Legal

Privacy Policy

Last updated: July 26, 2026

This Privacy Policy explains how Tend2Thrive collects, uses, and shares personal information, and the choices you have. Tend2Thrive is operated by McDoCo, LLC.

The short version. We collect what we need to run a professional relationship manager: what you give us when you ask for access, who you are (from the name, email, or phone on your account), the contacts and notes you choose to store, and basic usage data. We do not sell your personal information. You can export or delete your data at any time — including anything we hold from before you had an account, whether or not you ever get one. Questions: hello@mcdoco.com.

1. Who we are

Tend2Thrive is a professional relationship manager operated by McDoCo, LLC (“McDoCo,” “we,” “us”). For purposes of California privacy law, McDoCo is the “business” responsible for the personal information described here. You can reach us at hello@mcdoco.com or learn more at mcdoco.com.

This policy is written for users and visitors in the United States.

2. Information we collect

We collect the following categories of personal information:

CategoryExamplesSource
Access requests (including waitlists) The email address you give us, and your name if you give one. Collected before you have an account — and kept even if you never get one You, when you ask us for access to the Service or to a feature — for example by joining a waitlist, or by beginning sign-up at a time when access is limited
Identifiers & account data Name, email address, phone number(s), profile photo, and — if you choose to connect one — a LinkedIn or other social-profile identifier You, when you sign up or edit your profile
Relationship data (“Your Content”) Contacts you add, their phone numbers and profile links, notes, where and when you met or last spoke, reminders, touch cadence, and events you attend You; in-person connect-code scans you perform; address-book sync and forwarded calendar invites you set up; files you import
Connection metadata A link between a contact and their Tend2Thrive account, recorded when a person you scanned or invited signs in You (scan or invite) and the other person (sign-in)
Messages Messages you exchange with other members through the Service You and other members
Usage & device data Log data, IP address, browser/device type, push-notification tokens for devices where you turn on notifications, pages and features used, timestamps Automatically
Communications Messages you send us and support requests You

Sensitive personal information. Under California law, the contents of messages are “sensitive personal information” where we are not the intended recipient. That applies to the messages you exchange with other members through the Service: we store and transmit them so we can deliver them to the person you sent them to, and we use them for the security, abuse-prevention, support, and legal purposes described in Sections 5 and 6 — all purposes California law permits without triggering a right to limit their use. We do not use the contents of your messages to profile you, to train models, or for advertising.

Cookies, storage, and analytics

We use only essential storage and similar technologies needed to keep you signed in and to keep the Service secure. We do not use cookies for analytics or advertising anywhere in the Service.

Analytics. On our public website we use a privacy-friendly analytics service to count page views and see which pages people read; it sets no cookies, stores nothing on your device, and gives us aggregate counts rather than a profile of any visitor. Inside the app and the organization Platform — where you are signed in — the same service records which screens and features you use, so we can see where the product works and where it doesn’t. There, that activity is associated with a random identifier we generate for analytics alone: it is not your account identifier, it is not used anywhere else in the Service, and it is kept in your browser’s local storage rather than in a cookie. Signing out clears it. We do not record your screen, your keystrokes, or the contents of what you type.

Do Not Track and cross-site tracking. Some browsers can send a “Do Not Track” signal. There is no common industry standard for how to respond to one, so we do not respond to Do Not Track signals differently — but we do not engage in cross-context behavioral advertising, and we do not allow third parties to collect personal information about you across other websites through the Service, so there is no such tracking to switch off. If your browser or an extension blocks our analytics, the Service works normally.

If we add analytics or other technologies that set non-essential cookies, that record your session, or that would track you across other websites, we will update this policy and provide any choices the law requires.

3. How you join and sign in

Asking for access. Access to Tend2Thrive, or to a particular feature, is sometimes limited. When it is, you can ask us to let you know when there’s room — a waitlist. You give us an email address, and a name if you’d like to; we hold it until we have room, then email that address. If you begin signing up at a time when access is limited, we treat that as the same request and record it then, so you don’t have to ask twice.

