Privacy Policy
Last updated: 29 June 2026
This Privacy Policy explains how MR Analytics Hub ("we", "us", "our") collects, uses, stores, and protects your information when you use DashLabs at dashlabs.mranalyticshub.com and mranalyticshub.com.
MR Analytics Hub is operated by MR ANALYTICS HUB LIMITED. We are the data controller for your personal data.
We are committed to protecting your privacy and handling your data transparently and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information we collect
Account information: When you create an account, we collect your email address and password (stored in encrypted form). If you subscribe to a paid plan, payment information is collected and processed directly by Stripe — we do not store your credit card details.
Data you upload: You may upload CSV data files to generate dashboards. This data is stored on our infrastructure to provide the service. We process your uploaded data solely to generate dashboards, run AI analysis, and provide the features you request.
Connected data sources: As an alternative to uploading a file, you may choose to connect a data source such as Google Sheets, Google Drive or Google Analytics. Where you do, we access that source on a read-only basis only to build and refresh your dashboards. This is always optional and under your control. Section 5 sets out exactly what we access and how it is handled.
Usage data: We automatically collect information about how you use the service, including: pages visited, features used, dashboard creation activity, AI assistant queries (question text only, for service improvement), error logs, and session timestamps.
Technical data: We collect your IP address, browser type and version, device type, and operating system. This is used for security, analytics, and service improvement.
Cookies: We use essential cookies for authentication (session management and login state). We do not use advertising or third-party tracking cookies. The authentication cookie (mr_auth_token) is strictly necessary for the service to function and does not require consent.
2. Legal basis for processing
We process your data under the following legal bases (UK GDPR Article 6):
| Data | Legal basis | Purpose |
|---|---|---|
| Account email & password | Contract performance | To provide the service and manage your account |
| Payment information | Contract performance | To process subscription payments (via Stripe) |
| Uploaded data files | Contract performance | To generate dashboards and provide AI analysis |
| Connected source data | Contract performance | To build and refresh dashboards from sources you connect |
| Usage data | Legitimate interest | To improve the service, fix bugs, and understand usage patterns |
| Technical data | Legitimate interest | Security, fraud prevention, and service reliability |
| Authentication cookies | Contract performance | Strictly necessary for the service to function |
3. How we use your data
We use the information we collect to:
- Provide, maintain, and improve the DashLabs service.
- Process your uploaded data to generate dashboards and AI-powered insights.
- Build and refresh dashboards from data sources you choose to connect.
- Process payments and manage your subscription.
- Send essential service communications (account verification, subscription changes, security alerts).
- Monitor usage to enforce subscription limits and prevent abuse.
- Diagnose technical issues and improve service reliability.
We do not use your data for advertising, profiling, or automated decision-making that produces legal effects.
4. AI processing
DashLabs uses third-party AI models (provided by Anthropic and OpenAI) to analyse your data and generate dashboards and insights. When you use the AI assistant or generate a dashboard:
- A summary of your data schema (column names and types) and sample data is sent to the AI provider to generate analysis.
- AI assistant queries include your question text and relevant data context.
- AI providers process this data under their own data processing agreements and do not retain your data for training purposes.
- We do not send your complete raw datasets to AI providers — only the minimum context needed for the specific request.
5. Connected data sources and Google user data
DashLabs lets you connect your own data sources to build dashboards directly from live data, as an alternative to uploading a file. We currently support Google Sheets and files held in Google Drive, and Google Analytics 4. Connecting a source is always optional and entirely under your control.
When you connect a Google account, you are taken to Google's own consent screen. Google shows you exactly which permissions we ask for, and you choose whether to allow them. We request read-only access only, and only the following:
- Google Drive (drive.file): access limited to the single file you explicitly select using Google's file picker. We can read only that one file, and we use it solely to build and refresh your dashboard. We cannot see or access any other file in your Google Drive.
- Google Analytics (analytics.readonly): read-only access to your Google Analytics 4 reporting data. We use it to list the Analytics properties you can access so you can choose one, and to pull aggregated report data such as sessions, users, key events and revenue by date and channel, which we display back to you as charts and tables.
We use information obtained through these Google permissions solely to provide the features you have asked for, namely building, displaying and refreshing your dashboards. We do not use it for advertising, we do not sell it, and we do not use it to train any artificial intelligence model.
