Privacy

Privacy Policy

Last updated: April 29, 2026

1. Who we are

Dishplay (“Dishplay”, “we”, “us”) provides a cloud-based digital signage platform that includes the marketing website at www.dishplay.io, the customer portal at portal.dishplay.io, and the Dishplay Player apps for Android, Android TV, Fire TV, and other supported devices. This Privacy Policy explains what data we collect, why, how we use it, and the rights you have over it.

2. Data we collect

2.1 Account information (portal users)

When you create a Dishplay account, we collect:

  • Name and email address
  • Hashed password (bcrypt)
  • Business name and billing address
  • Role assigned to you within your customer account

2.2 Content you upload

Images, videos, playlists, and layouts you upload to your account are stored in our cloud storage and served to your screens. You retain ownership of your content.

2.3 Player app data

The Dishplay Player app does not ask for personal information. It collects only:

  • A locally-generated 8-character screen pairing key
  • Device fingerprint: Android ID, model, brand, and manufacturer (used to recover the screen on reinstall)
  • Heartbeat and event data: connection status, screen resolution, app version, currently-playing content ID, and diagnostic events

The app does not access contacts, photos, location, microphone, or camera.

2.4 Billing data

Payment information (card details, billing address) is handled by our PCI-compliant payment processor. We receive only a token, the last four digits of the card, and invoice records.

2.5 Logs and analytics

Server logs include IP address, user agent, and request timestamps. We use these for security monitoring, debugging, and abuse prevention.

3. How we use your data

  • To operate the platform and serve content to your screens
  • To authenticate you and protect your account
  • To bill you and prevent fraud
  • To send service emails (renewals, payment notices, security alerts)
  • To diagnose issues and improve reliability
  • To comply with legal obligations

We do not sell your personal data. We do not use it for advertising or behavioural profiling.

4. Encryption and security

All data in transit between your device, our portal, and our backend is encrypted using HTTPS / TLS. Passwords are hashed with bcrypt. Backups are encrypted at rest. Production access is restricted to a small set of authorised engineers and audited.

5. Data sharing

We share data only with service providers who help us run the platform, under contracts that bind them to confidentiality and use limitations:

  • Cloud hosting and storage providers
  • Email delivery for transactional notifications
  • Payment processor for card processing
  • Error reporting and analytics tooling

We may also disclose data if required by law, to protect our rights, or to investigate fraud or security incidents.

6. Data retention

  • Account and content data: retained while your account is active
  • Heartbeat and event logs: retained for up to 90 days
  • Billing and invoice records: retained for 7 years to meet tax and accounting obligations
  • Server logs: retained for up to 30 days
  • Encrypted backups: purged within 90 days of deletion

7. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (see our Data Deletion page for instructions)
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email hello@dishplay.io.

8. Children

Dishplay is a business product and is not intended for children under 13. We do not knowingly collect personal information from children.

9. International transfers

Your data may be processed in countries other than the one where you live. When we transfer data internationally, we use standard contractual clauses or other lawful transfer mechanisms.

10. Changes to this policy

If we make material changes to this policy, we will notify account holders by email and update the “Last updated” date above. Continued use of the service after changes take effect constitutes acceptance of the revised policy.

11. Contact

Questions about this policy or how we handle your data? Email us at hello@dishplay.io.