Everywhere Design

Privacy Policy

Last updated: May 11, 2026

1. Scope

This Privacy Policy applies to all personal data collected, used and protected by Everywhere Design (the "Service"). By using the Service, you agree to the terms of this policy.

2. Data We Collect

We collect the following types of data:

  • Account information: company name, email address, password (stored encrypted)
  • Usage data: project schedules, shift schedules, check-in records, todos, vendor records, QC records
  • Device information: browser type, operating system version (for feature compatibility)
  • Location data: the check-in feature collects GPS coordinates after you grant permission, used solely for attendance records

3. How We Use Data

Collected data is used only to:

  • Provide and maintain the functionality of the Service
  • Verify identity and manage account security
  • Send service-related notifications (system announcements, billing reminders)
  • Improve service quality and the user experience

We do not sell your personal data to third parties, nor use it for advertising purposes.

4. Data Storage and Security

All data is stored on protected cloud servers (the Zeabur platform), with HTTPS encryption used during transmission. Passwords are stored after bcrypt hashing — we cannot read your original password.

We use a multi-tenant isolation architecture to ensure that data across different company accounts is fully separated and cannot be accessed across tenants.

5. Data Retention

While an account is active, related data is retained to keep the Service running. After you delete your account, all personal data is thoroughly erased from the system within 30 days.

6. Your Rights

You have the right to:

  • Access, correct or delete your personal data
  • Withdraw consent for data collection (such as GPS location)
  • Request account deletion and data erasure
  • Obtain a copy of your data

To exercise these rights, contact: [email protected]

7. Protection of Minors

The Service is a professional project-management tool and is not directed at persons under 18. We do not knowingly collect personal data from minors.

8. Tracking and Advertising

Mobile apps (iOS / Android): The Service's mobile applications do not integrate any third-party advertising SDK or behavioral tracking tools, do not track your behavior across other apps, and do not use your data for ad targeting.

Website (everywhere-design.com): To understand visitor behavior and improve service content and marketing performance, this website enables the following tracking technologies only after your explicit consent:

  • Meta Pixel (ID 1205247600165468): Records page-view events, used for ad remarketing and performance analysis on Meta platforms. Data is processed by Meta — see the Meta Privacy Policy.
  • Google Analytics 4 (ID G-28F69EDXH4): Collects anonymized visitor behavior (page views, time on page, referral source, device type), used to analyze website traffic and optimize the user experience. Data is processed by Google — see the Google Privacy Policy.

Consent mechanism (GDPR / ePrivacy friendly): On your first visit, a "cookie consent bar" appears at the bottom of the screen with "Accept" and "Decline" options. Tracking is off by default; Pixel and GA4 load only after you click "Accept." Choosing "Decline" means no tracking scripts load at all.

Changing your choice: If you previously accepted but wish to withdraw, you can clear the website data (localStorage) in your browser; the consent bar will reappear on your next visit so you can choose again.

Push notifications (no tracking):

  • Web Push Notification (browser push — requires your authorization in the browser)
  • Apple Push Notification Service (iOS push — requires your authorization on the device)
  • Google Firebase Cloud Messaging (Android push — requires your authorization on the device)

Push is used only to deliver service-related notifications (check-in reminders, todo updates, system announcements) and contains no advertising content.

8a. Announcement System

The Service includes a built-in announcement system that helps company managers and the platform operator deliver important messages:

  • Platform announcements: Published by the platform operator for system-maintenance notices, new feature launches, policy updates and similar. May be targeted by your subscription plan or business-type segment.
  • Internal company announcements:Published by your company's managers or those holding the "publish announcement" permission, for internal communication (e.g. holiday notices, site status, late check-in rules). May be targeted by your role (admin / regular employee).
  • Read records: The system records which announcements you have read to avoid showing them again and to let managers measure reach. Read records contain no information beyond the reading action itself.
  • Urgent announcements:In rare cases (at most 3 times per company per month), managers can publish an "urgent"-level announcement, which displays as a full-screen overlay when you open the app and closes only after you tap "I understand." The Service monitors urgent-announcement usage frequency on the backend to prevent abuse.
  • Audit and retention: All announcement publish, edit and delete actions are recorded in an audit log for review by managers and the platform operator. Announcements expired for more than 30 days are archived automatically; archived items older than 180 days are permanently deleted.

You cannot disable the announcement system itself (it is an essential service feature), but you can turn off push in your device settings.

9. Third-Party Payment Processors

Web subscriptions for the Service are processed by Paddle.com (Merchant of Record). Your payment information (card number, billing address) is collected and held directly by Paddle; we do not store your full credit card information.

In-app purchases are processed through the Apple App Store or Google Play, and the related data is managed by Apple / Google under their respective privacy policies.

10. Google API Services (if you use the Google Calendar integration)

The Service offers an optional "Connect Google Calendar" feature. If you actively authorize the connection, the Service will:

  • Access scope:Only read the "calendar events" of your Google account (scope: https://www.googleapis.com/auth/calendar.readonly) and your email address (scope: userinfo.email), used to identify the Google account you have connected.
  • Use:Display your Google Calendar events on the Service's calendar screen, alongside the Service's project schedules and todos, to help you consolidate your timeline. The Service does not modify, delete or add any event in your Google Calendar.
  • Storage:The Service only stores the Google OAuth refresh token (stored encrypted in the database), used to refresh access in the background; it does not store any of your Google Calendar event content on the Service's servers.
  • Sharing: Your Google user data is never shared, resold or disclosed to any third party, nor used for ad targeting, AI model training or similar purposes.
  • Revoking access:You may unlink at any time on the Service's "Account Settings" page, or revoke the Service's access on the Google account management page (https://myaccount.google.com/permissions). Once revoked, the Service immediately stops accessing your data and deletes the stored refresh token.

The Service's use and transfer of your Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

11. Changes to This Policy

We reserve the right to modify this policy. Significant changes will be communicated by email or in-app notification. Continued use of the Service constitutes acceptance of the revised policy.

12. Contact

For privacy-related questions, contact:

Everywhere-Design LTD.
Address: No. 11, Aly. 1, Ln. 48, Sec. 3, Muzha Rd., Wenshan Dist., Taipei City 116008, Taiwan (R.O.C.)
Email: [email protected]

© 2026 Everywhere-Design LTD.