Privacy Notice
The short version
Daash sells market estimates to businesses. Our product is built from publicly available retailer and product information and from licensed aggregate market data — not from personal information about consumers.
We hold personal information about three groups of people, and very little of it: the people at our client companies who log in to use our platform, the people at companies we talk to about business, and the people who visit this website. We do not sell personal information. We do not use it to train models. We do not build consumer profiles.
1. Who we are
Daash Intelligence, Inc. is a Delaware corporation with its principal place of business in California and offices in New York. For the personal information described in this notice, Daash is the controller, except where we hold a client's platform user data on that client's instructions, in which case the client is the controller and we are the processor.
Questions, requests, and complaints: privacy@daash.co.
2. What we collect, and why
2.1 If you use the Daash platform
Your employer has contracted with us and provisioned your account.
| What we hold | Why |
|---|---|
| Your name, business email address, and business role | To create your account, authenticate you, and give you access to the right workspace |
| What you do in the platform — reports viewed, queries run, exports taken, session times | To operate and support the service, verify usage against your employer's subscription, and detect misuse |
| Support correspondence | To answer you |
Your password is held and hashed by our authentication provider. We never see it and cannot retrieve it.
2.2 If we talk to you about business
| What we hold | Why |
|---|---|
| Name, business email, business phone, employer, role | To correspond with you about our services, respond to inquiries, and manage a commercial relationship |
2.3 If you visit this website
| What we hold | Why |
|---|---|
| Information you submit in a form | To respond to you |
| Standard technical and analytics information — IP address, browser and device type, pages viewed, referring page | To keep the site working and understand how it is used |
We use cookies and similar technologies in four categories: strictly necessary, analytics, personalization, and marketing. Only the strictly necessary category is always on. Where required, we ask for your consent first, and you can accept all, reject all, or choose categories individually. Declining does not cost you access to any of the site's content, and you can change your choice at any time through the Cookie Settings link in the footer.
3. What we do not do
- We do not sell, rent, license, or trade personal information, and we do not share it for cross-context behavioral advertising. We do not provide it to data brokers, and we do not run advertising networks or retargeting on this site. We use a marketing platform to send our own email and to run our own sign-up forms, described in section 5.
- We do not collect consumer shopping data, loyalty data, payment information, or purchase histories about individuals. Our estimates describe products, brands, and categories — not people.
- We do not use personal information to train our models. Our models are trained on publicly available retailer and product data and licensed aggregate market signals.
- We do not use our clients' data to train models, for them or for anyone else. We do not ask our clients for their business data, because our product does not need it.
- We do not make automated decisions about individuals. Nothing we produce has a legal or similarly significant effect on any person.
- We do not knowingly collect information from children. Our platform is a business tool sold to companies and is not directed to anyone under 18.
4. Our legal basis
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for operating the platform for a client's users; legitimate interests, for business correspondence, service security, and website analytics, balanced against the individual's interests; consent, where we ask for it, such as for non-essential cookies and marketing email; and legal obligation, where law requires us to retain or disclose.
Where Canadian privacy law applies, we handle personal information in accordance with PIPEDA and applicable provincial legislation, including Quebec's Law 25.
5. Who else sees it
We share personal information only with service providers who help us run the business, each under a written agreement that restricts what they may do with it. The categories of recipient are:
| Category | What they do for us |
|---|---|
| Cloud hosting and infrastructure | Host the platform and store its data |
| Identity and authentication | Authenticate users and hold credentials in hashed form |
| Business productivity | Corporate email, calendar, and document storage |
| Marketing and communications | Send our own email, run our sign-up forms, and measure how this website is used |
| Engineering services | Software development and production support under contract, with least-privilege access granted to named individuals |
We do not add a new category of recipient without updating this notice. A current list of the specific providers behind these categories is available to clients and prospective clients on request, and is provided as a matter of course during security and privacy review.
We may also disclose personal information where we are legally compelled to, or to establish or defend legal claims, or in connection with a merger, acquisition, or sale of assets — in which case this notice continues to apply until the acquirer gives notice of its own.
6. Where it is held
Personal information is stored in the United States, in our cloud hosting provider's United States regions and with our authentication provider. It is not stored anywhere else.
