Privacy Policy

We at Derigo Dash are committed to protecting your privacy. This privacy policy applies to our browser extension (Derigo Dash), our website (https://derigodash.com), any subdomains of derigodash.com.

The information we gather or process is used solely for core functionality of Derigo Dash and to improve the quality and security of our service. Your information isn’t and has never been sold to third parties.

What information is being stored, or accessed?

Derigo Dash account information
Your name, email, account settings, and extension data (such as to-dos and links) are transferred and stored securely, solely for your usage within our extension and not shared with any other third parties, except as specified in this policy.

Payment information
To upgrade to Derigo Dash Plus, your credit card number, credit card expiration date, security code, name, country and postal code are required. All payment processing is done through a PCI compliant third party (Stripe, Inc.). When paying by a credit card, the card details do not pass through our servers, they are sent directly to Stripe and are stored securely, as per their Privacy and Security policies.

To perform requested changes to or inquiries about your Derigo Dash Plus account (cancelling, refunding, or changing payment details), authorized members of Derigo Dash’s support team could potentially view payment-related information contained in Stripe’s databases (this is limited to billing name, billing address, postal code, the last four digits of credit card(s), and credit card expiry date(s)) while accessing subscription information via Stripe’s payment dashboard. This information will only be accessed upon your request.

Data accessible through WebExtensions API
WebExtension APIs used within Chrome Extensions and Firefox Add-ons have fine-grained permission levels that are enforced by the Web Browser, restricting information that our extension has access to within your Browser. The Derigo Dash extension can only access specific information that you have explicitly granted permission for. We can not and do not track your browsing history.

Additional optional permissions may be requested when you enable specific features. When you enable a feature that requests an optional permission, your Web Browser will make it clear what permission(s) are being requested. The feature will be accessible once you choose to allow the requested permission(s).

INFORMATION/PERMISSION FEATURE 
Bookmarks and most visited websites Bookmarks Bar are used only within the Extension to display a Bookmarks Bar. This is not sent or stored elsewhere.

Feature usage data
To improve the content, features and overall experience of the extension, we gather and log data on how our users access and use Derigo Dash Dashboard. For example, we may log actions like clicking on a photo source, favoriting a quote, or completing a to-do (not the content of the to-do, just the action of completing it).

Some of this usage data is sent to Google Analytics. In these cases, we do not send any identifying information that could be correlated with your account. We also make use of their IP anonymization feature to prevent your IP from being associated with your usage data.

What vendors/sub-processors do you use?

We use several vendors/sub-processors to conduct various aspects of our business. They include GitLab, Google Analytics, Unsplashed, Google Mail, HotJar, Google Cloud Platform, Sentry and Stripe.

What are my rights in relation to my personal data?
By using Derigo Dash Dashboard, you may exercise the following rights:

The right to refuse to provide your personal data
The voluntary Personal Data you provide to us is an integral part of your use of Derigo Dash Dashboard. You can choose to forego the provision of that data, but you will be restricted from using our services.

The right to access and modify your personal data
Through your use of Derigo Dash Dashboard, you can access and amend your own data at any time. This includes changing your email, name, and payment information on your Profile page. As well as adding, editing and deleting other Derigo Dash data like your to-dos, links, notes, quotes, etc.

The right to be forgotten
You can request to have your account deleted. See the “What happens to my data when I delete my account?” section below to learn more about the deletion process.

The right to obtain your personal data
Upon request, we will provide a data export of all your data stored in our system. If you wish to receive an export of your data, or have any problems deleting your account, please contact us.

The right to submit a complaint
If you have a complaint about the way in which your Personal Data is handled, please contact us. After submitting a complaint, we will reply within five (5) business days to confirm that we have received your complaint. After receiving your complaint, we will investigate it and provide you with our response within two (2) weeks.

The right to submit a complaint with a data protection authority
If you are a resident of the European Union, and you are not satisfied with the outcome of the complaint submitted to us, you have the right to lodge a complaint with your local data protection authority.

What happens to my data when I delete my account?
Upon account deletion, your account is flagged as deleted and your data is no longer accessible. This data is stored for a grace period (90 days) to allow for account recovery in the case of accidental or malicious deletion, or your desire to reopen your account. Upon request, you can expedite the process of performing a hard delete to remove all of your personal data from our databases. After a hard delete, your data will be deleted from our system, but could still be present in encrypted database backups for up to an additional 35 days.

To request an expedited hard delete, please contact us.

Is my data secure?
Data security is a priority at all times. We use a Tier 1 cloud provider to run our operations (Google Cloud Platform).

In Transit
All data communication in transit to and from our servers is secured using HTTPS/TLS. All Derigo Dash domains have HTTP Strict Transport Security (HSTS) enabled and are in the HSTS Preload list on the major browsers supporting this feature.

At Rest
All data in our databases and their associated backups are encrypted at rest.

Will the privacy policy change?
Although most changes are likely to be minor, Derigo Dash may change its Privacy Policy from time to time, and at Derigo Dash’s sole discretion. Derigo Dash encourages visitors to frequently check this page for any changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change.

If you have any questions about Derigo Dash’s Privacy policy, please contact us.


Last updated August 5, 2021.