Privacy policy

Last updated

Who this covers

This policy describes how DashDesk handles data for two groups: the people who sign in to a workspace, and the customers who message a business through a connected channel. The second group never has a DashDesk account, which is why their data is described separately below.

What we collect from account holders

Your email address, your display name, and an avatar URL if your sign-in provider supplies one. We store the workspace you belong to and your role in it. If you sign in with Google or Facebook, we receive your identity from that provider; we do not request access to your Pages or messages at sign-in.

What we receive from connected channels

When a workspace connects WhatsApp Business, Instagram Direct or Facebook Messenger, we receive the messages customers send to that account: message text, attachments, delivery and read status, and the display name and platform identifier the platform provides. This data belongs to the workspace, not to DashDesk.

We do not scrape, purchase, or enrich customer profiles from outside sources. The only profile data DashDesk holds on a customer is what they sent in a conversation, what an agent or the AI recorded as a tag or note, and — where a workspace connects a store — the order history described below.

Customer profiles and CRM data

DashDesk is a CRM, not just a message log: every customer who writes in gets a profile that persists across conversations, carrying their contact details, tags, and internal notes agents leave for each other. Notes are encrypted at rest and are never visible to the customer.

If a workspace connects a Shopify store, that same profile also carries the customer’s order drafts and confirmed orders, so an agent — or the AI — can see order history without leaving the conversation.

How AI processing works

Message text is sent to the AI provider configured for the deployment in order to classify the message, suggest tags, or draft a reply. That text is processed to produce a response and is not used to train models. Triage runs on inbound messages; automatic replies only run when the workspace has enabled them.

Where a workspace connects Shopify and enables AI order handling, the AI additionally reads product and stock data from that store to answer product questions, and can build an order draft from the conversation, confirm it with the customer, and write the confirmed order (or a cancellation) back to Shopify. These actions are gated the same way automatic replies are: off by default, and bounded by the allow-list and confidence settings a workspace Admin configures.

Where data is stored

The API and its realtime gateway run in Frankfurt, Germany. The database is managed Postgres. Channel access tokens are encrypted at rest with AES-256-GCM using a key held in the deployment environment, and are never returned to the browser.

Every tenant table is protected by row-level security, so one workspace cannot read another’s rows even if the application asks for them.

Sharing

We share data with the infrastructure and AI providers needed to run the service, with Meta when sending your replies back through its APIs, and — only for workspaces that connect a store — with Shopify, to read catalog and stock data and to write back the orders and cancellations your workspace confirms. We do not sell data and we do not share it with advertisers.

Retention, export and deletion

Conversation and order history is retained for as long as the workspace exists. A plan change never deletes it. A workspace Admin can export conversation history and can delete a customer along with their history, notes, tags and order records, which removes the records from the database rather than hiding them in the interface.

To delete an entire workspace and everything in it, email support@contact.dashdesk.ahmedsherifnabhan.online from the address of a workspace Admin.

Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Email support@contact.dashdesk.ahmedsherifnabhan.online and we will act on the request. DashDesk has not been through an independent GDPR audit; it describes the controls it actually operates rather than claiming certified compliance.

Contact

Questions about this policy, or about data in a specific workspace, go to support@contact.dashdesk.ahmedsherifnabhan.online.

One CRM inbox. AI that actually replies.

Create a workspace, connect WhatsApp, and watch AI triage, reply to and log every customer automatically.

Free plan, no card required.

Privacy policy · DashDesk