Back to Home

Privacy Policy

Last updated: October 3, 2026

1. Data Controller

MetricDash is a service provided by MJ Marketing, Mijo Jurisic, Olszańska 7, 31-513 Kraków, Poland (VAT ID: PL5130297952). MJ Marketing ("we", "us") is the data controller for personal data processed through the MetricDash platform. Questions about this policy: [email protected].

2. All Core Systems in the EU

All of MetricDash’s core infrastructure runs inside the European Union: the application server on our own server with Hetzner in the Falkenstein data center (Germany), the database and authentication with Supabase in the AWS Frankfurt region (eu-central-1), and our self-hosted product analytics in Germany as well. In normal operation your account and marketing data never leave the EU.

3. Data We Process

  • Account data: name, email address, company name provided at registration.
  • Integration credentials: OAuth tokens for connected platforms (e.g. Google Ads, Google Analytics 4, Google Search Console, Meta Ads, Microsoft Advertising, web-analytics tools). Tokens are stored encrypted and used solely to fetch metrics on your behalf.
  • Marketing metrics: campaign and web-analytics data (spend, clicks, impressions, conversions, sessions) fetched from your connected platforms.
  • Lead data: contact details and messages your forms submit to MetricDash via webhook (see section 5).
  • Payment data: billing is handled by Stripe; we do not store full payment details (e.g. card numbers).
  • Usage and support data: features used, support tickets and in-app feedback.

4. Purposes and Legal Basis (GDPR Art. 6)

  • Contract performance (Art. 6(1)(b)): providing the dashboard, client portals, reports and alerts.
  • Legitimate interest (Art. 6(1)(f)): product improvement, security, abuse and fraud prevention.
  • Consent (Art. 6(1)(a)): marketing communications, revocable at any time.

5. Lead Data: Roles

When you submit leads (data about your own prospects or end customers) to MetricDash via the webhook feature, you are the data controller for that data under the GDPR; we process it exclusively on your behalf as a processor (Art. 28 GDPR). You are responsible for collecting and transmitting this data lawfully. A data processing agreement (DPA) is available on request: [email protected].

6. Meta Ads (Facebook and Instagram Ads)

When an agency or its client connects a Meta ad account to MetricDash, MetricDash receives read access to the connected ad accounts and their performance data through Meta’s official interface. MetricDash only reads this data and never changes ads, campaigns or budgets.

  • Data: the list of ad accounts the connected Facebook account can access (ID, name, currency, status), so you can choose one. For the chosen ad account, campaign names, status, objective and budget, and performance metrics such as spend, impressions, clicks, reach and conversions (for the account as a whole, per campaign, per day, and per hour for single days). MetricDash does not access the profile data of personal Facebook accounts.
  • Purpose: the agency and its client see their ad performance in dashboards, the client portal and reports; we also use the daily figures for budget alerts. The legal basis is contract performance (Art. 6(1)(b) GDPR).
  • Access token: the Meta access token is stored encrypted and used only on our servers to fetch the data on your behalf.
  • No other use: we do not sell this data and do not use it for advertising.
  • Retention and deletion: the access token is deleted immediately when the connection is disconnected or the client is deleted in MetricDash. Stored metrics and reports are kept while your MetricDash account is active and are deleted on request. Instructions: https://metricdash.app/en/data-deletion.

7. Recipients and Processors

We do not sell personal data. Data is shared only with the following service providers, and only as far as necessary to operate the service:

  • Supabase: database and authentication (EU region, Frankfurt).
  • Hetzner Online GmbH: application hosting on our own server, Falkenstein data center, Germany (EU).
  • Cloudflare: content delivery and security proxy in front of the application; processes technical connection data (e.g. IP addresses) under EU standard contractual clauses.
  • Resend: transactional email delivery (e.g. reports, account notifications).
  • Sentry (Functional Software, Inc., USA): application error monitoring. When a technical error occurs, error reports with stack traces and technical request data (e.g. the requested address, browser type) are sent, plus load times for a sample of requests; we do not include IP addresses or user identifiers, and login cookies and access tokens are filtered out before sending. Data is stored in Sentry’s EU data region; any access by the provider from the USA is covered by EU standard contractual clauses.
  • Stripe: payment processing; Stripe acts as an independent controller for payment data.
  • Connected platforms (Google, Meta, Microsoft and others): data is fetched solely at your initiative through the connections you establish.

8. Analytics and Cookies

For product analytics we use Rybbit, a privacy-focused analytics tool that we self-host on our own server in Germany. Rybbit is cookieless: it does not set cookies or store anything on your device, which is why no cookie-consent banner is shown. It records only aggregated usage data (such as pages visited and referring source), builds no cross-site profiles and shares nothing with advertising networks. IP addresses are processed only transiently to derive coarse, anonymized statistics and are not retained in identifiable form.

The platform itself uses only technically necessary cookies (login session). We do not use marketing or tracking cookies.

9. Data Retention

  • Account data and marketing metrics: for as long as your account is active; complete deletion within 30 days of a deletion request.
  • Access tokens of connected platforms: until the connection is disconnected or the associated client is deleted in MetricDash, then deleted immediately.
  • Audit logs (security and change history): 180 days.
  • Webhook receipt logs (technical diagnostics): 30 days.
  • Report share links: valid for 30 days, then no longer accessible.

10. Your Rights

Under the GDPR you have the right to access, rectify and erase your data ("right to be forgotten"), to restrict processing, to data portability and to object to processing. You can trigger complete account deletion directly in the settings or by email.

You also have the right to lodge a complaint with a data protection supervisory authority: in Poland the President of the Personal Data Protection Office (UODO, https://uodo.gov.pl/), or the authority at your habitual place of residence.

11. Security

All connections are TLS-encrypted, integration tokens are stored encrypted, and data access is protected by role-based access controls at the database level (row level security).

12. Changes and Contact

We update this policy when the service or the legal situation changes; the current version is always available on this page. Privacy questions: [email protected] (MJ Marketing, Mijo Jurisic, Olszańska 7, 31-513 Kraków, Poland).