# Privacy policy

> What data Dashing collects, why, where it is stored, who sees it, how long it stays, and how to export or delete it. In plain words, without vague legal language.

Dashing (dashing.krd) is a point-of-sale, inventory and double-entry accounting platform for retail shops in Iraq — Arabic-first, also in Kurdish (Sorani) and English — with a cashier that works offline and a built-in AI assistant called Dash.

Canonical: https://dashing.krd/en/legal/privacy

This policy explains how Dashing — the team based in Baghdad, Iraq that operates dashing.krd and the app — handles your data and your shop's data. Version 1.2, effective 29 September 2026. If anything on this page is unclear, message us on WhatsApp; we will explain it and improve the wording.

_Last updated 2026-09-29_

## 1. What we collect

- Account data: shop name, owner name, email, and a password stored hashed so that we cannot read it. With Google sign-in we receive only your name and email from Google
- Shop data you and your staff enter: products, sales, customers and suppliers and their balances, expenses, staff, and the books. You are responsible for collecting this data from your customers lawfully
- Technical data: IP address, device and browser type, request logs, and error reports (with no personal data)
- Usage measurement. On the website and sign-up pages: which pages are read and where visitors come from. Inside the app: which screens and features are used, how long steps take, and where errors or refusals happen — linked to your account and your shop so we can see which shops are active, but never the content you enter: no customer or product names, phone numbers, amounts or addresses. Text on app screens is masked before anything is sent. We record anonymised screen sessions, in the app and on this site, to find what is hard to use: what you type, and your shop's names and numbers, are hidden on your device before anything leaves it. Now and then we may ask a short, optional question (such as what stopped you finishing sign-up); answering is voluntary, and the answer is kept with the usage data. We honour the browser's Global Privacy Control signal
- Cookies: one to remember your language, session tokens to keep you signed in, and one for usage measurement. No advertising cookies

## 2. Why we use it

- To run the service: the cashier, stock, accounting, reports and Dash
- For security: detecting illegitimate sign-in attempts, and keeping the audit log an accountant needs
- For support: when you message us, we look at what is needed in your account to solve the problem, and that access is logged
- To improve the product: usage statistics per shop — which features help and where people get stuck. We do not sell them or share them for advertising

## 3. AI (Dash)

When you ask Dash, your question and the figures needed to answer it are sent to an AI model. Before sending, phone numbers, email addresses and anything shaped like a bank account number are masked and replaced with tokens. We do not use your shop data to train AI models, and the model provider receives only the masked text. Every request is logged, and every change Dash proposes is applied only with your approval. You can simply not use Dash; the rest of the system does not depend on it.

## 4. Who sees your data

- You and your staff, according to the permissions you grant
- Infrastructure providers that run the service on our behalf: hosting, the protective network in front of the servers, an error-monitoring service (no personal data), a usage-analytics service (usage events only, never shop content), the AI model provider (after masking), and the delivery company if you enable delivery
- Whoever you send a receipt or statement link to on WhatsApp; a receipt link is valid for a year, a statement link for 30 days, and each shows only that document
- Authorities, only when the law requires it of us
- We do not sell your data or share it with anyone for marketing

## 5. Where it is stored and how long

- A backup of the servers every night (30 daily and 12 monthly copies are kept)
- As long as your account exists, your data stays, on the free or the yearly plan; the end of a yearly term does not close the account. If you close your account at your request, you have 90 days to export it; then it is deleted from live systems, and it expires from backups at the end of their cycle (12 months at most)
- The audit log and request logs stay for as long as the account exists, because the accounting depends on them

## 6. Your rights

At any time you can export invoices, customers and products to CSV files and the journal to Excel from inside the system, ask for an export of the rest, correct your data, ask for your whole account to be deleted, and object to any use you consider inappropriate. Message us on WhatsApp from the contact page; we verify your identity and respond within a few working days.

## 7. Security

The details of protection — every shop isolated at the database level, encryption, the audit log, backups — are on the security page, with a plain list of what we have not done yet.

## 8. Children, changes, and contact

- The service is for business owners; we do not accept accounts for anyone under 18
- When we change this policy we update the date above and announce the change inside the app before it takes effect
- Contact: WhatsApp from the contact page, or by post to our address in Baghdad

## Common questions

### Do you read my sales?

No — only when you ask for support, to the extent needed to solve it, and that access is logged. What we look at routinely is aggregate numbers that identify no shop.

### Can I delete my account entirely?

Yes. Export what you need first, then request deletion on WhatsApp. The account is deleted from live systems, and backups expire within 12 months at most.

## Other languages

- العربية: https://dashing.krd/legal/privacy
- کوردی: https://dashing.krd/ckb/legal/privacy

---

Dashing · https://dashing.krd/en
