Legal

Privacy policy

Draft version. This policy is being finalized and is under legal review. It is published for transparency and may change before it takes effect. Questions? Email info@measurebase.com.

This policy explains how Dash Forward, trading as Measurebase, handles personal data. It covers the data we hold about our own customers, their team members, and visitors to measurebase.com.

Dash Forward, trading as Measurebase
Denarius 55, 6661 SV Elst (GLD), The Netherlands
Chamber of Commerce (KVK) number: 91017408
Contact: info@measurebase.com

1. Two different roles, two different documents

Measurebase handles personal data in two distinct capacities, and it matters which one applies:

If you are a visitor to a website that uses Measurebase, we are not the controller of your data. Contact the operator of that website; their own privacy policy applies.

2. What we collect, and why

Account data. Your first and last name, email address, and optionally a phone number. Your password is stored only as a cryptographic hash, never in readable form. If you sign in with Google, we store the identifier Google returns rather than a password. If you enable two-factor authentication, we store the secret and recovery codes needed to verify your codes.

Organization and billing data. Organization name, address, VAT and Chamber of Commerce numbers, billing email, and billing contact name. Payments are processed by Stripe: we never see or store full card numbers. We keep only the identifiers Stripe gives us and non-sensitive display details such as the card brand and last four digits.

Login activity. For each sign-in attempt: the IP address, browser user-agent string, sign-in method, whether it succeeded, and when. This exists so you can spot unauthorized access to your own account, and so we can detect and block credential-stuffing attacks.

Account activity log. A record of significant actions taken in your account — domain changes, plan changes, team invitations, and similar — with who performed them and when.

Support and feedback. The content of support tickets and feedback you send us, including any screenshots you attach and the page you were on when you submitted feedback.

Waitlist signups. If you request early access: your name, email address, business type, and whether you want product updates.

3. What we deliberately do not do

4. Cookies and local storage

Two cookies are set without asking. Everything else waits for your consent.

The two exempt ones are these. If you switch language using the link in the footer, your choice is stored in a cookie named mb_lang so the site opens in that language next time. It holds nothing but en or nl, it is never read by anyone else, and it is never written unless you actually click the switcher — visiting pages in either language does not set it, and we do not look at your browser's language settings. Separately, when you answer the cookie banner, your answer itself is stored in a cookie named mb_consent, so we do not have to ask again on every page. It holds nothing but your own choice and expires after six months.

A cookie that only remembers a preference you explicitly chose is a user-interface customisation cookie, and a cookie that records a consent decision is necessary to honour that decision. Both are exempt from consent under the ePrivacy Directive and the Dutch Telecommunications Act.

Measurement on this site. We measure how measurebase.com is used, through our own product: a Google Tag Manager container hosted on our own base.measurebase.com subdomain, on the same EU infrastructure we run for customers. It is the same setup this site sells, used on this site.

The page sets Google Consent Mode v2 to denied for analytics, advertising, advertising user data, advertising personalisation and personalisation storage before any tag is able to load, and that state only changes when you choose it in the banner.

Tags do still load in that denied state, and it is worth being precise about what that means. What they cannot do is read or write a cookie, give you an identifier, or recognise you on a later page, a later visit, or another website. What they can still do is send a signal that a page was viewed, carrying the page address and your IP address, with nothing attached that singles you out. If you choose "Necessary only", or ignore the banner entirely, it stays that way for as long as that choice stands: no analytics or advertising cookie is ever set.

Which domains your browser talks to. Most of this traffic goes to base.measurebase.com. Where it does, your browser never contacts Google at all: our own server forwards the request onward, with none of your cookies attached to it. Some requests still go to Google directly, namely www.googletagmanager.com for part of the tag setup, and www.google.com and pagead2.googlesyndication.com for advertising signals. Google receives your IP address either way, since forwarding a request does not hide where it came from.

The banner offers "Accept all" and "Necessary only" as equally prominent choices, and a "Preferences" panel where the two optional categories can be allowed separately. There are no pre-ticked boxes, and refusing takes exactly as few clicks as accepting. The categories are:

Changing your mind. Withdrawing consent is as easy as giving it. Once you have answered the banner, a "Cookies" button stays in the bottom-left corner of every page; it reopens your choices, already showing what is currently allowed, so you can change any category at any time. You can also . Clearing your browser cookies has the same effect, and the banner will simply ask again.

The dashboard at dashboard.measurebase.com uses your browser's local storage for one purpose: keeping you signed in and remembering which account you are viewing. This is strictly necessary to deliver a service you have asked for, so it does not require consent under the ePrivacy Directive or the Dutch Telecommunications Act. It is not a tracking identifier, it is never read by any third party, and clearing your browser storage simply signs you out.

Separately, Measurebase's product handles cookies on your behalf — features like Cookie Keeper extend the lifetime of your own first-party cookies on your own website. Those are your cookies on your domain, set under your responsibility as controller, and are covered by the DPA rather than this policy.

5. Legal bases for processing

Under Article 6 GDPR we rely on:

6. Who else processes this data

We keep the list of third parties deliberately short. Each is bound by a written data processing agreement.

ProviderPurposeLocation
TransIP B.V. Hosting for our infrastructure and databases The Netherlands
Stripe Payments Europe, Limited Payment processing and invoicing Ireland (some processing by Stripe affiliates outside the EEA, under Chapter V safeguards)
AC PM, LLC (Postmark) Sending account, alert, and support emails United States, under Standard Contractual Clauses

We may also disclose personal data where we are legally required to — for example in response to a valid order from a competent authority. We will not do so voluntarily, and will tell you unless legally prohibited from doing so.

7. International transfers

All infrastructure that stores your account data and the data flowing through your tagging server runs in the Netherlands. It does not leave the European Union in the ordinary course of providing the Service.

The one routine exception is transactional email: our email provider is US-based, so the email address a message is sent to, and the content of that message, reach the United States. That transfer is covered by the Standard Contractual Clauses incorporated into their data processing addendum. Alert emails describe the event, not your visitors' data.

8. How long we keep it

9. How we protect it

10. Your rights

Under the GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing is based on it.

Many of these you can exercise yourself from the dashboard: your profile page lets you correct your details, review your login history, and delete your account; your settings page lets you export data and manage your organization details. For anything else, email info@measurebase.com and we will respond within one month.

If you believe we are handling your data improperly, we would like the chance to put it right first. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the supervisory authority where you live or work.

11. Children

Measurebase is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

If we change this policy in a way that materially affects you, we will notify account holders by email before the change takes effect. The "last updated" date at the top always reflects the current version.

13. Contact

Questions about this policy, or about how we handle your data, go to info@measurebase.com. We have not appointed a Data Protection Officer, as we are not required to; your questions reach us directly.