01 Who we are
Epic Dashboards is a product of Epic Tech Software LLC (“Epic Tech Software”, “we”, “us”), a Wyoming limited liability company registered at 1021 E Lincolnway, Suite 10047, Cheyenne, WY 82001, United States.
We are the data controller for this website and for our customer accounts. For any privacy question or request, contact [email protected].
02 Two different roles
Which one applies to you changes who is responsible for your data:
- We are the controller for people who visit this website, join our founding list, or hold an Epic Dashboards account. We decide what is collected and why. This policy governs that.
- We are a processor for the data our customers connect to the platform — their CRM contacts, calls, invoices and advertising data, including information about their clients. We handle it on our customer’s instructions. If a marketing agency uses Epic Dashboards and you are one of their leads or customers, that agency is your controller, not us. Send your request to them; we will help them answer it.
03 Our own analytics
We run our own first-party analytics from t.epicdashboards.io, a domain we control, which sends data to our own database. It records:
| What | Detail | Why |
|---|---|---|
| Pages viewed | Path, page title, referring URL, time of visit | Understand which content works |
| Visit behaviour | Scroll-depth milestones, seconds actively engaged, clicks on phone and email links | Measure whether pages are actually read |
| Campaign source | utm_* parameters and ad click identifiers (such as gclid, fbclid, msclkid, ttclid) present in the URL you arrived on | Know which ad or link brought you here |
| Device type | Desktop, mobile or tablet, derived from your browser’s user-agent string | Fix layout problems |
| Approximate location | Country, region and city, derived by our hosting provider from your connection | Regional reporting |
| Coarse network identifier | Your IP address truncated before it is stored — we keep only a network-level prefix, not the full address | Rough de-duplication |
| Hashed device signature | A one-way hash of your user-agent string, rather than the string itself | Distinguish visits |
| Identifiers | Random visitor and session IDs we generate (see §6) | Recognise a returning visit |
If you submit a form
Our analytics records that a submission happened and sends a one-way hash of the email address and phone number rather than the values themselves. The hashing happens in your browser, so our analytics pipeline does not receive those details in readable form.
The form itself, separately, sends what you typed to our CRM so that we can contact you. That is covered in §7.
04 Advertising & third-party tags
In addition to our own analytics, this website uses (or will use) advertising and analytics technologies operated by third parties, including:
- Meta Pixel and Conversions API (Meta Platforms) — measuring the performance of Facebook and Instagram advertising, and building advertising audiences.
- Google Ads conversion tracking, Google Analytics and Google Tag Manager (Google) — measuring campaign performance and website usage, and supporting remarketing.
- Other advertising or measurement platforms we may add as our marketing changes.
These technologies work differently from our own. They set their own cookies and identifiers, they receive your IP address and browser information directly as part of the request your browser makes to them, and they may combine that with data they already hold about you and use it to recognise you across other websites and apps. That processing is governed by their own privacy policies, and for some of it they act as independent or joint controllers alongside us.
Where these tags pass details such as an email address or phone number for conversion matching, they are hashed before transmission — but the receiving platform can still match them to an existing account it holds.
Where the law requires consent — including the UK and EEA — these tags are set to load only after you agree through our cookie banner, and you can change or withdraw that choice at any time. In the United States we treat a Global Privacy Control signal as an opt-out of sharing for advertising (see §17). You can also opt out directly with Meta and Google.
05 Limits we build in
These constraints apply to our own analytics and platform. They cannot bind the third-party tags described in §4, which is exactly why we keep the two separate:
- We truncate IP addresses before storage. Our database holds a network prefix, not your full address.
- Form details reach our analytics only as one-way hashes, never as readable text.
- We do not run session-replay software. No keystroke logging, mouse-movement capture or screen recording.
- Our own tracker is first-party. It runs only on domains we operate and does not follow you around the wider web.
- We do not seek special category data — health, biometrics, political or religious beliefs and similar. We have no use for it and do not ask for it.
- We do not sell personal information for money.
07 Customer & enquiry data
When you join the founding list, apply for a seat, or open an account, we collect what you give us: name, work email, mobile number, agency name, and the answers in your application. Paying customers also have billing details processed by Stripe, who handle card data directly — we do not receive or store full card numbers.
We use this to reply to you, run onboarding, provide the service, and send service messages. Marketing email and SMS go only to people who opted in, and every message includes a way to unsubscribe.
08 Data we process for customers
The platform connects a customer’s existing tools and joins the data. When a customer connects a system we ingest the records needed to report on it — typically contacts and leads, opportunities, appointments, call records and metadata, invoices and payments, and advertising spend and performance.
