Privacy Policy

This Privacy Policy explains what information DashMEOW collects, why, and what you can do about it. It's written to reflect what the product actually stores and transmits — including the third-party Credentials at the center of how DashMEOW works.

Effective date: [Effective Date — not yet published]

§1Scope

This Policy covers information we collect through the DashMEOW application. It doesn't cover the privacy practices of the third-party services you choose to connect (Vercel, Stripe, Supabase, Google, and others) — their own privacy policies govern how they handle your data.

§2Information We Collect

CategoryExamplesSource
Account & WorkspaceName, email address, workspace name, role (Admin/Viewer)You, at sign-up or invite acceptance
Third-party CredentialsVercel access tokens, Stripe restricted keys, Supabase service-role keys, social/API keysYou, when configuring an integration
Retrieved integration dataDeployment status, revenue figures, analytics sessions, connection countsThe third-party service, fetched using your Credential
Monitoring dataUptime results, response times, SSL certificate expiry, for sites you registerOur own automated checks
Customer Data you enterProject details, subscription & cost records, tool notes, logosYou
Usage & log dataPages visited, actions taken, timestamps, IP address, browser typeAutomatically, from your use of the Service
CookiesSession and authentication cookiesAutomatically, to keep you signed in

Credentials are encrypted at rest and are never displayed back to you in plaintext except through an explicit "reveal" action you take yourself.

§3How We Use It

  • To operate the Service — authenticating you, scoping data to the right Workspace, and enforcing Admin/Viewer permissions;
  • To run the integrations you configure, using your stored Credentials solely to fetch the data that feature displays;
  • To run scheduled monitoring (uptime/SSL checks) against sites you register;
  • To communicate with you about your account, security notices, or (if you opt in) product updates;
  • To detect, prevent, and respond to fraud, abuse, or security issues;
  • To improve the Service, generally in aggregated or de-identified form.

We don't sell your information, and we don't use your Customer Data or Credentials to train machine-learning models.

§4Who We Share It With

We share information only as needed to run the Service:

  • Sub-processors that host or run the Service itself — currently Supabase (database, authentication, encrypted secret storage, and file storage), Vercel (application hosting), and Resend (sending service emails such as team invitations, which include the recipient's email address and your Workspace name).
  • The third-party services you connect — when you configure an integration, your Credential is sent directly to that service's own API (e.g., Stripe, Vercel, Google) to retrieve the data you asked for. That request doesn't pass through any other party.
  • Site checks — to check the sites you add, the Service sends requests to those sites (identified as DashMEOW), and sends their addresses to Google's PageSpeed Insights service to measure performance. Only the site address is shared for this, not your Credentials or account details.
  • Payment processing — subscription payments, where applicable, are handled by our payment processor (Stripe); we don't store full card numbers ourselves.
  • Legal & safety — if required by law, subpoena, or to protect the rights, property, or safety of DashMEOW, our users, or the public.
  • A business transfer — if DashMEOW is acquired or merges with another company, your information may transfer as part of that deal, subject to this Policy (or a materially similar one).

§5How We Protect It

  • Third-party Credentials are stored encrypted at rest (via Supabase Vault) and are never logged or transmitted anywhere except to the service they authenticate to.
  • Access to Workspace data is enforced by role: Viewers can't create, edit, or reveal secrets; only Admins can.
  • Database access is scoped per-Workspace at the database level (row-level security), so one Workspace's data isn't reachable from another's session.
  • No system is perfectly secure, and we can't guarantee absolute security — but we design for the principle that a Credential you give us is used for exactly the purpose you gave it, and nothing else.

§6Retention

We keep your information for as long as your Workspace is active. If you delete a project, Credential, or your Workspace itself, we remove the associated data (including encrypted Credentials) within a reasonable period, except where we're required to retain it longer for legal, tax, or security purposes.

§7Your Rights & Choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. In the Service today, you can:

  • Remove a stored Credential at any time from a project's settings;
  • Edit or delete Customer Data you've entered;
  • Ask an Admin to remove your access to a Workspace, or remove your own if you're the Admin;
  • Contact us (below) to request a copy of your data or full account deletion.

If you're in the EEA, UK, or a U.S. state with its own privacy law (such as California), you may have additional statutory rights; contact us and we'll handle your request under the law that applies to you.

§8Children's Privacy

The Service is intended for business use and isn't directed at children. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we'll delete it.

§9International Transfers

We may process and store information in the United States, which may differ from the privacy laws of your own country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

§10Changes to This Policy

We'll post any changes here and update the effective date above. For material changes, we'll provide additional notice, such as an in-app banner or an email.

§11Contact

Questions about this Policy or the Terms, or a request regarding your data, can be sent to ezcabrera@untappd.net or Untapped Technologies LLC, [Company Mailing Address].