Dashboard

Privacy Policy

Last updated October 5, 2026

This policy explains what the StrapsCo Dashboard (the “Dashboard”) collects about the people who use it, why, and how it is protected. It applies to the Dashboard only, which is used by StrapsCo employees and contractors. StrapsCo is Delaware 74105 Ventures Inc. (“StrapsCo”, “we”, “us”).

Shoppers on strapsco.com are covered by the store’s own Privacy Policy, not this one.

1. What we collect about you

When an administrator invites you and you set up your account, the Dashboard stores:

  • Your name and work email address, and the role and permissions an administrator assigns to you.
  • Your sign-in credentials: your password (stored only as a salted hash, never in readable form), the secret for your authenticator app, the public keys of any passkeys you register, and your recovery codes (stored hashed).
  • Invitation records: the email the invitation was sent to, when it was sent, and when it was used.

While you use the Dashboard it also records:

  • Sessions: when each started, when it expires, when it was last active, the IP address and the browser and device description your browser sends.
  • An audit trail of security and administrative events: sign-ins, sign-outs, failed sign-in attempts, sign-in resets, permission changes, and edits to settings, inputs and integrations, with who did what and when.

Your theme preference (light, dark or match device) is kept in your own browser only. The Dashboard sets one cookie, which keeps you signed in; it does not use advertising, tracking or third-party analytics cookies.

2. Why we collect it

  • To sign you in securely and make sure only the right people see each part of the Dashboard.
  • To notice and investigate security problems, such as unusual sign-ins or a lost device.
  • To know who changed a setting or an input when a figure needs explaining.
  • To send you account emails: your invitation, sign-in resets and security notices. We do not send marketing from the Dashboard.

We process this information because it is necessary to run the tool you use for your work with StrapsCo and to keep StrapsCo’s business data secure.

3. Business data shown in the Dashboard

The Dashboard also holds StrapsCo’s business records pulled from the systems StrapsCo uses: orders and refunds from the store, advertising spend and results from advertising platforms, website analytics, inventory and cost data, email-marketing results and Amazon sales. This is StrapsCo’s data, and you may only use it as described in the Terms of Use.

Where the Dashboard needs to tell new customers from returning ones, it keeps a one-way hash of the order’s billing email rather than the email itself. Customers’ names, addresses and payment details are not copied into the Dashboard.

4. Who can see your information

  • StrapsCo administrators can see your account details, your permissions, your active sessions and the audit trail.
  • Service providers that host or deliver the Dashboard on our behalf: the application and its database run on Railway (United States); account emails are sent through Resend. If an administrator connects alerts to Telegram or Slack, alert messages (figures and notes, not your account details) are delivered through those services.
  • Nobody else. We do not sell or share your information, and the Dashboard shows no advertising.

5. How it is protected

Every connection to the Dashboard is encrypted (HTTPS). Sign-in needs your password, plus a 6-digit authenticator code or a passkey once you have set one up. Passwords and recovery codes are stored only as hashes, and the credentials the Dashboard uses to reach other systems are stored encrypted. Each person sees only what their permissions allow, and administrative changes are recorded.

6. How long we keep it

  • Account details and credentials: for as long as your account exists. When an administrator removes your account, they are deleted.
  • Sessions: until they expire or you sign out, after which they are removed.
  • The audit trail: kept for security and accountability for as long as StrapsCo needs it, including after your account is removed.

7. Your choices

You can change your name, password, authenticator app, passkeys and recovery codes, and sign out other devices, from Profile & security in the Dashboard. To correct anything else, or to have your account removed, ask a StrapsCo administrator or email info@strapsco.com.

8. Changes to this policy

We may update this policy as the Dashboard changes. The date at the top shows the current version; significant changes will be pointed out when you next sign in or by email.

Contact

Privacy questions: info@strapsco.com, or write to Delaware 74105 Ventures Inc., 35 Gateway Dr, STE 100, Plattsburgh, NY 12901-5381, United States.