Privacy Policy

This page explains what BoardUI collects when you use boardui.com or the BoardUI CLI, why, and what you can ask us to do about it.

Last updated 23 August 2026

Who is responsible

BoardUI operates this website and is the data controller for the processing described here. For anything in this policy — including access, correction or deletion requests — write to hi@boardui.com and we will respond within 30 days.

Website analytics

We measure how the site is used: which pages are visited, which install and Pro buttons get clicked, where on a page those clicks land, and which template previews get opened. That is how we know what to build next. This runs on PostHog, hosted in the EU.

What it does depends on where you are, and on what you chose. If you are in the EU, the EEA or the UK, you are shown a prompt asking whether anything may be kept on your device. Until you accept, and for good if you decline, it is configured to leave nothing behind at all:

  • No cookies and no local storage. The identifier that groups your actions within a visit exists only in your browser tab's memory and is gone when you close or reload it. Outside those regions it is instead saved in your browser, so a second visit is recognised as the same one as the first. If you accept the prompt, you get that same treatment by choice. You can change your mind at any time, and declining costs you nothing: the measurement still happens, it just keeps no record of you between visits.
  • No profiles in the EU, the EEA or the UK. In those regions nothing groups your visits together, so there is no record of you to build. Elsewhere, the identifier saved in your browser lets us see that a return visit came from the same browser as an earlier one, and the pages and clicks from both are grouped under it. That record is built on the identifier and nothing else: we hold no name, no email address and no account against it, and we cannot tell who you are from it.
  • Click and scroll maps. We collect where clicks land on a page and how far down it people scroll, as plain coordinates attached to the page address. They are pooled across visitors and are not tied to you.
  • No session recording in the EU, the EEA or the UK. If you are in those regions we do not record your session at all: replay is switched off in code and never starts. Elsewhere it may record how the page is used, including scrolling and mouse movement, with every form field masked so that what you type is never captured. Your region is worked out from your IP address as the page loads, and is not stored. Either way, nothing is written to your device.
  • No data selling. These analytics are ours, and are not sold or handed to anyone else. Advertising is separate, and is covered in the next section.

Your region is worked out from your IP address as the page loads and is not stored. If it cannot be established, you get the EU treatment. Vercel's audience and performance measurement, which runs alongside all this, is cookieless everywhere. The Meta Pixel described next follows the same prompt: in those regions it does not load at all until you accept it.

Advertising and the Meta Pixel

We advertise BoardUI on Facebook and Instagram. So that we can tell which of those ads actually bring people who install components or buy Pro, this site loads the Meta Pixel, a piece of Meta's code, on every page.

In the EU, the EEA and the UK it does not load at all unless you accepted the prompt described above, because unlike everything else here it does not leave your device untouched:

  • It sets a cookie, which is why it is behind the prompt. The pixel stores an identifier called _fbp in your browser, and reads one called _fbc if you arrived here by clicking one of our ads. Both persist until they expire or you clear your browser data.
  • It sends your visit to Meta. Each page you open here reports the page address, the referring page, your browser and your IP address to Meta in the USA. We use it only for the pageview, and for knowing that an install or a purchase happened.
  • Meta may connect it to your account. If you are signed in to Facebook or Instagram in the same browser, Meta can match the visit to you, and will use it under their own terms as well as ours. We never see your Meta account, and we do not upload email addresses or customer lists to them.
  • It is used to show you ads. That includes showing BoardUI ads again to people who have been here, and helping Meta find people similar to them.
  • Starting and completing a purchase are reported. When you begin a checkout, and again if a Pro licence is bought, Meta is told it happened, with the amount, the currency and the plan. Some of that is sent by our own server rather than by your browser, so a tracking blocker will not always stop it. It is matched to you by the pixel identifier described above, and by the same IP address and browser your visit already reports. Your name, your email address and your billing details are not part of it, and never go to Meta.

