Dashpoint logo

You can request deletion of your Dashpoint account through the public account deletion page.

Data protection

Data Privacy Statement – Dashpoint GmbH

Version: 11 September 2026

This data privacy statement explains how Dashpoint GmbH, Freisinger Landstraße 25, 85748 Garching bei München (“Dashpoint”, “we”, “us”) processes personal data when you use our websites, web and mobile applications, APIs, and event, ticketing, community, organiser, analytics and AI features (the “Services”).

Legal Notice: This is a user-friendly translation. The legally binding version is the German text above. In case of any discrepancies, the German version shall prevail. German law applies.

Controller (Art. 4 No. 7 GDPR)

Dashpoint GmbH

Freisinger Landstraße 25

85748 Garching bei München

Germany

Email: support@dashpoint.app

1. Role Model (Platform / Organizer)

For platform-related data (account, security, billing, fraud prevention), we act as independent controller.

For event and participant data, the respective organizerreceives the information for event execution as independent controller. Dashpoint also processes this data partly as processorof the organizer (Art. 28 GDPR, data processing agreement).

2. Categories of Personal Data

Account Data: Name, email, password hash, organization/access rights, settings

Guest/Session Data: Anonymous technical identity, session identifier, consent status and basket status

Event/Ticket Data: Orders, categories/seats, discount codes, wallet, claim, transfer, resale, refund, check-in history, participant information (name, email, phone number, optional form fields)

Payment/Transaction Data: Payment status, amounts, transaction IDs, timestamps from payment service providers (esp.Stripe). We do not store complete card data.

Communication Data: Support requests, chat/email metadata

Instagram support: When a business connects its Instagram account to Dashpoint, Meta provides account and sender identifiers, message content, timestamps and delivery information. We process these data to assign conversations to the correct organisation, display them in its support inbox and transmit replies. We also process the account name and protected access credentials for the authorised connection. Where Meta provides them, we also show the sender’s name, username, profile picture, follower count, verification status and follow relationships with the business. These details help staff identify the conversation. Authorised staff and the service providers needed to operate the service receive access. The roles, purposes and retention rules in this statement apply.

You can request deletion of your Instagram data without a Dashpoint account through our public deletion instructions. Disconnecting does not automatically delete stored conversations. Copies held independently by Meta or an organiser follow their own procedures.

Location Data: Current location and live location coordinates, accuracy and altitude where you choose to share your location in chats or use location-based map/discovery features. If you grant Always location access, live location sharing in chats may collect location data even when the app is closed or not in use for the duration you choose.

Community and Content Data: Public profiles, posts, memories, Plus One interactions, channels, chats and attachments

Analytics, Intelligence and AI Data: Search queries, interactions, segments, reason codes, inferred preferences, AI inputs and outputs, and session, goal and audit information

Acquisition Data: Publicly available professional contact, company, event and source data, and sending, opening, click, reply and objection status

Feedback/Uploads: Texts, screenshots, files, links, device/browser information; optional AI-supported structuring (Google Vertex AI) and transfer to GitHub

Usage/Log Data: IP address, browser/device information, timestamps, interactions (e.g., checkout progress)

Newsletter Data: Email address, optional salutation/name, and consent and double-opt-in logs (timestamp, IP address, version of the consent text) – see section 15

Admin/Security Data: Audit logs, permissions, security events

Note: Special categories of personal data (Art. 9 GDPR) are not deliberately collected as a platform category. If an organiser asks for such data through its own forms, it must determine the purpose, legal basis and necessity; Dashpoint also fulfils the obligations applicable to its role.

3. Sources of Data

• Directly from you (registration, ticket purchase, support requests)

• From organizer (e.g., guest lists)

• Automatically during use (cookies/SDKs/logs)

• From integrations like Stripe (payment status), Google Firebase/Google Cloud incl. Vertex AI (auth/hosting/DB/analytics/AI), Amazon Web Services (SES) (email sending and technical assets), Google Maps and Mapbox (maps/geocoding), Vercel (hosting/CDN), GitHub (issue/feedback management), and Firecrawl (user-triggered web research)

• From permitted public sources for individual B2B business development

4. Purposes & Legal Bases

PurposeLegal Basis
AI-assisted search, support, analytics, suggestions and intelligence profilesArt. 6(1)(b)/(f) GDPR; consent where required for a specific optional feature
Individual contact with prospective organisers using public professional sourcesArt. 6(1)(f) GDPR; electronic advertising only where additionally permitted under section 7 UWG
Provision and operation of services (account, ticketing, check-in, fraud protection)Art. 6 para. 1 lit. b GDPR
Payment processing via Stripe / payouts to organizersArt. 6 para. 1 lit. b GDPR
Organizer tools (event management, communication, analytics)Art. 6 para. 1 lit. b/f GDPR
Support and dispute managementArt. 6 para. 1 lit. b/f GDPR
Location-based features and live location sharing in chats, including background updates while activeArt. 6 para. 1 lit. a/b GDPR
Product improvement, AI-supported feedback triageArt. 6 para. 1 lit. f GDPR
Security/system notificationsArt. 6 para. 1 lit. b GDPR
Marketing/newsletter (with consent)Art. 6 para. 1 lit. a GDPR
Legal obligations (tax, accounting, AML, compliance)Art. 6 para. 1 lit. c GDPR
Law enforcement / abuse preventionArt. 6 para. 1 lit. f GDPR

5. Data Sharing

To organizers: for event execution (own responsibility)

To chat participants: when you send or share your current/live location in a chat, the location is visible to the people in that chat for the sharing duration. We do not use this location data to provide ads.

