CustomerDashboard Privacy and Cookie Policy

Effective date: 2026-07-26

This policy explains how CustomerDashboard (we, us) handles personal data through CustomerDashboard.io and the related service (the Service).

1. Who is responsible for personal data?

CustomerDashboard is the controller of personal data used to operate its business, such as account, billing, support, security, marketing, and analytics information.

When a business customer connects its database or uses the Service as a client portal, that customer normally controls the information shown through its dashboards. CustomerDashboard processes that information on the customer’s behalf. Questions about information in a customer dashboard should normally be directed to that customer.

2. Information we handle

Depending on how the Service is used, we may handle:

Payment-card details are handled by our payment provider rather than directly by CustomerDashboard, except for limited transaction information we receive for account and accounting purposes.

We receive information directly from users and customers, automatically from use of the Service, from connected databases, and from service providers such as Auth0 and Lemon Squeezy.

3. Why we use personal data

We use personal data to:

Under European data-protection law, our legal bases are performance of a contract, our legitimate interests in operating and protecting the Service, consent where requested, and compliance with legal obligations. We process customer-controlled dashboard data under the customer’s instructions and our Data Processing Addendum.

We do not use personal data to make decisions producing legal or similarly significant effects solely by automated means.

4. Service providers and disclosures

We may disclose personal data to providers that help us operate the Service, including:

We may also disclose information to professional advisers, authorities where legally required, or a buyer or successor involved in a proposed business transaction. We do not disclose customer dashboard data for advertising.

5. International transfers

Our primary AWS infrastructure is located in the Europe (Frankfurt) region. Some providers, including Auth0 and analytics providers, may process information in the United States or other countries.

Where European personal data is transferred outside the European Economic Area, we rely on an applicable legal transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where available, or European Commission Standard Contractual Clauses, together with additional safeguards where required.

6. Retention

We keep personal data only as long as reasonably needed for the purposes described above:

Because the connected database remains under the customer’s control, CustomerDashboard does not currently provide a general export of dashboard configurations or cached data.

7. Cookies and analytics

We use necessary cookies and similar technologies for authentication, security, network management, and remembering essential settings. These are required for the Service to work.

With consent where required, we also use Microsoft Clarity, Mixpanel, and Google Analytics to understand visits and product usage. These tools may collect identifiers, IP-derived location, browser and device details, pages or features used, clicks, scrolling, and session information.

We aim to avoid sending database contents, credentials, or sensitive dashboard values to analytics providers. Microsoft Clarity content masking should be used within the Service. Nevertheless, customers should not place analytics identifiers or confidential information in page titles, URLs, event names, or other fields that may be collected automatically.

Where consent is required, optional analytics will be disabled until the user accepts them. Users can reject optional cookies and later change or withdraw their choice through the cookie settings made available on the site. Browser controls can also delete or block cookies, although necessary functions may then stop working.

8. Marketing communications

We may send product news and offers where permitted. Marketing messages will include a way to unsubscribe. Opting out of marketing does not stop necessary account, billing, security, or service messages.

9. Security

We use reasonable technical and organisational measures intended to protect personal data. These include managed cloud infrastructure, authentication through Auth0, access restrictions, and protection of data in transit. No service can guarantee absolute security, and customers remain responsible for limiting database credentials and dashboard access appropriately.

10. Individual rights

Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or obtain a copy of their personal data; object to certain processing; and withdraw consent at any time. They may also complain to a data-protection authority.

For data controlled by CustomerDashboard, requests may be sent to sales@customerdashboard.io. We may need to verify the requester’s identity.

For data displayed in a customer’s dashboard, requests should normally be sent to that customer. We will assist the customer where required by law.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman: https://tietosuoja.fi/en/home.

11. Children

The Service is intended for business use and is not directed to children. Customers are responsible for determining whether their own use involves children and whether that use is lawful and appropriate for the Service.

12. Changes

We may update this policy to reflect changes to the Service or law. We will post the current version with a revised effective date and provide additional notice where appropriate.

13. Contact

Questions about this policy may be sent to sales@customerdashboard.io.