Privacy Policy

Last updated: July 23, 2026

1. Introduction

GetDandy is an AI-powered platform that helps local businesses manage their online presence — collecting and responding to customer reviews, creating and publishing social media content, and handling day-to-day customer communication from a single place. Our customers are businesses in industries such as auto repair, home services, medical and dental, legal, beauty and spa, and veterinary care.

This Privacy Policy explains what information we collect across the entire GetDandy platform, why we collect it, who we share it with, and what control you have over it. It applies to our website, our web application at app.getdandy.com, and any connected integrations you choose to enable.

We built GetDandy on a simple principle: we collect what we need to run the service you asked for, and nothing more. We do not sell your data.

If anything here is unclear, contact us at support@getdandy.com and we’ll explain it in plain terms.

2. Information We Collect

We practice data minimization. We request, collect, and retain only the minimum information and permissions necessary to provide the features you have enabled. If you don’t use a feature, we don’t collect the data that feature would require. When you enable an integration, we request only the permissions that integration needs — and if a feature is later disabled or disconnected, we stop collecting the associated data.

Account information. When you create an account, we collect your name, email address, phone number (if provided), password (stored in hashed form), and details about your business such as company name, address, industry, website, and business hours.

Usage and analytics data. We record how you interact with the platform — pages viewed, features used, actions taken, timestamps, and referring pages. This helps us understand which parts of the product work well and which need improvement.

Device and browser information. We automatically collect your IP address, browser type and version, operating system, device type, screen resolution, language settings, and time zone. Some of this is collected through cookies and similar technologies.

Uploaded content. Photos, videos, logos, documents, and other files you upload to the platform — for example, images you attach to a social media post or media you store in your content library.

AI-generated content. Text, captions, review replies, and other material generated by our AI features. We store both the prompts or inputs you provide and the resulting output so you can review, edit, and reuse them.

Business data managed through the platform. Customer reviews and ratings, review responses, customer names and contact details you import or that arrive through connected services, messages, appointment or service records, and campaign and performance data.

Information from connected third-party integrations. When you connect an external account, we receive data from that service according to the permissions you approve. For example, connecting a Facebook Page gives us the Page name and ID, the access token needed to post on your behalf, and post performance metrics. Connecting a Google Business Profile gives us your location details and customer reviews. You control which integrations are connected, and you can revoke them at any time.

Contact data (where applicable). If you choose to import contacts — including from Apple or Google address books — to send messages through the platform, those contacts are stored securely and used only for the purposes you initiate, in line with applicable law including the CAN-SPAM Act.

3. How We Use Information

We use the information described above to:

  • Provide platform features — publish your posts, sync and display your reviews, generate AI content, deliver messages, and run the tools you’ve enabled.
  • Authenticate users — verify your identity, keep you signed in, and maintain the security of your account and connected integrations.
  • Provide customer support — respond to your questions, troubleshoot problems, and investigate issues you report.
  • Improve the product — understand how features are used, identify bugs and friction points, and develop new functionality.
  • Analytics and service improvements — measure performance, reliability, and usage patterns in aggregate.
  • Security and fraud prevention — detect and prevent unauthorized access, abuse, spam, and other harmful activity, and protect our users and our systems.
  • Communicate with you — send service notifications, security alerts, billing messages, and, where permitted, product updates you can unsubscribe from.
  • Meet legal obligations — comply with applicable laws, respond to lawful requests, and enforce our Terms.

We do not use your business data or your customers’ data to train third-party AI models.

4. Third-Party Integrations

GetDandy works with a number of third-party services to deliver the platform. Depending on which features you use, these may include:

  • Meta (Facebook and Instagram) — publishing posts and managing connected Pages and Instagram Business accounts
  • Google — Google Business Profile reviews, location data, and sign-in
  • OpenAI and other AI providers — generating content and review replies
  • Stripe — subscription billing and payment processing
  • Amazon Web Services (AWS) — hosting, storage, and infrastructure
  • Analytics, email delivery, and customer support providers — operating and supporting the service

We share with each provider only the data necessary to deliver the functionality you’ve requested. For example, when you generate an AI caption, we send the prompt and relevant context to the AI provider — not your full customer database. Payment card details go directly to our payment processor; we never store full card numbers on our systems.

Each of these providers handles your data under its own privacy policy, and we encourage you to review the policies of any service you connect.

5. Social Media Integrations

GetDandy lets you connect Facebook Pages and Instagram Business accounts so you can create, schedule, and publish content from within the platform, and see how that content performs.

Meta Platform Data usage. Data we receive from Meta APIs is used only to provide the features you have requested — connecting and managing your Pages and Instagram Business accounts, publishing and scheduling posts, and displaying analytics about that content inside your GetDandy account.

We do not use Meta Platform Data for advertising or ad targeting, to build user profiles or audience segments, to sell, license, or transfer it to data brokers or any other third party, to train AI or machine learning models, or for any purpose unrelated to the features you have enabled. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.

Permissions we request. We request only the permissions required for the features you choose to use. In general, these allow GetDandy to view the Pages and Instagram Business accounts you manage so you can select which to connect, publish and schedule posts to the accounts you have connected, and retrieve basic account information and post performance metrics needed to display your content and analytics.

During the connection process, Meta shows you exactly which permissions you are granting, and you can decline any of them. We do not request access to your personal Facebook profile content, your friends list, or your private messages.

