Privacy Policy
Last updated: July 6, 2026
1. Introduction
DB Island Inc. ("we," "us," or "our"), operating the Ensiglo platform at ensiglo.com, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform, whether as a service provider ("Provider") or as a customer booking services through a Provider ("Customer").
Ensiglo is a technology platform that enables service providers to create booking pages and manage appointments with their customers. We act as an intermediary and do not provide the underlying services ourselves.
By accessing or using ensiglo.com, any subdomain thereof, or our related services, you consent to the practices described in this Privacy Policy.
2. Information We Collect
Information from Providers
When you register as a service provider on Ensiglo, we collect:
- Full name, email address, and phone number
- Business name, service category, and business description
- Business location and service area details
- Profile photos and images uploaded for your booking page
- Payment and banking information (processed securely by Stripe)
- Service offerings, pricing, and availability schedules
- Country of operation and preferred language
Information from Customers
When you book a service through a Provider on our platform, we collect:
- Name, email address, and phone number
- Booking details including date, time, and service selected
- Special requests or notes provided during booking
- Address information (for mobile/on-location services)
- Payment information (processed securely by Stripe; we do not store card details)
Automatically Collected Information
When you visit our platform, we may automatically collect:
- IP address, device type, and operating system
- Browser type and version
- Pages visited, time spent on pages, and navigation patterns
- Referral source and search terms used to find our platform
- Approximate geographic location based on IP address
3. How We Use Your Information
We use the information we collect to:
- Operate, maintain, and improve the Ensiglo platform
- Create and manage Provider accounts and AI-generated booking pages
- Process bookings between Customers and Providers
- Process payments, deposits, and platform fees via Stripe
- Send booking confirmations, reminders, and status updates
- Provide customer support and respond to inquiries
- Send administrative notices, including policy updates and security alerts
- Analyze usage patterns to improve our services and user experience
- Detect, prevent, and address fraud, abuse, and security issues
- Comply with legal obligations and enforce our Terms of Service
- Send marketing communications to Providers (with consent; you may opt out at any time)
4. Information Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Between Providers and Customers: When a Customer makes a booking, their name, contact details, and booking information are shared with the relevant Provider to fulfill the service. Similarly, Provider business information is displayed publicly on their booking page.
- Payment Processors: We share necessary transaction data with Stripe to process payments, deposits, refunds, and platform fees. Stripe handles payment data in accordance with PCI-DSS standards.
- Service Providers (Third-Party): We use trusted third-party services for email delivery, SMS messaging, analytics, hosting, and other operational functions. These providers only receive the data necessary to perform their services.
- Legal Requirements: We may disclose information when required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of the transaction. We will notify you of any such change.
Our Sub-processors
We engage the following categories of sub-processors to operate the Platform. Each acts under a written data-processing agreement and receives only the data needed for its function:
- Payments — Stripe, Inc. (payment processing, deposits, subscriptions, fraud prevention)
- Cloud hosting & infrastructure (application hosting, databases, and backups)
- Email delivery (transactional and, with consent, marketing email)
- SMS / messaging delivery (booking notifications and one-time passcodes)
- Content delivery & security (Cloudflare — CDN, DDoS protection, coarse geo)
- AI content generation (used to draft booking-page copy from your onboarding answers)
A current list of sub-processors is available on request at [email protected]. We remain responsible for the personal information handled on our behalf by these sub-processors.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our platform. These include:
- Essential Cookies: Required for the platform to function properly, including authentication, session management, and security features.
- Analytics Cookies: Help us understand how visitors interact with our platform so we can improve functionality and user experience.
- Preference Cookies: Remember your settings and preferences, such as language and country selection.
You can control cookies through your browser settings. Disabling essential cookies may prevent certain features of the platform from functioning correctly.
6. Data Security
We implement industry-standard technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication mechanisms including OTP verification
- Regular security assessments and updates
- Limited access to personal data on a need-to-know basis
- Stripe-managed payment processing (we never store credit card details on our servers)
While we take every reasonable precaution, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
7. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal, accounting, and regulatory obligations
- Resolve disputes and enforce our agreements
- Maintain backup records for disaster recovery purposes
When you delete your account, we will remove or anonymize your personal information within 90 days, except where retention is required by law. Booking records may be retained in anonymized form for analytics and reporting purposes.
Inactive Provider accounts may be archived or deleted after 12 months of inactivity, with prior notice sent to the registered email address.
8. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Restriction: Request that we restrict the processing of your information in certain circumstances
- Portability: Request a machine-readable copy of your data
- Objection: Object to the processing of your information for direct marketing purposes
- Withdraw Consent: Withdraw consent for processing where consent is the legal basis
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
If you are a Customer and wish to exercise rights regarding data held by a specific Provider, please contact that Provider directly in the first instance.
9. Legal Basis for Processing
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions that require a legal basis for processing personal data, we rely on the following grounds:
- Contractual Necessity: Processing your data is necessary to provide the services you have requested, including creating your account, generating your booking page, processing bookings, and facilitating payments.
- Legitimate Interests: We process data for our legitimate business interests, including improving the Platform, preventing fraud, enforcing our terms, conducting analytics, and communicating with users about their accounts. We balance these interests against your rights and freedoms.
- Consent: Where required by law, we obtain your consent before processing data for specific purposes such as marketing communications and non-essential cookies. You may withdraw consent at any time.
- Legal Obligation: We process certain data to comply with legal obligations, including tax reporting, financial regulations, and responding to lawful government requests.
The data controller / responsible party is DB Island Inc. (Wyoming Registration No. 2024-001462996), 30 N Gould St Ste R, Sheridan, WY 82801, United States ([email protected]). Depending on where you live, additional rights and protections apply, as set out below.
United Kingdom & European Economic Area (UK GDPR / GDPR)
If you are in the UK or EEA, we process your personal data under the UK GDPR and, where applicable, the EU GDPR, on the legal bases described above. You have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent at any time. Where we transfer data outside the UK/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.
You have the right to lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office (ICO), ico.org.uk. We would, however, appreciate the chance to address your concerns first — please contact [email protected].
South Africa (POPIA)
If you are in South Africa, we process your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA). The responsible party is DB Island Inc. You have the right to access your information, request correction or deletion, object to processing (including for direct marketing), and not to have your information processed unlawfully. Requests may be directed to [email protected].
You have the right to lodge a complaint with the Information Regulator (South Africa), inforegulator.org.za.
California & other U.S. states (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect and how we use it, to request access to and deletion or correction of that information, and to be free from discrimination for exercising these rights. Comparable rights apply in certain other U.S. states.
We do NOT sell your personal information, and we do NOT share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share personal information, no "Do Not Sell or Share My Personal Information" action is required; you may still exercise your access, deletion, and correction rights by emailing [email protected]. You may use an authorized agent to submit a request on your behalf.
10. AI and Automated Processing
Ensiglo uses artificial intelligence (AI) to generate booking page content for Providers, including business descriptions, service descriptions, and page layouts. This AI processing is based on information you provide during the onboarding questionnaire.
Our AI systems:
- Generate text and design elements for Provider booking pages based on your answers to onboarding questions
- May analyze booking patterns to suggest optimal availability settings
- Perform content moderation to detect inappropriate or prohibited content
- Do not make automated decisions that produce legal effects or similarly significant effects on you
You have the right to review and edit all AI-generated content on your booking page at any time through your dashboard. If you have concerns about automated processing, please contact us at [email protected].
11. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by applicable law
- Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms
- Document the breach, its effects, and the remedial actions taken
- Take immediate steps to contain and mitigate the impact of the breach
Breach notifications will include the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address the breach.
12. Children's Privacy
Ensiglo is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] and we will promptly delete such information.
13. Third-Party Links and Services
Our platform may contain links to third-party websites, services, or applications that are not operated by us. This includes payment processing pages (Stripe), social media profiles of Providers, and external websites linked from Provider booking pages. We are not responsible for the privacy practices of these third parties and encourage you to review their respective privacy policies.
14. International Data Transfers
Ensiglo operates globally and your information may be transferred to and processed in countries other than the country in which you reside, including the United States where DB Island Inc. is registered. These countries may have data protection laws that differ from your country of residence.
By using our platform, you consent to the transfer of your information to the United States and other countries where we or our service providers operate. We take appropriate safeguards to ensure your information remains protected in accordance with this Privacy Policy.
For transfers of personal data out of the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, or on another lawful transfer mechanism. A copy of the relevant safeguard is available on request at [email protected].
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Your continued use of the platform after any changes constitutes your acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
DB Island Inc.
Operating as Ensiglo
Email: [email protected]
Website: ensiglo.com
Registered office: 30 N Gould St Ste R, Sheridan, WY 82801, United States. Wyoming Registration No. 2024-001462996.