You can request deletion of your Dashpoint account through the public account deletion page.
Data protection
Data Privacy Statement – Dashpoint GmbH
Version: 11 September 2026
This data privacy statement explains how Dashpoint GmbH, Freisinger Landstraße 25, 85748 Garching bei München (“Dashpoint”, “we”, “us”) processes personal data when you use our websites, web and mobile applications, APIs, and event, ticketing, community, organiser, analytics and AI features (the “Services”).
Legal Notice: This is a user-friendly translation. The legally binding version is the German text above. In case of any discrepancies, the German version shall prevail. German law applies.
Controller (Art. 4 No. 7 GDPR)
1. Role Model (Platform / Organizer)
For platform-related data (account, security, billing, fraud prevention), we act as independent controller.
For event and participant data, the respective organizerreceives the information for event execution as independent controller. Dashpoint also processes this data partly as processorof the organizer (Art. 28 GDPR, data processing agreement).
2. Categories of Personal Data
Account Data: Name, email, password hash, organization/access rights, settings
Guest/Session Data: Anonymous technical identity, session identifier, consent status and basket status
Event/Ticket Data: Orders, categories/seats, discount codes, wallet, claim, transfer, resale, refund, check-in history, participant information (name, email, phone number, optional form fields)
Payment/Transaction Data: Payment status, amounts, transaction IDs, timestamps from payment service providers (esp.Stripe). We do not store complete card data.
Communication Data: Support requests, chat/email metadata
Instagram support: When a business connects its Instagram account to Dashpoint, Meta provides account and sender identifiers, message content, timestamps and delivery information. We process these data to assign conversations to the correct organisation, display them in its support inbox and transmit replies. We also process the account name and protected access credentials for the authorised connection. Where Meta provides them, we also show the sender’s name, username, profile picture, follower count, verification status and follow relationships with the business. These details help staff identify the conversation. Authorised staff and the service providers needed to operate the service receive access. The roles, purposes and retention rules in this statement apply.
You can request deletion of your Instagram data without a Dashpoint account through our public deletion instructions. Disconnecting does not automatically delete stored conversations. Copies held independently by Meta or an organiser follow their own procedures.
Location Data: Current location and live location coordinates, accuracy and altitude where you choose to share your location in chats or use location-based map/discovery features. If you grant Always location access, live location sharing in chats may collect location data even when the app is closed or not in use for the duration you choose.
Community and Content Data: Public profiles, posts, memories, Plus One interactions, channels, chats and attachments
Analytics, Intelligence and AI Data: Search queries, interactions, segments, reason codes, inferred preferences, AI inputs and outputs, and session, goal and audit information
Acquisition Data: Publicly available professional contact, company, event and source data, and sending, opening, click, reply and objection status
Feedback/Uploads: Texts, screenshots, files, links, device/browser information; optional AI-supported structuring (Google Vertex AI) and transfer to GitHub
Usage/Log Data: IP address, browser/device information, timestamps, interactions (e.g., checkout progress)
Newsletter Data: Email address, optional salutation/name, and consent and double-opt-in logs (timestamp, IP address, version of the consent text) – see section 15
Admin/Security Data: Audit logs, permissions, security events
Note: Special categories of personal data (Art. 9 GDPR) are not deliberately collected as a platform category. If an organiser asks for such data through its own forms, it must determine the purpose, legal basis and necessity; Dashpoint also fulfils the obligations applicable to its role.
3. Sources of Data
• Directly from you (registration, ticket purchase, support requests)
• From organizer (e.g., guest lists)
• Automatically during use (cookies/SDKs/logs)
• From integrations like Stripe (payment status), Google Firebase/Google Cloud incl. Vertex AI (auth/hosting/DB/analytics/AI), Amazon Web Services (SES) (email sending and technical assets), Google Maps and Mapbox (maps/geocoding), Vercel (hosting/CDN), GitHub (issue/feedback management), and Firecrawl (user-triggered web research)
• From permitted public sources for individual B2B business development
4. Purposes & Legal Bases
| Purpose | Legal Basis |
|---|---|
| AI-assisted search, support, analytics, suggestions and intelligence profiles | Art. 6(1)(b)/(f) GDPR; consent where required for a specific optional feature |
| Individual contact with prospective organisers using public professional sources | Art. 6(1)(f) GDPR; electronic advertising only where additionally permitted under section 7 UWG |
| Provision and operation of services (account, ticketing, check-in, fraud protection) | Art. 6 para. 1 lit. b GDPR |
| Payment processing via Stripe / payouts to organizers | Art. 6 para. 1 lit. b GDPR |
| Organizer tools (event management, communication, analytics) | Art. 6 para. 1 lit. b/f GDPR |
| Support and dispute management | Art. 6 para. 1 lit. b/f GDPR |
| Location-based features and live location sharing in chats, including background updates while active | Art. 6 para. 1 lit. a/b GDPR |
| Product improvement, AI-supported feedback triage | Art. 6 para. 1 lit. f GDPR |
| Security/system notifications | Art. 6 para. 1 lit. b GDPR |
| Marketing/newsletter (with consent) | Art. 6 para. 1 lit. a GDPR |
| Legal obligations (tax, accounting, AML, compliance) | Art. 6 para. 1 lit. c GDPR |
| Law enforcement / abuse prevention | Art. 6 para. 1 lit. f GDPR |
5. Data Sharing
• To organizers: for event execution (own responsibility)
• To chat participants: when you send or share your current/live location in a chat, the location is visible to the people in that chat for the sharing duration. We do not use this location data to provide ads.
