Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains how Xamtac Consulting LLC (“Xamtac”, “we”, “us” or “our”), 33 W Delaware Pl, Chicago, IL 60610, United States, handles personal information in connection with AI Marketing Dashboard (the “Service”) and our website at www.aimarketingdashboard.com.
The Service is a business platform used by marketing agencies to run their own client work. That means we handle two very different kinds of information, and Section 2 explains which is which, because it decides who you should contact about yours.
1. Introduction
Xamtac Consulting LLC operates AI Marketing Dashboard, an agency operations platform for client reporting, CRM, projects, chat, meetings, files, notes, client portals, a marketing library, campaign planning and publishing.
This policy covers our public website, the sign-up and billing flow, the agency console and the client portals we host. Your use of the Service is also governed by our Terms & Conditions. It does not cover the privacy practices of the third-party platforms you connect to the Service, or of the agencies who use the Service to serve their own clients; those are governed by their own policies.
2. Our Role: Business and Service Provider
Where we act for ourselves. For visitors to our website, people who sign up for an account, workspace administrators and the people we market to, we decide how and why information is used. Under United States state privacy laws we are the “business” for that information (a “controller” under similar laws elsewhere), and this policy describes what we do with it.
Where we act for our customers. Most of the information in the Service is Customer Content: the client records, CRM leads, files, messages, notes, form and booking submissions collected through pages our customers publish, and the activity of the portal users they invite. For that information the agency is the business, and we act as its service provider (a “processor”), handling the data on that agency’s instructions in order to provide the Service. We do not use Customer Content for our own advertising, and we do not sell it.
If you are the client of an agency, or a visitor who filled in a form on a page an agency published, contact that agency first about your information. If you contact us instead, we will route your request to the agency and assist it in responding.
3. Information We Collect
Information you provide. Your name, email address, password credentials, company and workspace details, job title, profile photo, and the content you create or upload in the Service (files, notes, messages, tasks, CRM records, campaign material and similar). When you subscribe, our billing and payment providers collect your billing contact, plan and payment details; we receive the subscription and payment status and the billing contact. We do not store full payment card numbers. We also keep the content of support requests you send us.
Information collected automatically. Device and browser information, IP address, approximate location derived from it, pages viewed, referring pages, the actions taken in the product, session identifiers, and error, performance and diagnostic logs. Some of this is collected using cookies and similar technologies, described in Section 7.
Information from platforms our customers connect. At a customer’s direction and with the permissions that customer grants, we retrieve advertising, analytics, search, email and social data from the accounts they connect. Today that is the Google Ads API; as further report integrations ship, it will include Google Analytics, Google Search Console, the Meta Marketing API, the LinkedIn Marketing API, the Microsoft Advertising (Bing) API, Bing Webmaster Tools, Klaviyo and similar reporting integrations. This is usually campaign and performance data rather than information about individuals, and it is stored in that customer’s workspace.
Workspace and employment records. Where an agency uses the Service’s team features, its workspace administrators enter information about their own people: profiles and roles, onboarding documents and signed agreements, time off requests, payslips and payroll details. Bank account and routing numbers entered for payroll are written to an encrypted vault; the product stores and displays only the last four digits and provides no way to read a full number back. This information belongs to the agency, and we handle it on the agency’s behalf.
Communications content. Messages sent in workspace and client chat; video meetings hosted through LiveKit, which may be recorded and transcribed, including by automated transcription; and voice calls placed or received through telephony providers such as Twilio, which may be recorded where the workspace has enabled it. See Section 13.
Submissions to pages our customers publish. Landing pages, forms and booking pages published through the Service collect what the customer asks for, typically a name, email address, phone number, message and campaign attribution parameters, together with the technical information any web request carries. Those submissions are collected on the publishing customer’s behalf and land in that customer’s workspace.
4. How We Use Information
We use information for the following purposes:
- to provide, operate, maintain and secure the Service, including authentication, workspace isolation, backups and abuse prevention;
- to retrieve and present reporting from the platforms a customer connects, and to show sync status and errors;
- to power AI-assisted features such as drafting, summaries, suggestions and transcription (see Section 6);
- to process subscriptions, payments, renewals and invoices through our billing and payment providers;
- to communicate with you about the Service, including service notices, security alerts, billing messages and support responses;
- to market our own product, including sending marketing email you can unsubscribe from at any time, measuring our campaigns, and building and reaching audiences for our advertising (this uses information about our own website visitors and account holders, never our customers’ connected platform data or Customer Content);
- to analyze and improve the Service, understand which features are used and diagnose problems, including through aggregated and de-identified analysis;
- to comply with legal obligations, respond to lawful requests and keep required records; and
- to establish, exercise or defend legal claims and to enforce our Terms.
5. Connected Marketing Platform Data
Data retrieved from a marketing platform a customer connects is used only to provide the Service to that customer’s workspace: to build their reports, power the insights and exports in the product, and show the status of a sync. It is not used for our own advertising, is not combined across customers for any purpose other than operating and securing the Service, and is never sold or shared for cross-context behavioral advertising.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
As integrations with the Meta Marketing API, the LinkedIn Marketing API and the Microsoft Advertising APIs ship, we will handle data received through them on the same basis, in accordance with those platforms’ terms and developer policies. Disconnecting an account stops future syncing; data already retrieved remains in the customer’s workspace until they delete it or their account is terminated.
