ExpoDashExpoDash
HomeFeaturesIntegrationsPricingAffiliateRoadmapContact
Sign inGet started
HomeFeaturesIntegrationsPricingAffiliateRoadmapContact
Sign inGet started
Legal

Privacy Policy

Last updated: June 11, 2026

This Privacy Policy explains how ExpoDash ("we", "us", "our") collects, uses, shares and protects personal data in connection with the ExpoDash service, an online operations dashboard for e-commerce businesses offered at expodash.io (the "Service"), and in connection with our website, sales process and customer support. It also explains the rights you have under the General Data Protection Regulation ("GDPR") and how to exercise them. This Privacy Policy should be read together with our Terms of Service and our Refund Policy.

1. Who we are

The Service is operated by a company established in the Netherlands ("ExpoDash"). Our full legal entity details, including our Chamber of Commerce registration and registered address, are listed in the Contact section at the end of this policy.

ExpoDash is the data controller within the meaning of Article 4(7) GDPR for the personal data we collect and decide on ourselves: account data, billing data, website and usage data, support communications and sales application data, each as described in section 3. For all privacy matters you can reach us at info@expodash.io.

2. Two roles: controller and processor

ExpoDash plays two distinct roles under the GDPR, and it matters which one applies to a given piece of data.

ExpoDash as controller. For the data we collect to run our own business, such as your account details, invoices, log files and support emails, we decide why and how the data is processed. For that data we are the controller, and sections 3 and 4 of this Privacy Policy apply.

ExpoDash as processor.Our customers connect their own third-party accounts to the Service, such as their store platform (such as Shopify), advertising accounts, helpdesk and related tools. The data that flows from those connected accounts into the dashboard, including orders, customer messages, advertising metrics and similar records ("Customer Data"), belongs to the customer. For Customer Data the customer is the controller and ExpoDash acts solely as processor, on the customer's documented instructions. A data processing agreement that meets the requirements of Article 28 GDPR is available on request via info@expodash.io and forms part of the service agreement concluded under our Terms of Service.

If you are a customer of one of our customers, for example a shopper whose order or support message appears in a customer's dashboard, please direct any privacy request to that business. It controls your data; we will assist it in responding, but we cannot answer on its behalf.

3. Data we collect as controller

We collect the following categories of personal data for our own purposes:

  • Account data: name, email address, organization name, role within the organization and authentication data needed to secure your login.
  • Billing data: billing contact details, invoicing details, VAT number where applicable, subscription plan and payment status. Payment card details are handled by our payment processors; we do not store full card numbers.
  • Usage and log data: IP address, device and browser information, actions performed in the Service, timestamps and related technical event logs.
  • Support communications: the content of emails and messages you exchange with our support team, including any attachments you choose to send.
  • Custom plan application data: the information submitted through the Custom plan application form, including company name, number of stores, revenue range, markets served and contact details.

We apply data minimisation: we do not collect more personal data than we need for the purposes set out in section 4.

4. Purposes and legal bases

We process the personal data described in section 3 for the following purposes, each with its legal basis under Article 6 GDPR:

  • Providing the Service: creating and managing accounts, authenticating users and operating the dashboard. Legal basis: performance of a contract (Article 6(1)(b)).
  • Billing and administration: invoicing, collecting payment and keeping required business records. Legal basis: performance of a contract (Article 6(1)(b)) and compliance with legal obligations, including Dutch tax law (Article 6(1)(c)).
  • Security and abuse prevention: monitoring for unauthorized access, fraud and misuse, maintaining audit logs and protecting the Service and its users. Legal basis: our legitimate interest in keeping the Service secure (Article 6(1)(f)).
  • Product improvement: analysing usage in aggregated form to understand how the Service is used and to improve it. Legal basis: our legitimate interest in improving the Service (Article 6(1)(f)). We do not use Customer Data for this purpose other than in aggregated form that does not identify individuals.
  • Service communications: messages about maintenance, changes to the Service, security notices and responses to your support requests. Legal basis: performance of a contract (Article 6(1)(b)) or our legitimate interest in keeping customers informed about the Service (Article 6(1)(f)).
  • Marketing: we send marketing communications only with your consent (Article 6(1)(a)) or, where permitted, under the existing customer relationship exception in Dutch e-privacy rules for similar products and services. Every marketing message contains a working unsubscribe option, and you can opt out at any time.
  • Compliance with law: responding to lawful requests from authorities and meeting statutory retention, accounting and reporting obligations. Legal basis: compliance with legal obligations (Article 6(1)(c)).

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests or fundamental rights and freedoms. You may object to such processing as described in section 10. We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

5. How we handle Customer Data as processor

For Customer Data, the following commitments apply in addition to the data processing agreement:

  • We process Customer Data only to provide the Service and only in accordance with the customer's documented instructions, unless we are required to process it otherwise by law, in which case we will inform the customer unless prohibited.
  • We never sell Customer Data.
  • We never use Customer Data for advertising, profiling for third parties or any purpose of our own beyond providing the Service.
  • Persons authorized to process Customer Data are bound by confidentiality obligations, and access is restricted on a need-to-know basis.
  • Upon termination of the service agreement, Customer Data is deleted in accordance with our Terms of Service: deletion within 30 days after termination, after which residual copies in backup systems rotate out within a bounded period in the ordinary course of our backup cycle.
  • We assist the customer, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification and data protection impact assessments.