• To processors: hosting/CDN ( Vercel), auth/DB/storage/functions/analytics/AI (Firebase/Google Cloud, Google Vertex AI), email sending and technical assets ( Amazon Web Services/SES/S3), maps and geocoding ( Google Maps, Mapbox), payments (Stripe), feedback/issue management (GitHub), user-triggered web research ( Firecrawl), and further IT/support/monitoring service providers. The role, contractual basis and transfer mechanism depend on the specific processing.
• To authorities or claimants: if legally required or for legal defense
• In anonymized/aggregated form: for statistics without personal reference
Important: We do not sell personal data.
6. International Data Transfers
Some recipients may process data outside the EEA (e.g., Stripe, Google Firebase, Vercel). Transfers only take place in accordance with Chapter V GDPR, in particular on the basis of an applicable adequacy decision or Standard Contractual Clauses with any necessary supplementary measures.
You may request a copy of the relevant safeguards from the privacy contact. Providers, subprocessors, certification status and transfer assessments are maintained in our provider register.
7. Storage Duration
• Account data: until account deletion or the end of the contract; necessary evidence is kept afterwards only while statutory obligations or claims remain
• Ticket/transaction data: accounting records subject to retention under commercial and tax law; unnecessary detail data is deleted sooner
• Feedback/support: until completion plus a documented short evidence period; unnecessary attachments are deleted sooner
• Logs/analytics: short periods graduated by purpose and risk; longer retention only for specific security incidents or legal claims
• Live location: live updates stop when the timer ends or you stop sharing. The resulting chat message follows chat/channel retention.
• Location summary: until reset, deactivation or fulfilment of purpose; stored observations and the summary can be deleted in the AI/location settings.
• Acquisition profiles and objections: until objection, identified unsuitability or expiry of the review period; a minimised suppression record may be retained longer to honour the objection.
• Longer storage: as long as legal claims exist or legally required.
8. Security
We use encryption (transport/rest), role-based access, secret management, logging, vulnerability management and regular access controls.
No system is absolutely secure; please use secure passwords and enable security features.
9. Cookies & Similar Technologies
We use essential cookies (e.g., session, checkout).
Non-essential cookies/tracking are only set with your consent (§ 25 TDDDG). You can manage/revoke consents in the consent banner.
Analytics includes Firebase Analytics and Google Analytics 4 for product measurement. Organisers may configure advertising pixels from Meta, Google, X, and TikTok for their public organiser pages, event pages, and checkout. These provider pixels are loaded only when marketing consent is allowed. Organisers remain responsible for their own campaign purposes and controller obligations.
Provider processing may involve international transfers. Where required, we rely on consent, contractual safeguards, and provider transfer mechanisms. You can withdraw non-essential analytics and marketing consent at any time under Settings → Privacy settings.
10. Your Rights
You have the following rights under GDPR:
• Access, rectification, erasure, restriction, data portability
• Objection (Art. 21 GDPR)
• Withdrawal of given consents
• Complaint to a supervisory authority, e.g.:
Direct marketing: You may object at any time, without giving reasons, to processing of your data for direct marketing. After your objection, we no longer use your data for that purpose; a minimised suppression record may remain so that we can honour the objection permanently.
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach, Germany
11. Children
Our services are not directed at persons under 16 years of age. If we detect corresponding use, we delete the data and may block access.
12. Automated Decisions
No exclusively automated decisions with legal effect. Fraud/risk assessments may be automated, with human review.
13. Third-Party Services/Links
For external services (e.g., Stripe Checkout, form services), their privacy notices apply.
14. Changes
We adapt this statement when legal or organizational framework conditions change. We inform about material changes in advance.
15. Newsletter, Double-Opt-In, Existing-Customer Advertising & B2B Acquisition
When you sign up for the newsletter of an organisation/organizer or of Dashpoint, we process your email address and – where provided – salutation and name to send the respective emails.
Double-Opt-In (DOI): Sign-up generally uses the double-opt-in procedure. After you enter your details, we send you an email with a confirmation link; only after your confirmation do we add you to the distribution list. If confirmation is not provided, the entry is deleted after a reasonable period.
Proof of consent (logging): To meet our accountability obligations (Art. 5(2), Art. 7(1) GDPR) we log the sign-up and confirmation time, the IP address used, and the version of the consent text shown at the time of consent.
Legal basis: Your consent (Art. 6(1)(a) GDPR). For advertising to existing customers for our own similar goods/services, processing may additionally be based on § 7(3) UWG in conjunction with Art. 6(1)(f) GDPR.
Roles: For an organizer newsletter, the organizer is the independent controller for content and sending purpose; Dashpoint provides the technical sending and consent infrastructure and acts as processor in this respect (Art. 28 GDPR).
Individual B2B acquisition: We may use publicly available professional contact data to offer an individually prepared organiser preview. This only takes place where the specific contact is permitted under Art. 6(1)(f) GDPR and the additional requirements of section 7 UWG. Every acquisition email contains an individual objection link; a confirmed objection suppresses further acquisition messages for that lead.
Withdrawal/unsubscribe: You can withdraw receipt at any time for the future – via the unsubscribe or objection link in the relevant email or by message to support@dashpoint.app. We document the withdrawal and retain it for evidence purposes. The lawfulness of processing carried out until withdrawal remains unaffected.
