Privacy Policy
Last updated: 8 October 2026
- The session itself stays between the two computers. Screen, sound, mouse and keyboard input, files, chat and clipboard are sent directly and end-to-end encrypted. They never go through our server.
- Our server only sets up the connection. It passes the connection request and the technical connection details on and deletes them within minutes.
- The app and your sessions aren't tracked. The app uses no analytics or advertising services. The website uses Google Tag Manager with a consent banner; measurement only runs with your consent (see section 2).
- Accounts are optional and only for technicians who want a shared address book, team profiles and a session log.
1. Who is responsible
The controller for the processing described here is:
MarketVision AGHagenholzstrasse 84
8050 Zürich, Switzerland
info@marketvision.ch · +41 44 557 91 91
We process personal data in line with the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).
2. This website
Server logs
When you open a page, our web server records the IP address, date and time, the requested address, the status code, the amount of data transferred, the referring page and the browser's identification (user agent). We use these logs to run the website securely and to find errors. The legal basis under the GDPR is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR).
Google Tag Manager
The website, the account area (/account/) and IT companies' customer pages (/brand/…, /s/…) load Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). We use it to manage measurement and marketing tags on these pages. Google Tag Manager itself loads on every one of these pages and shows a consent banner; your browser loads it from Google's servers, which receive your IP address.
Measurement and marketing tags, for example Google Analytics, only run after you consent in that banner. Google may then process usage data: the pages you visit, the time, the referring page, information about your device and browser, an approximate location derived from your IP address, and cookie identifiers. These tags may set their own cookies. The data may be transferred to the USA; Google LLC is certified under the EU–US Data Privacy Framework and the Swiss–US Data Privacy Framework, and standard contractual clauses also apply.
Before you decide, and if you decline, Google Analytics may still send limited signals without cookies or identifiers (Google’s Consent Mode), which tell Google only that the page was viewed and which choice you made; Google uses them to estimate usage in aggregate.
The purpose is to understand how the website is used, to improve it and to measure our campaigns. The legal basis for the measurement and marketing tags is your consent (Art. 6(1)(a) GDPR; Swiss FADP); loading Google Tag Manager and its consent banner is based on our legitimate interest in asking for and recording that consent (Art. 6(1)(f) GDPR). The data is kept as configured in Google's services, at most 14 months for Analytics data.
You can change or withdraw your consent at any time in the consent banner's settings; a withdrawal doesn't affect processing before it. You can also block or delete cookies in your browser's settings, or install Google's browser add-on to opt out of Google Analytics (tools.google.com/dlpage/gaoptout). For questions, write to info@marketvision.ch.
The ShareDesk app and the content of your sessions are not sent to Google.
Language
The website shows English, German, French or Italian depending on the language your browser asks for. If you switch the language yourself, a cookie (lang, containing only en, de, fr or it) remembers your choice for a year so we can show the right pages. On the page an IT company gives its customers (under /brand/… or /s/…), your choice of language is kept the same way in a cookie brand_lang (only en, de, fr or it). These two cookies are used for nothing else. The consent banner of Google Tag Manager and the tags you consent to may set their own cookies (see above).
Downloads from a branding link
When you download ShareDesk from an IT company's own link (its page under /brand/… or /download/…), our server keeps your IP address (for IPv6 only the network part), the time of the download and which branding it was for. A newly installed app uses this to show the right IT company's name and contact even if the download lost that information. These records are deleted after 8 days. The legal basis is our legitimate interest in a working service for the IT company you chose (Art. 6(1)(f) GDPR).
Branding pages and downloads
For each branding we count page views of its customer page and downloads of its branded app, per day. Only these numbers are stored, without IP addresses or any other personal data; visits by link previews and search robots are not counted. The counts are deleted after 13 months.
If a team shows its technicians on its customer page, the name and profile photo of the technicians it chose are public there, with an optional role such as “Support”; never their e-mail addresses. The team decides this and can remove it at any time.
3. The ShareDesk app and service
ShareDesk ID
When ShareDesk starts for the first time, it receives a permanent 9-digit ID from our server. For each ID we store a hashed device token, the last public IP address and the network (MAC) addresses of the Mac. The IP and MAC addresses let a technician wake a sleeping Mac on the same network (Wake-on-LAN). This data is kept for as long as the ID is in use. We also store which app runs under the ID (Mac, Windows or the version for older Macs), its version and the operating system version, when the ID was first and last online, and on which days it was online; we use this to plan updates and see how many installations are in use.