We use what you give us this way for one thing: deciding who to let in, and telling them when we do. We do not use it to market to you, and we do not add you to a mailing list. If we decide not to invite you, we keep the request so we don’t ask you to repeat it, but we will not email you about it — which does mean that no news is not, by itself, news. You can ask us at hello@mcdoco.com where you stand or to delete what we hold, at any time, whether or not you ever get an account. See Section 11.

Invitations from other people. Someone already using Tend2Thrive can also bring you in directly — for example a member inviting you to connect, an event host sending you a ticket, or an organization’s invite link. Then you come in through that invitation rather than by asking us, and we collect what the invitation carries, as described in Section 4.

Signing in. You access your account with your email address; we confirm it’s you with a one-time code we email (or send to a phone number you add). When someone brings you in — a member scanning your code, an event’s ticket link — you can start with just a name, no address at all, and add an email later to keep the account. That name-only path always rides on the invitation it arrives with; it is not a way in on its own. We never store a password. Signing in to an account you already have never involves a waitlist.

You may also connect other accounts — such as LinkedIn, GitHub, or X — to your profile or to a contact, either to sign in or to verify that a profile link you show on your card is really yours. When you connect one, that service shares a limited set of information with us based on the permissions you grant — typically your name or username, profile picture or URL, and an account identifier — which we use to confirm you control the account and to operate the Service. For “Sign in with LinkedIn,” that also includes your email address. We never receive your password for these services, and we do not read your messages or post on your behalf. Your use of each connected service is governed by that service’s own terms and privacy policy.

4. Information about your contacts

Tend2Thrive is a tool for managing your professional relationships, so you may store information about other people — including people who are not Tend2Thrive users. When you add a contact, scan a LinkedIn QR code in person, or import contact information, we store that information on your behalf so we can provide the Service to you.

For this information, you direct what is collected and stored. You are responsible for having the right to store it and for using it appropriately, as described in our Terms of Service. We store it in order to provide the Service to you, and we do not use the contact information you store to build a separate marketing database or to contact your contacts on our own initiative. If you are one of those contacts rather than a user, Section 11 sets out what you can ask us for directly.

Address-book sync. If you turn on contact sync, you can connect Tend2Thrive to your device address book so your contacts stay in step across the two. When you do, we receive and store the contact entries you sync so we can keep them current for you. Sync is optional, you control which devices are connected, and you can disconnect a device at any time.

Forwarded calendar invites and emails. If you forward a calendar invite or similar email to your Tend2Thrive timeline address, we process its contents to create events and contacts on your timeline — which may include information about other people named in the invite. We use what you forward only to build your timeline, at your direction.

If you are a non-user and want to know about or remove information someone has stored about you, see Section 11.

5. How we use information

6. How we share information

We share personal information only in these circumstances:

7. We do not sell or “share” your information

We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding 12 months. The sensitive personal information we handle — the contents of member-to-member messages, described in Section 2 — is used only to deliver the Service you asked for and for the security, abuse-prevention, support, and legal purposes California law permits, so we do not use or disclose it for any purpose that would give you a right to limit that use.

8. How long we keep information

We keep personal information for as long as your account is active or as needed to provide the Service. By category:

CategoryHow long we keep it
Access requests (including waitlists) Kept while your request is open, and for a reasonable period after we close or retire the list it was on, so we don’t ask you to repeat it or contact you twice. We do not delete these on a schedule of our own — including requests we decided not to grant, which we keep for that same reason. Ask us and we will delete yours; if you do get an account, the request records that and is deleted with the account.
Identifiers & account data For as long as your account exists, and deleted when you delete your account.
Relationship data (“Your Content”) Until you delete the item or your account. We do not delete it on a schedule of our own.
Connection metadata For as long as either account exists. A connection describes two people, so it is removed when either side deletes their account.
Messages Kept as each participant’s record of the exchange. Deleting your account detaches the conversation from you — it is no longer associated with any account, and is marked that way — but does not erase it from the other participant’s account, where they continue to see the contact name they saved themselves.
Usage & device data Retained for 30 days for security, debugging, and analytics, then deleted. Push tokens are an exception: they last as long as the device stays subscribed, and are deleted when you turn notifications off or the device unsubscribes.
Communications Kept as long as needed to handle your request and for a reasonable period afterwards as a record of the exchange.