One point we want to be explicit about. We engage an engineering services vendor whose personnel are located outside the United States. Those named individuals have least-privilege access to our production platform environment for software development and production support, which means they may encounter platform account records and usage data in the course of that work. They do not have access to our corporate email, support correspondence, or business contact records. No personal information is stored outside the United States as a result, but access to it does occur from outside the United States, and we would rather say so than imply otherwise.
If you are outside the United States, including in Canada, the United Kingdom, or the European Economic Area, your personal information is transferred to and stored in the United States and may be accessible to United States authorities under that country's laws. For transfers from the UK or EEA we rely on the European Commission's standard contractual clauses and the UK addendum, and our engineering services vendor is bound by equivalent contractual protections. For transfers from Canada, we disclose the location of storage and the fact of access from outside the country here and in our client agreements, so that our clients can inform their own people.
7. How long we keep it
| Information | Retained |
|---|---|
| Platform user accounts | For as long as your employer's agreement runs, then deleted from live systems within 90 days |
| Platform usage records | A rolling operational window, and no longer than the client relationship plus 90 days |
| Business contact records | While the commercial relationship is live, and for a reasonable period afterward in line with our internal retention schedules. You can ask us to delete yours at any time |
| Support correspondence | Generally 24 months |
| Website analytics | In line with the analytics provider's standard retention |
Copies in automated backups expire on their own schedule rather than being individually removed.
8. How we protect it
We maintain administrative, technical, and organizational safeguards designed to protect personal information. These include encryption in transit and at rest, least-privilege access limited to named individuals, multi-factor authentication on administrative access, logging of administrative activity, periodic access reviews, and a documented information security program owned by named executives and assessed against risk at least annually.
No set of safeguards is perfect, and we do not claim otherwise. Clients and prospective clients can request our full security documentation, which describes these controls in detail, under a confidentiality agreement.
9. Your rights
You may ask us to:
- Tell you what personal information we hold about you, why, and who we have shared it with
- Correct it if it is wrong
- Delete it
- Give you a copy in a portable format
- Stop or restrict a particular use, or object to it
- Withdraw consent you have given, at any time, without affecting what we did before you withdrew it
- Stop sending you marketing — every marketing email also carries an unsubscribe link
Write to privacy@daash.co. We will acknowledge promptly and respond within 30 calendar days, or within any shorter or longer period that applicable law requires. If a request is complex we may take a further period where law allows it, and we will tell you why within the original 30 days. There is no charge. We will not ask you to create an account or give up any right in order to make a request.
If you use the Daash platform through your employer, we generally process your account and usage information on your employer's instructions, as their processor. For those records your employer decides what is kept and what is deleted, so we will refer your request to them or coordinate with them before acting — and we will tell you when we do. If your employer's contract with us has ended, or they direct us to act, we will act directly. For personal information where we are the controller — business contact records and website data — you can exercise these rights with us directly.
We will not discriminate against you for exercising any of these rights.
If you are unhappy with our answer, you can complain to your data protection authority: in Canada, the Office of the Privacy Commissioner of Canada; in the UK, the Information Commissioner's Office; in the EEA, your national supervisory authority. We would rather you came to us first, and we will take it seriously.
10. California residents
Daash is based in California, and California law may give California residents rights over their personal information, including the right to know what is collected and why, to access it, to correct it, to delete it, and to receive information about how it is disclosed.
Two statements that matter most under California law:
- We do not sell personal information, and we have not sold personal information in the preceding twelve months.
- We do not share personal information for cross-context behavioral advertising, and we have not done so in the preceding twelve months.
Because neither applies to us, we do not operate a "Do Not Sell or Share My Personal Information" mechanism. If that changes, we will add one and say so here.
The categories of personal information we collect, the sources, the purposes, and the categories of recipient are set out in sections 2, 5, and 7 above, which together describe every category we hold. We do not collect sensitive personal information as California law defines it, and we do not use or disclose personal information for purposes other than those described in this notice.
California residents may exercise these rights by writing to privacy@daash.co, on the terms in section 9. We will not discriminate against you for doing so, and you may use an authorized agent.
11. Changes
We will post any change to this notice on this page. If a change materially affects how we handle your personal information, we will tell affected clients directly.
12. Contact
Daash Intelligence, Inc. — General support and security reports: help@daash.co