Privacy Policy
Last updated: July 26, 2026
This Privacy Policy explains how Tend2Thrive collects, uses, and shares personal information, and the choices you have. Tend2Thrive is operated by McDoCo, LLC.
- Who we are
- Information we collect
- How you join and sign in
- Information about your contacts
- How we use information
- How we share information
- We do not sell or “share” your information
- How long we keep information
- Your choices and controls
- Your California privacy rights
- If you are not a Tend2Thrive user
- Security
- Children
- Changes to this policy
- Contact us
1. Who we are
Tend2Thrive is a professional relationship manager operated by McDoCo, LLC (“McDoCo,” “we,” “us”). For purposes of California privacy law, McDoCo is the “business” responsible for the personal information described here. You can reach us at hello@mcdoco.com or learn more at mcdoco.com.
This policy is written for users and visitors in the United States.
2. Information we collect
We collect the following categories of personal information:
| Category | Examples | Source |
|---|---|---|
| Access requests (including waitlists) | The email address you give us, and your name if you give one. Collected before you have an account — and kept even if you never get one | You, when you ask us for access to the Service or to a feature — for example by joining a waitlist, or by beginning sign-up at a time when access is limited |
| Identifiers & account data | Name, email address, phone number(s), profile photo, and — if you choose to connect one — a LinkedIn or other social-profile identifier | You, when you sign up or edit your profile |
| Relationship data (“Your Content”) | Contacts you add, their phone numbers and profile links, notes, where and when you met or last spoke, reminders, touch cadence, and events you attend | You; in-person connect-code scans you perform; address-book sync and forwarded calendar invites you set up; files you import |
| Connection metadata | A link between a contact and their Tend2Thrive account, recorded when a person you scanned or invited signs in | You (scan or invite) and the other person (sign-in) |
| Messages | Messages you exchange with other members through the Service | You and other members |
| Usage & device data | Log data, IP address, browser/device type, push-notification tokens for devices where you turn on notifications, pages and features used, timestamps | Automatically |
| Communications | Messages you send us and support requests | You |
Sensitive personal information. Under California law, the contents of messages are “sensitive personal information” where we are not the intended recipient. That applies to the messages you exchange with other members through the Service: we store and transmit them so we can deliver them to the person you sent them to, and we use them for the security, abuse-prevention, support, and legal purposes described in Sections 5 and 6 — all purposes California law permits without triggering a right to limit their use. We do not use the contents of your messages to profile you, to train models, or for advertising.
Cookies, storage, and analytics
We use only essential storage and similar technologies needed to keep you signed in and to keep the Service secure. We do not use cookies for analytics or advertising anywhere in the Service.
Analytics. On our public website we use a privacy-friendly analytics service to count page views and see which pages people read; it sets no cookies, stores nothing on your device, and gives us aggregate counts rather than a profile of any visitor. Inside the app and the organization Platform — where you are signed in — the same service records which screens and features you use, so we can see where the product works and where it doesn’t. There, that activity is associated with a random identifier we generate for analytics alone: it is not your account identifier, it is not used anywhere else in the Service, and it is kept in your browser’s local storage rather than in a cookie. Signing out clears it. We do not record your screen, your keystrokes, or the contents of what you type.
Do Not Track and cross-site tracking. Some browsers can send a “Do Not Track” signal. There is no common industry standard for how to respond to one, so we do not respond to Do Not Track signals differently — but we do not engage in cross-context behavioral advertising, and we do not allow third parties to collect personal information about you across other websites through the Service, so there is no such tracking to switch off. If your browser or an extension blocks our analytics, the Service works normally.
If we add analytics or other technologies that set non-essential cookies, that record your session, or that would track you across other websites, we will update this policy and provide any choices the law requires.
3. How you join and sign in
Asking for access. Access to Tend2Thrive, or to a particular feature, is sometimes limited. When it is, you can ask us to let you know when there’s room — a waitlist. You give us an email address, and a name if you’d like to; we hold it until we have room, then email that address. If you begin signing up at a time when access is limited, we treat that as the same request and record it then, so you don’t have to ask twice.
We use what you give us this way for one thing: deciding who to let in, and telling them when we do. We do not use it to market to you, and we do not add you to a mailing list. If we decide not to invite you, we keep the request so we don’t ask you to repeat it, but we will not email you about it — which does mean that no news is not, by itself, news. You can ask us at hello@mcdoco.com where you stand or to delete what we hold, at any time, whether or not you ever get an account. See Section 11.
Invitations from other people. Someone already using Tend2Thrive can also bring you in directly — for example a member inviting you to connect, an event host sending you a ticket, or an organization’s invite link. Then you come in through that invitation rather than by asking us, and we collect what the invitation carries, as described in Section 4.
