Privacy Policy

Last updated: March 1, 2026 · Effective date: March 1, 2026

Summary: DashFields / Wemarka ("DashFields", "we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, share, and protect your data when you use our platform at https://dashfields.com. We comply with the General Data Protection Regulation (GDPR) and the Jordan Personal Data Protection Law No. 24 of 2023.

1. Information We Collect

We collect the following categories of personal information:

1.1 Information You Provide Directly

  • Account Information: Name, email address, password (encrypted), and profile picture when you register.
  • Billing Information: Payment method details (processed securely by Stripe — we do not store full card numbers).
  • Social Media Credentials: OAuth tokens for connected platforms (Facebook, Instagram, TikTok, etc.) — stored encrypted.
  • Content: Posts, campaigns, and other content you create or schedule through our platform.
  • Communications: Messages you send to our support team.

1.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, clicks, and time spent on the platform.
  • Device Information: IP address, browser type, operating system, and device identifiers.
  • Log Data: Server logs including access times, error logs, and API calls.
  • Cookies: Session cookies, preference cookies, and analytics cookies (see Section 7).

1.3 Information from Third Parties

  • Social Media Platforms: When you connect your accounts, we receive data permitted by each platform's API (e.g., page insights, ad performance metrics).
  • Google OAuth: If you sign in with Google, we receive your name, email, and profile picture.

2. How We Use Your Information

We use your personal information for the following purposes:

  • Service Delivery: To provide, operate, and maintain the DashFields platform and its features.
  • Account Management: To create and manage your account, authenticate your identity, and provide customer support.
  • AI Features: To power AI-driven features such as content generation, audience analysis, and campaign recommendations. Your content may be processed by our AI models but is never used to train third-party models.
  • Analytics & Improvement: To analyze platform usage, identify bugs, and improve our services.
  • Communications: To send service-related emails (account verification, password resets, billing receipts) and, with your consent, marketing communications.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.
  • Security: To detect, prevent, and respond to fraud, abuse, and security incidents.

Legal Basis (GDPR): We process your data based on: (a) contract performance (to provide our services), (b) legitimate interests (security, fraud prevention, product improvement), (c) legal obligation, and (d) your consent (for marketing communications).

3. Sharing Your Information

We do not sell your personal information. We may share your data with:

  • Service Providers: Third-party vendors who help us operate our platform, including:
    • Supabase (database and authentication hosting)
    • Stripe (payment processing)
    • AWS / CloudFront (file storage and CDN)
    • OpenAI / AI providers (for AI feature processing)
  • Social Media Platforms: When you publish content or sync data through our platform, the relevant platform (Facebook, Instagram, etc.) receives that content.
  • Legal Requirements: We may disclose your information if required by law, court order, or governmental authority.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

All third-party service providers are bound by data processing agreements and are required to protect your data in accordance with applicable law.

4. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention requirements.
  • Right to Restriction: Request that we restrict processing of your data in certain circumstances.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

5. Cookies and Tracking Technologies

We use the following types of cookies:

  • Essential Cookies: Required for the platform to function (session management, authentication). Cannot be disabled.
  • Preference Cookies: Remember your settings (language, theme, dashboard layout).
  • Analytics Cookies: Help us understand how you use the platform (page views, feature usage). We use privacy-respecting analytics.

You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.

6. Data Security

We implement industry-standard security measures to protect your personal data, including:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for sensitive data at rest (OAuth tokens, passwords)
  • Row-Level Security (RLS) in our database
  • Regular security audits and penetration testing
  • Access controls and employee training
  • Incident response procedures

While we take all reasonable precautions, no method of transmission over the internet is 100% secure. In the event of a data breach, we will notify affected users and relevant authorities as required by law.

7. Data Retention

We retain your personal data for the following periods:

  • Account Data: For as long as your account is active, plus 90 days after deletion.
  • Usage Logs: 12 months.
  • Billing Records: 7 years (as required by financial regulations).
  • Support Communications: 2 years.

8. International Data Transfers

DashFields is operated by DashFields / Wemarka, based in Jordan. Your data may be processed in countries outside your home country, including the United States (where our cloud providers are based). We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) approved by the European Commission.

9. Children's Privacy

DashFields is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at [email protected].

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our platform. Your continued use of DashFields after the effective date of the updated policy constitutes your acceptance of the changes.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

DashFields / Wemarka

Email: [email protected]

Website: https://dashfields.com

Amman, Jordan