Where your records live.
BatchDash holds your formulas, your costs and the record of every batch you have made. This page says where that sits, who can open it, and how you take it back.
Connections are encrypted. One organization is separate from every other, and inside one you decide who sees what. Database backups are encrypted before they leave the server, and your records are yours to export or delete whenever you want.
In the EU, on machines we run.
BatchDash runs in the European Union, on hardware we operate ourselves rather than on a managed platform assembled out of other people's services. The database, the cache and the file storage are reachable only from inside that private network. None of them answers the public internet.
If a company needs its own isolated instance, or one in a particular place, that can be arranged. Write to us and say what the requirement is.
How your data is kept.
Nothing exotic. The ordinary protections, applied to the records you put in.
On the way there
Every connection between your browser and BatchDash is encrypted, so nothing you type and nothing you read crosses the network in the clear.
In the backups
The database is backed up nightly, and the backup is encrypted on the server before it is written anywhere. Nothing unencrypted leaves the machine.
The files you upload
The documents on a sourcing project and the artwork a label renders are streamed through a route that checks who you are, rather than sitting on a public link. Holding the URL opens nothing.
Your password
Passwords are hashed. We do not hold the password itself and cannot read it back, so no support conversation can ever end with someone reading yours to you.
Standard practice
The rest is what a system holding production records is expected to do: hardened servers running nothing but BatchDash, no public route to the database, and a deploy that rolls back rather than leaving a change half applied.
Who sees what, person by person.
A workshop is not one person with one login, and your costs are not everyone's business. This is the part worth reading.
Four roles to start from
An owner, admins, members who do the work, and readers who can look at everything without changing any of it.
Down to the single action
Under the roles sits one right per thing a person can do: see stock, move it, run a batch, receive a delivery, invite someone, manage the organization. A role is a set of them, so a permission can be as narrow as one screen.
Money is its own right
Seeing what an ingredient costs and seeing what an hour of work costs are two separate rights. You can hand someone the production screens without handing them your margins.
Roles you write yourself
Build a role out of those rights to match a job in your workshop, then adjust it for one person without inventing a second role for them.
What nobody can be granted
Billing and deleting the organization belong to the owner. No role carries them and no adjustment adds them.
What leaves, and where it goes.
BatchDash relies on a short list of outside services. This is all of them.
| Service | What it does | What goes there |
|---|---|---|
| OVHcloud | Hosting | Everything, at rest on hardware in the European Union. |
| Stripe | Payments and subscriptions | Your billing contact and company details, and the card itself, which Stripe holds and we never see. |
| OpenAI | The optional AI features | Only what you hand over, and only when you ask for it: a recipe you paste to be read, a delivery note you photograph, a supplier quote you upload. Nothing goes in the background, nothing goes from a record you did not act on, and none of it is used to train models. |
| Our email provider | Transactional email | Your email address, and the text of the messages BatchDash sends you. |
| Your connectors | The services you connect | Whatever you connect, and only what you let it sync. A shop (Shopify) is sent your stock levels and sends its orders back; an accounting tool (QuickBooks, Xero) would see invoices and nothing else. Anything you have not connected exchanges nothing, and you can disconnect what you have. |
No analytics company, no advertising, no tag of any kind. Our own visit counter stores no IP address and forgets which visitor you were every night.
Your data is yours.
Ask for a full export from the organization settings and BatchDash builds a zip of your records as CSV files, then emails you a link. It works on every plan. Uploaded photos, documents and label artwork are not in it; those you download from where they already are.
Deleting the organization takes the owner's password and the organization's name typed out in full. It then sits for 30 days in a window where we can bring it back, and after that it is removed from every table and every file store. Invoices stay with Stripe for as long as the law requires.
Something this page does not answer? Write to us