Setting up a connection
To connect two computers, our server passes these details between them:
- the connection request with the technician's profile: name, company, phone, email, website and portrait, and the technician's IP address; if the technician is signed in, also the account's name and email
- technical connection details (WebRTC offers and network candidates), which contain the IP addresses of both computers
- for unattended access, a one-time proof derived from the password; the password itself is never sent
These messages are stored only until the other computer picks them up and are deleted after about two minutes at the latest. The list of currently connected computers, with their IP addresses, is deleted 45 seconds after a computer goes offline.
To protect against password guessing and misuse, we store failed attempts and dismissed requests for 10 minutes, together with the IP address or ShareDesk ID involved.
Connection statistics
To run and improve the service, our server keeps a record of each connection request: the ShareDesk IDs of both computers, whether the technician used the app or the browser and which version, the technician's account if signed in, the kind of session (screen, files only or terminal), whether a password was used for unattended access, when the request was made, answered and ended, the outcome (accepted, dismissed, timed out, cancelled) and whether the connection ran directly or through a relay. It contains no IP addresses, names or content of the session. These records are deleted after 13 months.
Status checks
To show whether ShareDesk works, our server checks its own public pages once a minute and keeps the results (time, part checked, success, response time, a short technical error) for 100 days. No personal data or IP addresses are recorded.
The session
Screen, sound, microphone, mouse and keyboard input, drawings, files, chat, clipboard, terminal sessions, TCP tunnels and the computer information shown in the Info panel are sent directly between the two computers (peer-to-peer, WebRTC with DTLS/SRTP encryption). They don't pass through our server, and we can't see them.
If a direct connection isn't possible, the encrypted data is forwarded by a relay server (TURN). The relay only sees the IP addresses of both computers, the ShareDesk ID and the amount of data; it can't read the content and doesn't log individual connections.
Finding the network address (STUN)
To find the best connection, the app and the web viewer ask public STUN servers of Google (stun.l.google.com) and Cloudflare (stun.cloudflare.com) for the computer's public IP address. These providers receive the IP address of the request and may process it outside Switzerland, including in the USA. No other content is sent to them.
Diagnostics
To help us fix problems, the app sends a diagnostics report to our server in three cases:
- when you choose Help → Send Diagnostics
- automatically after ShareDesk has crashed: then only ShareDesk's crash report is sent, no log
- when a technician who is controlling your Mac asks for it during a session
A report contains the ShareDesk and macOS versions, the Mac model and processor type, the ShareDesk ID, the system language, whether ShareDesk has its permissions, the display sizes, the time since the last restart, ShareDesk's own log entries of the last 30 minutes and ShareDesk's crash reports of the last 7 days. We also store the IP address it came from. Reports are stored on our server, are readable only by our administrators and are deleted when they are no longer needed to solve the problem, or on request.
Updates
The app checks our server for a new version once an hour. The request contains the IP address and the app and version name, as for any web request. No other information about your Mac is sent.
Technician accounts
Technicians can sign in with an account. Teams can create their account themselves; we store the company name with it. We then store:
- email address, name and the password as a secure hash (bcrypt); sign-in tokens, valid for 180 days
- the address book: saved computers with their name, group (organisation, department or category), tags, notes and optionally a key for unattended access
- the computer details collected automatically each time a technician connects to a saved computer: computer name, user name and login name, operating system and version, model, serial number, processor, memory, disk size and free space, the computer's local IP addresses, displays, battery level, when it was last started and the ShareDesk version. Each new session replaces the previous details
- who an entry or group is shared with
- team profiles: name, company, phone, email, website and portrait
- invitation links with the inviting technician's profile; when a customer accepts an invitation, their computer name, user name, macOS version and model are added to the technician's address book
- the session log: start and end, remote ID, the name of the remote computer and user, the IP address of the other side, the kind of access, the names of transferred files (not their content), how the session ended and any note
Team administrators can see the session log of their team. The data is kept until it is deleted in the app or until the account is removed. To have an account removed, write to us.
Technicians can also manage all of this on the website, in the account area (/account/). When you sign in there or in the web viewer, your browser keeps the sign-in token in its local storage until you sign out.
E-mail confirmation and sign-up check
When you create a team, we send a link to your e-mail address to confirm it. The link is stored only as a hash and expires after 48 hours or when used. Until confirmed, adding members, invitations and your customer page are unavailable. At sign-up we also check your e-mail address's domain against a list of throwaway mail services and ask the public DNS whether the domain can receive mail. Nothing about this check is stored.
