Loading…
Loading…
Dysplay handles two quite different kinds of information: the little we gather about people who visit this site, and whatever a brand puts inside its own showroom. They are kept apart here, because the rules that govern them are not the same.
Dysplay builds virtual showrooms and works out of Milan, Italy. Anything on this page reaches a person at support@dysplay.io.
We play two roles, and it is worth knowing which one you are meeting. For this website — the pages you are reading and the walkthrough request form — we decide what is collected and why, which makes us the controller of it. For everything inside a showroom, the brand running that showroom decides; we hold it for them and act on their instructions, which makes us their processor.
The practical consequence: if a company showed you a showroom and you want your details out of it, that company is the right first knock. Ask us and we will tell you who they are and help them do it, but the decision is theirs to make rather than ours.
If you ask us for a walkthrough, we receive what the form asks for: your name, your company, your address, roughly what you sell, and anything you chose to add. We use it to answer you and to keep track of the conversation that follows. As this is written the form does not even send it — it hands the finished message to your own email program so you can read it before it goes — and whichever way it reaches us, it is correspondence, treated like any other letter.
While the site is unfinished it sits behind a shared password. Getting past it sets one cookie so you are not asked again on every page. That cookie holds a token derived from the password rather than the password itself, and it is the only cookie this part of the site sets.
Our host records what any web server records in order to stay up and to spot abuse: the address a request came from, the page it asked for, and when. We also measure how this site is used — which pages get read, what people came looking for, where a visit went next — and we may use ordinary analytics tooling to do it. That measurement is ours, we use it to decide what to write and what to build, and it is not sold or handed to anyone else for their own purposes.
A showroom is a brand’s room, not ours. What is on the walls, who is invited, whether a passcode is needed — the brand sets all of it, and we run the room to those instructions.
While you are in one, the room measures how it is used, so the brand can understand its own showroom: which room was opened, which parts came into view, how long each held attention, how far you read, when it happened, how a visit progressed from one moment to the next, roughly where in the world it came from, and what kind of device and connection it arrived on. Enough, in short, to tell one visit from another and to describe a visit as a visit rather than a scatter of unrelated moments.
During a live call, we also record who joined, how long the call lasted, and whether each participant’s call tab reported itself visible or hidden. When transcription is enabled, we can measure how speaking time was shared. These facts are saved with the call record and used to provide a weighted call-quality indicator. A hidden tab may mean another tab, a minimized window, or a locked screen; we cannot see which other tab or app someone used, or tell whether a visible person was paying attention.
A gallery — the page a brand sends you after a visit, with the documents it chose for you — asks for your name, email address and job title before it opens. The brand sees who opened its gallery under those details, how often and for how long, which documents were read and which were downloaded, and whether the gallery reached somebody other than the person it was sent to. We do not check the address you give, and we keep these details for as long as the brand keeps that gallery.
We build reports and dashboards on top of that, and we expect to keep building better ones. Some of it is shown to the brand whose room it is. Some of it we keep as telemetry — the ordinary business of knowing whether the product is working, what is slow, what people cannot find, and what to fix next. Where we can answer a question without knowing who you are, we do, because it is usually the easier engineering as well as the better manners.
The limit is on what happens next, and it is firm. None of it is sold. None of it is handed to another company to use for their own ends — an advertising network, a data broker, or anyone who would like to buy a view of who is shopping for what. Where a company processes any of it for us, it does so on our instructions and for no purpose of its own. What a room learns stays between us and the brand that owns the room.
A live visit is a call in the room, with a host on the other side. To be let in you give a display name — whatever you want the host to call you — and the room keeps a log of the visit: who knocked, when they were admitted, who was in the room under the name they gave and when they arrived, what was put on the stage, and the chat messages typed in the room. The brand hosting the visit can read that log afterwards, including in the notes it keeps about the visit. A chat message you have started but not sent is held in your own browser so a refresh does not lose it, and it never leaves the device until you send it.
Your camera, microphone and anything you share are carried by LiveKit, encrypted between you and the service that relays them. We do not store any of it.
When the visit ends, the brand keeps a record of it: who was in the room under the name they gave, how long it ran, what was put on the stage, which documents were left there and anything that was signed, together with the notes the host wrote afterwards. That record outlives the room. A brand can tidy away a room it no longer uses, and the record of the visits held in it stays — otherwise a brand could not answer, months later, what it showed you and when. It is kept for as long as the brand keeps you on its client list, and deleting you from that list deletes it.
We do not record live visits today. If that changes, this page will say so, the room will make it plain to the people in it, and a recording will belong to the brand hosting the visit on the same terms as everything else in its room — ours to hold, never ours to sell.
An account for the console holds your email address, your name, a password you never send us in a readable form, which team you belong to, and what you are allowed to do in it. If a colleague invited you, we keep the invitation until it is accepted or expires.
