Privacy Policy
Last updated: March 8, 2026
This Privacy Policy describes how Beyond Dues, Inc. ("Beyond Dues," "we," "us," or "our") collects, uses, and protects your information when you use Beyond Dues (the "Service").
1. Information We Collect
a) Information You Provide
- Account information: name, email address, and password when you sign up.
- Profile information: association type, industry, membership size, budget range, and revenue streams during onboarding.
- Context data: association URLs, member challenges, programs, goals, and documents you upload to improve AI recommendations.
- Payment information: processed securely by Stripe. We do not store credit card numbers on our servers.
b) Information Collected Automatically
- Usage data: pages visited, features used, and interactions with the Service.
- Device information: browser type, operating system, and user agent.
- Referral data: how you arrived at the Service (e.g., referral codes, referring URLs).
2. How We Use Your Information
- Provide the Service: generate AI-powered ideas, analyses, and recommendations tailored to your association.
- Improve the Service: analyze usage patterns to enhance features and performance.
- Billing: process payments and manage subscriptions.
- Communication: send account-related notifications, trial reminders, and product updates. You can opt out of non-essential emails.
- Security: detect and prevent fraud, abuse, and unauthorized access.
3. AI Processing
Your profile and context data are processed by AI models to generate revenue ideas and evaluations. This data is:
- Used solely to provide the Service to you.
- Not used to train third-party AI models.
- Not shared with other users or made publicly available.
4. Data Sharing
We do not sell your personal information. We share data only with:
- Service providers: Stripe (payments), cloud infrastructure providers (hosting and database), and AI model providers (idea generation) — all bound by contractual obligations to protect your data.
- Legal obligations: when required by law, regulation, or valid legal process.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
5. Data Retention
- Active accounts: data is retained for the duration of your account.
- Deleted accounts: personal data is deleted within 30 days of account termination. Anonymized usage data may be retained for analytics.
- Uploaded documents: stored securely and deleted upon your request or account termination.
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/SSL) and at rest.
- Row-level security policies on database tables.
- Secure authentication with email verification.
- Regular security reviews and vulnerability scanning.
No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data ("right to be forgotten").
- Export your data in a portable format.
- Object to or restrict certain processing activities.
To exercise these rights, contact us at hello@beyonddues.com.
8. Cookies & Analytics Tracking
We use essential cookies for authentication and session management. We also collect first-party analytics to understand how the Service is used and improve it.
- What we collect: pages visited, features used, session duration, clicks, referral URLs, UTM parameters, device type (mobile/tablet/desktop), and anonymized visitor/session identifiers.
- How we use it: to understand usage, diagnose issues, improve features, and measure the impact of product changes.
- Who sees it: analytics data is stored in our own database and is not shared with third-party advertising or analytics trackers.
- Opt-out: you can disable analytics tracking in your Profile settings. Opting out stops new analytics events from being recorded, but essential authentication cookies remain required to use the Service.
9. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has provided personal data, contact us to have it removed.
10. International Data Transfers
Your data may be processed in the United States. By using the Service, you consent to the transfer of your data to the U.S. We take appropriate measures to ensure your data is protected in accordance with this Privacy Policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.
12. Contact Us
For questions or concerns about this Privacy Policy or your data, contact us at: