D
DeskGo
Terms of Service →

Privacy Policy

Last updated: 7 July 2026 · The short version: EU-hosted, one cookie, no ad tracking, and we never sell your data.

1. What we collect

Account data: your name, work email, password (hashed — we never see it), and company name.

Workspace data: the offices, floors, desks, and rooms you set up, plus bookings — who booked what, when.

If your organisation connects SSO (Microsoft Entra ID or Google Workspace), we receive your name, email, and group membership from your identity provider at sign-in. That's all we ask for.

Basic technical data: IP address and browser details in server logs, used for security and debugging.

2. What we use it for

Running DeskGo: signing you in, showing availability, recording bookings, sending booking and account emails.

Keeping the lights on: billing, support, security monitoring, and fixing bugs.

We don't sell your data, we don't run ads, and we don't use your data to train AI models. Booking patterns may be aggregated and anonymised to improve the product — never in a way that identifies a person.

3. Where it lives

Your data is stored with Supabase in the EU (Frankfurt). Backups are encrypted and kept within the EU. Data in transit is encrypted with TLS; data at rest is encrypted too.

4. Who else touches it

We use a small set of processors, each under a data processing agreement: Supabase (database and hosting, EU), Resend (transactional email), Stripe (payments — card details go straight to Stripe and never touch our servers), and Fly.io (application hosting).

We share data with nobody else, unless the law requires it.

5. How long we keep it

As long as your organisation has an account. If you cancel, workspace data is kept for 30 days so you can export it, then deleted. Server logs rotate within 90 days. Invoices are kept as long as tax law requires.

6. Your rights

Under UK and EU data protection law you can ask us to access, correct, export, or delete your personal data, or object to how we process it. Email hello@deskgo.io and we'll sort it — usually within a few days, always within a month.

If you're not happy with how we handle it, you can complain to the ICO (ico.org.uk) or your local data protection authority.

7. Cookies

DeskGo uses one cookie: a session token that keeps you signed in. No ad trackers, no third-party analytics cookies, no cookie banner theatre. The cookie expires after 24 hours.

8. Changes to this policy

If we make material changes we'll email your account owner before they take effect. The date below always tells you when this page last changed.

9. Contact

DeskGo is the data controller for account data. For anything privacy-related, email hello@deskgo.io — a human reads it.

Privacy question we haven't answered? Email hello@deskgo.io — we reply within a business day.