Privacy Policy
This Privacy Policy explains what information DashMEOW collects, why, and what you can do about it. It's written to reflect what the product actually stores and transmits — including the third-party Credentials at the center of how DashMEOW works.
Effective date: [Effective Date — not yet published]
§1Scope
This Policy covers information we collect through the DashMEOW application. It doesn't cover the privacy practices of the third-party services you choose to connect (Vercel, Stripe, Supabase, Google, and others) — their own privacy policies govern how they handle your data.
§2Information We Collect
| Category | Examples | Source |
|---|---|---|
| Account & Workspace | Name, email address, workspace name, role (Admin/Viewer) | You, at sign-up or invite acceptance |
| Third-party Credentials | Vercel access tokens, Stripe restricted keys, Supabase service-role keys, social/API keys | You, when configuring an integration |
| Retrieved integration data | Deployment status, revenue figures, analytics sessions, connection counts | The third-party service, fetched using your Credential |
| Monitoring data | Uptime results, response times, SSL certificate expiry, for sites you register | Our own automated checks |
| Customer Data you enter | Project details, subscription & cost records, tool notes, logos | You |
| Usage & log data | Pages visited, actions taken, timestamps, IP address, browser type | Automatically, from your use of the Service |
| Cookies | Session and authentication cookies | Automatically, to keep you signed in |
Credentials are encrypted at rest and are never displayed back to you in plaintext except through an explicit "reveal" action you take yourself.
§3How We Use It
- To operate the Service — authenticating you, scoping data to the right Workspace, and enforcing Admin/Viewer permissions;
- To run the integrations you configure, using your stored Credentials solely to fetch the data that feature displays;
- To run scheduled monitoring (uptime/SSL checks) against sites you register;
- To communicate with you about your account, security notices, or (if you opt in) product updates;
- To detect, prevent, and respond to fraud, abuse, or security issues;
- To improve the Service, generally in aggregated or de-identified form.
We don't sell your information, and we don't use your Customer Data or Credentials to train machine-learning models.
§5How We Protect It
- Third-party Credentials are stored encrypted at rest (via Supabase Vault) and are never logged or transmitted anywhere except to the service they authenticate to.
- Access to Workspace data is enforced by role: Viewers can't create, edit, or reveal secrets; only Admins can.
- Database access is scoped per-Workspace at the database level (row-level security), so one Workspace's data isn't reachable from another's session.
- No system is perfectly secure, and we can't guarantee absolute security — but we design for the principle that a Credential you give us is used for exactly the purpose you gave it, and nothing else.
§6Retention
We keep your information for as long as your Workspace is active. If you delete a project, Credential, or your Workspace itself, we remove the associated data (including encrypted Credentials) within a reasonable period, except where we're required to retain it longer for legal, tax, or security purposes.
§7Your Rights & Choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. In the Service today, you can:
- Remove a stored Credential at any time from a project's settings;
- Edit or delete Customer Data you've entered;
- Ask an Admin to remove your access to a Workspace, or remove your own if you're the Admin;
- Contact us (below) to request a copy of your data or full account deletion.
If you're in the EEA, UK, or a U.S. state with its own privacy law (such as California), you may have additional statutory rights; contact us and we'll handle your request under the law that applies to you.
§8Children's Privacy
The Service is intended for business use and isn't directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.
§9International Transfers
We may process and store information in the United States, which may differ from the privacy laws of your own country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
§10Changes to This Policy
We'll post any changes here and update the effective date above. For material changes, we'll provide additional notice, such as an in-app banner or an email.
§11Contact
Questions about this Policy or the Terms, or a request regarding your data, can be sent to ezcabrera@untappd.net or Untapped Technologies LLC, [Company Mailing Address].