Skip to content

Privacy

Privacy Policy

A direct account of what the Enumake app collects today, why we use it and the choices available to you.

Last updated
4 September 2026
Data controller
SmartDealMind LLC, operator of Enumake
  • Enumake introduces customers to independent service providers. Enumake does not carry out the work and never holds customer funds.
  • The app collects what it needs for accounts, booking requests, optional public profiles, reviews, security and communications that you choose.
  • Text-only applications for new providers may open after the required legal gate is recorded. Applicant file upload remains closed, and every vetting decision is made by a person.

01

Controller and scope

SmartDealMind LLC operates Enumake and decides why and how the personal data described here is used. Our correspondence address is 4519 Woodruff Rd Ste 4 PMB 6356, Columbus, GA 31904-6096, United States.

This policy covers the Enumake site and app. It does not govern a service provider's independent use of information that you give that provider directly outside Enumake.

02

What we collect now

This list is limited to features that are currently available. Optional fields are marked in the relevant form.

Account and sign-in

Examples
Name, email address, verified phone number, optional profile image, Google sign-in provider if chosen, password in protected form, verification state, two-factor authentication data, IP address, browser type and session dates.
When it is collected
When an account is created, verified, secured or used to sign in.

Customer profile

Examples
First and last name, optional birth year, optional sex and an optional address or landmark.
When it is collected
When you complete or update account settings.

Booking request

Examples
Requested service, catalogue estimate, GPS location supplied with browser permission, landmark, problem description, date, time slot, contact phone, selected beneficiary, preference for a woman provider and request status.
When it is collected
While you prepare and submit a request.

Existing provider profile

Examples
Trade, introduction, experience, base area, service radius, availability, ability to meet selected preferences, assigned jobs, ratings, internal service notes and, when chosen by the provider, a public display name and published service rates.
When it is collected
To manage providers already authorised to use the service and display only the public elements when the provider enables publication.

Provider application and vetting

Examples
Applicant-declared name, verified phone number, trade and experience, professional references, declared residence and guarantor details, plus a staff-recorded confirmation of the issuing office and date of a criminal-record check.
When it is collected
When a prospective provider completes the text-only application and authorised staff perform the required in-person checks. Applicant file upload is not open.

Reviews and communications

Examples
A rating from 1 to 5, optional comment, WhatsApp choice, message delivery state, destination email address, booking reference and support requests.
When it is collected
When you leave a review, choose a channel or contact support.

Security and audit

Examples
Technical identifiers, timestamps, rate-limited attempts, booking events, status changes and audit records kept to what is needed.
When it is collected
As the service is used and supported.

What the current flow does not collect

Enumake does not currently receive card numbers, Mobile Money credentials, deposits or applicant files. Provider applications are text-only, and documents are checked offline and in person by authorised staff.

03

How and why we use it

We use the data to open and protect accounts, receive a request, look for an available provider, track the job, collect a review, provide support and maintain a security record.

An active provider separately chooses whether to publish their display name, the permitted profile details and service rates. Withdrawing that choice hides the public page and current rates without automatically deleting history needed for accountability.

In Togo, the ground depends on the purpose and may be your consent, performance of the requested service or steps before a contract, a legal duty, or protection of your interests and fundamental rights. Where the GDPR applies, our legitimate interest in operating and securing a marketplace may also apply, subject to your rights, under Article 6.

Mandatory provider application and vetting data is processed for steps before and performance of the provider relationship and for our legitimate interest in trust and safety, not through consent extracted as a condition of access to work. Criminal-record confirmation is processed only after the specific legal basis and required IPDCP authorisation are confirmed.

  • Precise location is requested only after you take an action in the browser.
  • Booking updates through WhatsApp are prepared only when the required choice is recorded and remains valid.
  • We do not use this data for behavioural advertising, and the current app has no advertising or audience analytics tool installed.

04

Who receives personal data

We provide only the information needed for the relevant task. An assigned independent provider may receive the booking details needed to carry out the job. Authorised team members may access data for support, security and operation of the service.

When a provider enables a public page, any visitor with the link can see the chosen display name, trade, introduction, declared experience, general request-acceptance state and current rates. Reviews, contact details, precise location, detailed hours, internal notes and evidence are not published on that page.

We may also disclose information when the law requires it, to protect a person or to defend legal rights. Enumake does not sell personal data.

Cloudflare

Role
Hosting, delivery, traffic protection, limited technical storage and secure database connectivity.
Data involved
Requests, IP address, session data and data needed to operate the app.

Neon

Role
Hosting the PostgreSQL database used by the app.
Data involved
Accounts, profiles, bookings, reviews, choices, delivery queues and application records.

Meta, through WhatsApp

Role
Phone sign-in codes and booking updates you choose.
Data involved
Recipient number and limited template fields, such as the booking reference, service or provider first name.