Token storage. OAuth access tokens are encrypted at rest and transmitted only over secure connections. They are used solely to perform actions you have authorized, and are never shared with other customers or third parties.

Use of connected account data. Information from your connected accounts — Page names, account IDs, published posts, and engagement metrics — is used only to provide social posting and analytics features within your GetDandy account.

Disconnecting. You can remove the Facebook or Instagram integration at any time by going to Settings → Connections in your GetDandy dashboard and selecting Disconnect for the connected account. You can also remove GetDandy’s access directly from your Facebook settings under Settings & Privacy → Settings → Business Integrations.

Once you revoke access or disconnect the integration, GetDandy can no longer access your Meta account or retrieve any data from it unless you choose to reconnect it. When you disconnect, we revoke and delete the associated access tokens.

For full instructions on deleting Meta integration data, see our Facebook & Instagram Data Deletion Instructions page.

6. Data Sharing

We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.

We share data only in these situations:

  • With service providers who help us operate the platform (hosting, payment processing, AI generation, analytics, email delivery, customer support), limited to what they need to perform their function and bound by contractual confidentiality obligations.
  • At your direction — for example, publishing a post to a social network you’ve connected.
  • For legal reasons — when required by law, subpoena, court order, or other valid legal process, or to protect the rights, safety, and property of GetDandy, our users, or the public.
  • In a business transfer — if GetDandy is involved in a merger, acquisition, or sale of assets, your information may transfer as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

7. Data Retention

We retain your information for as long as your account is active and for as long as needed to provide the service.

  • Account and business data is retained while your account is open. After you close your account, we delete or anonymize it within 90 days, except where we must keep records longer for legal, tax, accounting, or fraud-prevention purposes.
  • OAuth tokens are deleted immediately when you disconnect an integration or close your account.
  • Uploaded content and AI-generated content is deleted along with your account, subject to the same retention window.
  • Billing records are retained for 7 years as required by financial and tax regulations.
  • Aggregated, anonymized analytics that cannot identify you or your business may be retained indefinitely.

If you submit a deletion request while your account is still active, we process it as described in Section 9.

8. User Rights

Depending on where you live, you may have some or all of the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — update inaccurate or incomplete information (most of this can be done directly in your account settings)
  • Export — receive your data in a portable, machine-readable format
  • Deletion — request that we erase your personal data
  • Restriction and objection — ask us to limit or stop certain processing
  • Withdraw consent — where we rely on consent, withdraw it at any time
  • Disconnect integrations — remove any connected third-party account at any time from your settings

To exercise any of these rights, email support@getdandy.com. We will respond within the timeframe required by applicable law (generally 30 days). We may need to verify your identity before acting on a request.

Some data may be exempt from deletion where we are legally required to retain it.

9. How to Request Data Deletion

You can request deletion of your data in any of the following ways:

1. From your account. Go to Settings → Account and select Delete Account. This begins the deletion process for your account and associated data.

2. By email. Send a request to support@getdandy.com from the email address associated with your account, with the subject line “Data Deletion Request.” Include your account email and business name so we can locate your records. We will confirm receipt and complete the deletion within 30 days.

3. For Meta-connected accounts. If you have connected a Facebook Page or Instagram Business account, see our dedicated Facebook & Instagram Data Deletion Instructions page for step-by-step guidance on deleting your Meta integration data.

You can also remove GetDandy’s access directly from your Facebook account under Settings & Privacy → Settings → Business Integrations: select GetDandy and choose Remove. Meta’s own instructions are available at https://www.facebook.com/help/204306952528565

Removing the integration on Facebook revokes our access going forward. To also delete the data already stored in your GetDandy account, submit a deletion request using one of the methods above.

10. Security

We use industry-standard measures to protect your information, including:

  • Encryption in transit — all traffic to and from the platform is served over HTTPS/TLS
  • Encryption at rest — stored data, including OAuth tokens and credentials, is encrypted
  • Secure token storage — access tokens are stored in encrypted form and never exposed in logs or client-side code
  • Access controls — role-based permissions and the principle of least privilege limit internal access to customer data
  • Password protection — passwords are hashed using industry-standard algorithms and are never stored in plain text
  • Infrastructure security — hosting with providers that maintain recognized security certifications, with firewalls, network isolation, and regular patching
  • Monitoring and logging — systems are monitored for unauthorized access and unusual activity
  • Regular review — periodic assessment of our security practices and dependencies

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

You can help protect your account by using a strong, unique password and keeping your login credentials confidential.

11. Children’s Privacy

GetDandy is a business tool intended for use by adults operating a business. The platform is not directed at children, and we do not knowingly collect personal information from anyone under the applicable minimum age — 13 in the United States, or 16 in jurisdictions where that higher age applies.

If we learn that we have collected personal information from a child below the applicable minimum age, we will delete it promptly. If you believe a child has provided us with personal information, contact us at support@getdandy.com.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the platform, our practices, or legal requirements. The current version will always be available on this page, with the “Last updated” date at the top.

If we make material changes, we will provide additional notice — such as an email to your account address or an in-app notification — before the changes take effect. Continuing to use GetDandy after an update means you accept the revised policy.

13. Contact Us

If you have questions about this Privacy Policy or how we handle your data, get in touch:

GetDandy
Email: support@getdandy.com
Support: https://getdandy.com/support/
Address: 9891 Irvine Center Dr, Irvine, California 92618, US

We aim to respond to all privacy inquiries within 5 business days.