Switzerland, that means your data is transferred out of your region. Where that happens we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies, together with any supplementary measures the transfer requires. You can ask us for details of the safeguards used for a particular provider at info@getherd.io.
How we protect it
- LinkedIn access tokens are encrypted at rest with AES-256-GCM. They are never displayed after connecting and never sent to your browser.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Access is scoped per organisation. Members of one organisation cannot see another’s content, media or connections.
- All traffic is served over HTTPS.
- Administrative access to production systems is limited to the people who need it to run the service, and every such person is bound by confidentiality.
No system is perfectly secure. If a breach affects your personal data we will notify you, and any regulator that must be told, without undue delay and as the applicable law requires.
How long we keep it
| Data | Kept for |
|---|---|
| Account and content data | As long as the account or client relationship is active, then deleted within 30 days of it ending — see below. |
| LinkedIn tokens | Until you disconnect, you are removed from the organisation, or the token expires. Disconnecting deletes them. |
| Activity log | 24 months from the date of the action, then deleted. |
| Technical log data | As long as our hosting and database providers retain it under their own terms, typically a short rolling window. |
| Support messages | 24 months from the last message in the thread. |
After an account or client relationship ends you have 30 days to export your content. After that we delete it. We may keep records for longer where the law requires it, or where we need them to establish or defend a legal claim — and only for that purpose.
Your rights
Wherever you are, you may ask us to:
- Give you access to the personal data we hold about you, and a copy of it.
- Correct data that is wrong or incomplete.
- Delete your data, where we have no overriding reason to keep it.
- Restrict how we process it while a dispute about it is resolved.
- Port it — receive it in a structured, machine-readable format, or have it sent to another provider where technically feasible.
- Object to processing we base on legitimate interests.
You may also withdraw consent to the LinkedIn connection at any time, without affecting anything published beforehand or the lawfulness of processing before you withdrew.
To exercise any of these, email info@getherd.io. We respond within 30 days, or sooner where the law requires it. If a request is complex we may need a further 30 days, and we will tell you before the first 30 are up. We may ask you to confirm your identity before we act. Exercising these rights is free; we only charge where a request is manifestly unfounded or excessive, and we tell you first. We will not discriminate against you for exercising them.
If the data is content held on behalf of a client organisation, we act on that client’s instructions — we will pass your request to them and help them answer it.
If you are in the United States
Residents of California and of other states with comprehensive privacy laws have the rights above, and in addition the right to opt out of the sale or sharing of personal information and of profiling, and the right to limit the use of sensitive personal information. None of those apply to us in practice: we do not sell or share personal information, we do not profile you, and we do not collect sensitive personal information. We have not sold or shared personal information in the preceding twelve months.
You may use an authorised agent to make a request; we will ask for proof of their authority. If we decline a request and you are in a state with an appeal right, you may appeal by replying to our decision, and we will respond in writing. You may also contact your state Attorney General.
If you are in the EEA, the UK or Switzerland
You have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office. We would appreciate the chance to address your concern first, at info@getherd.io.
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you.
Children
Herd CMS is a business tool. It is not directed to children, and it is not intended for anyone under 18. We do not knowingly collect data from children under 13. If you believe a child has given us personal data, email info@getherd.io and we will delete it.
Changes
If we change how we handle personal data we will update this page and its date. Material changes will be communicated to account holders directly, before they take effect where we reasonably can.
Contact
For anything in this policy, write to info@getherd.io or to Herd LLC at TODO — registered business address, United States.