Signing in. You access your account with your email address; we confirm it’s you with a one-time code we email (or send to a phone number you add). When someone brings you in — a member scanning your code, an event’s ticket link — you can start with just a name, no address at all, and add an email later to keep the account. That name-only path always rides on the invitation it arrives with; it is not a way in on its own. We never store a password. Signing in to an account you already have never involves a waitlist.
You may also connect other accounts — such as LinkedIn, GitHub, or X — to your profile or to a contact, either to sign in or to verify that a profile link you show on your card is really yours. When you connect one, that service shares a limited set of information with us based on the permissions you grant — typically your name or username, profile picture or URL, and an account identifier — which we use to confirm you control the account and to operate the Service. For “Sign in with LinkedIn,” that also includes your email address. We never receive your password for these services, and we do not read your messages or post on your behalf. Your use of each connected service is governed by that service’s own terms and privacy policy.
4. Information about your contacts
Tend2Thrive is a tool for managing your professional relationships, so you may store information about other people — including people who are not Tend2Thrive users. When you add a contact, scan a LinkedIn QR code in person, or import contact information, we store that information on your behalf so we can provide the Service to you.
For this information, you direct what is collected and stored. You are responsible for having the right to store it and for using it appropriately, as described in our Terms of Service. We store it in order to provide the Service to you, and we do not use the contact information you store to build a separate marketing database or to contact your contacts on our own initiative. If you are one of those contacts rather than a user, Section 11 sets out what you can ask us for directly.
Address-book sync. If you turn on contact sync, you can connect Tend2Thrive to your device address book so your contacts stay in step across the two. When you do, we receive and store the contact entries you sync so we can keep them current for you. Sync is optional, you control which devices are connected, and you can disconnect a device at any time.
Forwarded calendar invites and emails. If you forward a calendar invite or similar email to your Tend2Thrive timeline address, we process its contents to create events and contacts on your timeline — which may include information about other people named in the invite. We use what you forward only to build your timeline, at your direction.
If you are a non-user and want to know about or remove information someone has stored about you, see Section 11.
5. How we use information
- To provide, maintain, and secure the Service, including authentication and your relationship timeline, reminders, and dormancy tracking;
- To decide and manage who has access — including any waitlist we run, and the invitation system that generates the invite links you choose to send;
- To deliver push notifications to devices where you turn them on, and to enable messaging between members who can contact each other;
- To respond to your requests and provide support;
- To monitor, debug, and improve the Service and develop new features;
- To detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms; and
- To comply with legal obligations and enforce our agreements.
6. How we share information
We share personal information only in these circumstances:
- Service providers. Vendors who process information on our behalf to run the Service — such as hosting, database, email delivery, analytics, and authentication providers — under contracts that limit their use of the information to providing services to us.
- At your direction. When you choose to make yourself discoverable, send an invitation, message another member, share your card with a specific person, or otherwise share information through a feature of the Service.
- Programs you authorize. You can create API keys that let a program or another tool you choose read or write your data on your behalf, within the permissions you grant the key. What that program then does with your data is outside our control and is your responsibility; you can revoke a key at any time.
- Legal and safety. When we believe disclosure is required by law or legal process, or is necessary to protect the rights, safety, or property of McDoCo, our users, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
7. We do not sell or “share” your information
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding 12 months. The sensitive personal information we handle — the contents of member-to-member messages, described in Section 2 — is used only to deliver the Service you asked for and for the security, abuse-prevention, support, and legal purposes California law permits, so we do not use or disclose it for any purpose that would give you a right to limit that use.
8. How long we keep information
We keep personal information for as long as your account is active or as needed to provide the Service. By category:
| Category | How long we keep it |
|---|---|
| Access requests (including waitlists) | Kept while your request is open, and for a reasonable period after we close or retire the list it was on, so we don’t ask you to repeat it or contact you twice. We do not delete these on a schedule of our own — including requests we decided not to grant, which we keep for that same reason. Ask us and we will delete yours; if you do get an account, the request records that and is deleted with the account. |
| Identifiers & account data | For as long as your account exists, and deleted when you delete your account. |
| Relationship data (“Your Content”) | Until you delete the item or your account. We do not delete it on a schedule of our own. |
| Connection metadata | For as long as either account exists. A connection describes two people, so it is removed when either side deletes their account. |
| Messages | Kept as each participant’s record of the exchange. Deleting your account detaches the conversation from you — it is no longer associated with any account, and is marked that way — but does not erase it from the other participant’s account, where they continue to see the contact name they saved themselves. |
| Usage & device data | Retained for 30 days for security, debugging, and analytics, then deleted. Push tokens are an exception: they last as long as the device stays subscribed, and are deleted when you turn notifications off or the device unsubscribes. |
| Communications | Kept as long as needed to handle your request and for a reasonable period afterwards as a record of the exchange. |
Accounts that expire on their own. Some accounts are created as a placeholder — a name-only sign-up, or a shell made when you were invited to an event — and are deleted automatically if they are never claimed. A name-only sign-up expires at midnight local time on the day it was created; an event shell expires at midnight local time after the event ends. Adding and verifying an email keeps the account, and the app prompts you to do so while this applies.