6. AI Features
Some features send the content you are working on to third-party AI service providers so they can generate a draft, a summary, a suggestion or a transcript. Those providers currently include OpenAI and, as we expand these features, Anthropic. They act as our service providers and may use the content only to return a result to us.
Under our agreements with these providers, content submitted through their business APIs is not used to train their models. AI output is generated automatically and may be inaccurate, so review it before you rely on it. Please do not enter sensitive personal information into an AI-assisted field unless the feature needs it.
9. Data Retention
We keep account information and Customer Content for as long as the account and subscription are active, and afterwards for as long as we need it to comply with legal obligations, resolve disputes, enforce our agreements and maintain security.
After an account is terminated, Customer Content remains available for export for the window described in our Terms & Conditions, after which we may delete it. Deleted data may persist for a limited period in routine encrypted backups before those backups expire. Aggregated and de-identified information that can no longer be linked to you may be kept indefinitely.
When you delete a record, a file or a client inside the Service, it is removed from your workspace. Some deletions are completed in the background, including the removal of stored files that belonged to the deleted record, so a large deletion may take a short while to finish. Logs kept for security and diagnostics are retained on their own schedule and are not a copy of your workspace.
10. Security
We protect information with measures appropriate to the Service, including encryption in transit, per-workspace data isolation enforced at the database layer, role and capability-based access controls, and vaulting of the credentials used for connected accounts and payroll details so that secrets are never displayed back in the product.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keeping your own credentials safe and managing who has access to your workspace are your responsibility. If you believe you have found a security issue, please report it to contact@xamtac.com.
11. Your Rights and Choices
Depending on where you live, including in California, Colorado, Connecticut, Texas and Virginia among other states, you may have the right to request access to the personal information we hold about you, to correct it, to delete it, to receive a portable copy, and to opt out of targeted advertising and of any “sale” or “sharing” of your personal information. You also have the right not to be discriminated against for exercising these rights.
To make a request, email us at contact@xamtac.com and tell us what you would like to do. We will verify your identity before acting, usually by confirming control of the email address on the account or by asking for information that matches our records; a request we cannot verify will be declined. An authorized agent may submit a request on your behalf with proof of authority. If we decline a request you may appeal by replying to our response, and we will review the appeal and explain the outcome.
We answer within the period the applicable law allows, which in several states is 45 days from a verified request, extendable where the law permits and we tell you why. There is no charge for a reasonable request. Deleting information that we need in order to keep your account running may mean closing the account, and we will say so before we act.
You can opt out of our marketing email at any time using the unsubscribe link in the message or by emailing us; we will still send service, billing and security messages about your account.
If your information is in a workspace operated by an agency, that agency controls it. Contact the agency first; if you contact us, we will route the request to them and help them respond.
12. Opt-Out Preference Signals
We do not respond to the legacy Do Not Track browser setting, because there is no common standard for it. Where applicable law requires it, we will treat a recognized opt-out preference signal, such as Global Privacy Control, as a request to opt that browser out of targeted advertising.
13. Meeting and Call Recordings
Meetings and calls held through the Service may be recorded and transcribed when a participant with the right permission turns recording on. Recordings and transcripts are stored in the workspace that created them and are visible to the people that workspace allows.
The workspace that starts a recording is responsible for giving notice and obtaining the consent the law requires. Some jurisdictions, including Illinois, require the consent of every party to the conversation. If you are a participant and do not want to be recorded, say so and leave the meeting or call.
14. Biometric Information
We do not use the Service to collect or process biometric identifiers or biometric information, such as fingerprints, voiceprints, retina or iris scans, or scans of hand or face geometry. Meeting and call recordings are stored and transcribed as audio and video; they are not used to generate a voiceprint or a face template, and we do not perform facial recognition.
15. Children
The Service is a business product. It is not directed to children, is not intended for anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact contact@xamtac.com and we will delete it.
16. International Users
We operate in the United States, and information we handle is processed and stored there. If you access the Service from another country, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your own country.
17. Agency Portals and Published Pages
Agencies use the Service to run white-labeled client portals and to publish landing pages, forms and booking pages, sometimes on their own domains and under their own branding. Those surfaces are operated by the agency.
The agency’s own privacy practices govern its relationship with its clients and with the visitors to the pages it publishes, and the agency is responsible for the notices and consents those pages require. This policy governs how Xamtac handles information as the provider of the underlying platform.
18. Changes to This Policy
We may update this policy. When we do, we will change the “Last updated” date at the top of this page, and for material changes we will give notice by email to the administrative contact on an account or through an in-app notice before the change takes effect. Continuing to use the Service after a change takes effect means you accept the updated policy.
19. Contact Us
For privacy questions, requests or complaints, contact us at contact@xamtac.com or by mail:
For the agreement that governs use of the Service, read the Terms & Conditions.