Is Outpost GDPR compliant?
Is Outpost GDPR compliant?
Outpost supports GDPR compliance with the following features:
- Member data export (right of access)
- Member deletion (right to erasure)
- Cookie-less visitor identification for non-members (CTA tracking uses browser storage, not cookies)
- Data processing agreements available
- EU data residency options (via Mailgun EU region)
Where is member data stored?
Where is member data stored?
Outpost stores member data on its hosted servers in Europe. Contact the Outpost team for information about data location and residency options if you have specific regional requirements.
How do I handle a member's right-to-access request?
How do I handle a member's right-to-access request?
Please contact Outpost to help with this.
How do I delete a member's data?
How do I delete a member's data?
Use the Delete Member button on the member’s detail page in Outpost (Members). It removes the member from Ghost and deletes their Outpost record in one step: you don’t need to delete them in Ghost separately. Cancel any active subscription in Stripe as well. If you need deletion beyond that (for example, purging processing logs), contact Outpost support.
How do I delete all the data Outpost holds for my site?
How do I delete all the data Outpost holds for my site?
The Site owner can request it with the Delete my Outpost account and data button at the bottom of Publication Details. Outpost schedules the deletion for 28 days later and emails everyone with an Outpost login on the site, with reminders 7 days and 1 day before the date. The site keeps working normally in the meantime, and the Site owner can stop the deletion at any point before the date with Keep my site. Requesting deletion doesn’t cancel your Outpost subscription. If you want billing to stop as well, use Cancel Subscription on the same page.When the date arrives, Outpost permanently removes its copy of your member records, subscriptions, email and campaign history, CTAs, offers, templates, integration connections, and Outpost logins. Nothing on your Ghost site is deleted. CSV files created on the Data Export page are handled separately. You can delete a physical address export from that page, and Outpost support can remove any other export files on request. Some billing records may be kept for a limited time where tax and accounting law requires it, and they are not used for anything else. Routine database backups expire on a fixed rotation and are never used to restore a deleted account.
Can I get a Data Processing Agreement (DPA)?
Can I get a Data Processing Agreement (DPA)?
Contact the Outpost team to request a DPA for GDPR compliance documentation.

