Privacy Policy
Effective and last updated: July 31, 2026
This GDPR-aware policy describes DashCaddy v1.0. It is not legal advice and may be refined following professional review.
1. Controller and contact
Sami Ahmed, operator of DashCaddy, controls personal data collected for subscriptions, licensing, and operation. Contact privacy@sami-ahmed.net. DashCaddy has no separate Data Protection Officer; this is the privacy contact.
2. Data collected
Account, login, and billing
- Email address for login, license delivery, support, billing, and essential notices.
- Subscription status, Stripe customer/session IDs, product, payment status, dates, and refunds. We do not receive or store full card numbers or security codes.
License and server metadata
- License key, tier, activation/expiry dates, and machine/host metadata embedded in or associated with the license.
- Connection metadata needed to validate and secure licenses, such as IP address, timestamp, host/machine identifier, version, and request outcome.
- The key containing machine metadata is stored locally in
data/credentials.jsonand on the operator’s license server.
Optional Tailscale data
Only if enabled, DashCaddy sends coordination API requests and may process Tailscale device IDs, tailnet/user IDs, names/status, and minted device or pre-auth keys. Keys are stored only as needed for the configured integration or share flow. Tailscale independently processes data under its terms.
Support
We collect messages and diagnostics you voluntarily provide. Do not send passwords, private keys, or unrelated personal data.
3. Data not intentionally collected
The hosted licensing service does not intentionally collect proxied content, DNS query history, injected credentials, or card details. Credentials and local configuration remain customer-controlled unless deliberately provided for support. v1.0 makes no automated decisions with legal or similarly significant effects.
4. Purposes and GDPR lawful bases
- Contract: licenses, authentication, optional features, billing/refunds, and support.
- Legitimate interests: per-host enforcement, fraud/abuse prevention, security, troubleshooting, and proportionate product improvement.
- Legal obligation: required transaction/tax records and valid legal requests.
- Consent: optional marketing and integrations where consent is appropriate. Consent may be withdrawn without affecting earlier lawful processing.
5. Sharing and processors
We do not sell personal data. Necessary disclosures are to:
- Stripe for Checkout, billing, fraud prevention, receipts, and refunds. Card data goes directly to Stripe.
- Tailscale only when you configure/use the integration, for coordination and device/key operations.
- Our email delivery provider for login, license, billing, security, and support email; it receives the address and message content.
We may disclose data when legally required, to protect rights/safety, or in a business transfer with safeguards. We do not otherwise share personal data except as described in this policy.
6. International transfers
Processors may handle data outside your country. Where GDPR applies, we will use a legally recognized transfer mechanism where one is required, such as an adequacy decision or Standard Contractual Clauses. Contact us for information about safeguards applicable to your data.
7. Retention
- License keys and host metadata: life of subscription plus 30 days after cancellation, then deleted or irreversibly anonymized unless law requires longer.
- Billing records: as required for tax, accounting, chargebacks, and fraud prevention.
- Connection/security logs: normally no more than 30 days unless an incident requires preservation.
- Support records: while active and normally up to 12 months afterward.
- Optional Tailscale keys: until expired, used/revoked, share removal, or integration disablement, subject to Tailscale retention.
Backups may retain deleted data for a limited rotation and are restored only for disaster recovery.
8. Security
We use reasonable safeguards and data minimization, but no system is completely secure. DashCaddy does not claim SOC 2, HIPAA, PCI-DSS, or another audited certification. Stripe Checkout processes cards; card data never touches DashCaddy servers.
9. GDPR and other privacy rights
Depending on location, you may request access, correction, deletion, restriction, objection, withdrawal of consent, and data portability in a structured machine-readable format, and complain to your supervisory authority. Email privacy@sami-ahmed.net with “Privacy Request.” We may verify identity. We aim to respond within 30 days (one month), explain lawful extensions/refusals, and normally charge no fee. Without a central account, we search using identifiers you provide.
10. Children, cookies, and marketing
DashCaddy is not directed to children under 16. Checkout/login may use strictly necessary cookies. We request consent before non-essential analytics/marketing cookies where required. Marketing email is optional and includes unsubscribe.
11. Changes and contact
Revisions will show a new date, with reasonable notice for material changes. Questions and rights requests: privacy@sami-ahmed.net.