In one paragraph.
OffDeck stores the data you give us — account details, the assessments and reflections your team writes, the configurations you make — and uses it to operate the product, give you useful insights, and improve OffDeck for everyone. We do not sell your data. We do not use it to train third-party models. Anonymous pulse responses are aggregated and never tied to a specific person. You can export everything you've put in, any time. You can delete everything, any time.
Who we are.
OffDeck, Inc. is a Delaware corporation with offices in Brooklyn, NY and Lisbon, Portugal. For the purposes of GDPR and similar laws, OffDeck is the data controller for the personal data you provide directly (e.g. when you sign up) and a data processor for data your company puts into the product about its team members. Our EU representative is EDPO; details on request.
What we collect.
Three categories. We try to keep it narrow.
Account data
- Identifiers — name, work email, role, company. Provided by you or your administrator.
- Authentication — password hash, SSO identifiers, magic-link tokens. We do not store plaintext passwords.
- Billing — company name, billing address, last four digits of payment card. Card data is held by Stripe; we never see it.
Product data
- Assessments, pulses, reflections — the answers and notes your team writes inside OffDeck.
- Skills map & growth plans — competency entries and the development notes attached to them.
- Configurations — the services you've added, the engagement levels you've chosen, the cadence settings.
Usage data
- Operational telemetry — pages visited, features used, error reports. We use this to keep OffDeck fast and not broken.
- Device & network — IP address, browser version, time zone, approximate location. Kept for security and fraud prevention.
How we use it.
- To run the product. Authenticate you, store your work, deliver the rituals you've configured, send the emails you signed up for.
- To make OffDeck useful. Aggregate trend lines, signal "the two roles that would change everything", remind you that pulse 14 is due. Always for you or your team — never to score individuals against each other.
- To improve OffDeck. We learn from anonymised, aggregated patterns across companies. We never use one company's data to inform another company's experience.
- To keep things safe. Detect abuse, prevent fraud, defend the product against attacks.
- To support you. When you write to us, we use your data to write back helpfully.
We do not sell your data, ever. We do not use your data to train third-party AI models. We do not share identified pulse responses with your managers, your investors, or anyone — including ourselves — outside of OffDeck.
Assessment & pulse data — specifically.
This is the data founders ask about most. Three commitments:
- Aggregation only. Your administrators see distributions and free-text quotes, never individual scores tied to identity.
- Suppression at small n. If fewer than four people respond to a question, the result is hidden. The math cannot be reverse-engineered.
- Quotes by consent. When we surface a free-text response, the respondent has opted in to it being shown. Default is private.
If you want a deeper read, the security page covers the technical controls.
Sharing & sub-processors.
We share data with a small list of vendors that help us operate OffDeck. Each is contractually bound by data processing agreements and reviewed annually.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting, encrypted storage | US (us-east-1) · EU (eu-west-1) |
| Stripe | Payment processing | US |
| Postmark | Transactional email delivery | US |
| Sentry | Error monitoring (anonymised) | US |
| WorkOS | Single sign-on (SSO) | US |
We notify customers at least 30 days before adding or changing a sub-processor. You can subscribe to that notification at security.html#subprocessors.
Retention & deletion.
While your account is active, we keep your data. When you cancel:
- 30 days — your account is suspended; you can reactivate without loss.
- 60 days — we email an export link. Download it.
- 90 days — we permanently delete your data, except where law requires us to retain certain records (e.g. billing for tax purposes — held seven years).
You can also request deletion at any time by writing to [email protected]. We action requests within 30 days.
Your rights.
Wherever you live, you have the right to:
- Access the data we hold about you.
- Correct any data that's wrong.
- Export a portable copy in JSON, CSV, or PDF.
- Delete your account and all associated data.
- Object to specific processing — and we'll explain what we'd do without it.
In the EU, UK, California, and elsewhere with similar regimes, you have additional rights granted by local law. Email [email protected] and we'll honor them.
Children.
OffDeck is for adults running and joining companies. We do not knowingly collect data from anyone under 18. If you believe we have, write to us and we'll delete it.
Cookies & similar.
We use a small set of cookies:
- Strictly necessary — session, authentication, CSRF. Cannot be disabled.
- Preferences — UI choices like the time zone you've selected.
- Analytics — first-party only, anonymised, no cross-site tracking. We use Plausible.
We do not place advertising cookies. We do not load Facebook, Google Ads, or third-party tracking pixels. If you'd like more detail, see cookies.html.
Changes to this policy.
When we change something material, we'll email every active account at least 30 days before the change takes effect. The current version, and a dated history, lives at the top of this page.
Contact us.
Privacy questions: [email protected]. Security or vulnerability reports: [email protected]. Everything else: [email protected].
OffDeck, Inc., 67 Bedford Avenue, Brooklyn, NY 11211, United States.