Legal
Privacy Policy
A formal policy is being prepared with legal counsel ahead of launch.
What follows describes how the system actually handles data today. It will be replaced by a complete policy before Embaro accepts payment.
What we store
Your organization name, the name and email of each person with an account, and the contents of the requests you file — which may include the names, email addresses and access details of employees you are onboarding or offboarding.
How it's protected
Passwords are hashed with scrypt and are never recoverable, by us or anyone else. Two-factor secrets and any mail-server credentials you enter are encrypted at rest with AES-256-GCM. Every record is scoped to your organization, and every request is checked against your account's organization before data is returned.
Who can see it
People you invite to your organization, and the Embaro operator for support and maintenance. Your data is never sold, and it is not shared with other organizations on the platform.
Subprocessors
Embaro runs on Vercel (hosting) and Neon (database), sends mail through Resend, and — once billing is live — will process payments through Stripe. Stripe handles card details directly; Embaro never sees or stores a card number.
Deletion
Trial accounts that don't convert are permanently deleted 14 days after the trial locks. You can request deletion of a paid account at any time, and it removes every record belonging to your organization.
Questions
Ask via the contact page.