Skip to content
mostra

Privacy Policy

Last updated: October 2026

This policy explains what personal data Mostra collects, why, and what rights you have.

1. What we collect

Account data: your email address, display name and sign-in identifier. Content you create: page text, links, images and videos you upload. Billing data: handled by Stripe; we keep only your Stripe customer and subscription identifiers and the plan you are on, never your card number.

2. Why we use it

To run your account and publish your pages, to process payments, to keep the service secure and prevent abuse, and to answer your messages. Our legal bases are performance of our contract with you, our legitimate interest in a secure service, and your consent where we ask for it.

3. Analytics and cookies

Mostra does not use advertising or tracking cookies. Visitor statistics for your page are aggregated and cookieless. We set only the cookies strictly needed to keep you signed in and to remember your preferences.

4. Who processes your data

We use trusted processors: Google Firebase (authentication), Stripe (payments), and Cloudflare (hosting, storage, video and network security). They process data only on our instructions and under data protection agreements. We do not sell personal data.

5. International transfers

Some processors operate outside the European Economic Area. Where this happens we rely on adequacy decisions or standard contractual clauses.

6. How long we keep it

We keep account and content data while your account is open. When you delete your account we delete your content and personal data, except what we must keep for tax or legal obligations, for the period the law requires.

7. Your rights

You may ask to access, correct, export or delete your data, to object to or restrict processing, and to withdraw consent at any time. You may also complain to your local data protection authority. To exercise a right write to hello@mostra.bio.

8. Children

Mostra is not meant for people under 16 and we do not knowingly collect their data.

9. Changes

We will update this policy when our practices change; the date above shows the latest version.

Booking and order requests

Business pages can show a booking form or an order-request form. This section explains what happens to the details a visitor sends through them.

1. Who is responsible

The owner of the page is the controller of the details you send through their form. Mostra processes them on the owner's behalf and only to deliver your request to the owner.

2. What is stored

Your name, your contact detail, the details of your request (for example date, time, party size or the items you picked) and the note you write. If an estimate is shown, it is the owner's estimate and not a price we charge. To prevent abuse, on the basis of our legitimate interest in keeping the service secure, Mostra stores a keyed, daily-rotating hash of the requester’s network address for no more than 48 hours.

3. Who sees it

The owner sees your request in their Mostra inbox. The owner may also get a notification email; that email includes the booking date, time, party size and number of lines, but never your name, email or phone number.

4. No payment

Sending a request does not process a payment and does not confirm a reservation or an order. Mostra is not a party to it.

5. How long it is kept

A request is deleted 365 days after it was made. The owner can delete it earlier, and it is deleted when the owner deletes the page or the account.

6. Deleting your request

To have your request deleted, contact the business that owns the page, or write to hello@mostra.bio with the page address and the contact detail you used.

Connected services and embeds

Page owners can connect outside services to their page. This section explains what Mostra does with the data of each.

1. Shopify

When an owner connects a Shopify store, Mostra reads product data only (titles, descriptions, images, prices and availability) in order to show it on the owner's page. Mostra cannot change the store. The access token is stored encrypted, and the synced product data is deleted when the owner disconnects the store.

2. Instagram

When an owner connects Instagram, Mostra reads their posts (media and captions) and keeps a copy of the images so the page can show them. The copies, the list of posts and the encrypted access token are deleted when the owner disconnects Instagram or removes Mostra's access from Instagram. If Meta sends us a data-deletion request, we delete the same data. You can follow a request at /legal/data-deletion.

3. Embedded players

Players such as music or video embeds load only after a visitor taps them. Until then nothing is requested from the provider. After the tap, the provider's own privacy policy applies to what it collects.

Questions: hello@mostra.bio