Legal
Security
Snagr is a small, focused product, and its best security property is how little it holds. It never sees a card number, never stores a Polar password, and does not record your screen. This page describes the rest honestly, including what we have not done yet.
Last updated 22 September 2026
1. What we never hold
- Payment credentials. Card numbers and bank details go to Polar, which is Merchant of Record. They never reach our servers.
- Your Polar password. Access is by OAuth, so you grant scoped permission and can revoke it from Polar at any time.
- Session recordings. Replay, surveys and dead-click capture are disabled in our analytics configuration, and we do not load PostHog’s recorder.
2. Encryption
- All traffic is served over TLS 1.2 or better, with HSTS. There is no plaintext HTTP endpoint.
- Data at rest is encrypted by our database and object storage providers.
- Polar OAuth access and refresh tokens are stored in our database, which encrypts data at rest. They are used in memory to call Polar and are deleted when you disconnect the organisation.
- Passwords, for accounts that use one, are hashed with a modern memory-hard algorithm and are never stored or logged in the clear.
3. Access control and isolation
- Every dashboard query is scoped to the signed-in user’s team at the data-access layer, so one merchant cannot read another merchant’s checkouts, customers or emails.
- Production access is limited to the person who operates the service, protected by multi-factor authentication on the provider accounts used to run it.
- Webhook endpoints verify signatures — Polar webhooks against the Standard Webhooks signature, Resend against its signing secret — so forged events are rejected.
- Scheduled jobs authenticate with a shared secret and are not reachable anonymously.
4. Email security
- The shared sending domain is configured with SPF, DKIM and DMARC.
- Merchants who send from their own domain must complete DNS verification before a single message goes out under it.
- Unsubscribes are enforced through a suppression list checked at send time, so a suppressed address cannot be emailed again even by reimporting it.
5. Data lifecycle
Deleting your account disconnects Polar, cancels billing and removes your records from the live database immediately. Residual copies in backups typically expire within 30 days. Disconnecting a store deletes its tokens immediately. Retention for each category of data is listed in the Privacy Policy.
6. What we have not done yet
Being straight about this is more useful than a badge. Snagr does not currently hold a SOC 2 or ISO 27001 certification, and has not had a third-party penetration test. It is a one-person operation, and we would rather tell you that than imply otherwise. If your procurement process requires either, write to tejas@snagr.sh and we will tell you honestly where we stand.
7. Reporting a vulnerability
Email tejas@snagr.sh with enough detail to reproduce the issue. We acknowledge within two business days and aim to ship a fix for a confirmed high-severity issue within seven days.
Good-faith research is welcome and will not be treated as a breach of the Acceptable Use Policy, provided you use only accounts you control, avoid accessing or modifying other people’s data, do not degrade the service, and give us reasonable time to fix the issue before publishing. We do not currently run a paid bounty, and we will credit you if you would like us to.
8. Incident notification
If a breach affects personal data we notify affected account holders and any relevant regulator within the legal deadline — 72 hours under GDPR, and within 48 hours to merchants under our DPA.