Files you upload to a room — brochures, films, contracts, images — sit in our file storage and are served to a guest through a link that expires. We keep a log of significant actions in the console: who changed a room, who started a visit, who admitted whom. It is there so a brand can answer questions about its own room, and so we can investigate when something goes wrong.
| Who | What they do | When they see anything |
|---|---|---|
| Vercel | Hosts and serves this site and the product. | Every request |
| Supabase | The database, the sign-in, and the file storage behind every room. | Whenever something is read or saved |
| LiveKit | Carries the audio, video, screen share and the movements two people make in a room together. | Only during a live visit |
| MapTiler | Draws the map when a room has a map on the wall. | Only in a room whose host added one |
| YouTube | Plays an embedded film. We embed through youtube-nocookie.com, the variant that holds off until you press play. | Only in a room with a film embedded |
| Shows an embedded post. | Only in a room with one | |
| Hyperbeam | Runs the cloud browser when a host opens a live website in the room and walks a guest through it. | Only while a co-browse is open |
| jsDelivr | Serves the code that blurs or replaces a camera background. | Only when someone in a call turns a background effect on |
| Serves two pieces of machinery the room downloads to work: the background-effect model, and the decoder that unpacks a compressed 3D model. | Only in a call using background effects, or a room with a 3D model | |
| Google Drive | Opens your own Drive so you can choose files to bring into a room. Only the files you pick are ever shared with us — we copy each one into the room’s own storage, and we cannot see anything else in your Drive. | Only when someone setting a room up chooses to bring a file over |
| Google Calendar | Puts your confirmed viewings on a calendar of ours in your Google account, reads back changes you make to those entries, and checks whether you are free before offering a client a slot. We can only see and change entries this app created — we cannot open, read or alter anything else in your calendar. For your own appointments we are told only that you are busy, never what they are or who they are with. | From when you connect Google until you disconnect it |
| Cloudflare | Stores large files for deployments configured to use it. | Whenever such a file is fetched |
Most of those are companies your browser talks to directly rather than through us, and a company you connect to can see your address the way any site you visit can. Nearly all of them appear only inside a room, and only when the host used the feature that needs it — a map on the wall, a film, a background blur, a 3D model, a website walked through together. The two Google rows are the exceptions: they are reached only on behalf of the person running a workspace, from their own Google account, and only after they have connected it.
That is the list as the product stands, and it will change as the product does — a company gets added when a feature needs one, and this page is updated when that happens. What does not change is the rule every one of them is held to: they process this data to do a job for us, on our instructions, and none of them is permitted to use it for their own purposes. There is no advertising network on that list and no data broker, and neither will be joining it.
Connecting Google is worth describing properly, because it is the only place we hold a lasting key to something of yours. When someone running a workspace connects their Google account, we store a credential that lets us keep working on their behalf between visits — not a password, and not something anyone can sign in with. It is encrypted before it is written down, and it is the only credential of this kind the product keeps.
What that key can reach is deliberately narrow, and the narrowness is enforced by Google rather than promised by us. For files, it opens the Drive picker so a person can choose what to bring across; only what they pick reaches us. For the calendar, it can see and change the entries this app created and nothing else — your own meetings are not readable by us, and for those we are told only that you are busy at a time, never what you are doing or with whom. We never add your clients as guests on a Google invitation, so Google is not given their email addresses and does not email them.
It lasts until it is taken back, and taking it back is one click: Disconnect, on the account page in the console. That revokes the key with Google at the moment you press it rather than only forgetting it at our end, so it stops working everywhere and not just here. You can also remove our access from your Google account’s own security settings, and it will stop working just the same.
One honest limit. A host can put an arbitrary web page or image into a room, and when they do, your browser fetches it from wherever it lives — so the full set of companies a particular room reaches is decided by the brand that built it, not by us, and we cannot enumerate it here.
Our own operational alerts — a service degrading, an error spiking — go to a private channel of our own. They carry identifiers and error text so we can find the problem, and we work to keep names, addresses and message contents out of them.
Dysplay’s primary application hosting, database and file storage, and real-time media processing are configured in the European Union. The companies above operate around the world, however, and some support, security or feature-specific processing may happen outside the European Economic Area. Where it does, the transfer runs on the European Commission’s standard contractual clauses, which is the mechanism those providers offer and the one we rely on.
We do not yet run a single automatic deletion schedule across every category, so these are purpose-based limits rather than exact calendar promises. A brand can ask us to delete a room, a visit or a whole account sooner; we will act on a valid request unless the law requires us to keep something.
If you are in the European Union or the United Kingdom the law gives you a specific set of rights, and we extend the same handling to everybody else, because running two standards is how a company ends up honouring neither.
Write to support@dysplay.io and we will answer within 30 days. If the request is about something inside a brand’s showroom we will pass it to that brand and tell you we have, because there it is their call and our job is to make it easy rather than to make it for them. If we get it wrong you can complain to your data protection authority; in Italy that is the Garante per la protezione dei dati personali.
Everything travels over an encrypted connection and is encrypted where it is stored. Each brand’s data is fenced off in the database by rules the database itself enforces, and our build refuses to merge a change that would let one brand read another’s — that check runs against a real database with a real anonymous key, attacking every new rule, because we have shipped that exact bug before and would rather a machine caught the next one.
Addresses used to hold back abusive traffic are stored as a one-way hash rather than as addresses, so the table that rate-limits a form cannot be turned back into a list of who filled it in. Passwords are never stored in a form anybody can read, ourselves included.
None of that is a guarantee, and a page offering one would be lying. If you find a hole, support@dysplay.io reaches us, and we would rather hear it from you than from somebody else.
Dysplay is a tool for sales teams and the people they sell to. It is not built for children, we do not market it to them, and we do not knowingly collect anything from anyone under 16. If you believe a child’s information has reached us, tell us and we will remove it.
This page carries the date it last changed, at the top. If we change something that matters — a new company in the table above, a new use for something we already hold — we will say so plainly rather than quietly moving the date, and we will do it before the change takes effect rather than after. It last changed on 27 September 2026.