OpsDashBack to site

Privacy Policy

Last updated: 2 August 2026

This policy explains how Rohit Raj(“OpsDash”, “we”, “us”) handles personal data through the OpsDash service. It's written in plain language and is a summary of our practices, not legal advice.

1. Two kinds of data, two roles

Your account data — your name, email and business details. For this, we are the controller.

Your customers' data — the names, phone numbers, emails, appointment history, notes and reviews you add to OpsDash. For this, you are the controller and we act as your processor. You are responsible for having a lawful basis and, where required, consent to hold and contact these people. See our Terms.

2. What we collect

  • Account: name, email, password (stored hashed), business name, timezone, country.
  • Customer records you create or import: name, phone, email, notes, appointments, reviews.
  • Enquiry messages handled by the AI agents.
  • Usage and device data via analytics (see section 9).
  • Billing details if you subscribe — handled by our payment processor; we do not store card numbers.

3. How we use it

  • To run the service: answer enquiries, manage your calendar, request and handle reviews.
  • To send messages you have configured (reminders, review requests) to your customers, on your instruction. Every agent starts in approval mode.
  • To operate, secure and improve the service, and to provide support.

4. Who else processes it (sub-processors)

We share data only with providers that help us run the service:

  • Supabase — database and authentication (cloud-hosted; data may be stored in India or other countries).
  • Vercel — application and website hosting.
  • Anthropic— AI processing. Enquiry text and relevant customer context are sent to Anthropic's Claude models to generate replies. Anthropic does not train its models on data sent through its API.
  • Google Analytics — website and product analytics.
  • Calendly — scheduling setup calls; booking details you enter there are processed by Calendly.
  • When you enable the relevant features: Resend (email delivery), Twilio (SMS delivery), Stripe (payments).

We do not sell your data or your customers' data.

5. Where data is stored

Your data is held on Supabase and Vercel infrastructure, which may process it in India and other countries. Where data is transferred across borders, we rely on appropriate safeguards.

6. Retention and cancellation

We keep data while your account is active. If you cancel, we delete or anonymise your account and customer records within 30 days, except where we must keep certain records to meet a legal obligation. You can request export or deletion at any time.

7. Security

Access is scoped per business (row-level security), the database and connections are encrypted, and administrative keys are restricted. No system is perfectly secure, and we cannot guarantee absolute security.

8. Your rights

Depending on where you are — including under India's Digital Personal Data Protection Act 2023 and, for relevant individuals, the GDPR — you may have rights to access, correct, delete or export personal data, and to withdraw consent. Contact us at getaigent@gmail.com. Where a request concerns your customers' data, it should be directed to the business that holds it; we assist that business as its processor.

9. Cookies and analytics

We use Google Analytics, which sets cookies to measure how the site and product are used.

10. Children

The service is not intended for anyone under 18.

11. Changes to this policy

We will post changes on this page and update the date above.

12. Contact

Rohit Raj. Email getaigent@gmail.com.