CustomerDashboard Privacy and Cookie Policy
Effective date: 2026-07-26
This policy explains how CustomerDashboard (we, us) handles personal data through CustomerDashboard.io and the related service (the Service).
1. Who is responsible for personal data?
CustomerDashboard is the controller of personal data used to operate its business, such as account, billing, support, security, marketing, and analytics information.
When a business customer connects its database or uses the Service as a client portal, that customer normally controls the information shown through its dashboards. CustomerDashboard processes that information on the customer’s behalf. Questions about information in a customer dashboard should normally be directed to that customer.
2. Information we handle
Depending on how the Service is used, we may handle:
- name, work email, company, role, and account details;
- login identifiers and authentication information provided through Auth0;
- subscription, transaction, and billing records;
- support requests and other communications;
- IP address, device, browser, usage, cookie, and security-log information;
- dashboard settings, database connection information, and encrypted or otherwise protected credentials;
- database query results and cached dashboard data; and
- marketing preferences.
Payment-card details are handled by our payment provider rather than directly by CustomerDashboard, except for limited transaction information we receive for account and accounting purposes.
We receive information directly from users and customers, automatically from use of the Service, from connected databases, and from service providers such as Auth0 and Lemon Squeezy.
3. Why we use personal data
We use personal data to:
- create accounts and provide the Service;
- authenticate users and protect accounts;
- process subscriptions and maintain transaction records;
- connect databases, run queries, cache results, and display dashboards;
- provide support and communicate about the Service;
- monitor performance, diagnose problems, and prevent misuse;
- understand and improve the website and Service;
- send marketing where permitted and manage opt-outs;
- establish, exercise, or defend legal claims; and
- comply with legal obligations.
Under European data-protection law, our legal bases are performance of a contract, our legitimate interests in operating and protecting the Service, consent where requested, and compliance with legal obligations. We process customer-controlled dashboard data under the customer’s instructions and our Data Processing Addendum.
We do not use personal data to make decisions producing legal or similarly significant effects solely by automated means.
4. Service providers and disclosures
We may disclose personal data to providers that help us operate the Service, including:
- Amazon Web Services (AWS) for hosting and infrastructure;
- Auth0/Okta for authentication;
- Lemon Squeezy for subscriptions and payments;
- Microsoft Clarity for session and behavioural analytics;
- Mixpanel for product analytics;
- Google Analytics for website and product analytics; and
- an email provider for service and marketing communications.
We may also disclose information to professional advisers, authorities where legally required, or a buyer or successor involved in a proposed business transaction. We do not disclose customer dashboard data for advertising.
5. International transfers
Our primary AWS infrastructure is located in the Europe (Frankfurt) region. Some providers, including Auth0 and analytics providers, may process information in the United States or other countries.
Where European personal data is transferred outside the European Economic Area, we rely on an applicable legal transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where available, or European Commission Standard Contractual Clauses, together with additional safeguards where required.
6. Retention
We keep personal data only as long as reasonably needed for the purposes described above:
- account and service information is generally kept while the account is active;
- database credentials are disabled or deleted promptly after termination;
- cached customer data and active dashboard configurations are normally deleted within 30 days after termination;
- residual backup copies may remain for up to 90 days;
- analytics information is retained according to our settings and the provider’s applicable retention period; and
- billing, security, dispute, and legal records may be retained longer where reasonably necessary or legally required.
Because the connected database remains under the customer’s control, CustomerDashboard does not currently provide a general export of dashboard configurations or cached data.
7. Cookies and analytics
We use necessary cookies and similar technologies for authentication, security, network management, and remembering essential settings. These are required for the Service to work.
With consent where required, we also use Microsoft Clarity, Mixpanel, and Google Analytics to understand visits and product usage. These tools may collect identifiers, IP-derived location, browser and device details, pages or features used, clicks, scrolling, and session information.
We aim to avoid sending database contents, credentials, or sensitive dashboard values to analytics providers. Microsoft Clarity content masking should be used within the Service. Nevertheless, customers should not place analytics identifiers or confidential information in page titles, URLs, event names, or other fields that may be collected automatically.
Where consent is required, optional analytics will be disabled until the user accepts them. Users can reject optional cookies and later change or withdraw their choice through the cookie settings made available on the site. Browser controls can also delete or block cookies, although necessary functions may then stop working.
8. Marketing communications
We may send product news and offers where permitted. Marketing messages will include a way to unsubscribe. Opting out of marketing does not stop necessary account, billing, security, or service messages.
9. Security
We use reasonable technical and organisational measures intended to protect personal data. These include managed cloud infrastructure, authentication through Auth0, access restrictions, and protection of data in transit. No service can guarantee absolute security, and customers remain responsible for limiting database credentials and dashboard access appropriately.
10. Individual rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or obtain a copy of their personal data; object to certain processing; and withdraw consent at any time. They may also complain to a data-protection authority.
For data controlled by CustomerDashboard, requests may be sent to sales@customerdashboard.io. We may need to verify the requester’s identity.
For data displayed in a customer’s dashboard, requests should normally be sent to that customer. We will assist the customer where required by law.
In Finland, the supervisory authority is the Office of the Data Protection Ombudsman: https://tietosuoja.fi/en/home.
11. Children
The Service is intended for business use and is not directed to children. Customers are responsible for determining whether their own use involves children and whether that use is lawful and appropriate for the Service.
12. Changes
We may update this policy to reflect changes to the Service or law. We will post the current version with a revised effective date and provide additional notice where appropriate.
13. Contact
Questions about this policy may be sent to sales@customerdashboard.io.