Privacy Policy
Last updated: July 31, 2026
Overview
DashyCast ("we", "our", or "us") operates the website at dashycast.com and the application at app.dashycast.com. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. By using DashyCast, you agree to the practices described here.
Information We Collect
Account and organization information. When you sign up or join an organization, we collect information such as your name, email address, organization membership, role, invitations, and service settings.
Salesforce connection information. When you connect Salesforce, we store the connection configuration needed to access the reports and dashboards permitted to the integration user. Depending on the connection method, this can include a Salesforce organization identifier, login URL, client identifier, and an encrypted client secret or other authentication credential. We do not collect or store your Salesforce password.
Salesforce report and dashboard data. DashyCast fetches Salesforce Reports and Dashboards API responses to render published charts, tables, metrics, and dashboards. We store a cached copy of each published asset's response, which can include report rows, aggregates, labels, and dashboard metadata. The cached copy is retained until it is refreshed or the asset, Salesforce connection, organization, or account is deleted. An asset marked public can be viewed by anyone with its URL; private assets require an authorized DashyCast organization member.
Product and asset usage data. We collect product analytics such as pages visited and features used. For published assets, we retain daily embed and image-view counts, an asset-specific irreversible viewer identifier used to estimate unique viewers, and normalized referring website domains. We do not retain raw viewer IP addresses or full referring URLs in asset analytics.
Diagnostics and communications. We collect error and diagnostic information and any feedback you submit. We also process email addresses and delivery information for account, invitation, connection, billing, and support messages.
Billing information. Payment is processed by Stripe. We do not store credit card numbers. We receive a customer ID and subscription status from Stripe.
How We Use Your Information
- To provide and operate the DashyCast service
- To authenticate you with Salesforce via OAuth
- To render and serve your published embeds and image URLs
- To process payments and manage your subscription
- To send transactional emails (account, billing, security)
- To diagnose bugs and improve the service
We do not sell your data. We do not use your Salesforce data for any purpose other than rendering your own charts.
Third-Party Services
We use the following third-party services:
- Salesforce — OAuth authentication and data access. Governed by Salesforce's privacy policy.
- Stripe — Payment processing. Governed by Stripe's privacy policy.
- Supabase — Database and authentication infrastructure.
- Vercel — Hosting and edge delivery.
- Resend — Transactional and support email delivery.
- Sentry — Application error monitoring and diagnostics.
- Google Analytics — Website and product usage analytics.
Cookies
We use session cookies to keep you signed in and preference cookies to remember your settings. We do not use third-party advertising cookies. You can clear cookies at any time through your browser settings, though this will sign you out.
Data Retention
We retain account, organization, connection, subscription, and published-asset data for as long as needed to operate the service. Cached Salesforce responses remain associated with a published asset until that asset is refreshed or deleted. Disconnecting Salesforce deletes the connection and its published assets from DashyCast.
If you delete your account, we remove the account and organization data controlled by DashyCast, subject to limited retention needed for security, fraud prevention, billing, legal obligations, and infrastructure backups. Aggregated or de-identified information that no longer identifies you may be retained.
Your Rights
Depending on your location, you may have rights including: access to your data, correction of inaccurate data, deletion of your data, and objection to certain processing. To exercise any of these rights, contact us at the address below.
If you are in the EU or UK, you have rights under GDPR. If you are in California, you have rights under CCPA.
Security
We use industry-standard security practices including encrypted connections (HTTPS), encrypted storage of tokens, and access controls. No system is perfectly secure — if you discover a vulnerability, please contact us responsibly at legal@dashycast.com.
Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or by displaying a notice in the app. Continued use of DashyCast after changes constitutes acceptance.
Contact
Questions about this policy? Email us at legal@dashycast.com.