Privacy Policy
At EnsembleIO ("we", "our", or "us"), we prioritize the privacy and security of our users. This Privacy Policy outlines how your personal data is collected, used, protected, and shared when you use the EnsembleIO mobile applications (iOS, Android), web suite, and associated cloud services (collectively, the "Service").
1. Information We Collect
We collect only the information necessary to provide and enhance our team operations platform:
- Account & Profile Information: When you register or are added by an organization administrator, we collect your name, email address, phone number (optional), and organization role memberships.
- Attendance & Check-in Data: When you mark attendance via NFC DNA tag tap, QR code scan, or manual check-in, we record the timestamp, session ID, check-in method, and attendance status.
- Venue Geolocation (Foreground Only): If an organization enables venue geofencing for a specific session, the app requests one-time foreground location access to verify that check-in occurred within the designated venue boundary. We never track your location in the background or store continuous location histories.
- Biometric Credentials: When you enable Face ID, Touch ID, or Biometric Unlock, biometric data is processed entirely by your device's secure enclave (Apple Secure Enclave / Android BiometricPrompt). We never receive, transmit, or store your biometric fingerprints or facial geometry on our servers.
- Diagnostic & Telemetry Data: We collect non-identifiable crash logs and basic performance metrics via PostHog to maintain application stability and improve reliability.
2. How We Use Your Information
Your data is used strictly for legitimate organizational and app operational purposes:
- To authenticate your identity and secure access to your organization's workspace.
- To log, calculate, and display attendance records and team availability matrices.
- To dispatch essential session reminders and schedule updates via email or SMS (as configured by your organization).
- To troubleshoot bugs, prevent abuse, and optimize platform performance.
Our Privacy Commitment
We do not sell, rent, or monetize your personal data. We do not track your activity across third-party apps or websites, and we do not serve targeted third-party advertising.
3. Data Retention & Security
All data transmitted between your device and EnsembleIO servers is encrypted using modern TLS (HTTPS). Data at rest is secured in hardened, access-controlled databases with strict role-based access permissions.
Attendance records and organizational member profiles are retained for as long as your organization maintains an active account with EnsembleIO, or until a member or administrator requests deletion.
4. Organizational Data Governance & User Rights
EnsembleIO is an organization-managed enterprise platform. Customer organizations (tenants) act as the Data Controller of their rosters, session schedules, and attendance records, while EnsembleIO acts as the Data Processor.
- Member Profile Removal: Individual members added to an organization roster are managed by that organization's administrators. Members who leave a group or wish to be removed from an active roster can request removal directly from their organization administrator, follow our Account Deletion Instructions, or contact support@ensembleio.com for assistance disassociating their login credentials.
- Organization Data Deletion: Organization administrators have the authority to manage, export, deactivate, or delete member profiles and attendance histories at any time through the management suite.
- Tenant Account Closure: Upon an organization's termination of their EnsembleIO tenancy, all associated organizational records and member profile data are permanently deleted from active systems.
5. Contact Us
If you have questions, feedback, or concerns regarding this Privacy Policy or our data protection practices, please contact us at:
EnsembleIO Support & Privacy Team
Email: support@ensembleio.com
Website: https://ensembleio.com