Privacy Policy
Last updated:
This Privacy Policy explains how Szara Sowa Development - Władysław Kłaczkow collects, uses, shares, and protects information when you use the EventDash website and analytics service (the "Service").
EventDash is a privacy-first product analytics platform. We collect as little personal data as we need to run the Service, and we design the tracker so customers can understand product usage without relying on third-party advertising cookies.
Who we are and our roles
The Service is operated by Szara Sowa Development - Władysław Kłaczkow, with its place of business at Stefana Batorego 18/108, 02-591 Warszawa, Poland (European Union). EventDash is the product name of the Service. In this policy, "EventDash", "we", "us", or "our" means the operator. You can contact us at contact@eventda.sh. The Service is available at https://www.eventda.sh/.
Our data-protection role depends on whose information is involved:
- Account, billing, and website visitors. When you create an EventDash account, pay for a plan, contact us, or browse our marketing site or dashboard, we decide how that information is processed. We are the data controller for that information.
- Analytics event data from your product. When you install our tracker or send events through our API, we process end-user event data on your instructions so you can see dashboards, funnels, and reports. For that information, you are the controller and EventDash is the processor.
If you need a data processing agreement for analytics data, email contact@eventda.sh.
Information we collect as controller
Account information
When you sign up or update your profile, we collect:
- Email address
- Name
- Password (stored as a hash by our authentication provider; we do not store plaintext passwords)
- Optional profile photo
- Authentication provider (email and password, or Google if you choose Google sign-in)
Billing information
Paid plans are billed through Stripe. Stripe processes payment card details. We do not store full card numbers. We receive and store:
- Stripe customer and subscription identifiers
- Plan tier, billing interval, and subscription status
- Limited payment history needed to provide the Service (for example, period end dates)
Support and contact information
If you use the contact form or email us, we collect your name, email address, and message so we can reply. We also send a confirmation email.
Service usage data
When you use our website or dashboard, we automatically collect technical information such as IP address, browser type, device type, pages visited, and timestamps. We use this to operate, secure, and improve the Service, including rate limiting abuse of public endpoints.
Emails we send
We send transactional email only: account security (for example, confirmation and password reset), billing notices, and support replies. We do not operate a marketing mailing list. See our email preferences page for details.
Analytics event data we process for customers
When a customer uses EventDash on their website or app, we process event data they send or that our tracker collects, which may include:
- Event names, types, and timestamps
- Page URLs, titles, and navigation metadata
- Referrer and campaign parameters
- Device, browser, and operating system
- Approximate location derived from IP (country and city)
- IP address (used for location, security, and rate limiting)
- Anonymous session identifiers stored in the customer's site localStorage
- Device characteristics used to keep sessions stable (browser, OS, screen, timezone, language, and rendering hashes). This is not used to identify a person and is not linked to an EventDash login
- Custom properties and events the customer explicitly sends
- Optional error and performance metrics, depending on the customer's plan
By default the tracker:
- Does not require cookies
- Filters common personal data from URLs and form fields (for example email addresses, phone numbers, payment card numbers, and similar secrets)
- Honors the browser Do Not Track (DNT) setting unless the customer disables that option
Filtering reduces accidental collection. It is not a guarantee that no personal data will ever be sent. Customers must not include personal data in event names or custom properties, and they are responsible for a lawful basis, notices, and any required consent for tracking on their own properties.
How we use information
We use information to:
- Create and manage accounts, apps, API keys, and domain allowlists
- Ingest events, enforce plan quotas, and show dashboards, goals, and funnels
- Process subscriptions, invoices, and plan changes through Stripe
- Send transactional email and respond to support requests
- Secure the Service, prevent abuse, and debug failures
- Improve the product based on how the Service is used
- Comply with law and enforce our Terms of Service
Legal bases (EEA, UK, and similar jurisdictions)
Where data-protection law requires a legal basis, we rely on:
- Contract. To provide the Service you asked for (account, tracking, dashboards, billing).
- Legitimate interests. To secure, operate, and improve the Service, provided those interests are not overridden by your rights.
- Legal obligation. To keep records required by tax or other law.
- Consent. Where we ask for it, or where a customer relies on consent for their own tracking. You can withdraw consent at any time without affecting processing already carried out.
Cookies and similar technologies
The EventDash tracker does not require cookies. Anonymous session IDs for customer sites are stored in that site's localStorage.
Our own website and dashboard use a small number of strictly necessary cookies and similar storage:
- Authentication cookies set by our auth provider (Supabase) so you can stay signed in to the dashboard.
- sidebar_state — remembers whether the dashboard sidebar is open (7 days).
- Theme preference — stored in localStorage so the interface can follow light, dark, or system mode.
These are needed to run the Service. We do not use advertising cookies, and we do not sell personal information.
How we share information
We do not sell personal information. We share information only with service providers that help us operate the Service, and only as needed for that work:
- Supabase — authentication, database, and file storage (including profile photos).
- Stripe — payment processing and subscription billing. Stripe Privacy Policy.
- Resend — transactional email delivery.
- Vercel — application hosting, including IP-based country and city headers used for analytics location.
- Google — if you sign in with Google, Google processes that sign-in under its own terms. If you connect Google Search Console, we store encrypted OAuth tokens, pull indexation and search-performance data, and can submit your sitemap on your behalf.
We may also disclose information if required by law, to protect the Service or users, or as part of a merger, acquisition, or asset sale, in which case we will take reasonable steps to keep the information protected.
International transfers
We are established in Poland, in the European Union. Some of our providers may process information in the United States and other countries outside the EEA. Those countries may not provide the same legal protections as EU law. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses used by our providers, together with the security measures described below.
Retention
We keep information only as long as needed:
- Account data — until you delete your account, plus a short period needed to complete deletion and close billing.
- Raw event detail — 30 days on the Free plan and 90 days on Standard and Professional plans, after which raw rows are removed.
- Aggregated chart history — dashboard rollups may remain after raw events age out so longer-term trends can still be shown.
- Billing records — as required by tax and accounting law.
- Support messages — as long as needed to handle your request and maintain a support history.
Security
No method of transmission or storage is completely secure. We use commercially reasonable technical and organizational measures, including:
- Encryption in transit (HTTPS)
- Access controls and authenticated APIs
- API keys and optional domain allowlisting for event ingest
- Rate limiting on public endpoints
- Automatic filtering of common personal data in tracker payloads
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal data, to object to or restrict certain processing, and to withdraw consent. You also have the right not to be discriminated against for exercising privacy rights.
You can update profile details and delete your account in dashboard settings. Deleting your account cancels any active subscription and removes associated apps, events, and profile data. Standard and Professional plans can also export analytics data from the Service.
To make a privacy request, email contact@eventda.sh. We may need to verify that the request comes from the account holder. If we process analytics data for a customer, we will direct end-user requests to that customer where appropriate.
If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. Our lead supervisory authority in Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
California (CCPA / CPRA)
We do not sell personal information and we do not share it for cross-context behavioral advertising. California residents may request disclosure or deletion of personal information we hold as controller by emailing contact@eventda.sh.
Children
The Service is built for businesses and product teams. It is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact contact@eventda.sh and we will delete it.
Changes
We may update this Privacy Policy from time to time. We will post the updated policy on this page and change the "Last updated" date. If a change is material, we will also provide additional notice (for example by email or an in-product message) where appropriate. Continued use of the Service after the updated policy takes effect means you accept the changes.
Contact
Questions about this Privacy Policy or privacy requests can be sent to the controller:
Szara Sowa Development - Władysław KłaczkowStefana Batorego 18/108
02-591 Warszawa
Poland
Email: contact@eventda.sh