6. Sharing and subprocessors

We do not sell personal data. We share personal data only as follows:

  • Subprocessors and service providers, engaged by category: cloud hosting and storage providers, database infrastructure providers, payment processors, email delivery providers and error monitoring providers. Each is bound by a written contract imposing data protection obligations consistent with this Privacy Policy and, for Customer Data, with Article 28 GDPR. The current list of subprocessors is available on request via info@expodash.io.
  • Legal disclosure, where we are required to disclose personal data by law, regulation, court order or a binding request from a competent authority. We disclose no more than is required and, where lawful, we notify the affected customer.
  • Corporate transactions, such as a merger, acquisition or sale of assets, in which case personal data may be transferred to the acquiring entity subject to safeguards at least equivalent to those in this Privacy Policy.

7. International transfers

The Service is hosted with reputable infrastructure providers. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision of the European Commission or, in its absence, on the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organizational measures. You can request information about the safeguards applicable to a specific transfer via info@expodash.io.

8. Retention

We keep personal data no longer than necessary for the purposes for which it was collected, applying the following periods:

  • Account data: for the life of the account, plus up to 12 months after closure to handle residual administration and disputes.
  • Invoices and billing records: 7 years, as required by Dutch tax law.
  • Usage and log data: up to 12 months.
  • Custom plan application data: up to 12 months after our last contact with you.
  • Customer Data: for the duration of the service agreement, then deleted as described in section 5.

After the applicable period, personal data is deleted or irreversibly anonymised.

9. Security

We implement appropriate technical and organizational measures under Article 32 GDPR, including: encryption of data in transit and at rest, encrypted storage of the credentials customers use to connect third-party accounts, role-based access controls, least-privilege access for our staff, logging and monitoring of access to production systems, and a documented incident response process.

In the event of a personal data breach, we notify the competent supervisory authority and, where required, affected individuals in accordance with Articles 33 and 34 GDPR. Where we act as processor, we notify the affected customer without undue delay after becoming aware of a breach affecting Customer Data.

10. Your rights

Where ExpoDash is the controller, you have the following rights under the GDPR: the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object to processing based on legitimate interests, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, email info@expodash.io. We may ask you to verify your identity before acting on a request. We respond within one month; for complex or numerous requests this period may be extended by up to two further months, in which case we will tell you within the first month.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority of the EU member state where you habitually reside or work. We would appreciate the chance to address your concern first, but you are not required to contact us before complaining.

11. Cookies

expodash.io uses only functional cookies that are strictly necessary to deliver the site and the Service, such as session and security cookies. These cookies do not require consent under Dutch law. We do not use advertising or third-party tracking cookies on expodash.io. If this ever changes, we will update this Privacy Policy first and, where required, ask for your consent before placing any non-essential cookie.

12. Not directed at children or consumers

The Service is offered exclusively to businesses and is not directed at consumers or at children. We do not knowingly collect personal data from anyone under 16 years of age for our own purposes. If you believe a child has provided us with personal data, contact info@expodash.io and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect changes in the Service, in our subprocessor categories or in applicable law. The "Last updated" date at the top of this page shows the current version. For material changes we will give customers reasonable advance notice through the Service or by email. Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy, without prejudice to rights you have under mandatory law.

14. Contact

Nielscommerce
Chamber of Commerce (KvK) number: 96111372
Registered address: Braambos 18a, 5563 AB Westerhoven, the Netherlands

  • Privacy requests: info@expodash.io
  • General support: info@expodash.io
  • Billing and refunds: info@expodash.io (see also our Refund Policy)
  • Legal notices: info@expodash.io (see also our Terms of Service)

This Privacy Policy is governed by Dutch law. Disputes that cannot be resolved amicably will be submitted to the competent court in Amsterdam, the Netherlands, without prejudice to your right to complain to the Autoriteit Persoonsgegevens.

ExpoDash

An AI team that runs your store's ads, listings, sourcing, returns, email and support in the background, and only pings you for the few calls a human should make. One screen tells you if everything is under control. Wired into Shopify, Meta and Klaviyo.

info@expodash.io
Product
  • Features
  • Pricing
  • Integrations
  • Affiliate program
  • Roadmap
  • Apply for Custom
  • Contact
  • Create account
  • Sign in
Modules
  • AI command center
  • Product Lister
  • Size Charts
  • Creative Studio
  • Creative Intelligence
  • Campaign Launcher
  • Campaign Killer
  • Email Insights
  • Customer Service
  • Finance & Profit
  • Action Center
  • Ask ExpoDash
  • Account Guardian
Integrations
  • Shopify
  • Meta Ads
  • Klaviyo
  • Customer Service
  • Claude
Legal
  • Terms of Service
  • Privacy Policy
  • Security
  • Refund Policy
© 2026 ExpoDash. All rights reserved.Built for multi-store e-commerce teams.