Privacy Policy

Last updated:

1. Who we are

Enhance More is a multi-tenant workspace for organizations and their teams, available at enhancemo.com and as an iOS application.

The data controller is Enhance More. You can reach us at [email protected].

Enhance More is used by organizations. If your employer or another organization invited you, that organization decides what information is put into the service and is the controller of that content; we process it on their behalf. This policy describes what we do in both roles.

2. What we collect

We collect only what the features you use require. Nothing here is sold.

CategoryExamplesWhere it comes from
Account Email address, password (stored only as a salted hash), name You, at sign-up, or an administrator who invites you
Profile Name, job title, phone number, profile photo You, in your profile page
Organization Organization name, logo, member list and roles Your organization's administrators
Work content Notes, reminders, contacts, service-calendar jobs, progress entries You and your colleagues, as you use the product
Forms Form definitions, and whatever a form's respondents submit Form owners and the people who fill in their forms
Messages Team chat messages and attachments You and your colleagues
Device Push notification token (iOS), push subscription id (web) Your device, only after you enable notifications
Billing Subscription status and a payment-provider customer reference Our payment provider. We never receive or store card numbers.
Technical Server logs, IP address, error diagnostics Automatically, when you use the service

We do not use advertising trackers, and we do not build advertising profiles.

Website analytics. Our public website uses Google Analytics to count visits and see which pages people find useful. It records the pages you view, roughly where in the world you are, and the kind of device and browser you use, and it stores an identifier in your browser so repeat visits can be counted as one visitor rather than several. We use it to understand how the site is found and read — not to identify you, and not to advertise to you.

You are asked before this happens, and you can change your mind. Where consent is required by law — across the EEA, the UK and Switzerland — nothing is measured until you accept. Elsewhere you can decline at any time, and declining also deletes the analytics cookies already stored on your device.

Analytics covers the website and the Enhance More iOS app, with the same consent choice applying in both. It does not cover the embedded form page: visitors to a third-party site that embeds one of our forms are never measured by us. We do not use Google Analytics for advertising — advertising storage, advertising user data and ad personalisation are switched off permanently and cannot be enabled from the consent prompt. You can also opt out in any browser using Google's opt-out add-on, or by using your browser's tracking protection.

3. Why we use it

  • To provide the service — signing you in, showing your organization's data, delivering messages and notifications.
  • To keep it secure — detecting abuse, investigating incidents, enforcing access rules.
  • To bill for it — where your organization has a paid plan.
  • To support you — responding when you contact us or submit a feature request.
  • To improve the product — counting visits and seeing which pages and screens people use, so we know what is worth building on. Only where you have accepted analytics.
  • To meet legal obligations — where the law requires us to keep or produce records.

Where the GDPR applies, our legal bases are performance of a contract, our legitimate interest in operating and securing the service, your consent (for push notifications), and compliance with legal obligations.

4. Who else processes it

We use a small number of infrastructure providers. Each processes data only to provide its part of the service, under contract.

ProviderWhat it handles
SupabaseDatabase, authentication, file storage
NetlifyWeb hosting and server-side functions
StreamTeam chat messages and attachments
OneSignalWeb push notifications
Google AnalyticsVisit statistics for the website and the iOS app, with consent
Apple (APNs)Push notifications to the iOS app
StripePayments and subscription billing (Not implemented yet)

Some of these providers operate outside your country. Where personal data is transferred internationally, it is covered by the safeguards those providers maintain, such as Standard Contractual Clauses.

We disclose data outside this list only when compelled by valid legal process, or as part of a merger or acquisition, in which case we will tell you beforehand.

5. How long we keep it

  • Account and profile — until you delete your account.
  • Organization content — until deleted by your organization, or until the organization itself is deleted.
  • Push tokens — until you turn notifications off, sign out, or the device unregisters. Tokens our provider reports as invalid are removed automatically.
  • Billing records — retained as long as tax and accounting law requires, typically several years, even after deletion.
  • Server logs — a short rolling window, then discarded.

6. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, object to, or delete your personal data. You can exercise most of these in the product directly — your profile is editable, and account deletion is in Settings.

For anything you cannot do yourself, contact us at [email protected] and we will respond within the period the applicable law requires. If we cannot resolve your concern, you may complain to your local data protection authority.

If your account was created by an organization, some requests may need to go to that organization, since they control the content. We will tell you if that is the case.

7. Deleting your account

You can delete your account at any time from Settings → Delete Account. Deletion is permanent and cannot be undone.

When you delete your account we remove:

  • your login credentials and profile, including your profile photo;
  • your memberships in every organization;
  • your personal notes, reminders and private contact notes;
  • your chat identity and your registered push devices.

Content you contributed to an organization — service-calendar jobs, shared contacts, form submissions — remains with that organization, because it belongs to them and their other members still rely on it. Where we can, we disassociate it from you rather than deleting their records.

If you are the only administrator of an organization that still has other members, we will ask you to promote another administrator first, so your colleagues are not locked out of their own data. If you are the only member, the organization and its content are deleted with your account.

8. Security

Data is encrypted in transit with TLS and encrypted at rest by our infrastructure providers. Access between organizations is enforced at the database level by row-level security policies, not only in the interface. Passwords are stored only as salted hashes and are never visible to us. Administrative access to production is limited to the people who need it.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.

9. Children

Enhance More is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will give notice in the product or by email before it takes effect.

11. Contact

Enhance More

Privacy enquiries: [email protected]

See also our Terms of Service.