Privacy Policy

This page is maintained by the EnVivo360° Hub team.

Your data is your data

We do not sell, rent, or share your sponsor, contact, or event data with third parties for marketing. You retain full ownership of everything you put into the app.

1. Who we are

EnVivo360° Hub (“we”, “us”, “the app”) is a sponsor-relationship management tool for event planners. This policy explains what personal data we handle when you use the app and what rights you have over it.

Contact for privacy questions: [privacy@your-domain.com] · Operator: [Your legal entity name and address].

2. What we collect

  • Account data — email address, name, and authentication credentials you provide at sign-up.
  • CRM data you enter — sponsors, contacts, deals, events, communications, activities, and notes.
  • Usage data — basic technical logs (timestamps, IP address, browser type) needed to operate and secure the service.

We do not intentionally collect special categories of data. Please do not enter sensitive personal data (health, financial account numbers, government IDs) into free-text fields.

3. How we use your data

  • To provide the CRM features you actively use inside the app.
  • To authenticate you and keep your account secure.
  • To send transactional messages (password resets, security alerts, service notices).
  • To diagnose bugs and improve reliability using aggregated technical logs.

We do not sell your data. We do not use your CRM contents to train AI models or share them with advertisers.

4. Data isolation and access control

Each workspace is isolated. Row-level security in the database restricts every read and write to the signed-in user's account. Sales team members added by an admin can only see the sponsors and related records that admin has delegated to them — nothing else.

5. Subprocessors

We use a small set of trusted infrastructure providers to run the service:

  • Lovable Cloud / Supabase — application hosting, database, and authentication.
  • [Email delivery provider] — transactional email (invites, password resets).

If you need a current subprocessor list or a data processing agreement (DPA), contact [privacy@your-domain.com].

6. Retention and deletion

We keep your data for as long as your account is active. You can delete individual sponsors, deals, events, and communications from within the app at any time. To delete your entire account and associated data, contact [privacy@your-domain.com].

7. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email [privacy@your-domain.com]. We will respond within a reasonable timeframe.

8. Security

Data in transit is protected with TLS. Passwords are hashed by the authentication provider. Access to production data is restricted to authorized personnel. No online service can guarantee absolute security; report suspected vulnerabilities to [security@your-domain.com].

9. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app or by email. The effective date below always reflects the current version.

Effective date: [YYYY-MM-DD].

This page is app-owned editable content, not an independent certification. It reflects currently enabled controls and the operator's stated practices; it does not on its own constitute a claim of compliance with any specific regulation.