Legal
Privacy Policy
Last updated 28 July 2026
1. Who we are, and which hat we wear
Embaro is provided by [LEGAL ENTITY NAME], [REGISTERED BUSINESS ADDRESS]. This policy explains what we do with personal data.
There are two different relationships here, and they matter legally:
- For your own account — the name and email of the people who sign in — we are the controller, and this policy governs it.
- For the employee data you put into requests — the people being onboarded or offboarded — you are the controller and we are your processor. We act on your instructions, and your own privacy notice governs how that data may be used.
That second relationship is governed by our Data Processing Agreement, which applies automatically to every customer and is binding on us as published — the version on that page is the agreement.
2. What we collect
Account data. Your name, work email address, a hashed password, your display preference, and — if you enable two-factor authentication — an encrypted authenticator secret.
Sign-in providers. If you sign in or sign up with Google or Microsoft, we receive your name, email address and an account identifier from that provider, and we store the identifier so the same account can sign you in next time. We receive no password, no contacts, and no mailbox access, and we never post or act as you. Your use of the provider itself is governed by its own privacy policy.
Organization data. Your organization name, the support address requests are sent to, an optional logo, and optional mail-server settings (any password there is encrypted).
Content you create. Your request forms, resource catalog, employee records, and the requests your people file. The personal data in these is whatever your form asks for — typically a name, work email, department, job title and manager.
Technical data. For each sign-in session we store the IP address and browser user-agent, so you can review and revoke active devices. We keep an audit log of actions taken in your account: who did what, when, and from which IP.
Support conversations. When you reach us from inside the product, we store what you write, your name and email address, the page you were on, your browser version, and every reply on the thread. Please keep employee details and passwords out of these — they are not needed to help you, and a support thread is not the place for them.
If you are a client of an IT provider, your support conversations go to that provider and not to us. We cannot read them at all unless your provider forwards the ticket to us, and even then our replies go to them. See section 4.
Billing data. Handled by Stripe. We store an identifier and your subscription status. We never receive card numbers.
We do not use advertising trackers, and we do not build profiles for marketing.
3. Why we use it
To provide the service, authenticate you, send the transactional email the product depends on (verification, invitations, password resets, and delivering completed requests to your IT desk), take payment, keep the service secure, and answer you when you contact support.
Where the UK or EU GDPR applies, our lawful bases are performance of a contract (to provide the service you signed up for), legitimate interests (keeping the service secure and preventing abuse), and legal obligation (financial records).
4. Who else processes it
We use a small number of providers to run Embaro. Each processes data only to provide its service to us:
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting and content delivery | Everything transiting the app, plus request logs and IP addresses |
| Neon | Managed PostgreSQL database | All account data and customer content stored by the service |
| Resend (using Amazon SES) | Transactional email — verification, invitations, password resets, and delivery of completed requests to your IT desk | Recipient addresses and the contents of those messages |
| Upstash | Rate limiting on sign-in and other sensitive endpoints | Counters only, keyed by an irreversible digest — no email address or IP is stored |
| OpenAI | Generating a draft request form from a description, when you use that feature | Only the description you type and your resource catalog names. No employee records or filed requests are ever sent |
| Stripe | Subscription billing | Billing contact and payment details, which are collected by Stripe directly — Embaro never receives card numbers |
Two of those deserve a specific note. Our rate limiting stores counters against an irreversible keyed digest, so no email address or IP is held there. And when you use the AI form builder, only the description you type and the names in your resource catalog are sent — never employee records or filed requests, and nothing is used to train models.
Your IT provider, if you have one.Where your account is run by a managed IT provider, that provider's staff act as your IT desk and can see your workspace — that is the arrangement you have with them, not a sub-processing arrangement of ours. Support you send from inside the product goes to them rather than to us. They may forward a ticket to us when they need our help, and if they do we can then read that thread; our reply goes back to them, and they answer you. We are not otherwise a party to it.
