Privacy policy
Version
What we collect, why we collect it, and what you can do about it.
What we collect
Because you gave it to us — your name, email address, phone number, password (stored only as a hash we cannot reverse), profile picture if you upload one, and your notification preferences.
Because you use the service — which organizations you belong to and your role in each; a record of sign-in attempts, including the IP address and browser; a list of your active sessions; and an audit record of actions taken on your account.
If you turn on two-factor — the secret your authenticator app shares with us, held encrypted, and hashes of your recovery codes.
What we do not collect
No advertising trackers, no third-party analytics on the signed-in parts of the service, and no social-login providers — there is no “sign in with” button here, so no third party is told when you log in.
We do not sell personal data, and we do not share it with anyone for their own marketing.
Why we keep the security records
Sign-in attempts, session records and the audit log exist to answer one question: was that you? They are what makes it possible to tell you that somebody else signed in, to end a session you do not recognize, and to reconstruct what happened if an account is compromised.
The audit log records what was accessed and never what it contained. It holds the identity of a record, not the record.
How long we keep it
Your account data is kept while your account exists.
Audit and authentication records are kept for six years, because the regulations this platform is built for require it. Operational logs are kept for 30 days and then deleted. Database backups roll off after 35 days.
Deletion is enforced by the systems themselves rather than by intention — a retention rule nothing applies is a promise nobody keeps.
Who else sees it
Other members of your organizations — people who administer an organization you belong to can see your name, email address, role, and whether you have two-factor enabled. They cannot see your password, your authenticator secret, your recovery codes, or anything about your other organizations.
Our infrastructure and email providers, only to the extent needed to run the service and deliver messages you asked for. We keep that list deliberately short, and adding to it is a decision we record rather than something that happens because a library was convenient.
Nobody else, unless the law requires it.
How it is protected
Everything is encrypted in transit and at rest. High-value secrets — authenticator seeds, access tokens — are additionally encrypted field by field, so reading the database is not enough to use them. Passwords are hashed, and recovery codes are stored as hashes, which is why we can never show you a recovery code twice.
Access to production data by our own staff is restricted, time-boxed and logged.
What you can do
See and change your details, and end any session, from your account settings. Withdraw marketing consent at any time from privacy settings; it takes effect immediately.
Ask us for a copy of your data, or ask us to delete your account, by emailing support@dashfordevs.com. Some records — the audit and authentication log in particular — are kept for their retention period even after an account closes, because we are required to keep them.
Health information
This service is built to handle health information under HIPAA where a customer’s agreement with us covers it. The accounts service itself holds no health information: it controls access to systems that may, and holds none of its own.
Where health information is involved, the relevant notice and business associate agreement govern, not this page.
Changes
If this policy changes materially we will say so, and the version stamp above will change with it.