Privacy policy
Effective: September 8, 2026 · Contact: privacy@posra.app
Short version: the plugin sends nothing anywhere until you click “Generate my app preview”. When you do, we receive your store's branding and product catalog structure — never customer data. You can delete everything at any time.
Who we are
Posra (“we”) provides the Posra Preview WordPress plugin, the Posra Preview mobile app, the builder dashboard, and an app publishing service, operated at posra.app.
Data from the WordPress plugin
Installing and activating the plugin causes no external communication — no update pings, no telemetry, no remote assets. Data is transmitted to us only when you, the store administrator, click “Generate my app preview”. At that moment the plugin sends:
- Store name, site URL, logo URL and brand color
- Product catalog structure: names, prices, images, categories (read-only)
- Product and category counts, WordPress/WooCommerce versions
Never sent: customer data, orders, emails, passwords, payment details, or REST API keys.
The click also issues a read-only preview token that lets our service read your catalog structure through the plugin's REST endpoint. Tokens are stored hashed, expire after 7 days, and are revocable at any time from the plugin page.
Data from the builder dashboard
If you create an account to design or publish your app, we store your email address, a password hash, your app design configuration, and — if you subscribe — billing status. Store API credentials you connect for a published app are encrypted at rest and never logged.
Data from the preview app
The Posra Preview mobile app fetches your store's preview configuration and catalog from our service. It contains no advertising or analytics SDKs and does not collect personal data from the phone.
How long we keep it, and how to delete it
- Preview data: deleted when you click “Delete preview data & revoke access” in the plugin, or uninstall the plugin. Deactivating revokes the token immediately.
- Account data: deleted when you delete your account from the dashboard, or on request to privacy@posra.app.
- Shopper account data: deleted from inside the app under Account → Settings → Delete account. Step-by-step instructions for every case are on Delete your account and data.
Service providers (subprocessors)
- Railway — hosts our API and database.
- Cloudflare — hosts this website and the dashboard, and serves app configurations (CDN).
- Polar — merchant of record for paid subscriptions. Payment details go directly to Polar; we never receive or store card numbers, only your subscription status.
We do not sell data, share it with advertisers, or use it for any purpose other than providing the preview and publishing service.
Changes
If this policy changes materially, we will note it here with a new effective date. Questions: privacy@posra.app.