Privacy
Privacy Policy
Last updated: [insert date this policy is published/updated]
Who this policy covers
This policy applies to EnlightIn, an online platform operated by [Your company’s legal name and registered address]. If you’re in the EU/EEA or UK, your personal data is processed by us as described below.
Information we collect
Based on what the product actually stores today, this includes:
- Account information: your email address and password (managed securely by our authentication provider — we never see or store your raw password).
- Profile information: name, headline, bio, years of experience, areas of expertise, industries, location, company, rate, availability, and profile photo — whatever you choose to add.
- Content you create: posts, articles, comments, reactions, and the questions you post if you’re an asker.
- Messages: the content of messages you send to other users through EnlightIn.
- Booking and calendar information: meeting times, durations, budgets, and the purpose you provide when requesting or scheduling a consultation.
- Video call information: EnlightIn’s video calls connect two participants directly (peer-to-peer); EnlightIn’s servers relay only the connection setup, not the audio/video content itself, and do not record calls.
- Usage information: which profiles you’ve viewed (shown back to the profile owner as part of their analytics), and — only if you accept analytics cookies — general usage patterns via Google Analytics.
- Payment information: EnlightIn does not currently process payments or store any payment method details. [Update this section once a payment provider is connected — payment data would be handled by that provider directly, not stored by EnlightIn].
How we use your information
- To operate the core product: showing your profile, matching you with relevant problems/experts, enabling messaging and booking.
- To keep the platform secure (detecting abuse, enforcing access controls).
- To communicate with you about your account and activity on the platform.
- With your consent, to understand aggregate usage patterns via analytics — use Cookie settings in the footer to control this.
[State your specific legal basis for each purpose under GDPR Art. 6 — e.g. contract performance for core features, consent for analytics, legitimate interest for security — this requires a legal basis assessment we haven’t performed for you].
Cookies
We use strictly necessary cookies to keep you signed in and to remember your cookie preferences. With your consent, we also use analytics cookies. See our full Cookie Policy and Cookie settings (in the footer) for full control, including withdrawing consent at any time.
Who we share information with
- Other EnlightIn users: your profile, posts, and public activity are visible to other authenticated EnlightIn members by design (this is a professional networking platform). Your messages are visible only to you and the person you’re messaging.
- Service providers (processors): Supabase (database, authentication, file storage) and, only if you’ve consented, Google Analytics. [List any additional processors you add — email delivery, payments, customer support tooling — along with links to their own privacy policies and, where required, a Data Processing Agreement with each].
- We do not sell your personal information.
International data transfers
[Confirm where your infrastructure providers (e.g. Supabase’s hosting region, Google Analytics) actually store/process data, and — if that’s outside the EU/EEA — what transfer mechanism applies, e.g. Standard Contractual Clauses. This needs to be verified against your actual provider configuration, not assumed].
Data retention
We keep your information for as long as your account is active. If you delete your account, your profile, posts, comments, messages, bookings, and connections are permanently deleted immediately (see Your rights below) — with one disclosed exception: your login credentials remain registered in our authentication system until removed by an administrator. [Decide and document a specific retention period for backups and any data retained for legal/security reasons after account deletion].
Your rights
If you’re in the EU/EEA, UK, or another jurisdiction with similar protections, you generally have the right to:
- Access the personal data we hold about you — use Export your data in Settings.
- Correct inaccurate data — edit your profile directly, anytime.
- Delete your data — use Delete account in Settings.
- Withdraw consent for analytics at any time — use Cookie settings.
- Object to or restrict certain processing, and data portability — [provide a real contact channel for these requests, since they may need manual handling beyond the self-service export/delete tools].
Security
We use industry-standard practices including encrypted connections (HTTPS), database-level access controls (Row Level Security), and secure authentication. No system is perfectly secure, and we can’t guarantee absolute security. See our Security page for more detail.
Children
EnlightIn is a business platform intended for professional use and is not directed at children.
Changes to this policy
We’ll update this page when our practices change and update the date at the top.
Contact
For any privacy question or to exercise your rights: [insert a real contact email, e.g. privacy@yourdomain.com], or use our contact form. [If you’re required to have a Data Protection Officer, name them here].
This page is not a substitute for legal review.
Every [bracketed] item above needs a decision from you or review by a qualified privacy professional before this policy is complete.