Privacy policy
This policy explains how Dash Forward, trading as Measurebase, handles personal data. It covers the data we hold about our own customers, their team members, and visitors to measurebase.com.
Dash Forward, trading as Measurebase
Zwanenbloem 57, 6661 LZ Elst (GLD), The Netherlands
Chamber of Commerce (KVK) number: 91017408
Contact: hello@measurebase.com
1. Two different roles, two different documents
Measurebase handles personal data in two distinct capacities, and it matters which one applies:
- As a controller — for data about you as our customer: your account, your billing details, your support requests. That is what this policy covers.
- As a processor — for the tracking data that flows through your tagging server, which belongs to your own website visitors. You decide what that data is and why it is collected; we only host the transport layer. That relationship is governed by our Data Processing Agreement, not by this policy.
If you are a visitor to a website that uses Measurebase, we are not the controller of your data. Contact the operator of that website; their own privacy policy applies.
2. What we collect, and why
Account data. Your first and last name, email address, and optionally a phone number. Your password is stored only as a cryptographic hash, never in readable form. If you sign in with Google, we store the identifier Google returns rather than a password. If you enable two-factor authentication, we store the secret and recovery codes needed to verify your codes.
Organization and billing data. Organization name, address, VAT and Chamber of Commerce numbers, billing email, and billing contact name. Payments are processed by Stripe: we never see or store full card numbers. We keep only the identifiers Stripe gives us and non-sensitive display details such as the card brand and last four digits.
Login activity. For each sign-in attempt: the IP address, browser user-agent string, sign-in method, whether it succeeded, and when. This exists so you can spot unauthorized access to your own account, and so we can detect and block credential-stuffing attacks.
Account activity log. A record of significant actions taken in your account — domain changes, plan changes, team invitations, and similar — with who performed them and when.
Support and feedback. The content of support tickets and feedback you send us, including any screenshots you attach and the page you were on when you submitted feedback.
Waitlist signups. If you request early access: your name, email address, business type, and whether you want product updates.
3. What we deliberately do not do
- No analytics or tracking on measurebase.com. This website loads no third-party scripts, no analytics, no advertising pixels, and no social media trackers. The only scripts it loads are our own.
- We do not sell personal data, and we do not share it with advertisers or data brokers.
- We do not use your data for advertising or profiling, and we do not use the tracking data flowing through your tagging server for any purpose of our own.
- No automated decision-making that produces legal or similarly significant effects.
4. Cookies and local storage
measurebase.com sets no cookies at all. There is no cookie banner on this site because there is nothing to consent to.
The dashboard at dashboard.measurebase.com uses your browser's local storage for one purpose: keeping you signed in and remembering which account you are viewing. This is strictly necessary to deliver a service you have asked for, so it does not require consent under the ePrivacy Directive or the Dutch Telecommunications Act. It is not a tracking identifier, it is never read by any third party, and clearing your browser storage simply signs you out.
Separately, Measurebase's product handles cookies on your behalf — features like Cookie Keeper extend the lifetime of your own first-party cookies on your own website. Those are your cookies on your domain, set under your responsibility as controller, and are covered by the DPA rather than this policy.
5. Legal bases for processing
Under Article 6 GDPR we rely on:
- Performance of a contract (Article 6(1)(b)) — creating and running your account, providing the Service, billing you, and providing support.
- Legitimate interests (Article 6(1)(f)) — securing the platform, keeping login and activity records, preventing fraud and abuse, and improving the product. We have weighed these interests against your rights and consider them proportionate given how limited the data is.
- Legal obligation (Article 6(1)(c)) — retaining invoices and related records for the period Dutch tax law requires.
- Consent (Article 6(1)(a)) — waitlist product updates, where you asked to receive them. You can withdraw consent at any time, and doing so does not affect processing that already happened.
6. Who else processes this data
We keep the list of third parties deliberately short. Each is bound by a written data processing agreement.
| Provider | Purpose | Location |
|---|---|---|
| TransIP B.V. | Hosting for our infrastructure and databases | The Netherlands |
| Stripe Payments Europe, Limited | Payment processing and invoicing | Ireland (some processing by Stripe affiliates outside the EEA, under Chapter V safeguards) |
| AC PM, LLC (Postmark) | Sending account, alert, and support emails | United States, under Standard Contractual Clauses |
We may also disclose personal data where we are legally required to — for example in response to a valid order from a competent authority. We will not do so voluntarily, and will tell you unless legally prohibited from doing so.
7. International transfers
All infrastructure that stores your account data and the data flowing through your tagging server runs in the Netherlands. It does not leave the European Union in the ordinary course of providing the Service.
The one routine exception is transactional email: our email provider is US-based, so the email address a message is sent to, and the content of that message, reach the United States. That transfer is covered by the Standard Contractual Clauses incorporated into their data processing addendum. Alert emails describe the event, not your visitors' data.
8. How long we keep it
- Account, login activity, and account activity logs — for as long as your account exists. Deleting your account removes them from our production systems, subject to short-lived residual copies in encrypted backups — the nightly rotation overwrites those within seven days.
- Invoices and financial records — seven years, as Dutch tax law requires. This obligation survives account deletion.
- Support tickets and feedback — for as long as your account exists, so that support history stays useful to both of us.
- Waitlist signups — until launch or until you ask to be removed, whichever comes first.
- Request logs (your visitors' data, processed on your behalf) — from 3 days on the Free plan up to 30 days on Business (3/7/14/21/30 days for Free/Solo/Growth/Scale/Business), then automatically and permanently deleted. Visitor IP addresses are anonymized at the point of capture (the last part of the address is discarded before anything is written to disk), the underlying server access logs are deleted within 72 hours, and beyond these windows only anonymous daily statistics — counts, with no personal data — are kept. See the DPA.
9. How we protect it
- Two-factor authentication is available on every account, and we encourage it.
- Sign-in endpoints are rate-limited. Sessions expire on a schedule and are revoked automatically when you change your password, reset it, or disable two-factor authentication.
- Connections are encrypted in transit with TLS. Sensitive credentials are encrypted at rest.
- Our staff cannot look inside your account unless you let them. Support access is off by default; you turn it on yourself from your profile settings. When enabled, access is a temporary, single-use session that cannot change billing or delete anything, and every session is recorded in your own activity log.
10. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing is based on it.
Many of these you can exercise yourself from the dashboard: your profile page lets you correct your details, review your login history, and delete your account; your settings page lets you export data and manage your organization details. For anything else, email hello@measurebase.com and we will respond within one month.
If you believe we are handling your data improperly, we would like the chance to put it right first. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, or with the supervisory authority where you live or work.
11. Children
Measurebase is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
If we change this policy in a way that materially affects you, we will notify account holders by email before the change takes effect. The "last updated" date at the top always reflects the current version.
13. Contact
Questions about this policy, or about how we handle your data, go to hello@measurebase.com. We have not appointed a Data Protection Officer, as we are not required to; your questions reach us directly.