Privacy Policy
Last updated: July 26, 2026
BusinessDash ("we," "us," or "our") operates the BusinessDash platform at https://www.biab.app, including the web dashboard, customer portals, developer SDK and APIs, and sites our customers publish with our tools (together, the "Platform"). This Privacy Policy explains what we collect, how we use it, and the choices you have.
Questions or requests: 240designworks@gmail.com.
The two kinds of data we handle
BusinessDash is a business platform used by organizations (our customers) to run their own businesses. That means we handle data in two distinct roles:
- Platform data (we are the controller). Information about the people who hold BusinessDash accounts — organization owners, administrators, and staff — and about visits to our own website.
- Organization Data (we are a processor). Business records an organization stores in the Platform about its customers, leads, staff, and operations — CRM contacts, form submissions, orders, invoices, expenses, documents, photos, messages, and similar. The organization controls this data. If a business you deal with uses BusinessDash, that business — not us — decides why and how your information is collected, and its own privacy notices apply. We process Organization Data only on the organization's instructions, to operate the Platform.
Information we collect
Account information. When you sign up or are invited to an organization we receive your name, email address, and profile photo through our authentication provider (WorkOS AuthKit, including sign-in with Google where you choose it). We never receive or store your password when you use social sign-in.
Organization Data. Organizations and their staff enter business records into the Platform: contacts and leads, quotes and proposals, orders and invoices, expense records and receipt images, staff scheduling and compensation records, uploaded documents and media, form submissions (including submissions from the public forms and sites an organization publishes), customer-portal messages, and — for organizations using field-sales tools — door-visit records that can include addresses, location coordinates, and photos captured by their staff.
Payment information. Card and bank payments are processed by payment processors (Stripe). Card numbers, security codes, and expiry dates go directly to the processor and are never stored on or transmitted through our servers — we store only opaque payment references plus the card brand and last four digits, for receipts and reconciliation.
Usage and device information. Standard server logs (IP address, browser type, pages requested, timestamps) and product analytics events that record how the Platform's features are used, to keep the service secure and improve it.
Correspondence. If you contact us for support, we keep the correspondence and your contact details for future reference.
Cookies
We use cookies that are necessary for the Platform to function: an authentication session cookie (issued through WorkOS AuthKit) that keeps you signed in, and preference cookies (such as your selected workspace view). We do not run third-party advertising cookies on the Platform. You can disable cookies in your browser, but signed-in areas will not function without the session cookie.
How we use information
- To provide, operate, secure, and support the Platform;
- To process transactions you or your organization initiate (subscriptions, invoices, orders, payouts through connected processors);
- To send transactional messages — receipts, invoices, portal notifications, scheduling confirmations — on behalf of the organization you deal with, honoring that organization's notification settings and your opt-outs;
- To send you service communications about your own account, and marketing you can unsubscribe from at any time;
- To power optional AI-assisted features (see below);
- To comply with law and enforce our agreements.
We do not sell personal information, and we do not use Organization Data to advertise to an organization's customers.
AI-assisted features
Some features use third-party AI providers (such as OpenAI or Anthropic) — for example, generating form drafts or reading an uploaded receipt image to prefill an expense entry. When an organization uses these features, the relevant content (for example, the receipt image) is sent to the AI provider to produce the result and is subject to that provider's data-handling terms. These features are optional and fail gracefully when not configured.
Service providers (subprocessors)
We share data with service providers only as needed to run the Platform:
- Hosting and storage: Vercel (application hosting), Supabase (database), Cloudflare R2 (file and media storage);
- Authentication: WorkOS;
- Payments: Stripe (including Stripe Connect for organizations that accept payments);
- Accounting integrations: Intuit QuickBooks, when an organization connects its own QuickBooks company — we exchange the accounting records the organization chooses to sync;
- Shipping: shipping-rate and label providers (such as Shippo) receive recipient names and addresses for shipments an organization creates;
- Email and SMS delivery: transactional email services (Amazon SES, Resend) and SMS carriers;
- Maps and geocoding: Google Maps Platform, for address validation and mapping features;
- Monitoring and analytics: Sentry (error monitoring — receives error reports with technical context when something breaks) and PostHog (product analytics and session context for BusinessDash's own surfaces; not loaded on sites organizations publish on their own domains);
- AI providers: as described above.
Each provider receives only what its function requires and is bound by its own contractual and legal obligations.
Data retention and deletion
Platform account data is kept while your account is active. Organization Data is kept while the organization's account is active and is controlled by the organization — its administrators can edit and delete records, and can export data before closing the account. When an organization is deleted, its data is removed from our production database; residual copies in encrypted backups age out on our backup rotation schedule rather than being individually purged. Some records (for example, invoices and tax-relevant accounting entries) may be retained where the organization or the law requires it.
If a business stored your information in BusinessDash and you want it corrected or deleted, contact that business — it controls the record. We support organizations in honoring such requests, and where the law gives you rights directly against us, we honor them.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal information we hold about you, and to object to or restrict certain processing. To exercise them for platform account data, email 240designworks@gmail.com. We will verify the request and respond within the time the law requires. We do not discriminate against you for exercising privacy rights.
Security
We use industry-standard measures: encryption in transit (TLS), encrypted storage for sensitive credentials (such as integration tokens), role-based access controls inside each organization, tenant isolation between organizations, and audit logging on sensitive surfaces. No system is perfectly secure — maintain strong credentials and report suspected issues to us immediately.
Children
The Platform is a business tool, not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
International users
We operate from the United States and process data there and in the regions our service providers use. Where required, we rely on appropriate safeguards for international transfers.
Changes to this policy
We may update this policy from time to time. Material changes will be announced through the Platform or by email, with the "Last updated" date revised above. Continued use after the effective date constitutes acceptance.
Contact
See also our Terms of Service and End User License Agreement.