DotDash Privacy Policy

    Last updated: January 2, 2026

    DotDash Privacy Policy

    1. Controller Information and Scope

    Controller Details:

  1. Company Name: DotDash
  2. Website: https://getdotdash.today
  3. Email: hello@getdotdash.today
  4. Data Protection Officer: dpo@getdotdash.today
  5. Scope and Applicability:

    This Privacy Policy applies to all users of the DotDash mobile app, including visitors, registered users, and customers globally.

  6. Consent: Obtained for marketing communications and optional features.
  7. Contract: Necessary for service delivery and account management.
  8. Legitimate Interests: Used for analytics, security, and business operations, with a balancing test to ensure user rights are not overridden.
  9. Legal Obligation: Compliance with tax records, safety reporting, and regulatory requirements.
  10. Vital Interests: Processing in emergency situations if applicable.
  11. 3. Data Processing Matrix

    Data Category

    Processing Purpose

    Legal Basis

    Retention Period

    Account Information

    Service delivery, account management

    Contract

    Until account deletion or 3 years after last activity

    Service Data

    Mobile app operations

    Contract

    Until account deletion or 3 years after last activity

    Technical Data

    Security, bug tracking

    Legitimate Interest

    12 months

    Communication Data

    Support, feedback

    Legitimate Interest

    3 years

    ## 4. Information We Collect

  12. Account Information: Name, email, username (for service delivery - Contract basis)
  13. Service Data: Specific to Mobile App operations
  14. Technical Data: IP address, browser info (Legitimate Interest for security)
  15. Communication Data: Support tickets, feedback (Legitimate Interest for service improvement)
  16. 5. Automated Decision-Making Disclosure

    We do not use automated decision-making that produces legal effects.

    6. How We Use Your Information

  17. Service Delivery (Contract): Core functionality, account management
  18. Service Improvement (Legitimate Interest): Analytics, feature development, bug fixes
  19. Communication (Contract/Consent): Service updates, marketing (with opt-out)
  20. Security (Legitimate Interest): Fraud prevention, system security
  21. Legal Compliance (Legal Obligation): Regulatory requirements, law enforcement
  22. 7. Data Sharing & Third Parties

  23. Service Providers: Hosting (AWS/Google Cloud), email services
  24. Analytics: Google Analytics, usage tracking (with anonymization where possible)
  25. Legal Disclosures: Data may be shared in response to court orders or regulatory requests.
  26. Business Transfers: M&A scenarios with data protection continuity
  27. 8. International Data Transfers

  28. Primary Processing: Global
  29. Transfer Mechanisms: Standard Contractual Clauses (2021), adequacy decisions
  30. Third-Party Processors: Verified adequate protection or use appropriate safeguards
  31. 9. Data Retention & Deletion

  32. Account Data: Until account deletion requested or 3 years after last activity
  33. Technical Logs: 12 months for security and service optimization
  34. Support Records: 3 years for quality assurance and legal protection
  35. 10. Your Privacy Rights

  36. Access: Request copy of your data (free, 30-day response)
  37. Rectification: Correct inaccurate information (immediate where possible)
  38. Erasure: Request data deletion, subject to legal retention exceptions.
  39. Portability: Export your data in a common format (JSON/CSV).
  40. Restriction: Limit processing while disputes are resolved
  41. Objection: Opt-out of processing based on legitimate interests.
  42. Consent Withdrawal: Withdraw consent without affecting other legal basis
  43. Process: Email requests to privacy@getdotdash.today with identity verification.

    11. Supervisory Authority Complaint Rights

  44. Right to lodge complaints with supervisory authorities
  45. Specific authority contact information for global
  46. No prejudice to other administrative or judicial remedies
  47. Internal complaint resolution process
  48. 12. Data Security

  49. Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  50. Access Controls: Role-based access and multi-factor authentication for staff
  51. Regular Audits: Security assessments and penetration testing
  52. Incident Response: 72-hour breach notification to authorities, user notification
  53. Staff Training: Regular data protection training and confidentiality agreements
  54. Essential: Authentication, security, basic functionality (Legitimate Interest)
  55. Analytics: Usage statistics, performance monitoring (Consent in EU, with opt-out)
  56. Marketing: Advertising, retargeting (Consent-based with controls)
  57. Cookie Management: Via browser settings and preference center
  58. 14. Children's Privacy

  59. Age Limit: 13+ (US), 16+ (EU), with age verification procedures
  60. Parental Controls: Consent mechanisms and account management for minors
  61. Special Protections: Limited data collection, enhanced security
  62. 15. Updates & Changes

  63. Notification: Email notice 30 days before material changes
  64. Version Control: Clear version history and effective dates
  65. User Options: Continued use implies acceptance, with the option to delete account
  66. Note: Missing required information such as phone number and postal address is marked for compliance.

    Contact Information

    If you have any questions about this Privacy Policy, please contact us:

  67. Email: hello@getdotdash.today
  68. Website: https://getdotdash.today
  69. Response Time: We will respond to your inquiry within 30 days.

    Data Protection Officer: For GDPR-related inquiries, you may contact our Data Protection Officer at dpo@getdotdash.today

    Consent Required

    By clicking "I Agree", you acknowledge that you have read and understood this policy.

    Powered by PolicyForge — AI-Powered Compliance Platform