We do not sell personal data. We disclose it otherwise only where legally required, or to a successor if the business is transferred, in which case we will tell you.
5. Where it is processed
Our infrastructure is hosted in the United States. If you are in the UK or EU, that means your data is transferred outside your region; where required we rely on standard contractual clauses with our providers.
6. How long we keep it
Trials that do not convert. After 5 days an unconverted trial becomes read-only, and 14 days after that, the organization and everything in it are permanently deleted. We email you before each step.
Canceled accounts. Deleted on the same schedule.
Form versions. Every version of your request form is kept for as long as the account is active. This is deliberate: a filed request is rendered through the exact version it was filed against, so renaming a field today cannot rewrite what last month's request appears to say. Versions hold your form's structure — field labels, groups, resource names — not employee records. They are deleted with the account.
Support conversations. Kept while the account is active, so a thread you reopen still has its history, and deleted with the account. We do not keep them as a support archive afterwards.
Sessions. Removed when they expire or when you sign the device out.
Audit logs. Deleted automatically on a rolling 90-day window, so entries older than that are removed while the account is still active. That window is set by us and is the same for every account — it is not something you configure, and we will tell you here if it changes. Billing records are kept as long as needed for legal and accounting obligations.
These deletions are automatic. A daily job removes lapsed organizations, expired sessions and out-of-window audit entries without human review. Deletion of an organization is a real cascading delete, not a flag, and cannot be reversed or restored from a backup on request — see the Terms for the full schedule.
You can ask us to delete your data sooner at any time.
7. How it is protected
These are measures the product actually implements today:
- Passwords are stored using scrypt, a deliberately slow hash designed to resist cracking. They are never stored or logged in a readable form.
- Two-factor secrets and saved mail-server passwords are encrypted at rest with AES-256-GCM.
- Login details your IT desk hands back through a completed request are encrypted in the technician’s browser before they reach us, with a key that is never sent to our servers. We store a sealed value we cannot read; it can be revealed once by its intended recipient and is then destroyed, or destroyed automatically if never opened. Embaro staff cannot access these values under any circumstances.
- Sign-in sessions are opaque tokens held server-side and stored hashed, so a session can be revoked instantly — disabling a user or locking an account takes effect on their next request.
- Each organization’s data is isolated, and every request is checked against the signed-in user’s own organization rather than anything supplied by the browser.
- Actions that change data are recorded in an audit log you can read.
- Sign-in and other sensitive endpoints are rate limited.
- Traffic is encrypted in transit, and our database provider encrypts data at rest.
- Two-factor authentication is available, and we recommend enabling it.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you, and any regulator we are required to notify, without undue delay.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict processing, and complain to your data protection regulator.
Much of this you can do yourself: your profile page lets you change your details and revoke sessions, and an administrator can export or delete organization data. For anything else, email privacy@embaro.app and we will respond within one month.
If you are an employee whose data was entered into Embaro by an employer, please contact that employer first — they control that data, and we act on their instructions.
9. Cookies
We set four cookies. None is used for tracking or advertising, none is shared with anyone, and we run no third-party scripts that set their own:
- embaro_session — keeps you signed in. Set only after you sign in, and unreadable by JavaScript.
- embaro_2fa — a short-lived, encrypted cookie that carries you from the password step to the two-factor step. Cleared as soon as you finish signing in.
- embaro_oauth — a short-lived, encrypted cookie used only while you are signing in through Google or Microsoft. It is what stops someone forging that sign-in, and it is discarded immediately afterwards.
- embaro-theme — remembers whether you chose light or dark. A display preference and nothing else.
The first three are strictly necessary to sign you in and keep the sign-in secure, so no consent is required for them. The theme cookie only ever stores a preference you set yourself, holds no identifier, and is not read for any other purpose.
10. Children
Embaro is a workplace tool sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes
We may update this policy. For material changes we will notify account administrators by email. The date at the top always reflects the current version.
12. Contact
Privacy questions and requests: privacy@embaro.app. Anything else: hello@embaro.app, or the contact page.