Privacy Policy
Last updated: May 5, 2026
1. What We Collect
When you use Enrollo, we collect:
- Account information: Name, email address, and organization name (via Clerk authentication).
- Student data: Names, contact details, nationality, education background, and application records that you enter into the system.
- Usage data: Pages visited, features used, and timestamps for product improvement.
- Payment information: Processed by Polar (polar.sh). We do not store credit card numbers.
2. How We Use Your Data
- To provide and maintain the Enrollo CRM service.
- To process payments and manage subscriptions.
- To send essential service communications (account, billing, security).
- To improve our product based on aggregate usage patterns.
We do not sell your data to third parties. We do not use your student data for advertising.
3. Third-Party Services & Data Residency
We use the following services to operate Enrollo:
- Supabase (database hosting, AWS EU / eu-west-1) — stores your data encrypted at rest and in transit.
- Clerk (authentication) — handles login, sessions, and team management.
- Polar (payments) — processes subscription billing.
- Vercel (hosting, edge network) — serves the application.
- Resend (transactional email) — delivers account, billing, and digest emails.
- PostHog (product analytics) — aggregate usage patterns; no student-level identifiers.
Primary data residency is AWS EU (eu-west-1). The full sub-processor list is published at /sub-processors. International transfers (US sub-processors such as Sentry, Resend) are governed by Standard Contractual Clauses.
4. Data Retention
Your data is retained as long as your account is active. If you cancel your subscription, your data remains accessible in read-only mode for 90 days, after which it may be deleted.
5. Your Rights (GDPR)
If you are in the EU/EEA or UK, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Delete your data (“right to be forgotten”).
- Export your data in a portable format.
- Object to processing of your data.
To exercise these rights, contact us at hello@enrollo.io. We respond within 30 days as required by GDPR Article 12.
EU representative (GDPR Article 27): Enrollo is currently operated by a sole founder based outside the EU. We do not have a formal Article 27 representative appointed at this time. If you are an EU/EEA data subject and need to exercise your GDPR rights or raise a concern, please contact us directly at hello@enrollo.io with subject line “GDPR inquiry” — we will respond within 30 days. You also retain the right to lodge a complaint with your local data protection supervisory authority.
6. Cookies
Enrollo uses only essential cookies for authentication and session management. We do not use tracking cookies or advertising pixels.
7. Security
We use industry-standard security measures including encrypted data storage (Supabase), secure authentication (Clerk), and HTTPS-only connections (Vercel). Access to your data is restricted to authenticated members of your organization.
8. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email or in-app notification.
9. Contact
For privacy-related questions, contact us at hello@enrollo.io.