Resend

Role
Sending sign-in codes and service emails.
Data involved
Email address, message content, necessary booking reference and delivery state.

Google

Role
Optional Google sign-in and delivery of site fonts.
Data involved
Sign-in data returned by Google when selected, plus technical data sent with a font request.

05

Cookies and browser storage

The current app has no advertising or audience-measurement cookie. The cookies below support sign-in, security, language and the recording of your choice. On HTTPS connections, Better Auth cookie names may begin with __Secure-.

The booking draft is the only optional browser storage described here. If you decline it, the form remains usable without saving a draft in the tab.

better-auth.session_token

Purpose
Keep an authenticated session secure.
Duration
7 days after issue, with possible renewal during active use, or removed on sign-out.
Status
Necessary after sign-in.

better-auth.state

Purpose
Protect the return from Google sign-in.
Duration
About 5 minutes, then removed on return.
Status
Necessary only when Google is selected.

better-auth.two_factor

Purpose
Complete a two-factor authentication check.
Duration
10 minutes.
Status
Necessary when that check is required.

NEXT_LOCALE

Purpose
Remember the selected language.
Duration
Until the browser session ends.
Status
Necessary for that choice.

enumake_privacy_preferences

Purpose
Remember whether optional draft storage is allowed.
Duration
180 days.
Status
Necessary to respect the choice.

sessionStorage enumake:booking:draft:v1

Purpose
Keep draft fields in this tab, including location, description, date, contact, beneficiary and preferences.
Duration
Until successful submission, withdrawal in this tab or closing the tab.
Status
Optional and off by default until chosen.

Change your choice

The button below reopens the panel. Declining or withdrawing clears the draft in the current tab. Close any other open Enumake tab to end its own storage session.

06

How long we keep data

Email codes expire after 5 minutes, the Google sign-in state cookie after about 5 minutes and its associated server record after 10 minutes. Two-factor challenges expire after 10 minutes. An ordinary session is issued for 7 days and may be renewed during active use. The storage choice expires after 180 days. The optional draft follows the duration above.

A WhatsApp permission stops authorising new messages after no more than 180 days, or earlier when withdrawn. The record proving that choice is not automatically deleted when the permission expires.

For a rejected provider application, the appeal window lasts 90 days from the decision. After that date, an automated sweep deletes the mutable application evidence and clears the draft biography and internal notes unless a legal hold applies. The minimised case, event and audit history remains for accountability.

The current version does not yet apply one automatic deletion deadline to accounts, profiles, rate versions, publication choices, bookings, reviews, communication choices, delivery records, rate-limit records or audit trails. Withdrawing a rate closes its current version without erasing its history. Those records remain in the database until a manual operation or future retention rule is applied.

We assess deletion requests individually under the applicable law. Some records cannot be removed immediately when a legal duty, fraud prevention, evidence of an operation or another person's rights justifies retention.

07

Processing across borders

SmartDealMind LLC is established in the United States. Our technical providers may process data in the United States, the United Kingdom, the European Union or other countries where they operate. The precise locations depend on the service and its subprocessors.

Where law requires a particular approval or safeguard for a transfer, it must be in place before that transfer. You may ask us for the information available about the processing country and safeguards relevant to your situation.

08

Security measures

Measures include encrypted communications, hashed passwords, encryption of external sign-in tokens, role-limited access, two-factor authentication for relevant staff, rate limits and audit records.

Provider vetting requires a recorded in-person check and a human decision. Enumake does not automate the approval or rejection of an applicant.

No safeguard removes every risk. Report a compromised account or unintended disclosure promptly to support@smartdealmind.com.

09

Your rights and how to use them

Depending on the law that applies, you may ask for access, correction, deletion or restriction, object to some uses, withdraw consent and receive certain data in a portable format. Withdrawal does not undo processing that was lawful beforehand.

A provider can also change their display name and withdraw publication of a page or rate from the provider portal. Withdrawal stops future public display but does not necessarily erase versions and records kept for security, evidence or legal duties.

Email support@smartdealmind.com with the request and the account concerned. We may ask for proportionate proof of identity, but will not ask you to send a sign-in secret.

In Togo, you may contact the Instance de protection des données à caractère personnel. If the GDPR applies to your situation, you may also complain to the supervisory authority where you live, work or believe an infringement occurred. France's CNIL is one example of an EU authority.

10

Children and bookings for others

Enumake is not intended for direct use by a child. An adult may request a service for another person and should provide only the beneficiary information needed for that job.

If you believe a child supplied personal data directly without appropriate adult involvement, contact us so that we can review its deletion.

11

Changes and contact

We will update this page if the product or its processing changes materially. The date at the top identifies the published version.

For questions, rights requests or a security concern, email support@smartdealmind.com or write to SmartDealMind LLC, 4519 Woodruff Rd Ste 4 PMB 6356, Columbus, GA 31904-6096, United States.

Privacy Policy | Enumake