Privacy Policy
Last updated: August 8, 2026
1. Who we are
Dispatch ("Dispatch", "we", "us") operates the Dispatch Micro-CDP product and this website. For any question about this policy or your data, contact us at evskarthik@gmail.com.
2. What Dispatch does
Dispatch is a Micro-CDP (Customer Data Platform) for hybrid SMBs: it merges a business's in-store (Square) and online (Shopify) customers into one identity, so that business doesn't pay twice to retarget the same person. This policy covers three distinct surfaces, each with a different data footprint:
- This marketing site (dispatchcdp.com) — informational, plus a contact form.
- The interactive demo (
/demo) — a sales tool that runs entirely in your browser. - The authenticated product (
/app) — used by Dispatch's business customers and their staff.
3. Information we collect
What we don't collect
- No payment or billing information — Dispatch does not currently process payments.
- No cookies, and no third-party advertising or tracking pixels (see our Cookie Policy).
- No precise location data.
-
Nothing at all from the interactive demo (
/demo) — it runs entirely in your browser using an in-memory, scripted approximation of Dispatch's matching logic. No request ever reaches Dispatch's servers or database from that page. -
Nothing at all from the duplicate audit (
/audit), including the customer files you choose there. Those files are read and analysed entirely inside your own browser and are never uploaded, stored, or transmitted to Dispatch or anyone else — the page makes no network request of any kind, and works with your internet connection switched off. Dispatch therefore never receives that data and has nothing to retain or delete.
Data you submit directly
If you use this site's contact form, we collect your name, email address, an optional company name, and your message. This is stored so we can respond to your inquiry. It is not sold, and it is not used for advertising.
Account data (authenticated product)
The authenticated product (/app) has no public sign-up — accounts are provisioned directly
by Dispatch for a business customer's own staff. We store your email address and a role, via Supabase
Auth; we never see or store your plaintext password.
Data processed on behalf of business customers
When a business connects a Square or Shopify account, or uploads order history, Dispatch processes that business's own customers' data — name, email, phone number, postal code, and order/purchase history — strictly to build that business's unified customer identity graph and run the automations they've configured (e.g. suppressing redundant retargeting, sending win-back offers). Every record is isolated per business (tenant) and never shared across businesses.
For this category of data, the business is the data controller, and Dispatch acts only as a data processor acting on that business's instructions. If you are a customer of a business that uses Dispatch and want to exercise a data-subject right, please contact that business directly — Dispatch will assist them as required by law.
4. How we use information
We use the data described above to: respond to inquiries submitted through the contact form; operate the product for business customers who've signed up; and secure the service (e.g. detecting abuse). Dispatch's identity matching runs on deterministic rule-based logic (matching by email, phone, or name + postal code) — not an AI or machine-learning model, and no personal data is used to train any model.
5. Cookies
Dispatch does not set any cookies today. The authenticated product uses your browser's
localStorage (not a cookie) to keep you signed in. See our
Cookie Policy for full detail.
6. Third-party processors
Infrastructure providers that may process data on our behalf:
| Provider | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database, authentication | supabase.com/privacy |
| Render | Backend API hosting | render.com/privacy |
| Vercel | Frontend hosting | vercel.com/legal/privacy-policy |
7. Data retention
- Contact-form submissions: retained so we can follow up, until you ask us to delete them.
- Account rows: retained while you're an authorized user of the product, deleted on offboarding.
- Business-customer data (profiles, order history): retained per that business's own instructions and their contract with Dispatch.
- Server access logs: retained briefly for security and debugging, then discarded.
8. Your rights
Wherever you're located, you can ask us to access, correct, or delete the personal data we hold about you by emailing evskarthik@gmail.com. We'll respond within 30 days.
If you're in India, this includes the rights available to you under the Digital Personal Data Protection Act, 2023 (access, correction, erasure, and grievance redressal). If you're in the EU/UK or California, we honor equivalent access, deletion, and portability requests, and Dispatch does not sell personal information.
9. International transfers
Our infrastructure providers (§6) may process data outside your own country as part of their normal hosting operations. We rely on those providers' own security and compliance commitments for these transfers.
10. Children
Dispatch is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has submitted data to us, contact us and we'll delete it.
11. Security
Data in transit is encrypted via HTTPS/TLS. Passwords are never handled or stored by Dispatch directly — authentication is delegated to Supabase Auth. Business-customer data is isolated per tenant and enforced at the database level via row-level security policies, not just application code.
12. Changes
We'll post material changes here with a new "Last updated" date. Please check back periodically.
13. Contact
Questions about this policy or your data: evskarthik@gmail.com.