1. Who We Are
Dashmallow is an automated client reporting service for freelance media buyers. Dashmallow is operated by Dashmallow Limited, a company registered in England and Wales.
Company number: 17249841.
Registered office: Office 19301, 182-184 High Street North, East Ham, London, United Kingdom, E6 2JA.
We connect to Meta Ads and Google Ads on your behalf to retrieve advertising performance data and generate branded reports for your clients. For questions about this policy, contact us at info@dashmallow.com.
2. What Data We Collect
- Account information: name, email address, agency/business name, and optional logo.
- Client information: client names, email recipients, branding preferences, and report settings.
- OAuth tokens: Meta and Google access/refresh tokens used to connect accounts. Tokens are encrypted before storage.
- Advertising metrics: campaign performance data such as spend/cost, impressions, reach, clicks, CTR, CPC, conversions, cost per conversion, leads, CPL, campaign names, campaign status, and reporting periods.
- Billing information: subscription and payment details processed by Stripe. We do not store card numbers.
- Usage and technical data: logs and basic app activity used to operate, secure, and improve the service.
3. How We Use Your Data
- Authenticate your account and maintain your session.
- Connect to Meta Ads and Google Ads using your authorised OAuth tokens.
- Retrieve advertising performance metrics for reporting periods you configure.
- Generate report previews, PDF reports, Excel exports, and AI-assisted summaries.
- Send reports to client recipients configured by you.
- Process billing and send transactional notifications.
4. Google Ads Data
When you connect your Google Ads account, you authorise Dashmallow to access Google Ads data using the https://www.googleapis.com/auth/adwords scope.
We use this access only to retrieve read-only reporting data such as cost, impressions, clicks, CTR, average CPC, conversions, cost per conversion, campaign name, campaign status, and reporting period.
Dashmallow does not create, modify, pause, delete, or manage Google Ads campaigns, ads, ad groups, keywords, budgets, bidding strategies, audiences, billing settings, or account settings.
You can revoke Dashmallow's Google access at any time from Google Account Permissions or from the Data Sources page inside Dashmallow.
5. Meta Ads Data
When you connect your Meta Ads account, Dashmallow accesses Meta advertising data only to generate reports and allow you to select the correct ad account for each client.
- ads_read: used to read campaign performance metrics including spend, impressions, reach, clicks, CTR, CPC, leads/conversions, and campaign-level performance.
- business_management: used to list business assets and ad accounts you are authorised to access so you can assign accounts to clients.
Dashmallow does not create, edit, publish, pause, delete, or manage Meta campaigns, ad sets, ads, pages, business assets, budgets, or account settings.
We do not sell, transfer, or share Meta data with third parties for advertising or unrelated purposes. Meta data is used only to provide the Dashmallow reporting service.
You can revoke Dashmallow's Meta access via Facebook App Settings or from the Data Sources page inside Dashmallow.
6. Data Storage & Security
Data is stored in a managed PostgreSQL database hosted on Supabase. OAuth tokens are encrypted at rest before being stored. The encryption key is stored separately as a server-side environment variable and is never exposed in application code or logs.
Generated report data is stored as an immutable snapshot at generation time. PDF reports are stored in Supabase Storage and accessed through token-gated links.
7. Data Sharing
We do not sell your data. We share data only with service providers necessary to operate Dashmallow, such as hosting, database, payment, email, AI summary, and PDF rendering providers. These providers process data only as needed to provide their services to Dashmallow.
8. Data Retention
- Account data: retained while your account is active.
- OAuth tokens: retained while the connection is active and deleted when you disconnect or delete your account.
- Report data and metrics snapshots: retained for up to 24 months or until account deletion, whichever comes first.
- PDF reports: retained for up to 24 months or until account deletion.
- Billing records: retained where required by financial or tax laws.
You can request deletion through our Data Deletion page or by emailing info@dashmallow.com.
9. Your Rights
You may request access, correction, deletion, portability, or withdrawal of consent. You may disconnect Meta or Google access at any time from the Data Sources page inside Dashmallow.
To exercise privacy rights, email info@dashmallow.com. We aim to respond within 30 days.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page. For material changes, we may notify users by email or inside the app.