Privacy Policy
Last updated: 9 July 2026
Plain-language summary
Most of U-Dash runs in your browser: your Unity dashboard data is fetched live from Unity's API using a session you create by signing a message with your own wallet, and we never store your wallet's private keys or see your seed phrase. We do keep a small server-side record for two features — your subscription and, if you use it, your Referrals workspace — in our own database (Supabase). Subscription payments are handled by a third-party processor (MoonPay Commerce); we never see your card or wallet credentials. We also use privacy-conscious product analytics (PostHog, hosted in the EU)to understand how features are used and to improve U-Dash: it sets no cookies, records no sessions, and respects your browser's Do Not Track setting.
1. Who we are
For the purposes of GDPR (Regulation (EU) 2016/679), the operator of U-Dash at udash.xyz is the controller of any personal data processed in connection with the Service. You can reach us at support@udash.xyz.
2. What we process
U-Dash processes only what your browser needs to log you into Unity and display your data:
- Wallet address. The public address of the wallet you connect. This is needed to build the sign-in message and to look up your account on Unity's side.
- Authentication tokens. When you sign the sign-in message, Unity's backend issues access and refresh tokens. They are kept in your browser's
localStorageso you stay signed in. They are not sent to U-Dash servers — there are none. - Account data from Unity's API. Licenses, allocations, uptime history, lease state and similar fields, fetched on demand and held in your browser's memory while you use the Service.
- Subscription / entitlement record. If you subscribe (or are granted complimentary access), we store a small record in our database (Supabase): the wallet/account it applies to, your plan and billing interval, the period's expiry, and references to the payment — the on-chain transaction hash and the processor's transaction / subscription identifiers. This is what gates access to paid features.
- Payment data (via MoonPay Commerce). Subscription payments are processed by MoonPay Commerce (Helio). You interact with their checkout directly; they collect what they need to take the payment — including an email address for receipts and renewal reminders — and settle the on-chain transaction. We receive a webhook confirming the payment (wallet, plan, amount, transaction hash) but never receive your card or wallet credentials.
- Referrals workspace. If you use the Referrals area, the data you create there (referrers, schemes, deals, payouts) is stored in our database (Supabase), keyed to your wallet's sign-in.
- Operational logs from our hosting provider. Like any website, page requests reach a server (Vercel) which logs IP addresses, user agents, and request timing for security and availability. These logs are held by the hosting provider under their own policies.
- Aggregated, anonymous usage analytics (Vercel Web Analytics). When a page loads, a small first-party script sends Vercel a single anonymous data point per page view, containing: the path you visited (e.g.
/licensesor the dynamic pattern/licenses/[id], with sensitive segments such as license IDs redacted before sending), the referring URL, your approximate geolocation derived from your IP (country, region, city — your IP address itself is not stored), your device type, and your browser and OS version. Visitors are de-duplicated using a one-way hash derived from the incoming request that is automatically discarded after 24 hours; it cannot be used to track you across days or across other websites. No cookies, no fingerprinting, no advertising identifiers, no cross-site tracking. We use this only to understand which pages are used and to spot broken routes. - Product analytics (PostHog, EU). To understand how features are used and to inform product and pricing decisions, we use PostHog, hosted in the European Union. When you are signed in, we associate this analytics with your wallet address as a pseudonymous identifier, together with your plan tier (for example, free or pro). We capture page views (with sensitive URL segments such as license IDs and share/claim tokens removed, and query strings dropped) and a small number of product events. We deliberately do notenable PostHog's automatic click/keystroke capture or session recording, we configure it to use
localStoragerather than cookies, and we respect your browser's Do Not Track signal. PostHog does not receive your seed phrase or private key, your Unity authentication tokens, or the account data fetched from Unity's API.
3. What we do not collect
- We never ask for, see, or store your wallet's seed phrase, private key, or password.
- We do not run third-party advertising or marketing trackers (no Google Analytics, no Meta Pixel, no ad networks, no session replay tools).
- We do not perform cross-site tracking or device fingerprinting. Our analytics is confined to your use of U-Dash and is never linked to your activity on any other website.
- Our analytics providers never receive your wallet's seed phrase or private key, your Unity authentication tokens, or any account data fetched from Unity's API. Vercel Web Analytics additionally does not receive your wallet address; PostHog associates analytics with your wallet address only as a pseudonymous identifier, as described in section 2.
- We do not run advertising or share data with advertising networks.
- We do not sell or rent any data.
4. Where your data lives
- Your browser. Wallet address, tokens, and cached account data live in your browser's memory and
localStorage. Clearing your browser data deletes all of it. - Unity. Your Unity account data is stored by Unity under their own privacy policy and terms.
- Our database (Supabase). Your subscription / entitlement record and your Referrals workspace are stored in a Supabase project we operate. Supabase acts as our processor for this data under their own data-processing terms.
- MoonPay Commerce (Helio). Our payment processor. They handle subscription payments and hold the related payment data (including any email you give them) under their own privacy policy.
- Our hosting provider (Vercel). Serves the U-Dash files, may keep short-lived request logs, and — through Vercel Web Analytics — stores the aggregated, anonymous page-view data described in section 2. Vercel acts as our processor for this analytics data under their Data Processing Addendum.
- PostHog (EU). Our product-analytics provider. It stores the usage analytics described in section 2 on infrastructure in the European Union, acting as our processor under its own data-processing terms.
- Reown AppKit / your wallet provider. Wallet connection is brokered by Reown AppKit; their own data practices apply.
5. Legal basis (GDPR)
We process the limited data above on the basis of your request to use the Service (performance of a contract / your request to take pre-contract steps) and our legitimate interestin keeping the Service running, secure, and usable. The usage analytics in section 2 rely on legitimate interest: improving the Service and understanding how it is used. Both providers are configured without cookies, so they fall outside the ePrivacy Directive's cookie-consent scope. Vercel Web Analytics is fully anonymous; PostHog associates analytics with your wallet address as a pseudonymous identifier, but records no sessions, performs no cross-site tracking, and is used only to improve U-Dash. You can opt out at any time by enabling your browser's Do Not Track setting (which we honour) or by writing to support@udash.xyz, and we will stop this processing for you.
6. Your rights
Under GDPR you have rights to access, rectify, erase, restrict, object to, and port your personal data, and to lodge a complaint with your local data protection authority. For the limited personal data we hold in our own database — your subscription record and any Referrals workspace — contact us at support@udash.xyz and we will action your request. For the rest:
- Clearing your browser data (deletes everything U-Dash stores locally).
- Contacting Unity directly to access or delete the account data they hold.
- Contacting our payment processor (MoonPay Commerce) for the payment data they hold.
- Contacting our hosting provider for any logs they hold under their own policies.
- Enabling Do Not Track (which stops product analytics), or contacting us at support@udash.xyz to have your PostHog analytics profile deleted.
7. Cookies and storage
U-Dash does not set tracking cookies, and our analytics providers are configured not to use cookies either. We do use localStorage to keep you signed in across page reloads, to support the multi-wallet switcher, and (for PostHog) to remember your pseudonymous analytics identifier and preferences. This storage stays in your browser; analytics events themselves are sent to PostHog as described in section 2.
8. Changes to this policy
We may update this Privacy Policy. The version published at this URL is the current one; the "Last updated" date above shows when it was last revised.
9. Contact
For privacy questions, contact support@udash.xyz.
See also the Terms of Service.