Privacy Policy
Last updated: August 13, 2026
Who we are
Posta is a residential access platform used by neighborhoods, condominiums, and homeowner associations to manage visitor access, gate credentials, resident communications, and related community operations. Posta is operated by DLUM.LLC.
This policy explains what information Posta processes when you use the Posta mobile app or the Posta web console, and how we handle it.
You typically use Posta because a neighborhood you belong to — as a resident, a guard, or an administrator — has adopted it. That neighborhood decides who gets access, which modules are enabled, and how it manages its own community. Posta processes data to provide the service to that neighborhood.
Information we process
We process only the information needed to run access control and community operations.
Account and identity
- Your email address and password. Passwords are stored only as secure hashes; we never see or store your password in readable form.
- Your name and, where a workflow needs it, a contact phone number.
- Internal identifiers that link your account to your membership, household, and neighborhood.
- If you choose to sign in with Google, Google confirms your identity to us and we receive your verified email address. We do not store Google credentials or ID tokens.
Neighborhood and membership
- The neighborhood, unit or household, and role (resident, guard, administrator, auditor) you hold.
- Your language and formatting preferences.
Visitor and access activity
- Visitor announcements, passes, and the credentials issued for them.
- Access-credential metadata used to validate entry and prevent reuse of a spent pass. QR codes are opaque authorization artifacts — they are not identity, and raw QR payloads are never stored in logs or shared.
- Gate scans and entry and exit events recorded by guards.
Payments (only where a neighborhood enables them)
- Manual payment obligations, the proof you submit, and the review decision.
- Posta is not a payment processor. We do not collect card numbers, security codes, or bank login credentials, and we do not integrate a payment-settlement or advertising SDK.
Optional media (only where a neighborhood enables the workflow)
- Evidence images such as a payment receipt, ID photo, license-plate photo, visitor photo, or signature — collected only when a specific workflow requires it and you choose to provide it. These are kept as private files with time-limited access and are never exposed through public links.
- The app requests camera access for one purpose: scanning QR credentials at the gate and capturing the optional evidence photos described above. It asks for your photo library only when you attach a file you already have, such as a payment receipt, and for notification permission only to deliver the alerts described below. Posta does not request location access.
Notifications and devices
- If you use the mobile app, a device record and push token so we can deliver alerts. Notification payloads carry message references and deep-link identifiers only, never the underlying personal details.
- If you opt in to WhatsApp notifications, your phone number and the message content required to deliver that alert are processed by WhatsApp on our behalf. This is off by default, and turning it off returns you to in-app and push delivery.
Surveys, suggestions, and community feedback
- Responses you give to community surveys, which may be named or anonymous, and suggestions you submit. Where a survey is anonymous, your response is stored without your name or account on it, and administrators see aggregate results rather than who answered what.
Security and audit
- Redacted security and audit event metadata used for accountability, abuse prevention, and incident response, including which administrator viewed or changed sensitive records.
How we use information
- To provide the service — authentication, memberships, visitor access, reservations, payments, surveys, and notifications.
- To keep access secure — validating credentials, preventing pass reuse and fraud, and supporting incident response.
- To meet legal and compliance obligations of the operating neighborhood.
- To manage your account and respond to support requests.
We do not use your information to build advertising profiles or to make automated decisions that have legal effects on you.
What we do not do
- We do not track you across other apps or websites, and we use no advertising identifiers.
- We do not sell your personal information.
- We do not use analytics, advertising, or cross-app tracking SDKs in the app.
- We do not store raw QR or authentication tokens, card numbers, or biometric templates.
- We do not perform facial recognition, and we do not run optical character recognition on ID documents or license plates.
How information is shared
- Within your neighborhood. Administrators and guards can see the information they need to operate access control for the community you belong to. Administrator access to sensitive records is logged.
- Service providers. We use infrastructure providers to run Posta — including Supabase (database and authentication), Vercel (application hosting), Apple (app distribution and push delivery), Google (optional sign-in), and WhatsApp (optional notification delivery where you opt in). They process data on our behalf, under agreements, and only to provide their service.
- Legal and safety. We may disclose information where required by law or to protect the rights, property, or safety of residents, guards, or the public.
We do not share your personal information for advertising or marketing.
Security
Production traffic is encrypted in transit over HTTPS. Access to data is controlled by role and by neighborhood scope, enforced on the server and at the database layer rather than only in the app. Credentials are treated as opaque authorization artifacts, sensitive media is private and served through short-lived links, and sensitive values such as raw tokens and card data are never collected or logged. Access decisions fail closed: when a credential cannot be verified, entry is not granted.
No system is perfectly secure, and we cannot guarantee absolute security.
Retention and deletion
We keep information for as long as needed to provide the service and to meet security, legal, and audit obligations, after which it is archived, redacted, or deleted. Access records and audit metadata are retained longer than routine operational data because they exist to answer questions about who entered a community and who authorized it.
Your data rights
You can request access to, a copy of, correction of, or deletion of your personal information at any time. Contact your neighborhood’s administrator, who can escalate to us, or write to us directly:
Include the email address associated with your Posta account and the neighborhood you belong to so we can locate your records. We will respond within 30 days. If you ask us to delete your account, we will delete or de-identify your personal information except where we must retain it — for example, access and audit records the neighborhood is required to keep, records under a legal hold, and backups that expire on their own schedule. We will tell you what was retained and why.
Because neighborhoods authorize their own members, your account is created and removed by your neighborhood’s administrators rather than by self-service signup. Ending your membership removes your access to the neighborhood’s data.
Children
Posta is intended for use by adults administering or participating in residential access. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this policy as the product and our practices evolve. Material changes will be reflected here with a revised “Last updated” date.
Contact us
For privacy questions, or to exercise any of the choices described above, contact your neighborhood’s administrator or reach us at support.posta@deverr.io.
DLUM.LLC · Florida, United States