1. Preamble
This privacy policy describes how Fakeyourdash (hereafter the "Service") collects, uses and protects the personal data of users of fakeyourdash.com.
It complies with the General Data Protection Regulation (GDPR, EU 2016/679) and the amended French "Informatique et Libertés" Act.
2. Data we collect
Fakeyourdash only collects the data strictly required to run the Service.
2.1 Data you provide
- Email address — used as your account identifier and for transactional communications.
- Password — stored as a bcrypt hash. No plaintext password is ever kept.
- Numbers you type into the demo dashboards — saved to your account so you can pick simulations back up between sessions. These are yours alone and never shared.
2.2 Data collected automatically
- IP address, browser type, operating system, pages viewed, connection dates and times. Used solely for security and abuse prevention.
- Usage data — navigation between dashboards, features used. Aggregated and anonymised to improve the Service.
2.3 Payment data
Payments are processed exclusively by our secure third-party provider (Whop). No card data is stored by Fakeyourdash. Only the subscription status (active / inactive) and subscription ID are transmitted and retained.
3. Purposes of processing
- Creating and managing your user account
- Authentication and Service security
- Saving your personal simulations
- Billing and subscription tracking
- Transactional communication (renewal, cancellation, service updates)
- Fraud prevention and detection of usage contrary to these terms
- Improving the Service via anonymised usage statistics
4. Legal bases
- Contract performance — (GDPR Article 6.1.b) for account management, service delivery and billing.
- Legitimate interest — (Article 6.1.f) for security, fraud prevention and improving the Service.
- Consent — (Article 6.1.a) for non-essential cookies and optional marketing communications.
- Legal obligation — (Article 6.1.c) for applicable accounting and tax obligations.
5. Hosting and subprocessors
The Service relies on the following subprocessors. Each is bound by a Data Processing Agreement compliant with GDPR Article 28.
- Vercel Inc. — web application hosting and CDN. Data processed in Europe (ARN1 region, Stockholm) by default.
- Supabase Inc. — user database and authentication. Data processed in Europe (eu-central-1 region, Frankfurt).
- Whop Inc. — payment processing and subscription management. PCI-DSS Level 1 compliant.
No data is transferred outside the EU without appropriate safeguards (European Commission Standard Contractual Clauses).
6. Retention period
- Account data — kept as long as the account is active. Deleted within 30 days of an account-deletion request.
- Billing data — kept for 10 years from the last transaction, per French accounting obligations.
- Connection logs — kept for a maximum of 12 months, per French legal requirements.
- Anonymised usage data — kept indefinitely since they no longer allow identification.
7. Cookies
Fakeyourdash uses a minimal number of cookies:
- Strictly necessary cookies — user session, subscription cart, language preference. No consent required (Article 82 of the Informatique et Libertés Act).
- Anonymised audience measurement cookies — where applicable, configured to follow CNIL recommendations and qualify for the consent exemption.
No advertising or third-party profiling cookies are set.
8. Your rights
Per GDPR Articles 15 to 22, every user has the following rights over their personal data:
- Right of access — obtain a copy of the data held about you.
- Right of rectification — correct inaccurate data.
- Right to erasure — ("right to be forgotten") have your data deleted.
- Right to restriction — temporarily restrict processing.
- Right to portability — receive your data in a machine-readable format.
- Right to object — refuse processing based on legitimate interest.
- Right to withdraw consent — at any time, where consent was given.
To exercise these rights, just send an email to [email protected]. We'll reply within one month.
If a disagreement persists, you can file a complaint with the CNIL (French data protection authority, cnil.fr).
9. Security
Fakeyourdash implements appropriate technical and organisational measures:
- HTTPS encryption across the entire site
- bcrypt password hashing
- Data access limited to what's strictly necessary
- Regular, encrypted backups
- Regular security updates to all dependencies
10. Changes
This policy may evolve. Any substantial change will be communicated by email and reflected by an updated date at the top of this page.
11. Contact
Any question about this policy or about exercising GDPR rights can be sent to [email protected] or via the contact page.