Signed-in devices
For each sign-in we store the browser's or app's identification (user agent, e.g. "Safari on Mac"), when it signed in and when it was last used, so you can see and sign out your devices in Settings. We also remember which kinds of device (browser or app, and system) your account has used, to warn you about a new one. We don't store IP addresses or locations for this. A sign-in is deleted when you sign out or after 180 days.
Change log of a team
So that a team can trace changes to its account, ShareDesk records security-relevant actions in a change log: sign-ins and failed sign-ins to the team's accounts, changes to passwords and two-factor sign-in, signed-out devices, members added or removed and administrator rights, invitations, sharing, computers and groups added, renamed, moved or deleted (names and ShareDesk IDs, never notes), brandings, changes to the team and its plan, data and billing exports, and API keys and webhooks. Each entry contains the time, who acted (the account's name, "Operator" for MarketVision's support, or the name of an API key), the action and what it concerned. We do not record IP addresses or browser and device information, and never passwords, codes or keys. The team's administrators can see and export the change log; MarketVision sees it only to support the team or to handle abuse. Entries are deleted automatically after 13 months, and at once when the team is deleted. Legal basis: our legitimate interest and the team's in the security and traceability of its account (Art. 6(1)(f) GDPR; Swiss FADP).
Integrations
When a team's administrators create API keys or webhooks, ShareDesk sends the data they chose to the tools and addresses they set: session log entries (technician's name and e-mail, computer name, times, billing), computers of the address books, and new members' names and e-mail addresses. The team decides on these recipients and is responsible for them. We store API keys only as a fingerprint, and for each webhook the last 50 delivery attempts (time, kind of event, status code) for at most 30 days.
Two-factor sign-in
If you turn it on, we store the secret key your authenticator app shares with us, the time step of the last code used (so a code can't be reused), and fingerprints (hashes) of your recovery codes. We delete them when you turn it off.
Your data
In Settings you can download your account's data (administrators: the team's) as a file, and delete the account or the whole team at any time.
Trusted technicians and invitations
With an invitation link, a customer can choose to trust a technician's account, once or permanently. That technician can then connect without a prompt. The trust is stored on the customer's Mac and can be removed there at any time.
Data on your Mac
The app keeps its settings, the address book, profiles, trusted technicians, an access list and a session log on your Mac. Passwords, keys and sign-in tokens are stored in the macOS keychain. Screenshots and recordings are only made when the technician starts them and are saved on the technician's Mac.
When an IT provider supports you
If you are helped by an IT provider other than MarketVision AG, that provider decides what it saves about you in its address book and session log. Please contact that provider about this data.
4. Retention at a glance
| Data | Kept |
|---|---|
| Connection messages (requests, connection details) | until delivered, at most about 2 minutes |
| Connected computers with IP address | 45 seconds after going offline |
| Failed attempts and dismissed requests | 10 minutes |
| ShareDesk ID with last IP and MAC addresses, app and system version, days online | while the ID is in use |
| Connection statistics (no IP addresses, names or content) | 13 months |
| Downloads from a branding link (IP address or IPv6 network, time, branding) | 8 days |
| Page views and downloads per branding and day (numbers only) | 13 months |
| Accounts, address book, profiles, session log | until deleted by you, your team administrator or us on request |
| Change log of a team (no IP addresses or device data) | 13 months, or until the team is deleted |
| Webhook delivery attempts (time, event, status code) | the last 50 per webhook, at most 30 days |
| Diagnostics reports | until no longer needed to solve the problem, or on request |
| Web server logs | as long as needed to operate and secure the service |
| Usage data through Google Tag Manager (e.g. Google Analytics) | as configured in Google's services, at most 14 months for Analytics data |
5. Disclosure and location
We don't sell personal data. Our servers are operated by MarketVision AG in Switzerland. Apart from the STUN requests and Google Tag Manager described above, no personal data is sent to third parties unless the law requires it.
6. Your rights
You can ask us what personal data we hold about you and have it corrected or deleted. You can also object to processing and ask for your data in a common format. Write to info@marketvision.ch. You can complain to the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland or, if you live in the EU, to your local data protection authority.
7. Security
Connections to our server use HTTPS, and sessions are end-to-end encrypted. Passwords are stored only as hashes. Computers identify each other with device keys, so a server in the middle can't pose as one of them.
8. Changes
We update this policy when the service changes. The current version is always on this page.