1. Introduction
Dodger, Inc., a Delaware corporation (“Dodger,” “we,” “us,” or “our”), provides product management infrastructure to businesses. This Privacy Policy explains how we collect, use, disclose, and protect personal information.
We act in two distinct roles under this policy:
| Website and account data | Customer Data in the platform | |
|---|---|---|
| Our role | Controller / Business | Processor / Service Provider |
| What it covers | Our marketing site, sales inquiries, account signup, billing, support | Information our customers connect to or submit into the Dodger platform |
| Governed by | This policy | Our agreement with the customer and our Data Processing Addendum, available from privacy@dodger.ai |
| Who to contact about your rights | Us (see Section 9) | The customer organization whose platform contains your information |
If you are an employee, contractor, or end user of a company that uses Dodger: your information may be processed within that company’s Dodger environment. We process it on their instructions, not our own. Direct privacy requests to that company. We will assist them in responding.
2. Information We Collect as a Controller
2.1 Information you provide
| Category | Examples | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Contact and identity | Name, business email, phone, job title, company | Respond to inquiries, provide the Services, communicate | Contract; legitimate interests |
| Account | Username, credentials, role, workspace settings, preferences | Create and secure accounts, authenticate | Contract |
| Billing | Billing contact, address, tax ID, payment method (processed by Stripe; we do not store full card numbers) | Process payments, invoicing, tax compliance | Contract; legal obligation |
| Support and communications | Messages, tickets, call notes | Provide support, improve service | Contract; legitimate interests |
| Marketing | Demo requests, event registrations, newsletter signups, content downloads | Marketing, sales outreach | Consent; legitimate interests |
2.2 Information collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Device and connection | IP address, browser type, OS, device identifiers, language | Security, fraud prevention, service delivery |
| Usage | Pages viewed, features used, session duration, clicks, referring URL, timestamps | Analytics, product improvement, troubleshooting |
| Log and diagnostic | Error logs, API call metadata, performance metrics | Reliability, security, debugging |
| Cookies and similar | See Section 7 | Authentication, preferences, analytics |
2.3 Information from third parties
- Business contact data from lead generation and data enrichment providers, used for B2B marketing and sales outreach
- Authentication providers (e.g., Google, Microsoft, Okta), if you sign in via SSO: identifiers and basic profile data
- Integration partners: account-level metadata when you authorize a connection
- Payment processors: transaction confirmations and limited billing details
- Publicly available sources: company information, professional profiles
2.4 What we do not collect
We do not knowingly collect personal information from children under 16. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
3. Customer Data: Our Role as a Processor
When our customers use the Dodger platform, the platform ingests data from systems they connect, which may include messaging platforms, issue trackers, code repositories, documents, meeting recordings and transcripts, analytics, and support systems. That data (“Customer Data”) may contain personal information about the customer’s employees, contractors, and end users.
We process Customer Data only:
- On the documented instructions of the customer
- To provide, maintain, secure, and support the Services
- To comply with legal obligations
- As permitted by our agreement with the customer
We do not:
- Sell Customer Data
- Use Customer Data for our own marketing
- Use Customer Data to train, fine-tune, or improve general-purpose models made available to other customers, absent express opt-in
- Access Customer Data except as needed to provide, support, and secure the Services, or as legally required
Access controls. Access to Customer Data by our personnel is role-based and limited to those with a business need, logged and reviewable, and subject to confidentiality obligations.
Meeting participation. Where a customer configures Dodger to join meetings, the platform processes audio, video, transcripts, and participant information. Audio and video are processed transiently and discarded; only transcripts are retained.
Dodger joins meetings as a visible participant. Participant visibility cannot be disabled, and the platform provides notice of its presence to participants.
The customer remains responsible for obtaining all required notices and consents from participants. Some jurisdictions require consent from every participant before recording or transcription.
Automated processing. The platform generates inferences, summaries, prioritizations, and recommendations from Customer Data. Where this constitutes automated decision-making with legal or similarly significant effects concerning an individual, the customer is the controller and is responsible for compliance, including any required human review, notice, and rights.
Subprocessors. We use third-party subprocessors to deliver the Services, including cloud infrastructure and AI model providers. Our current subprocessors include: Supabase and Railway (cloud infrastructure and data storage), Cloudflare (hosting and network services), Anthropic (AI model provider, on zero-retention terms that prohibit training on Customer Data), WorkOS (authentication), Stripe (payments), PostHog (analytics), Resend (email delivery), and Recall.ai (meeting participation infrastructure). A current list is available from privacy@dodger.ai. We maintain written agreements imposing data protection obligations and provide at least 30 days’ notice of new subprocessors.
4. How We Use Information
As a controller, we use personal information to:
- Provide, operate, maintain, and secure the Services
- Create and administer accounts and authenticate users
- Process payments and manage billing
- Respond to inquiries and provide support
- Send service communications (security alerts, changes, outages, billing)
- Send marketing communications, where permitted, with an opt-out in every message
- Analyze usage to understand and improve our products
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our agreements
- Conduct business operations including audits, accounting, and corporate transactions
Aggregated and de-identified data. We may create aggregated or de-identified data and use it for any lawful business purpose, including benchmarking and publishing statistics. We maintain such data in de-identified form and will not attempt to re-identify it, except as permitted by law to test de-identification.