Accounts that expire on their own. Some accounts are created as a placeholder — a name-only sign-up, or a shell made when you were invited to an event — and are deleted automatically if they are never claimed. A name-only sign-up expires at midnight local time on the day it was created; an event shell expires at midnight local time after the event ends. Adding and verifying an email keeps the account, and the app prompts you to do so while this applies.

When you delete specific content, we delete it from active systems and remove it from routine backups on our standard backup cycle. When you delete your account, we delete or de-identify the personal information associated with it, except where we need to retain certain information to comply with legal obligations, resolve disputes, prevent abuse, or enforce our agreements — and except for records another member legitimately holds — such as a note they wrote about meeting you, or a conversation the two of you had — which belong to their own account. A conversation is detached from your account and marked as no longer connected to it; the other member continues to see the contact name they had saved for you.

9. Your choices and controls

10. Your California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), gives you the following rights:

How to exercise your rights. Email us at hello@mcdoco.com. We will verify your request, typically by confirming control of the email or LinkedIn account associated with your data, before acting on it. You may use an authorized agent to submit a request on your behalf with proof of authorization. We will respond within the timeframes the CCPA requires (generally 45 days, with the possibility of an extension).

California’s “Shine the Light” law: because we do not share personal information with third parties for their own direct-marketing purposes, no separate disclosure is required.

11. If you are not a Tend2Thrive user

We may hold information about you without your having an account, in a few ways.

You asked us for access. If you joined a waitlist, or otherwise asked us to let you know when there was room, we hold the email address you gave us and, if you gave one, your name. That is yours to withdraw: email hello@mcdoco.com and we will tell you what we hold or delete it, and you do not need an account to ask. See Section 3 for what we do and don’t use it for.

A user stored you as a contact. A Tend2Thrive user may store information about you as one of their professional contacts. In that case, the user directs what is stored, and you may wish to contact them directly. You may also contact us at hello@mcdoco.com to ask what information about you we may hold and to request its deletion, and we will respond consistent with applicable law and, where appropriate, coordinate with the user who stored it.

An event you were invited to is run on Tend2Thrive. An organization hosting an event may give us its guest list — typically a name and email address — so it can invite you and check you in. The organization directs what it gives us and remains responsible for it; we hold it to run that event for them. The same request applies: write to us and we will tell you what we hold or delete it, and we will coordinate with the organizer where that is appropriate.

If you are a California resident, the rights in Section 10 are available to you in either case.

12. Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Who at McDoCo can see your information. Our operator tools show member records with personal details — names, email addresses, phone numbers — redacted by default. Revealing them for a member is a separate, deliberate action, and each reveal is written to an audit trail recording whose details were shown and when. That trail is kept even after an account is deleted, so the record of what was viewed survives the data itself. Access to these tools is limited to people who need it, and we reveal details only where it is needed to provide support, investigate a report of abuse, keep the Service secure, or meet a legal obligation.

13. Children

The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. If we make material changes, we will take reasonable steps to notify you, such as by posting a notice in the Service or updating the date at the top. For a material change we do not rely on your continued use as agreement: the Service asks you to accept the updated policy before you can carry on using it. For any lesser change, your continued use after it takes effect means you accept the updated policy.

15. Contact us

For privacy questions or to exercise your rights:

McDoCo, LLC
hello@mcdoco.com
mcdoco.com

Join the waitlist

We're focusing on existing user referrals at the moment. Leave your name and email and we'll bring you in with the next group - your invite includes a seat at a networking event, so there are people to meet the moment you arrive.