If you would rather it did not run: any content or tracking blocker stops the pixel loading, as does the tracking protection built into Firefox, Safari and Brave. What Meta does with data they already hold is controlled in your Meta ad settings, and their side of it is described in the Meta Privacy Policy. Blocking it costs you nothing on this site: every page works exactly the same without it.

Waitlist

If you submit your email address to join the waitlist, we store that address, and we receive a private notification containing it so we know someone signed up. We use it only to tell you when BoardUI is available and about significant changes to it — no unrelated marketing, and no sharing with anyone else. Ask us at any time and we will delete it.

The BoardUI CLI

Installing components with npx boardui records an anonymous, randomly generated installation identifier, the CLI version, the package manager, and the names of the components installed. It exists to tell us which components people actually use.

The CLI never sends your source code, file paths, dependency lists, email address or anything else you have written. The identifier is not linked to your website visits or your purchase.

BoardUI Pro purchases

Pro is sold through Lemon Squeezy, which acts as the seller of record. They collect and hold the billing details, take the payment and issue the licence key; we receive the order and the email address attached to it so we can provide support and validate that key. We never see your full card details.

Server logs

Like any website, our host records requests — IP address, timestamp, page, browser — to serve pages, keep the site up and defend against abuse. These logs are short-lived and are not used to profile you.

Legal bases

Under the GDPR we rely on:

  • Legitimate interests for anonymous analytics, anonymous CLI counts and server logs: understanding and securing our own product. For visitors in the EU, the EEA and the UK this involves nothing stored on your device.
  • Legitimate interests for advertising measurement, which is the Meta Pixel above. It is the one thing here that stores an identifier on your device and shares your visit with a third party, and you can object to it, or simply block it, as described in that section.
  • Consent for the waitlist: you give us your address by choosing to submit it, and you can withdraw at any time.
  • Contract for Pro purchases — we cannot deliver a licence without processing the order.

Who else processes this data

ServiceWhat forRegion
VercelHosting and delivery. Server logs, plus privacy-friendly audience and performance measurement.USA
PostHogProduct analytics for this website, configured to store nothing on your device.EU (Frankfurt)
MetaThe Meta Pixel: measures which Facebook and Instagram ads bring people who install or buy.USA
NeonThe Postgres database holding waitlist email addresses and anonymous CLI counts.EU
TelegramA private message to us when someone joins the waitlist, containing that email address.Outside the EU
Lemon SqueezySeller of record for BoardUI Pro: checkout, payment, invoicing and licence keys.USA

Where a provider is outside the EU, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard in that provider's terms.

How long we keep things

  • Waitlist addresses — until we launch and have told you, or until you ask us to delete yours, whichever comes first.
  • Analytics events — retained by PostHog on our plan's standard schedule. They are anonymous, so they cannot be traced back to you.
  • Purchase records — as long as tax and accounting law requires.
  • Server logs — a short rolling window set by our host.

Your rights

If you are in the EU or UK you can ask us for a copy of the personal data we hold about you, have it corrected or deleted, object to or restrict how we use it, and take it elsewhere in a portable form. Email hi@boardui.com and we will action it within 30 days, free of charge.

One honest limitation: our website analytics are anonymous by design, so we have no way to find “your” events in them — there is nothing tying them to you. That protects you, but it does mean we cannot extract or delete them individually. Waitlist and purchase data we can, and will. Anything the Meta Pixel sent about your visit sits with Meta rather than with us, so requests about it go to them, through the settings linked above.

You also have the right to complain to your local data protection authority if you think we have got this wrong.

Changes to this policy

If we start collecting something new, we will update this page and move the date at the top. Material changes affecting waitlist subscribers will be emailed.

Questions? hi@boardui.com — or come and ask in the Discord. Back to boardui.com.

BoardUIBoardUI

BoardUI is a dashboard design system and UI kit for React + Tailwind CSS, with data tables, charts and dashboard templates, designed in Figma.

© 2026 Board UIPrivacyTermsLicenseContact