dashboardSMASHBOARD is a Shopify analytics tool. This Privacy Policy explains what data we collect, how we use it, and your rights. We've tried to write it in plain English.
The short version: We use your store data to power your dashboards. We store aggregate metrics, not customer records. We never sell your data. Ever.
We collect three categories of data:
Account data: When you install the app through Shopify, we receive your store name, store URL, and the email address associated with your Shopify account. This is used to identify your account and communicate with you.
Usage data: We collect information about how you use the Service — which dashboards you view, which features you use, and aggregate performance metrics. This data is used to improve the Service.
Shopify store data: To compute your analytics, we access your store's orders, products, and customer data via Shopify's API. See Section 3 for details on how this data is handled.
We use your data to:
We do not use your data for advertising. We do not build profiles of you or your customers for any purpose other than providing the Service.
For users in the EU and UK, we process your personal data on the following legal bases under GDPR Article 6:
This section is the most important one if you operate an EU- or Canada-facing Shopify store.
When you use dashboardSMASHBOARD, we access your Shopify customers' information (names, email addresses, order history) via the API solely to compute aggregate metrics for your dashboards.
What we store: Aggregate figures — totals, averages, counts. Not individual customer records.
What we don't store: Names, email addresses, shipping addresses, or any other personally identifiable information belonging to your customers.
Custom queries: A SmashQL query you write may return individual customer records to your browser session. We do not store those results on our servers. They exist only in your browser for the duration of your session.
Our role: Under GDPR and similar privacy laws, you (the merchant) are the data controller for your customers' information. dashboardSMASHBOARD is a data processor acting on your instructions. We process your customers' data only as directed by your use of the Service and only to the extent necessary to provide it.
If you're in the EU or UK (GDPR): You have the right to access, correct, delete, or export your personal data. You may also object to or restrict certain processing. To exercise any of these rights, email privacy@dashboardsmashboard.com. We will respond within 30 days. If you believe we've violated your rights, you may lodge a complaint with your local Data Protection Authority (DPA).
If you're in Canada (PIPEDA): You have the right to access the personal information we hold about you and to challenge its accuracy. Contact us at the email above. We will respond within 30 days (extendable to 60 days with notice where permitted).
All users: You may request deletion of your account and all associated data at any time. We will complete deletion within 30 days of your request.
Sub-processors: We use Render (render.com) as our hosting provider. Your data is stored on servers in the United States.
International transfers: If you are located in the EU or UK, your data is transferred to the US under Standard Contractual Clauses (SCCs) as provided under GDPR Article 46.
Cookies: We use functional cookies only — session management and preferences. We do not use advertising or tracking cookies.
Data breach notification: In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware, as required by GDPR.
Privacy questions, data subject requests, and legal inquiries:
privacy@dashboardsmashboard.com
This Privacy Policy is governed by the laws of the Commonwealth of Massachusetts. We may update this policy from time to time with at least 30 days' notice for material changes.