Legal

Privacy Policy

Last updated: September 2, 2026

This Privacy Policy explains how Xamtac Consulting LLC (“Xamtac”, “we”, “us” or “our”), 33 W Delaware Pl, Chicago, IL 60610, United States, handles personal information in connection with AI Marketing Dashboard (the “Service”) and our website at www.aimarketingdashboard.com.

The Service is a business platform used by marketing agencies to run their own client work. That means we handle two very different kinds of information, and Section 2 explains which is which, because it decides who you should contact about yours.

1. Introduction

Xamtac Consulting LLC operates AI Marketing Dashboard, an agency operations platform for client reporting, CRM, projects, chat, meetings, files, notes, client portals, a marketing library, campaign planning and publishing.

This policy covers our public website, the sign-up and billing flow, the agency console and the client portals we host. Your use of the Service is also governed by our Terms & Conditions. It does not cover the privacy practices of the third-party platforms you connect to the Service, or of the agencies who use the Service to serve their own clients; those are governed by their own policies.

2. Our Role: Business and Service Provider

Where we act for ourselves. For visitors to our website, people who sign up for an account, workspace administrators and the people we market to, we decide how and why information is used. Under United States state privacy laws we are the “business” for that information (a “controller” under similar laws elsewhere), and this policy describes what we do with it.

Where we act for our customers. Most of the information in the Service is Customer Content: the client records, CRM leads, files, messages, notes, form and booking submissions collected through pages our customers publish, and the activity of the portal users they invite. For that information the agency is the business, and we act as its service provider (a “processor”), handling the data on that agency’s instructions in order to provide the Service. We do not use Customer Content for our own advertising, and we do not sell it.

If you are the client of an agency, or a visitor who filled in a form on a page an agency published, contact that agency first about your information. If you contact us instead, we will route your request to the agency and assist it in responding.

3. Information We Collect

Information you provide. Your name, email address, password credentials, company and workspace details, job title, profile photo, and the content you create or upload in the Service (files, notes, messages, tasks, CRM records, campaign material and similar). When you subscribe, our billing and payment providers collect your billing contact, plan and payment details; we receive the subscription and payment status and the billing contact. We do not store full payment card numbers. We also keep the content of support requests you send us.

Information collected automatically. Device and browser information, IP address, approximate location derived from it, pages viewed, referring pages, the actions taken in the product, session identifiers, and error, performance and diagnostic logs. Some of this is collected using cookies and similar technologies, described in Section 7.

Information from platforms our customers connect. At a customer’s direction and with the permissions that customer grants, we retrieve advertising, analytics, search, email and social data from the accounts they connect. Today that is the Google Ads API; as further report integrations ship, it will include Google Analytics, Google Search Console, the Meta Marketing API, the LinkedIn Marketing API, the Microsoft Advertising (Bing) API, Bing Webmaster Tools, Klaviyo and similar reporting integrations. This is usually campaign and performance data rather than information about individuals, and it is stored in that customer’s workspace.

Workspace and employment records. Where an agency uses the Service’s team features, its workspace administrators enter information about their own people: profiles and roles, onboarding documents and signed agreements, time off requests, payslips and payroll details. Bank account and routing numbers entered for payroll are written to an encrypted vault; the product stores and displays only the last four digits and provides no way to read a full number back. This information belongs to the agency, and we handle it on the agency’s behalf.

Communications content. Messages sent in workspace and client chat; video meetings hosted through LiveKit, which may be recorded and transcribed, including by automated transcription; and voice calls placed or received through telephony providers such as Twilio, which may be recorded where the workspace has enabled it. See Section 13.

Submissions to pages our customers publish. Landing pages, forms and booking pages published through the Service collect what the customer asks for, typically a name, email address, phone number, message and campaign attribution parameters, together with the technical information any web request carries. Those submissions are collected on the publishing customer’s behalf and land in that customer’s workspace.

4. How We Use Information

We use information for the following purposes:

  • to provide, operate, maintain and secure the Service, including authentication, workspace isolation, backups and abuse prevention;
  • to retrieve and present reporting from the platforms a customer connects, and to show sync status and errors;
  • to power AI-assisted features such as drafting, summaries, suggestions and transcription (see Section 6);
  • to process subscriptions, payments, renewals and invoices through our billing and payment providers;
  • to communicate with you about the Service, including service notices, security alerts, billing messages and support responses;
  • to market our own product, including sending marketing email you can unsubscribe from at any time, measuring our campaigns, and building and reaching audiences for our advertising (this uses information about our own website visitors and account holders, never our customers’ connected platform data or Customer Content);
  • to analyze and improve the Service, understand which features are used and diagnose problems, including through aggregated and de-identified analysis;
  • to comply with legal obligations, respond to lawful requests and keep required records; and
  • to establish, exercise or defend legal claims and to enforce our Terms.