We process this only to provide the service to that customer. We do not sell it, we do not use it to build cross-customer profiles, and we do not use it to train machine-learning models. Each customer’s data is isolated at the database level through row-level security.
Customers who need one can request a Data Processing Agreement at [email protected].
09 Sub-processors
We use these providers to run the service. Each is bound by contract to protect the data it handles. This list may change; we will keep it current.
| Provider | Used for | Region |
|---|---|---|
| Supabase | Application database, authentication, serverless functions | United States |
| Vercel | Application hosting and content delivery | United States / global edge |
| HighLevel | Marketing site hosting, CRM, email and SMS delivery | United States |
| Stripe | Payment processing and card handling | United States / global |
| n8n (self-hosted) | Data synchronisation between connected systems | United States — New York |
| Meta Platforms | Advertising measurement and audiences | United States / global |
| Advertising measurement, analytics and tag management | United States / global |
Platforms a customer chooses to connect — GoHighLevel, CallRail, Meta, Google, QuickBooks, Xero, FreshBooks and others — remain under that customer’s own agreements with those providers. We read from them using the access the customer grants, and can be disconnected at any time.
10 How we use data
- To provide, operate and secure the platform.
- To understand which pages and campaigns bring people here, and to measure and improve our advertising.
- To respond to enquiries and run onboarding.
- To send service notices, and marketing where you opted in.
- To detect abuse, fraud and automated traffic.
- To meet legal, tax and accounting obligations.
11 Legal bases (UK/EU visitors)
- Legitimate interests — operating and securing our website, our own first-party analytics, and business-to-business contact.
- Contract — providing the service to customers and handling billing.
- Consent — advertising and non-essential analytics cookies, and marketing email and SMS. You can withdraw consent at any time.
- Legal obligation — tax, accounting and lawful requests.
13 Retention
We keep personal data only as long as we need it for the purposes above, then delete or de-identify it. In general:
| Data | Typically kept for |
|---|---|
| Raw website event records | About 90 days, then automatically purged |
| Summarised visit records | While the account is active, for trend reporting |
| Enquiry & founding-list contacts | Until you unsubscribe or ask us to delete, then removed within a reasonable period |
| Customer account & connected data | For the life of the account, then deleted within about 90 days of closure |
| Billing and tax records | As long as tax and accounting law requires |
Data held by the third parties in §4 is retained according to their own schedules, which we do not control.
14 Security
Data is encrypted in transit and at rest. Separation between customer accounts is enforced in the database itself through row-level security rather than only in application code. Credentials for connected platforms are stored encrypted and are not exposed to the browser. Administrative access is limited to staff who need it.
No system can be guaranteed completely secure. If a breach affects your personal data we will notify you and the relevant regulator as required by law.
15 Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and not be treated differently for exercising any of these.
To exercise a right, email [email protected]. We will take reasonable steps to verify your identity and respond within the timeframe the applicable law requires. If you are unhappy with our response you may complain to your data protection authority — in the UK, the Information Commissioner’s Office.
16 US state privacy rights
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what we collect, to request deletion or correction, to obtain a portable copy, and to opt out of the sale or sharing of your personal information and of targeted advertising.
As explained in §12, our use of advertising technologies may constitute “sharing” or “targeted advertising”. To opt out, use the cookie banner where it is shown, send a Global Privacy Control signal from your browser (§17), or email [email protected] with “Do Not Sell or Share” in the subject line. You may use an authorised agent, and we will not discriminate against you for exercising these rights.
We do not knowingly sell or share the personal information of anyone under 16.
17 Global Privacy Control & opt-out signals
We honour Global Privacy Control. If your browser sends a GPC signal, our own analytics disables itself for your visit and sends no events — that behaviour is built into the tracker itself. We also treat GPC as a valid opt-out of sharing your data for advertising, and configure our advertising tags accordingly.
Legacy “Do Not Track” headers have no agreed standard and we do not rely on them. GPC is the signal we act on.
18 International transfers
We are established in the United States and our infrastructure is primarily hosted there. If you are in the UK or EEA, your data will be transferred outside your country. Where that happens we rely on appropriate safeguards, including the UK International Data Transfer Addendum or EU Standard Contractual Clauses with our providers.
19 Children
Epic Dashboards is a business tool and is not directed at anyone under 16. We do not knowingly collect their personal data. If you believe a child has provided us information, contact us and we will delete it.
20 Changes
We will update this page when our practices change and revise the “last updated” date above. Where a change materially affects your rights we will give prominent notice before it takes effect.
21 Contact
Epic Tech Software LLC
1021 E Lincolnway, Suite 10047
Cheyenne, WY 82001
United States
[email protected]