Privacy policy
Last updated: June 30, 2026
This policy describes how Posh (“we,” “us,” or “our”) handles information when you use the Posh Android inventory and point-of-sale app, this marketing website, and—when enabled—the optional online storefront for your store.
Posh is built for small retailers. Inventory and sales run offline-first on your device. Cloud sync is required during first-launch setup and keeps a backup of your store data so you can use multiple devices and recover from a lost phone or tablet.
Information we collect
The data Posh stores depends on how you use the app. We do not sell your information to third parties.
Store and team setup
- Store name, owner name, and owner contact number (during setup)
- Cashier display names and role (admin or cashier)
- Hashed 4-digit PINs (PINs are stored as one-way hashes, not as plain text)
Business and sales data
- Product catalog, categories, variants, price breaks, and inventory levels
- Stock movement history on your device (operational changes such as sales, receiving, and cycle counts—local only, not synced to the cloud today)
- Sales, line items, payment method, discounts, taxes, and receipts
- Optional customer records (name, phone, email, notes, trade discount)
- Stock receipts, supply orders, and related operational records
- Store settings (business type, printer pairing, catalog layout, and similar preferences)
Online storefront orders
If you subscribe to the storefront add-on, shoppers can place orders on the web. Those orders may include a name, phone number, delivery or pickup details, and order notes. That information is stored with the sale in your store data and appears in the Orders tab of the app.
Subscriptions
POS and storefront plans are billed through Google Play. Purchase and subscription status are verified server-side so we can enable cloud sync and storefront features. We do not receive your full payment card details—Google processes payments.
Device and technical data
- A device-specific identifier used for cloud authentication and sync when cloud sync is active
- Bluetooth printer name and MAC address if you pair a thermal receipt printer
- Product images you upload, cached locally and stored in cloud storage when sync is on
This website
This marketing site does not use sign-in or checkout. We do not run advertising trackers on this page. Standard web server or hosting logs (such as IP address and browser type) may be collected by our hosting provider as part of operating the site.
Where data is stored
On your Android device
Posh keeps a local SQLite database on your device with sales, products, customers, settings, and related records. The register reads and writes this local copy first, including when you are offline. Sensitive sync credentials are stored in the device secure keystore.
In the cloud (when sync is enabled)
During first-launch setup you connect cloud sync (internet is required for that step). After that, copies of your store data are transmitted to and stored in a Supabase project operated for Posh. Data is encrypted in transit (HTTPS/TLS). You can use multiple devices on the same store; each device authenticates and syncs against your tenant.
We operate the cloud infrastructure that backs up and syncs merchant data. We use it only to provide the service (sync, recovery, multi-device teams, web orders, and subscription entitlements)—not to sell data to advertisers or data brokers.
How we use information
- Run inventory, optional POS, catalog, reports, and orders workflows you expect from the app
- Back up and sync data across your devices
- Recover a store after reinstall or device loss (with a recovery code)
- Deliver web orders to your Orders tab when the storefront add-on is active
- Verify Google Play subscriptions and apply plan entitlements
- Respond to support requests you send us
- Improve reliability and security of the service
Posh does not currently include third-party analytics or crash-reporting SDKs in the app. If that changes, we will update this policy before collecting analytics data.
App permissions
- Camera — scan product barcodes at the counter or in the product form
- Bluetooth — connect to a paired thermal receipt printer
- Location — on some Android versions, required only for Bluetooth device discovery; not used to track customer or staff location
- Internet — cloud sync, subscription verification, web orders, and product image upload when those features are in use
Third-party services
- Supabase — database, authentication, file storage, and server functions for cloud sync and billing verification
- Google Play — app distribution and in-app subscription billing
- Hosting providers — this website and the storefront are served over HTTPS by our hosting partners
These providers process data on our behalf to deliver the service. Their own privacy policies govern how they handle infrastructure-level data.
Data retention
Local data remains on your device until you clear app data, uninstall the app, or use in-app reset options in Settings. Cloud data is retained while your store is active and cloud sync is enabled, so your team can sync and recover.
If you cancel subscriptions, cloud-backed features may be limited according to your plan. You can delete business data from within the app (Settings) or contact us to request permanent deletion of your store’s cloud records.
Security
We use industry-standard measures including encrypted transport, hashed PINs, and secure credential storage on device. No system is perfectly secure; you are responsible for choosing a strong admin PIN, protecting recovery and invite codes, and controlling who has access to devices signed in to your store.
Children
Posh is a business tool for merchants and is not directed at children under 13 (or the applicable age in your country). We do not knowingly collect personal information from children.
Your choices and rights
- Access and export — view sales and reports in the app; export data from Reports where available
- Correction — edit products, customers, and settings directly in the app
- Deletion — use Settings to delete local and/or cloud business data, or email us to request full store deletion
- Shopper data — if you collect customer information through the storefront or POS, you are responsible for informing your customers and handling their requests under applicable law
Depending on where you live, you may have additional rights (such as access, deletion, or objection). Contact us and we will respond within a reasonable time.
International use
Posh is offered primarily to merchants in the Philippines. If you use the service from elsewhere, your data may be processed in countries where our providers operate. By using Posh you consent to that transfer where permitted by law.
Changes to this policy
We may update this policy from time to time. We will post the revised version on this page and change the “Last updated” date. Continued use of Posh after changes take effect means you accept the updated policy.
Contact
For privacy questions, data deletion requests, or concerns about how your store data is handled, reach out at bondoydev@gmail.com.