Skip to main content
Outpost supports GDPR compliance with the following features:
  • Member data export (right of access)
  • Member deletion (right to erasure)
  • Cookie-less visitor identification for non-members (CTA tracking uses browser storage, not cookies)
  • Data processing agreements available
  • EU data residency options (via Mailgun EU region)
Compliance is a shared responsibility: you control your member data and must ensure your own privacy policy and consent practices meet your legal obligations.
Outpost stores member data on its hosted servers in Europe. Contact the Outpost team for information about data location and residency options if you have specific regional requirements.
Please contact Outpost to help with this.
Use the Delete Member button on the member’s detail page in Outpost (Members). It removes the member from Ghost and deletes their Outpost record in one step: you don’t need to delete them in Ghost separately. Cancel any active subscription in Stripe as well. If you need deletion beyond that (for example, purging processing logs), contact Outpost support.
The Site owner can request it with the Delete my Outpost account and data button at the bottom of Publication Details. Outpost schedules the deletion for 28 days later and emails everyone with an Outpost login on the site, with reminders 7 days and 1 day before the date. The site keeps working normally in the meantime, and the Site owner can stop the deletion at any point before the date with Keep my site. Requesting deletion doesn’t cancel your Outpost subscription. If you want billing to stop as well, use Cancel Subscription on the same page.When the date arrives, Outpost permanently removes its copy of your member records, subscriptions, email and campaign history, CTAs, offers, templates, integration connections, and Outpost logins. Nothing on your Ghost site is deleted. CSV files created on the Data Export page are handled separately. You can delete a physical address export from that page, and Outpost support can remove any other export files on request. Some billing records may be kept for a limited time where tax and accounting law requires it, and they are not used for anything else. Routine database backups expire on a fixed rotation and are never used to restore a deleted account.
When an Outpost subscription ends, the site becomes inactive and Outpost queues its data for permanent removal. No date is set, so we cannot tell you when it will happen. Everyone with an Outpost login on the site is emailed, and a notice appears at the top of Publication Details.Nothing is removed while that notice is showing. The Site owner can take the site off the removal list at any time with Keep my site on that page. What gets removed, and the billing records Outpost has to keep, are the same as for a deletion you request yourself. Email support@outpost.pub if you want help starting the subscription again, or if you would rather we removed your data sooner.
The Outpost script on your site uses browser storage rather than cookies. It recognizes a repeat visitor, remembers that someone dismissed a call to action, and records the traffic source a visit came from.Stripe is the part worth knowing about before a consent scan surprises you. Any page that can take a payment loads Stripe’s script, and Stripe sets two cookies of its own: __stripe_mid, which lasts a year, and __stripe_sid, which lasts for the session. That covers checkout, the tip jar, and the gift and group subscription boxes. Those boxes run inside a frame served by Outpost, so when you embed one on your own site, a consent scanner reading your pages will report Stripe’s cookies there.Pages that cannot take a payment, such as sign in and password reset, do not load Stripe’s script.If you connect Angler AI, Outpost loads Angler AI’s own tracking script on your site unless you turn off Load the Angler tracking script on your site in the integration settings. A consent scan will report whatever that script sets.Outpost sets no advertising or third-party tracking cookies.
Outpost shares member data only with Mailgun and then any integrations you explicitly configure (e.g., HubSpot, Salesforce, Transistor). Outpost does not sell member data or share it with advertisers.Review each integration’s privacy policy: when you connect HubSpot, for example, member data flows to HubSpot’s servers under their privacy policy.
Contact the Outpost team to request a DPA for GDPR compliance documentation.