Last updated September 4, 2026
Privacy Policy
This policy explains how Manage handles personal information when people use the workspace or communicate with a project through WhatsApp or SMS.
Who operates Manage
non-square | Manage (“Manage”, “we”, “us”) is operated by [LEGAL BUSINESS / ENTITY NAME]. This operator is responsible for the processing described in this policy unless a customer or project organization determines how information is used for its own project.
Privacy questions and requests should be sent to [PRIVACY CONTACT EMAIL]. The operator name and contact address are placeholders that must be completed before publication.
Information we handle
Depending on how you interact with Manage, the service handles:
- Account and profile information, including name, email address, company, role, phone number, sign-in information, language, and permissions.
- Project information supplied by workspace members, including memberships, tasks, files, models, reports, comments, correspondence, and related activity.
- WhatsApp and SMS contact information, including phone number, WhatsApp identifier, display name, email address when supplied, and the project conversation to which the contact is assigned.
- Communication content and context, including inbound and outbound message text, replies, templates, provider message identifiers, raw provider payloads, timestamps, delivery/read states, errors, and a conversation preview.
- Media metadata, such as a provider media identifier, file name, type, caption, size when available, or an outbound media URL.
- Technical and security information needed to authenticate users, operate integrations, prevent abuse, diagnose failures, and maintain the service.
How messaging and attachments work
Manage uses Meta’s WhatsApp Business Platform to send and receive WhatsApp messages. Meta transmits message content, contact details, media identifiers, timestamps, and delivery/read events to Manage. SMS messages may be sent and received through Twilio.
For inbound WhatsApp media, Manage stores the provider’s media identifier and descriptive metadata. When an authorized project user opens the attachment, Manage requests the file from Meta and relays it to that user; the current messaging implementation does not copy the inbound WhatsApp binary into Manage’s own file storage. An outbound media URL is retained with the related message when one is supplied.
Why we use this information
- To provide authenticated project workspaces and assign communications to the relevant project.
- To send, receive, display, reply to, and maintain a project communication history.
- To show delivery and read status, identify participants, and make attachments available to authorized project users.
- To operate, secure, troubleshoot, and improve Manage and comply with applicable obligations.
Who receives information
Information is visible to workspace administrators and project members who have permission to access the relevant project feature. We also provide information to service providers only as needed to run the service, including Meta for WhatsApp delivery, Twilio for SMS delivery, Vercel for application hosting and configured file storage, and Neon for the hosted PostgreSQL database. Those providers process information under their own terms and privacy commitments.
Other optional integrations, such as Google, Microsoft, Autodesk, Zoom, or Google AI services, receive information only when the relevant feature is configured and used. We may also disclose information when required by law, to protect rights and security, or as part of a business transaction subject to appropriate safeguards.
Retention
The current Manage application does not automatically expire WhatsApp or SMS conversation records. Messaging data remains part of the project record until the related project or data is deleted, or until a verified deletion request is completed. Some information may be retained longer when needed for legal, contractual, accounting, dispute-resolution, fraud-prevention, backup, or security purposes.
Security and international processing
Manage uses access controls, signed webhook verification, encrypted connections, and provider credentials kept on the server to protect information. No system is completely secure. Because Manage and its providers operate across jurisdictions, information may be processed outside your country under the safeguards required by applicable law.
Your choices and rights
Depending on applicable law, you may ask to access, correct, export, restrict, object to, or delete personal information, or withdraw consent where consent is the basis for processing. Project records may be controlled by the organization responsible for the project, so we may refer a request to that organization. We will verify requests before acting and may retain information where permitted or required by law.
See the Data Deletion Instructions for the request process. You may also stop WhatsApp communication by asking the sender to stop or by using WhatsApp’s blocking controls.
Changes to this policy
We may update this policy as Manage changes. The date at the top identifies the current version.