Legal & compliance
Policy

Privacy Policy

Effective June 2026

Policy scope. This Privacy Policy should be read alongside our Terms of Service and Refund Policy, which together govern your use of the AshBoard platform.

1. Introduction

AshBoard (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the AshBoard platform (the “Service”).

By using the Service, you agree to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide

  • Name
  • Email address
  • Account credentials
  • Billing information (processed via third-party payment processors)
  • Any content you submit to the platform

2.2 Automatically Collected Information

  • IP address
  • Device and browser information
  • Usage data and interaction logs
  • Session activity

2.3 Third-Party Information

We may receive information from third-party services integrated with your account (e.g., authentication providers, analytics tools, or payment processors).

3. How We Use Information

We use collected information to:

  • Provide and operate the Service
  • Process transactions and subscriptions
  • Improve platform functionality and user experience
  • Monitor security and prevent abuse
  • Communicate with users regarding updates, support, and service notices
  • Comply with legal obligations

4. Legal Basis for Processing (where applicable)

We process personal data based on:

  • Contractual necessity (providing the Service)
  • Legitimate business interests (security, improvement, analytics)
  • Legal obligations
  • User consent (where required)

5. Data Sharing

We do not sell personal data. We may share information with:

  • Payment processors (e.g., Paddle) for billing
  • Cloud infrastructure providers for hosting
  • Analytics providers for usage insights
  • Legal authorities when required by law

All third-party providers are required to process data securely and only for specified purposes.

6. Data Retention

We retain personal data only as long as necessary to:

  • Provide the Service
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements

7. Data Security

We implement reasonable technical and organizational measures to protect data, including encryption, access controls, and monitoring systems. However, no system is completely secure, and we cannot guarantee absolute security.

8. International Data Transfers

Your information may be processed in countries other than your own. Where applicable, we take steps to ensure appropriate safeguards for cross-border data transfers.

9. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access your personal data
  • Request correction or deletion
  • Object to processing
  • Request data portability

To exercise these rights, contact us at the email below.

10. Cookies and Tracking

We may use cookies and similar technologies to:

  • Maintain session state
  • Improve performance
  • Analyze usage patterns

You may control cookies through your browser settings. For full details, see our Cookie Policy.

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.

12. Changes to This Policy

We may update this Privacy Policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact

For privacy-related inquiries:


14. GDPR and UK GDPR Compliance

Where applicable, AshBoard complies with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK General Data Protection Regulation (“UK GDPR”). This section applies to individuals located in the European Economic Area (EEA) and the United Kingdom.

14.1 Data Controller

For the purposes of applicable data protection laws, AshBoard acts as the “data controller” of personal data collected through the Service, unless otherwise stated. Contact: support@ashboard.io.

14.2 Legal Basis for Processing

We process personal data under one or more of the following lawful bases:

  • Contractual necessity: to provide and maintain the Service
  • Legitimate interests: to improve the Service, ensure security, and prevent fraud
  • Legal obligation: where processing is required by applicable law
  • Consent: where you have explicitly provided consent (e.g., marketing communications)

Where processing is based on consent, you may withdraw consent at any time.

14.3 Your Rights Under GDPR / UK GDPR

If you are located in the EEA or United Kingdom, you have the following rights:

  • Right of access: request a copy of your personal data
  • Right to rectification: request correction of inaccurate data
  • Right to erasure: request deletion of your personal data (“right to be forgotten”)
  • Right to restrict processing: limit how your data is processed
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interests or direct marketing
  • Right to withdraw consent: where processing is based on consent

14.4 International Data Transfers

Where personal data is transferred outside the EEA or United Kingdom, we ensure appropriate safeguards are in place, which may include Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum (where applicable), or transfers to jurisdictions recognized as providing adequate protection.

14.5 Data Processors

We may engage third-party service providers (“processors”) to process personal data on our behalf, including cloud hosting providers, payment processors (e.g., Paddle), and analytics and monitoring services. All processors are contractually required to process personal data only in accordance with our instructions and applicable data protection laws.

14.6 Data Protection Complaints

If you believe your data protection rights have been violated, you may contact us directly first. You also have the right to lodge a complaint with your local supervisory authority:

  • For EU users: your local Data Protection Authority (DPA)
  • For UK users: the Information Commissioner's Office (ICO) — ico.org.uk