When you delete specific content, we delete it from active systems and remove it from routine backups on our standard backup cycle. When you delete your account, we delete or de-identify the personal information associated with it, except where we need to retain certain information to comply with legal obligations, resolve disputes, prevent abuse, or enforce our agreements — and except for records another member legitimately holds — such as a note they wrote about meeting you, or a conversation the two of you had — which belong to their own account. A conversation is detached from your account and marked as no longer connected to it; the other member continues to see the contact name they had saved for you.
9. Your choices and controls
- Access and edit. You can view and edit the contacts, notes, and account details you store in the Service.
- Export. You can export Your Content, including via CSV and supported integrations.
- Delete. You can delete individual contacts or notes, or delete your entire account, which removes your profile, history, and connections as described in Section 8.
- Discoverability. Being discoverable to other users is opt-in. You control whether others can find you and what they see.
- Access requests. If you’ve asked us for access — by joining a waitlist or otherwise — you can ask where it stands, or have it deleted, by emailing hello@mcdoco.com. You do not need an account to do either. Deleting it means we will not email you when there’s room; you can ask again later.
- Communications. You can opt out of non-essential emails using the unsubscribe link or by contacting us. We may still send service and security messages.
10. Your California privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), gives you the following rights:
- Right to know. To request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we disclose it.
- Right to delete. To request that we delete personal information we collected from you, subject to certain exceptions.
- Right to correct. To request that we correct inaccurate personal information we maintain about you.
- Right to opt out of sale/sharing. We do not sell or share personal information, so there is nothing to opt out of, but you retain this right.
- Right to limit use of sensitive personal information. The only sensitive personal information we handle is the contents of member-to-member messages (Section 2), and we use it only for purposes California law permits — delivering the Service, security, abuse prevention, support, and legal compliance — so this right is not triggered. If that ever changes, we will offer the limit and say so here.
- Right to non-discrimination. We will not discriminate against you for exercising any of these rights.
How to exercise your rights. Email us at hello@mcdoco.com. We will verify your request, typically by confirming control of the email or LinkedIn account associated with your data, before acting on it. You may use an authorized agent to submit a request on your behalf with proof of authorization. We will respond within the timeframes the CCPA requires (generally 45 days, with the possibility of an extension).
California’s “Shine the Light” law: because we do not share personal information with third parties for their own direct-marketing purposes, no separate disclosure is required.
11. If you are not a Tend2Thrive user
We may hold information about you without your having an account, in a few ways.
You asked us for access. If you joined a waitlist, or otherwise asked us to let you know when there was room, we hold the email address you gave us and, if you gave one, your name. That is yours to withdraw: email hello@mcdoco.com and we will tell you what we hold or delete it, and you do not need an account to ask. See Section 3 for what we do and don’t use it for.
A user stored you as a contact. A Tend2Thrive user may store information about you as one of their professional contacts. In that case, the user directs what is stored, and you may wish to contact them directly. You may also contact us at hello@mcdoco.com to ask what information about you we may hold and to request its deletion, and we will respond consistent with applicable law and, where appropriate, coordinate with the user who stored it.
An event you were invited to is run on Tend2Thrive. An organization hosting an event may give us its guest list — typically a name and email address — so it can invite you and check you in. The organization directs what it gives us and remains responsible for it; we hold it to run that event for them. The same request applies: write to us and we will tell you what we hold or delete it, and we will coordinate with the organizer where that is appropriate.
If you are a California resident, the rights in Section 10 are available to you in either case.
12. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Who at McDoCo can see your information. Our operator tools show member records with personal details — names, email addresses, phone numbers — redacted by default. Revealing them for a member is a separate, deliberate action, and each reveal is written to an audit trail recording whose details were shown and when. That trail is kept even after an account is deleted, so the record of what was viewed survives the data itself. Access to these tools is limited to people who need it, and we reveal details only where it is needed to provide support, investigate a report of abuse, keep the Service secure, or meet a legal obligation.
13. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will take reasonable steps to notify you, such as by posting a notice in the Service or updating the date at the top. For a material change we do not rely on your continued use as agreement: the Service asks you to accept the updated policy before you can carry on using it. For any lesser change, your continued use after it takes effect means you accept the updated policy.
15. Contact us
For privacy questions or to exercise your rights:
McDoCo, LLC
hello@mcdoco.com
mcdoco.com