5. Connected Marketing Platform Data

Data retrieved from a marketing platform a customer connects is used only to provide the Service to that customer’s workspace: to build their reports, power the insights and exports in the product, and show the status of a sync. It is not used for our own advertising, is not combined across customers for any purpose other than operating and securing the Service, and is never sold or shared for cross-context behavioral advertising.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

As integrations with the Meta Marketing API, the LinkedIn Marketing API and the Microsoft Advertising APIs ship, we will handle data received through them on the same basis, in accordance with those platforms’ terms and developer policies. Disconnecting an account stops future syncing; data already retrieved remains in the customer’s workspace until they delete it or their account is terminated.

6. AI Features

Some features send the content you are working on to third-party AI service providers so they can generate a draft, a summary, a suggestion or a transcript. Those providers currently include OpenAI and, as we expand these features, Anthropic. They act as our service providers and may use the content only to return a result to us.

Under our agreements with these providers, content submitted through their business APIs is not used to train their models. AI output is generated automatically and may be inaccurate, so review it before you rely on it. Please do not enter sensitive personal information into an AI-assisted field unless the feature needs it.

7. Cookies, Analytics and Advertising Technology

Essential cookies. The Service uses cookies that are necessary for it to work: sign-in and session cookies set by our authentication provider Clerk, the cookie that records which client portal you are viewing, and cookies used for security. These cannot be turned off within the product.

Functional storage. We keep small preferences in your browser’s local storage, such as the client you last selected, the layout of a list, and dismissed notices. This information stays in your browser.

Product analytics and error monitoring. We use PostHog for product analytics and session replay, served through our own domain, and Sentry for error and performance monitoring. These help us understand how the Service is used and diagnose faults.

Marketing and advertising technology on our public pages. On our public marketing pages we use, or plan to use, Google Analytics, the Google Ads tag and remarketing pixel, the Meta Pixel, Microsoft Advertising UET and the LinkedIn Insight Tag. These measure the performance of our own campaigns and let us show our ads to relevant audiences, including people who have visited our site (remarketing). Depending on where you live, this activity may be treated as “sharing” or “targeted advertising” under state privacy law.

Your choices. Most browsers let you block or delete cookies through their settings, though blocking essential cookies will stop the Service from working. You can also use the ad-platform and industry controls below:

  • Google: adssettings.google.com;
  • Meta: the ad preferences and ad topic controls in your Facebook or Instagram account settings;
  • LinkedIn and Microsoft: the advertising and interest-based advertising controls in your LinkedIn and Microsoft account settings;
  • Network Advertising Initiative: optout.networkadvertising.org; and
  • Digital Advertising Alliance: optout.aboutads.info.

8. How We Share Information

We share information with service providers who help us run the Service, and only for that purpose. By function, they are:

  • Clerk, for authentication, organization membership and subscription billing;
  • the payment processors engaged by our billing provider, such as Stripe, for processing payments;
  • Supabase, for our database and file storage;
  • Vercel, for application hosting, delivery and AI request routing;
  • Amazon Web Services, for email delivery through Amazon SES and for supporting infrastructure;
  • LiveKit, for video meetings and recordings;
  • Twilio, for voice calls and telephony;
  • OpenAI and Anthropic, for the AI processing described in Section 6;
  • PostHog, for product analytics and session replay, and Sentry, for error monitoring; and
  • Google, Meta, Microsoft and LinkedIn, when you connect one of their accounts to the Service or when you interact with our advertising.

We review a provider before we adopt it, give it only the information it needs to perform its function, and require it by contract to protect that information and to use it only for us. This list changes as the Service evolves; the current set is described by function above rather than pinned to a version of this page.

We also share information inside a customer’s own workspace according to that customer’s settings: agency team members see what their roles and client assignments allow, and portal users see the client-scoped content the agency has shared with them. We may share information with our professional advisors (such as lawyers, accountants and auditors); where we believe disclosure is required by law or legal process, or is necessary to protect the rights, property or safety of Xamtac, our customers or the public; and in connection with a merger, acquisition, financing or sale of assets, in which case we will continue to protect the information under this policy or give notice before it becomes subject to a different one.

We do not sell your personal information.

To be precise about one point: the advertising and analytics technology on our public pages described in Section 7 may be treated as “sharing” for cross-context behavioral advertising or as “targeted advertising” under some state privacy laws, even though no money changes hands. You can opt out using the cookie and platform controls in Section 7, by sending a recognized opt-out preference signal (Section 12), or by emailing us at contact@xamtac.com.

