Skip to main content
Plexa.

Privacy Policy

Last updated: August 11, 2026

This Privacy Policy explains what information Plexa ("Plexa," "we," "us") collects, how we use it, and the choices you have. Plexa is a DevVoid product for creating and sharing digital business cards and portfolios. This policy describes what the product actually does today, based on how it is built - it does not claim any particular compliance certification or legal status (such as GDPR, DPDP, or SOC 2) unless stated explicitly, and we do not currently make that claim.

If you have questions about this policy, contact us at aneeshbhat@devvoid.org.

1. Information we collect

When you create an account

Plexa uses Clerk to handle sign-up and sign-in. When you create an account, Clerk collects your authentication details (such as your email address and, depending on the sign-in method you choose, other identifiers Clerk requires). We receive your name and email address from Clerk and store a corresponding account record in our own database.

Once you have an account, you may choose to add to your profile:

  • Your name, bio, company, position, and location
  • An avatar image
  • Notification and theme preferences

Before you have an account

The first time you visit Plexa, we set a first-party cookie (dvd_attr) and a matching entry in your browser's local storage that records where you came from - UTM parameters from the URL, the referring site, and the page you landed on. This cookie is not marked HttpOnly (so it is readable by the page's own scripts) and expires after 30 days. If you go on to create an account, this information is copied into your account record once, at signup, so we know how you found Plexa. It is not collected if you never create an account, beyond sitting in your browser.

What you choose to make public on your card or portfolio

Plexa is built around content you choose to make public. When you fill in a card or portfolio and set it to active/published, the information you enter is displayed to anyone who visits its public link - this can include your name, job title, company, tagline, email address, phone number, website, location, date of birth (if you add it), social media links, and any profile photo or company logo you upload. Anyone with the link, or who finds it in our public gallery (if you've opted into that), can view this information. Do not include information in a public card or portfolio that you do not want visible to anyone who finds the link.

Payment information

If you subscribe to a paid plan, billing is handled by Dodo Payments. We send Dodo your email address and name to create a checkout session; Dodo processes your payment details directly and shares subscription status (active, past due, cancelled, etc.) back with us via webhook. We do not receive or store your card number or other raw payment credentials.

2. Information about visitors who don't have an account

When someone views a public card or portfolio, scans a card's QR code, or submits a portfolio's contact form - regardless of whether they have a Plexa account - we record some information about that visit:

  • The visitor's IP address and browser user-agent string, taken from the request
  • The HTTP referrer (what page or link they came from)
  • A randomly generated visitor identifier stored in the visitor's browser local storage, used to distinguish repeat visits from new ones
  • For QR-code scans specifically: whether the scanner was signed in or anonymous, and which card owner the scan belongs to
  • How long the visitor spent on the page, for portfolio views

We do not derive a geographic location from this data - no geolocation lookup is performed. This information is used to power the view/scan counts and analytics shown to the card or portfolio owner, and is not shared with the visitor. A card or portfolio owner viewing their own content does not count toward these numbers. At present, these visit records are not automatically deleted after a fixed period - see Data retention below.

Separately, we use PostHog (for product analytics) and, in production only, Microsoft Clarity (for session-replay/heatmap analysis) to understand how the app is used - see Cookies and similar technologies below for what those tools do.

3. Lead and contact forms

Plexa has three separate forms, and they send information to different places:

  • Newsletter signup: collects only your email address, stored in our database. It is not forwarded to our CRM.
  • General contact/"concern" form: collects your email, subject, and message. It is stored in our database and also forwarded to our CRM (see below).
  • A portfolio's "Get in touch" form: collects the submitter's name, email, phone (if provided), subject, and message, and is stored against that portfolio for its owner to see. Submitting this form also logs an analytics event that includes the submitter's IP address and user-agent, as described in Section 2. This form's content is not forwarded to our CRM.

4. Our CRM

Plexa is a DevVoid product, and DevVoid uses its own internal CRM system to track leads and customer lifecycle across DevVoid's products, Plexa included. At the moment your account is created, we send your email, name, and how you found us to this CRM. As you use Plexa, we also notify the CRM of certain lifecycle events tied to your email address - for example, that your account was created, that one of your cards was scanned or shared, that a payment succeeded or failed, or that a subscription was cancelled. The general contact form (Section 3) is also forwarded here. This CRM is DevVoid's own system, not an outside marketing vendor.

