Home/Legal/Privacy Policy
Client-Agency Data Protection

Privacy Policy

Handshake provides collaborative review workspaces for agencies and their clients. We hold your project confidentiality, creative master files, and communication history to the highest security standards.

Effective Date: October 4, 2026•Version: 2.0 (Cloud & Realtime)

1. Overview & Commitment

Handshake ("Handshake," "we," "us," or "our") builds software designed to bridge the alignment gap between creative agencies, development studios, and their clients. Because our platform is used to exchange proprietary creative assets, preliminary video edits, and sprint agreements, privacy is central to our architecture.

This Privacy Policy explains what information we collect, how it is stored, how permissions and access are segmented by workspace roles, and the choices you have regarding your data.

2. Information We Collect

We collect information in the following categories when you use Handshake:

  • Account Information: Name, work email address, telephone number (optional), avatar image, and designated role (Owner, Staff, Client, or User) upon registration.
  • Project & Workspace Communications: Chat messages, system activity feeds, reply threads, forwarded updates, and emoji reactions.
  • Uploaded Creative Assets: Media files uploaded to the Vault or shared in chat, including high-resolution images (PNG, JPEG, SVG), video cut reels (MP4, WebM), audio voice notes, briefs (PDF), and ZIP deliverables.
  • Time-Coded & Coordinate Annotations: Feedback entries containing second-level timestamps for video reels and normalized (x, y) coordinates for design canvas pins.
  • Milestones & Task Status: Completion timestamps, checklist states, assigned milestone categories, and start/deadline dates.

3. How We Use Information

We utilize the collected information strictly for the following operational purposes:

Collaboration Delivery

Enabling instant sync across agency and client tabs for chats, milestone checks, and media review annotations.

Role-Based Access

Enforcing fine-grained visibility rules so clients only access their designated workspaces and private files.

Auditability & Accountability

Maintaining an immutable history of who approved, checked off, or requested revisions on deliverables.

Security & Verification

Authenticating user sessions, verifying authorization tokens, and preventing unauthorized workspace access.

4. Creative Assets & Intellectual Property

Guaranteed Asset Ownership

Handshake claims zero ownership or intellectual property rights over any creative work, raw assets, logos, video reels, design files, or feedback uploaded to the platform. All intellectual property remains exclusively between the agency and the respective client as governed by their mutual contracts.

We do not sell, rent, or monetize your assets, nor do we train public AI models on your private creative media, briefs, or project chat histories.

5. Data Storage & Security Controls

Handshake implements defense-in-depth security measures to protect your data:

  • Row Level Security (RLS): Every database query is verified at the PostgreSQL kernel level. Users can never query or manipulate rows belonging to workspaces they are not members of.
  • Private Object Storage: Assets uploaded to the handshake-vault storage bucket are private by default and require authenticated user tokens to download or stream.
  • Transport Encryption: All communications between your browser and our servers are encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Zero AI Badge/Sparkle Injections: Handshake never alters, scans, or injects promotional AI badges into your creative deliverables.

6. Data Sharing & Third Parties

We do not share your personal information or media assets with third parties, except in the limited circumstances below:

  • Infrastructure Providers: We use Supabase (PostgreSQL, Storage, Auth, Realtime) hosted on secure cloud infrastructure to power database operations.
  • Legal Obligations: If required by valid court order, subpoena, or applicable law, we will notify the affected workspace owner unless legally prohibited.

7. User Rights & Data Retention

You retain full control over your personal and workspace information:

  • Access & Export: You can download your files, view tasks, and export conversation transcripts at any time.
  • Workspace Deletion: Workspace Owners have the authority to permanently delete a workspace. Deleting a workspace cascades and removes all associated tasks, chat logs, files, and annotations.
  • Account Closure: You may request the complete deletion of your account and personal profile by contacting our privacy team.

8. Contact & Privacy Inquiries

If you have questions regarding this Privacy Policy, your rights, or data practices, please reach out directly:

Handshake Privacy & Compliance Team
privacy@handshake.app