Privacy Policy
Last updated: June 4, 2026
This Privacy Policy explains how Coodra collects, uses, shares, and protects information when you visit our website, request early access, create an account, contact us, or use Coodra services. For privacy questions, email contact@coodra.com.
Coodra is built for business users. We process connected retail data so store teams can review recommendations and stay in control of operational decisions.
1. Information We Collect
- Account information: name, business name, work email, role, account settings, authentication identifiers, and session information.
- Authentication information: passwords are handled by our authentication provider and are not visible to Coodra in plaintext. We may process authentication tokens, reset flows, MFA device identifiers, and sign-in metadata needed to keep accounts secure.
- Early access and contact information: form submissions, support messages, onboarding answers, POS system details, and communications with our team.
- Connected retail data: product catalogs, sales, orders, inventory levels, stock movement, pricing, margin, supplier, store, channel, and related operating data you choose to connect.
- Integration credentials and tokens: API keys, OAuth tokens, access tokens, store URLs, user emails, database names, or similar credentials needed to connect third-party systems. These are used to connect and maintain authorized integrations.
- Usage and technical data: device and browser information, IP address, log data, pages viewed, clicks, feature usage, error reports, and diagnostics.
- Local device data: browser storage may be used for session state, authentication state, MFA state, theme preferences, and early-access form state.
2. How We Use Information
- Provide, maintain, secure, and improve Coodra services.
- Authenticate users, manage sessions, verify account access, and prevent fraud or abuse.
- Connect authorized POS, ecommerce, inventory, accounting, and related retail systems.
- Analyze connected retail data to surface review-first recommendations, alerts, summaries, and operating insights.
- Respond to support requests, process early-access requests, and deliver onboarding communications.
- Send service, security, billing, product, and policy updates.
- Measure website and product performance, troubleshoot errors, and understand how users interact with Coodra.
- Comply with legal obligations and enforce our Terms.
3. What We Do Not Do
- We do not see or store plaintext account passwords inside Coodra.
- We do not sell personal information.
- We do not use connected retail data to make automatic business changes unless a user or authorized workflow approves the action.
- We do not use a retailer's private operating data to publicly identify that retailer without permission.
4. Service Providers
We use trusted service providers to operate Coodra, including providers for authentication, hosting, database infrastructure, analytics, email delivery, support, security, and integration workflows. These providers may process information for us under confidentiality, security, and data-protection obligations.
5. Third-Party Integrations
When you connect a third-party platform, such as a POS, ecommerce, inventory, accounting, or related business system, Coodra processes information made available through that connection. Your use of those third-party services remains governed by their own terms and privacy policies.
7. Communications
We may send service messages, security notices, onboarding messages, support responses, and product updates. Where required by law, including Canadian anti-spam rules and US commercial email rules, marketing emails will include sender identification and an unsubscribe mechanism.
8. Data Retention
We keep information for as long as needed to provide Coodra, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and operate backups. Connected retail data and integration credentials are retained while needed for the service or until removed, disconnected, or deleted according to account settings and applicable law.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, or alteration. These may include access controls, authentication safeguards, provider security controls, logging, and encryption in transit where supported. No method of transmission or storage is completely secure.
10. Your Rights
- You may request access to, correction of, or deletion of personal information we hold about you, subject to legal and contractual limits.
- You may withdraw consent where processing is based on consent, subject to legal or service-related limitations.
- Depending on where you live, you may have additional rights to know, access, correct, delete, or opt out of certain uses of personal information.
To make a privacy request, email contact@coodra.com.
11. International Data Transfers
Coodra and its service providers may process information in Canada, the United States, or other countries where we or our providers operate. Information may be subject to the laws of those jurisdictions.
12. Children's Privacy
Coodra is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
13. Policy Updates
We may update this policy from time to time. Material updates will be posted on this page with a revised "Last updated" date. Continued use of Coodra after an update means the revised policy applies.
14. Contact
Privacy questions and requests: contact@coodra.com