9. Data Retention

We keep account information and Customer Content for as long as the account and subscription are active, and afterwards for as long as we need it to comply with legal obligations, resolve disputes, enforce our agreements and maintain security.

After an account is terminated, Customer Content remains available for export for the window described in our Terms & Conditions, after which we may delete it. Deleted data may persist for a limited period in routine encrypted backups before those backups expire. Aggregated and de-identified information that can no longer be linked to you may be kept indefinitely.

When you delete a record, a file or a client inside the Service, it is removed from your workspace. Some deletions are completed in the background, including the removal of stored files that belonged to the deleted record, so a large deletion may take a short while to finish. Logs kept for security and diagnostics are retained on their own schedule and are not a copy of your workspace.

10. Security

We protect information with measures appropriate to the Service, including encryption in transit, per-workspace data isolation enforced at the database layer, role and capability-based access controls, and vaulting of the credentials used for connected accounts and payroll details so that secrets are never displayed back in the product.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keeping your own credentials safe and managing who has access to your workspace are your responsibility. If you believe you have found a security issue, please report it to contact@xamtac.com.

11. Your Rights and Choices

Depending on where you live, including in California, Colorado, Connecticut, Texas and Virginia among other states, you may have the right to request access to the personal information we hold about you, to correct it, to delete it, to receive a portable copy, and to opt out of targeted advertising and of any “sale” or “sharing” of your personal information. You also have the right not to be discriminated against for exercising these rights.

To make a request, email us at contact@xamtac.com and tell us what you would like to do. We will verify your identity before acting, usually by confirming control of the email address on the account or by asking for information that matches our records; a request we cannot verify will be declined. An authorized agent may submit a request on your behalf with proof of authority. If we decline a request you may appeal by replying to our response, and we will review the appeal and explain the outcome.

We answer within the period the applicable law allows, which in several states is 45 days from a verified request, extendable where the law permits and we tell you why. There is no charge for a reasonable request. Deleting information that we need in order to keep your account running may mean closing the account, and we will say so before we act.

You can opt out of our marketing email at any time using the unsubscribe link in the message or by emailing us; we will still send service, billing and security messages about your account.

If your information is in a workspace operated by an agency, that agency controls it. Contact the agency first; if you contact us, we will route the request to them and help them respond.

12. Opt-Out Preference Signals

We do not respond to the legacy Do Not Track browser setting, because there is no common standard for it. Where applicable law requires it, we will treat a recognized opt-out preference signal, such as Global Privacy Control, as a request to opt that browser out of targeted advertising.

13. Meeting and Call Recordings

Meetings and calls held through the Service may be recorded and transcribed when a participant with the right permission turns recording on. Recordings and transcripts are stored in the workspace that created them and are visible to the people that workspace allows.

The workspace that starts a recording is responsible for giving notice and obtaining the consent the law requires. Some jurisdictions, including Illinois, require the consent of every party to the conversation. If you are a participant and do not want to be recorded, say so and leave the meeting or call.

14. Biometric Information

We do not use the Service to collect or process biometric identifiers or biometric information, such as fingerprints, voiceprints, retina or iris scans, or scans of hand or face geometry. Meeting and call recordings are stored and transcribed as audio and video; they are not used to generate a voiceprint or a face template, and we do not perform facial recognition.

15. Children

The Service is a business product. It is not directed to children, is not intended for anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact contact@xamtac.com and we will delete it.

16. International Users

We operate in the United States, and information we handle is processed and stored there. If you access the Service from another country, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your own country.

17. Agency Portals and Published Pages

Agencies use the Service to run white-labeled client portals and to publish landing pages, forms and booking pages, sometimes on their own domains and under their own branding. Those surfaces are operated by the agency.

The agency’s own privacy practices govern its relationship with its clients and with the visitors to the pages it publishes, and the agency is responsible for the notices and consents those pages require. This policy governs how Xamtac handles information as the provider of the underlying platform.

18. Changes to This Policy

We may update this policy. When we do, we will change the “Last updated” date at the top of this page, and for material changes we will give notice by email to the administrative contact on an account or through an in-app notice before the change takes effect. Continuing to use the Service after a change takes effect means you accept the updated policy.

19. Contact Us

For privacy questions, requests or complaints, contact us at contact@xamtac.com or by mail:

Xamtac Consulting LLC
33 W Delaware Pl
Chicago, IL 60610
United States

For the agreement that governs use of the Service, read the Terms & Conditions.

Privacy Policy | AI Marketing Dashboard