To processors: hosting/CDN ( Vercel), auth/DB/storage/functions/analytics/AI (Firebase/Google Cloud, Google Vertex AI), email sending and technical assets ( Amazon Web Services/SES/S3), maps and geocoding ( Google Maps, Mapbox), payments (Stripe), feedback/issue management (GitHub), user-triggered web research ( Firecrawl), and further IT/support/monitoring service providers. The role, contractual basis and transfer mechanism depend on the specific processing.

To authorities or claimants: if legally required or for legal defense

In anonymized/aggregated form: for statistics without personal reference

Important: We do not sell personal data.

6. International Data Transfers

Some recipients may process data outside the EEA (e.g., Stripe, Google Firebase, Vercel). Transfers only take place in accordance with Chapter V GDPR, in particular on the basis of an applicable adequacy decision or Standard Contractual Clauses with any necessary supplementary measures.

You may request a copy of the relevant safeguards from the privacy contact. Providers, subprocessors, certification status and transfer assessments are maintained in our provider register.

7. Storage Duration

Account data: until account deletion or the end of the contract; necessary evidence is kept afterwards only while statutory obligations or claims remain

Ticket/transaction data: accounting records subject to retention under commercial and tax law; unnecessary detail data is deleted sooner

Feedback/support: until completion plus a documented short evidence period; unnecessary attachments are deleted sooner

Logs/analytics: short periods graduated by purpose and risk; longer retention only for specific security incidents or legal claims

Live location: live updates stop when the timer ends or you stop sharing. The resulting chat message follows chat/channel retention.

Location summary: until reset, deactivation or fulfilment of purpose; stored observations and the summary can be deleted in the AI/location settings.

Acquisition profiles and objections: until objection, identified unsuitability or expiry of the review period; a minimised suppression record may be retained longer to honour the objection.

Longer storage: as long as legal claims exist or legally required.

8. Security

We use encryption (transport/rest), role-based access, secret management, logging, vulnerability management and regular access controls.

No system is absolutely secure; please use secure passwords and enable security features.

9. Cookies & Similar Technologies

We use essential cookies (e.g., session, checkout).

Non-essential cookies/tracking are only set with your consent (§ 25 TDDDG). You can manage/revoke consents in the consent banner.

Analytics includes Firebase Analytics and Google Analytics 4 for product measurement. Organisers may configure advertising pixels from Meta, Google, X, and TikTok for their public organiser pages, event pages, and checkout. These provider pixels are loaded only when marketing consent is allowed. Organisers remain responsible for their own campaign purposes and controller obligations.

Provider processing may involve international transfers. Where required, we rely on consent, contractual safeguards, and provider transfer mechanisms. You can withdraw non-essential analytics and marketing consent at any time under Settings → Privacy settings.

10. Your Rights

You have the following rights under GDPR:

• Access, rectification, erasure, restriction, data portability

• Objection (Art. 21 GDPR)

• Withdrawal of given consents

• Complaint to a supervisory authority, e.g.:

Direct marketing: You may object at any time, without giving reasons, to processing of your data for direct marketing. After your objection, we no longer use your data for that purpose; a minimised suppression record may remain so that we can honour the objection permanently.

Bavarian State Office for Data Protection Supervision (BayLDA)

Promenade 18, 91522 Ansbach, Germany

www.lda.bayern.de

11. Children

Our services are not directed at persons under 16 years of age. If we detect corresponding use, we delete the data and may block access.

12. Automated Decisions

No exclusively automated decisions with legal effect. Fraud/risk assessments may be automated, with human review.

13. Third-Party Services/Links

For external services (e.g., Stripe Checkout, form services), their privacy notices apply.

14. Changes

We adapt this statement when legal or organizational framework conditions change. We inform about material changes in advance.

15. Newsletter, Double-Opt-In, Existing-Customer Advertising & B2B Acquisition

When you sign up for the newsletter of an organisation/organizer or of Dashpoint, we process your email address and – where provided – salutation and name to send the respective emails.

Double-Opt-In (DOI): Sign-up generally uses the double-opt-in procedure. After you enter your details, we send you an email with a confirmation link; only after your confirmation do we add you to the distribution list. If confirmation is not provided, the entry is deleted after a reasonable period.

Proof of consent (logging): To meet our accountability obligations (Art. 5(2), Art. 7(1) GDPR) we log the sign-up and confirmation time, the IP address used, and the version of the consent text shown at the time of consent.

Legal basis: Your consent (Art. 6(1)(a) GDPR). For advertising to existing customers for our own similar goods/services, processing may additionally be based on § 7(3) UWG in conjunction with Art. 6(1)(f) GDPR.

Roles: For an organizer newsletter, the organizer is the independent controller for content and sending purpose; Dashpoint provides the technical sending and consent infrastructure and acts as processor in this respect (Art. 28 GDPR).

Individual B2B acquisition: We may use publicly available professional contact data to offer an individually prepared organiser preview. This only takes place where the specific contact is permitted under Art. 6(1)(f) GDPR and the additional requirements of section 7 UWG. Every acquisition email contains an individual objection link; a confirmed objection suppresses further acquisition messages for that lead.

Withdrawal/unsubscribe: You can withdraw receipt at any time for the future – via the unsubscribe or objection link in the relevant email or by message to support@dashpoint.app. We document the withdrawal and retain it for evidence purposes. The lawfulness of processing carried out until withdrawal remains unaffected.

16. Contact

Dashpoint GmbH

Freisinger Landstraße 25

85748 Garching bei München

Germany

Email: support@dashpoint.app

Data Protection Officer:

Erik Lüth

Email: support@dashpoint.app