← Back to SocialDash

Privacy Policy

Last updated: August 2026

SocialDash ("we", "our", "us") is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable laws.

1. Data Controller

The data controller is Moustapha Segueda, operating SocialDash. Contact: musthafasegda775@gmail.com

2. Data We Collect

  • Account data: name, email address, password (hashed), profile picture.
  • Social account tokens: OAuth access tokens and refresh tokens for platforms you connect (LinkedIn, Twitter/X, Pinterest, Instagram, TikTok, YouTube, Facebook). These are used solely to publish content on your behalf.
  • Content data: posts, schedules, captions, uploaded images you create inside SocialDash.
  • Analytics data: engagement metrics fetched from connected platforms (likes, followers, impressions).
  • Billing data: Stripe customer ID, subscription plan, and renewal dates. We do not store full credit card numbers — Stripe handles payment processing.
  • Usage data: log data including IP addresses, browser type, pages visited, and timestamps, collected automatically when you use the Service.
  • Cookie data: session cookie to keep you logged in.

3. Lawful Basis for Processing (GDPR)

Processing ActivityLawful Basis
Providing and operating the ServiceContract (Art. 6(1)(b))
Posting content to social platforms on your behalfContract (Art. 6(1)(b))
Processing payments via StripeContract (Art. 6(1)(b))
Session cookies (essential)Legitimate interest (Art. 6(1)(f))
Service improvement and analyticsLegitimate interest (Art. 6(1)(f))

4. Third-Party Platforms & Sub-Processors

We share data with the following service providers to operate SocialDash:

  • Vercel — hosting and serverless infrastructure (USA)
  • Neon / PostgreSQL — database storage (USA)
  • Stripe — payment processing (USA)
  • Cloudinary — image storage and watermarking (USA)
  • OpenAI — AI-generated captions and images (USA)
  • LinkedIn, Twitter/X, Pinterest, Meta, TikTok, YouTube — social platform APIs

Where these processors are based outside the EEA, data transfers are covered by Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework.

5. Data Retention

  • Account data is retained for as long as your account is active.
  • After account deletion, all personal data is permanently erased within 30 days.
  • Stripe transaction records are retained for 7 years to comply with financial regulations.
  • Server logs are retained for a maximum of 90 days.

6. Your Rights

Under GDPR, CCPA, and other applicable laws, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your account and all associated data. You can do this instantly from Settings → Danger Zone, or by contacting us.
  • Portability — receive your data in a machine-readable format.
  • Restriction — request that we stop processing your data in certain circumstances.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email us at musthafasegda775@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU).

7. Cookies

We use only essential session cookies required to keep you authenticated. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. You can decline non-essential cookies via our cookie consent banner; this will not affect core Service functionality.

8. Security

Passwords are hashed with bcrypt. OAuth access tokens are stored in an encrypted PostgreSQL database. All data is transmitted over TLS. We follow industry-standard security practices and review our infrastructure regularly.

9. Children

SocialDash is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided data without parental consent, contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy periodically. Material changes will be communicated by email or via an in-app notice at least 14 days before they take effect.

11. Contact

For privacy questions, data subject requests, or complaints, contact us at: musthafasegda775@gmail.com