smengo

Privacy Policy

Last updated: 12 June 2026

This Privacy Policy explains how Smengo (“we”) collects, uses and protects personal data when you use smengo.com and the Smengo application (the “Service”). It applies to website visitors, account holders and members of organisations that use the Service. We process personal data in accordance with applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the Law of Ukraine “On Personal Data Protection”.

1. What data we collect

• Account data: name, email address, password (stored in hashed form), interface language. • Organisation data: company name, billing email, time zone, plan and subscription status. • Employee data added by your organisation: names, departments, positions, work schedules and statuses. • Payment data: processed by our payment provider Paddle; we do not store full card numbers. • Usage data: actions in the app, pages visited, device and browser type, IP address. • Support communications: messages you send us by email.

2. How we use data

We use data to: provide and maintain the Service; create and secure accounts; process subscription payments; respond to support requests; send service emails (email confirmation, password reset, important notifications about the account or changes to terms); analyse aggregated usage to improve the product; ensure security and prevent abuse. We do not sell personal data and do not use Customer Data for advertising.

3. Our role: controller and processor

For account data of registered users and website analytics we act as the data controller. For employee data that organisations add to the Service, the organisation is the controller and Smengo acts as a processor: we process such data only on the organisation’s instructions to provide the Service. If you are an employee whose data was added by your employer, please direct requests about that data to your employer in the first instance.

4. Legal bases

We rely on the following legal bases: performance of a contract (providing the Service); legitimate interests (security, preventing abuse, product improvement); consent (where required, e.g. for non-essential analytics); compliance with legal obligations (accounting and tax records).

5. Who we share data with

We share data only with service providers that help us run the Service: • Supabase — database, authentication and file storage; • Vercel — application hosting; • Paddle — payment processing as Merchant of Record; • Resend — transactional email delivery; • PostHog — product analytics; • Sentry — error monitoring. These providers process data under agreements that require an adequate level of protection. We may also disclose data where required by law.

6. International transfers

Our providers may process data in the European Union and the United States. Where data is transferred outside your jurisdiction, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms.

7. Data retention

We keep account and organisation data while the account is active. After the trial expires without payment, data is preserved in read-only mode. If an account is deleted, we delete or anonymise personal data within a reasonable period (up to 90 days), except where longer retention is required by law (e.g. billing records).

8. Your rights

Depending on applicable law, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; withdraw consent at any time; and lodge a complaint with a supervisory authority. To exercise your rights, contact us at hello@smengo.com.

9. Security

We use technical and organisational measures to protect data: encryption in transit (TLS), encrypted storage, access controls and row-level isolation of each organisation’s data, the principle of least privilege, and monitoring. No method of transmission or storage is completely secure, but we work to keep risks to a minimum.

10. Cookies

We use strictly necessary cookies (authentication session, interface language and theme) and analytics cookies that help us understand how the product is used. You can restrict cookies in your browser settings; necessary cookies are required for the Service to function.

11. Children

The Service is intended for business use and is not addressed to children under 16. We do not knowingly collect data from children.

12. Changes to this Policy

We may update this Policy. We will post the new version on this page and, for material changes, notify you by email or in the app.

13. Contact

Privacy questions and requests: hello@smengo.com.