5. How We Disclose Information
We disclose personal information to:
| Recipient | Purpose |
|---|---|
| Service providers | Cloud hosting, AI model providers, analytics, payments, CRM, email delivery, support tooling, and security, each bound by contract |
| Professional advisors | Lawyers, accountants, auditors, insurers |
| Corporate transactions | An acquirer or successor in a merger, acquisition, financing, or sale of assets, subject to this policy |
| Legal and safety | When required by law, subpoena, or legal process; to protect rights, property, or safety; to enforce agreements; to investigate fraud or security issues |
| With your direction | Integrations and third parties you authorize |
| Affiliates | Members of our corporate group, for the purposes in this policy |
Government and law enforcement requests. We review requests for validity and scope. Where legally permitted, we will notify the affected customer before disclosing Customer Data and will seek to redirect requests for Customer Data to the customer directly.
6. International Transfers
We are based in the United States and process personal information in the United States. We use service providers that may operate in multiple countries.
For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum, as incorporated into our Data Processing Addendum, and implement supplementary measures where required. Copies are available by contacting privacy@dodger.ai.
We do not currently offer regional data residency.
7. Cookies and Tracking
We use cookies and similar technologies for:
- Strictly necessary: authentication, security, session management, and load balancing. These cannot be disabled.
- Functional: preferences, language, and settings.
- Analytics: how the site and product are used. Provider: PostHog.
We do not run advertising or cross-context behavioral tracking cookies. We do not use retargeting pixels or share information with advertising networks.
Your choices. Browser controls and provider opt-outs.
8. Data Retention
| Data | Retention |
|---|---|
| Account data | Duration of the relationship + 2 years |
| Customer Data | As directed by the customer; deleted from active systems within 30 days and expiring from backups within 90 days |
| Billing and tax records | 7 years or as required by law |
| Marketing contacts | Until opt-out, or 2 years of inactivity |
| Security and access logs | 12 months |
| Support records | 2 years after resolution |
We retain information longer where required by law, or where necessary to resolve disputes, enforce agreements, or preserve evidence subject to legal hold.
9. Your Privacy Rights
Note on scope: These rights apply to information we hold as a controller. For information within a customer’s Dodger environment, contact that customer directly.
9.1 EEA, UK, and Switzerland (GDPR)
You have the right to access, rectify, erase, restrict processing, data portability, object to processing (including direct marketing), and withdraw consent. You also have the right to lodge a complaint with your supervisory authority.
9.2 California (CCPA/CPRA)
You have the right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and be free from discrimination for exercising rights.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Categories collected in the past 12 months: identifiers; commercial information; internet/network activity; professional or employment information; approximate location (derived from IP address); inferences. Sources, purposes, and recipients are described in Sections 2, 4, and 5.
Submit a request: privacy@dodger.ai. We will verify your identity before responding. Authorized agents may submit on your behalf with proof of authorization.
9.3 Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and certain profiling. If we decline a request, you may appeal by contacting privacy@dodger.ai. We will respond to appeals within 45 days.
9.4 How to exercise your rights
Contact privacy@dodger.ai. We respond within the timeframe required by applicable law (generally 30 to 45 days, extendable where permitted). We may need to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.
10. Security
We maintain administrative, physical, and technical safeguards designed to protect personal information, including:
- Encryption in transit and at rest
- SSO/SAML with required multi-factor authentication
- Role-based access controls and least-privilege access
- Logical tenant separation enforced at the database layer, with dedicated infrastructure available as a subscription option
- Logging of all personnel access to customer data
- Confidentiality obligations for all personnel with access
- Vendor security review
- Incident response procedures
No system is perfectly secure. We cannot guarantee absolute security. You are responsible for safeguarding credentials and configuring access appropriately.
Breach notification. We will notify affected customers within twenty-four (24) hours of confirming a security incident affecting their data, and will notify individuals as required by applicable law.
11. Marketing Communications
You may opt out of marketing emails via the unsubscribe link or by contacting privacy@dodger.ai. You cannot opt out of transactional and service communications while you maintain an account.
Where required, we obtain consent before sending marketing communications and honor withdrawal.
12. Third-Party Links and Services
Our site and platform link to and integrate with third-party services. This policy does not apply to them. Review their privacy policies. We are not responsible for their practices.
13. Changes to This Policy
We may update this policy. We will post the updated version with a revised “Last updated” date. For material changes, we will provide 30 days’ advance notice by email or prominent notice in the Services. Where required, we will obtain consent.
14. Contact Us
- Privacy inquiries: privacy@dodger.ai
- Data protection and DPA requests: privacy@dodger.ai
- Security: security@dodger.ai
- Legal: legal@dodger.ai
Dodger, Inc., a Delaware corporation.