Privacy Policy
This policy explains what we (Angelica Castro Tiburcio, who operates Dispatch) collect when you use Dispatch, why, and who we share it with. We collect only what Dispatch needs to work, and we do not sell your personal information.
1. What we collect
| Data | Examples | Where it comes from |
|---|---|---|
| Figma identity | Your Figma user ID | Figma, when you open the plugin |
| Device tokens | A hashed token for each plugin install (we never store the raw token) | Generated by Dispatch |
| Klaviyo connection | OAuth access and refresh tokens, Klaviyo account ID | Klaviyo, when you connect |
| Klaviyo account details | Organization name, default sender name and email, industry | Klaviyo |
| Email settings | Footer HTML, background color, email width | You |
| Design content | Image slices of your designs, including those sent for alt text | You, from your Figma file |
| License | License key, activation ID, seat use | Our payment provider, when you activate |
| Usage | Trial start date, last active date, error logs | Generated by Dispatch |
We do not collect your Figma or Klaviyo password, your payment card details, or the subscriber lists and profiles stored in your Klaviyo account. Dispatch can read list and segment names so you can target campaigns, but we do not copy subscriber data to our servers.
2. How we use it
- To run Dispatch: sign you in, connect to Klaviyo, and create images, templates and campaigns you ask for.
- To generate alt text when you request it.
- To check your trial or license status.
- To keep Dispatch secure, fix bugs and prevent abuse.
- To contact you about your account, security or material changes to these policies.
We do not use your content to train AI models, and we do not use it for advertising. We only use AI providers whose API terms bar them from training their models on the content we send.
3. Legal bases (GDPR)
Where the EU or UK GDPR applies, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Running Dispatch: sign-in, Klaviyo connection, exports, alt text | Performance of a contract, Art. 6(1)(b) |
| Trials and licenses | Performance of a contract, Art. 6(1)(b); legal obligations such as tax records, Art. 6(1)(c) |
| Security, abuse prevention, bug fixing | Our legitimate interest in keeping Dispatch safe and working, Art. 6(1)(f) |
| Account and policy notices | Performance of a contract and legitimate interests, Art. 6(1)(b) and (f) |
Where we rely on legitimate interests, you may object as described in Section 7.
4. Who we share it with
We share data only with service providers who help us run Dispatch, under contracts or terms that limit their use of it:
| Provider | Purpose | Data involved |
|---|---|---|
| Klaviyo | Destination for your images, templates and campaigns; hosts your image slices | Content you export, OAuth tokens |
| Figma | Platform the plugin runs in | Figma user ID |
| Hosting and database provider | Runs our API and stores account data | All stored account data |
| AI provider | Generates alt text | Image slices you submit for alt text |
| Payment and licensing provider | Sells and validates licenses; may act as merchant of record | License key, Figma user ID, purchase details |
The specific providers we use may change over time. Any replacement will fill the same role and receive only the data listed for it. Contact us for the current list.
Image slices are uploaded to your Klaviyo image library and served from public URLs so email clients can load them. Anyone with a link, including every recipient of your emails, can view them. Do not put confidential information in exported designs.
We may also disclose data if the law requires it, to protect our rights or users' safety, or as part of a merger, acquisition or sale of assets.
5. Security
We use encrypted connections (HTTPS), store device tokens only as SHA-256 hashes, use OAuth so we never see your Klaviyo password, and limit Klaviyo access to the scopes Dispatch needs. No system is perfectly secure, and we cannot guarantee the security of your data. If a breach affects your personal information, we will notify you as the law requires.
Reporting a vulnerability. If you find a security issue in Dispatch, email support@trydispatch.biz with the details. We'll reply within 3 business days and fix confirmed issues as a priority. Please don't disclose it publicly until it's fixed.
6. How long we keep data
| Data | Kept until |
|---|---|
| Account, Klaviyo tokens, settings, devices | You disconnect or delete your account, or 180 days with no activity. We then revoke Dispatch's Klaviyo access and delete these records. |
| Image slices | Stored in your Klaviyo image library, not on our servers. They stay there until you delete them in Klaviyo. |
| Content sent for alt text | Not stored by us after the response. Our AI provider processes it under its own terms. |
| Logs | Up to 90 days |
We may keep limited records longer where the law requires, for example billing records held by our payment provider.
7. Your rights
Depending on where you live, including Mexico, the EU and the UK, you may have the right to access, correct, delete or export your personal information, and to object to or restrict certain processing. To make a request, email support@trydispatch.biz. We will verify your identity and respond within 30 days, or sooner if the law requires. We will not discriminate against you for exercising these rights. You may also complain to your local data protection authority.
8. Your subscribers' data
For subscriber data in your Klaviyo account, you are the data controller and are responsible for having a lawful basis and giving notices to your recipients. To the extent Dispatch processes that data, we do so only on your instructions, as your processor. Contact us if you need a data processing agreement.
9. International transfers
We are based in Mexico, and our service providers operate mainly in the United States. By using Dispatch you understand your data will be processed in both countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. What the Figma plugin accesses
- It reads only the frame you select, to preview it, and sends it to Dispatch only when you save or schedule.
- It does not modify your Figma files, and does not open other files or projects.
- From your Figma profile, it reads only your user ID, to link the plugin to your Dispatch account.
- It keeps its sign-in token in Figma's client storage on your device, which other plugins cannot access.
- It communicates only with the Dispatch backend.
11. Children
Dispatch is not for anyone under 18, and we do not knowingly collect data from children.
12. Changes and contact
We will post changes here with a new effective date and give notice of material changes. Questions or requests: Angelica Castro Tiburcio, support@trydispatch.biz.
Dispatch