5. Cookies and similar technologies

We don't run a cookie-consent banner today. Here is what actually runs:

  • Clerk session cookies: set automatically by our authentication provider to keep you signed in. Required for the app to work.
  • dvd_attr cookie: our own first-party attribution cookie described in Section 1, holding UTM/referrer data. Expires after 30 days.
  • PostHog: product analytics, loaded on every page. It records page views and, once you're signed in, associates your account (user ID, email, name, plan) with your activity so we can understand product usage. PostHog data is processed on PostHog's EU infrastructure. PostHog primarily uses browser local storage rather than cookies for this.
  • Microsoft Clarity: in our production environment only (not on staging or local development), we load Microsoft Clarity for session-replay and heatmap analysis of how visitors use the site. Clarity sets its own cookies and may record on-page interactions such as clicks and scrolling.
  • Anonymous visitor ID: a randomly generated identifier stored in local storage (not a cookie) on the device of anyone who views a public card or portfolio, as described in Section 2.

You can block or clear cookies and local storage using your browser's settings. Blocking Clerk's session cookie will prevent you from staying signed in.

6. Third-party services we use

The services below process data on our behalf as part of running Plexa:

  • Clerk - authentication and session management
  • MongoDB Atlas - our database, where account, card, and portfolio records are stored
  • Cloudflare R2 - storage for uploaded profile photos, company logos, and portfolio images
  • Dodo Payments - billing and subscription processing
  • PostHog - product analytics (EU-hosted)
  • Microsoft Clarity - session-replay analytics, production only
  • DevVoid's internal CRM - lead and lifecycle tracking, described in Section 4

We do not currently send email on Plexa's behalf (account-related emails such as sign-in links come from Clerk directly), and we do not use Google Analytics, Mixpanel, Segment, Sentry, or similar tools beyond what's listed above.

7. Data retention

We keep your account information for as long as your account is active. Visitor analytics records (Section 2) do not currently have an automatic expiry and are retained indefinitely unless we change this. We may retain limited records after account deletion as described in the next section.

8. Deleting your account

You can delete your account from Settings at any time. When you confirm deletion:

  • Your account is deactivated immediately and you are signed out.
  • Every card and portfolio you own stops being active and is no longer publicly accessible - visiting their links or scanning their QR codes will show them as unavailable.
  • If you had an active paid subscription, we attempt to cancel it with Dodo Payments.
  • Your account's email address is changed internally so it's no longer tied to your old account, which also means you're free to sign up again later with the same email if you choose to.

This is an immediate deactivation, not a delayed or scheduled one, and we don't currently offer an "undo." A few things are handled differently and are worth being upfront about:

  • Uploaded images (profile photos, logos, and portfolio images) are removed from our storage provider when you delete an individual card, an individual portfolio, or your whole account.
  • Lead and lifecycle records already sent to our CRM (Section 4) under your email are not automatically deleted when you delete your account. If you'd like those removed, contact us directly.
  • A separate newsletter subscription (Section 3), if you signed up for one, is not automatically cancelled by account deletion, since it's stored independently of your account.
  • Visitor analytics records tied to your cards/portfolios (Section 2) are not automatically deleted by account deletion, since they primarily describe visitor activity rather than your own account data, and currently have no automatic retention limit.

If you want any of the above removed as well, email us at aneeshbhat@devvoid.org and we'll handle it manually.

9. Your choices

You can review and update your profile information, and set which cards/portfolios are public, from Settings and your dashboard at any time. You can delete your account as described above. For anything not self-serviceable in the product today - such as removing a CRM record, a newsletter subscription, or visitor analytics tied to your content - contact us and we'll assist directly.

10. Children's privacy

Plexa is not directed at children, and we do not knowingly collect information from children. If you believe a child has provided us with information, contact us and we will remove it.

11. Changes to this policy

We may update this policy as the product changes. We'll update the "Last updated" date above when we do. We encourage you to review it periodically.

12. Contact us

Questions about this policy or your data can be sent to aneeshbhat@devvoid.org.