Legal
The paperwork, written from the code
Eleven pages. Every field named in the privacy policy is a real database column, every sub-processor is named with what it actually receives, and the accessibility statement lists what falls short rather than claiming conformance. Where something is missing, it says so.
Agreements5 documents
What you agree to by buying, and what we agree to by selling.
- Terms of ServiceThe agreement between you and the business that sells Dispatch — what you are buying, what it costs, and what happens when either side stops.
- End User Licence AgreementThe licence for the desktop application itself — what you may do with the installed copy, what you may not, and what happens to it when the subscription stops.
- Subscription and cancellationAuto-renewal stated before you buy, cancellation without an email, what happens at the end of a period, and the 14-day right of withdrawal alongside the waiver that applies when a key is issued at once.
- Refund policyFourteen days, no reason needed, on a first subscription period — and what happens with annual plans, accidental renewals and chargebacks.
- Acceptable useThe short list of things that get a licence key revoked, and the much longer list of things that are none of our business.
Data3 documents
What is collected, who else sees it, and how long it is kept.
- Privacy PolicyEvery field the app sends, every row the server keeps, why the hardware id exists, how long an events row lives, what a support ticket holds, and what actually happens when a deletion request arrives while a subscription is live.
- Sub-processorsThe three companies that receive personal data on our behalf, each with its legal entity, what it gets, why, and a link to its own data processing agreement.
- CookiesOne strictly necessary session cookie in the account area, nothing anywhere else, no analytics — and why there is no consent banner asking you about it.
Trust3 documents
The things a buyer or a procurement team checks before spending money.
- Security and disclosureHow to report a vulnerability, what response to expect and when, what is in scope, and the list of weaknesses already known — so nobody spends a weekend finding one of those.
- AccessibilityWCAG 2.2 AA is the target. Here is what the site already does, the four places it is measurably short of that target, and how to tell us about a fifth.
- Trader identityWho you are actually buying from — legal name, registration, address and jurisdiction. Required by EU and UK consumer law, required by Stripe, and the thing whose absence makes a site look like it might vanish with the money.
Also worth knowing
- /.well-known/security.txt — the machine-readable version of the security contact, per RFC 9116.
- Licensing — how the gate works and, more usefully, what it does not stop. The privacy policy leans on it rather than repeating it.
- Pricing — what is charged, and the questions worth reading before paying it.