Privacy Policy
Effective Date: January 20, 2025
Last Updated: September 20, 2025
DASHBOARDLY INC (“Dashboardly,” “we,” “our,” or “us”) provides SaaS software for profit analytics and inventory management tailored for TikTok Shop sellers, brands, and agencies. We are committed to protecting your information and maintaining transparency about how we collect, use, and safeguard data.
This Privacy Policy applies to all users of our website (dashboardly.io), our web application, and our TikTok Shop integrations.
1. Data We Collect
From TikTok Shop (via official OAuth APIs)
When you connect your TikTok Shop account, we may access:
- Orders: IDs, SKUs, product details, timestamps, order value, discounts, refunds, shipping/handling fees.
- Products: SKUs, product IDs, names, pricing, inventory levels, listing metadata.
- Financials: TikTok commissions, transaction fees, taxes, promotions, payouts.
- Advertising: TikTok Ads spend & performance (if authorized).
From you directly
- Account information: name, email, password (hashed with bcrypt/argon2).
- Business inputs: cost of goods (COGS), supplier info, inventory adjustments, purchase orders.
- Billing details: subscription plan, invoices, payment details (processed securely by Stripe; we do not store card numbers).
- Support communications: messages via email or (in future) chat.
Automatically collected
- Device/browser type, IP, approximate geolocation.
- Session data, login timestamps, usage logs, crash/error reports.
- Analytics on feature usage for product improvement.
Cookies
- Essential: authentication, session, security.
- Analytics: anonymized usage tracking (Google Analytics).
- No third-party advertising cookies inside our app.
2. Purposes of Processing
We process collected data to:
- Deliver dashboards, profit analytics, inventory tracking, and alerts.
- Provide user support via email (hello@dashboardly.io) and (optionally) chat.
- Improve reliability, security, and features of the platform.
- Ensure compliance with TikTok Developer Terms, GDPR, CCPA, and other regulations.
- Communicate service updates and, with explicit consent, send marketing emails.
3. Legal Basis for Processing (GDPR)
- Contract: to deliver the services you subscribed to.
- Legitimate interests: to improve services, prevent fraud, and ensure security.
- Consent: for optional marketing and non-essential cookies.
- Legal obligations: when required by law or regulator.
4. Data Sharing & Subprocessors
We do not sell personal data. We share information only with trusted subprocessors, each bound by Data Processing Agreements (DPAs):
- Hosting: DigitalOcean (secure data centers).
- Payments: Stripe (PCI-DSS certified).
- Analytics: Google Analytics (anonymized).
- Support: email (hello@dashboardly.io); future chat (e.g., Intercom or Crisp).
- Monitoring & error tracking: Sentry (errors) and Datadog (infrastructure monitoring).
5. Security Measures
We follow industry best practices to protect your data:
- Encryption: TLS 1.2+ in transit; AES-256 at rest.
- Passwords: hashed and salted (bcrypt/argon2).
- Access control: Role-Based Access Control (RBAC), least-privilege model, audit logs.
- Monitoring: real-time monitoring, anomaly detection, incident response protocols.
- Backups: encrypted, rotated, retained only as necessary.
- Employee training: regular security & privacy training.
- Testing: penetration tests by independent security experts.
6. Data Retention & Deletion
- Account data: retained while your account is active.
- TikTok data: deleted automatically within 30 days of app uninstall.
- Manual deletion requests: via hello@dashboardly.io or Data Deletion Page.
- Backups: purged securely within 60 days of account termination.
- Billing records: retained up to 7 years (tax compliance).
7. Your Rights
Depending on your jurisdiction (GDPR, CCPA, PIPEDA, etc.), you may:
- Access your personal data.
- Rectify incorrect or incomplete data.
- Request erasure (“right to be forgotten”).
- Restrict or object to certain processing.
- Port your data to another provider in machine-readable format.
- Opt out of marketing at any time.
We respond to verified requests within 30 days. Under CCPA, you may appoint an authorized agent.
8. International Transfers
Your data may be processed in the United States, Canada, or the EU. For transfers outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs), or
- Adequacy decisions by the European Commission.
9. Children’s Privacy
Dashboardly is intended for business use and not for individuals under 18. We do not knowingly collect data from minors; if such data is identified, it will be deleted.
10. Data Breach & Incident Response
- We maintain a formal incident response plan.
- In case of a breach, we notify affected users within 72 hours (GDPR).
- We cooperate with regulators and take mitigation steps.
11. Complaint Handling
If you believe your privacy rights were violated, you may:
- Contact us at hello@dashboardly.io
- Contact our Data Protection Officer (DPO) at hello@dashboardly.io
- File a complaint with your local Data Protection Authority.
12. Updates
We may update this Privacy Policy periodically. Updates will appear at dashboardly.io/privacy-policy with a new “Last Updated” date. Significant changes will also be notified via email or in-app.
13. Contact
Dashboardly Support
📧 hello@dashboardly.io
🌐 https://dashboardly.io