How connected data is stored. As with an uploaded file, when you build a dashboard from a connected source we take a snapshot of the pulled data and store it in your private UK storage (Google Cloud Storage, with an optimised Parquet copy) so the dashboard and any scheduled refresh can run. If you enable manual or scheduled refresh, we re-pull the latest data from the source on your behalf.
Access tokens. To keep a connection working and to refresh your data, we store the access and refresh tokens that Google issues. These are encrypted at rest using strong symmetric encryption (Fernet) before being stored, and they are held only to operate your connection.
Your control. You can disconnect a source at any time from within DashLabs, which deletes the stored tokens for that connection. You can also revoke DashLabs' access directly from your Google Account at myaccount.google.com/permissions. If you decline a permission on Google's consent screen, the related feature is simply unavailable and we make no API calls that rely on it.
6. Data storage and security
Your data is stored on Google Cloud Platform (GCP) infrastructure in the europe-west2 (London, UK) region. We implement the following security measures:
- Encryption in transit using TLS 1.2+ for all connections.
- Encryption at rest for all stored data (Google-managed encryption keys).
- Connection tokens for connected data sources are additionally encrypted at the application level (Fernet) before storage.
- Authentication via JSON Web Tokens (JWT) with secure, HTTP-only cookies.
- Data isolation — each user's data is stored separately and access-controlled by user ID.
- Regular security reviews of our infrastructure and code.
While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Data sharing
We do not sell, rent, or trade your personal data. We share data only with the following third parties, solely to provide the service:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Google Cloud Platform | Infrastructure & storage | All stored data | UK (europe-west2) |
| Stripe | Payment processing | Payment details, email | EU/UK |
| Anthropic | AI analysis | Data schema, sample data, queries | US |
| OpenAI | AI analysis (fallback) | Data schema, sample data, queries | US |
Note: AI providers (Anthropic and OpenAI) are US-based. Data transfers to the US are covered by appropriate safeguards including Standard Contractual Clauses (SCCs) and the providers' data processing agreements. Only minimal data context is transmitted — not your complete datasets.
Data imported from a connected source is treated exactly like uploaded data once it reaches DashLabs: it is stored in your private UK storage and only the minimum schema and sample context is shared with our AI providers to build your dashboard. We do not send your connected data to any third party for any other purpose.
We may also disclose data if required by law, regulation, or legal process, or to protect the rights, safety, or property of MR Analytics Hub or others.
8. Data retention
- Active account: Your data is retained for as long as your account is active and your subscription is current.
- After cancellation: Dashboards are retained in read-only state for 30 days. After 30 days, data may be archived. After 90 days, data is permanently deleted.
- After trial expiry: Trial data is retained for 30 days, then permanently deleted.
- Connected sources: The data snapshot for a connected dashboard follows the same retention as any other dashboard. When you disconnect a source, the stored access and refresh tokens for that connection are deleted.
- Account deletion: Upon request, we will delete all your personal data and uploaded files within 30 days. Some data may persist in encrypted backups for up to an additional 30 days.
- Usage and technical logs: Retained for up to 12 months for service improvement, then deleted.
9. Your rights (UK GDPR)
Under the UK GDPR, you have the following rights:
- Right of access — Request a copy of the personal data we hold about you.
- Right to rectification — Request correction of inaccurate personal data.
- Right to erasure — Request deletion of your personal data ("right to be forgotten").
- Right to restrict processing — Request that we limit how we use your data.
- Right to data portability — Receive your data in a structured, machine-readable format.
- Right to object — Object to processing based on legitimate interest.
- Right to withdraw consent — Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at support@mranalyticshub.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.
10. Children's privacy
DashLabs is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete it.
11. International data transfers
Your uploaded and connected data is stored in the UK (Google Cloud europe-west2). However, limited data is transferred to the US for AI processing (see section 7). These transfers are protected by Standard Contractual Clauses and the data processing agreements of our AI providers. We only transfer the minimum data necessary for each AI request.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on our website at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact us
For privacy-related enquiries, data subject requests, or complaints:
- Email: support@mranalyticshub.com
- Website: mranalyticshub.com/contact-us
For complaints about data protection, you may also contact the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113