1. Overview & Commitment
Handshake ("Handshake," "we," "us," or "our") builds software designed to bridge the alignment gap between creative agencies, development studios, and their clients. Because our platform is used to exchange proprietary creative assets, preliminary video edits, and sprint agreements, privacy is central to our architecture.
This Privacy Policy explains what information we collect, how it is stored, how permissions and access are segmented by workspace roles, and the choices you have regarding your data.
2. Information We Collect
We collect information in the following categories when you use Handshake:
- Account Information: Name, work email address, telephone number (optional), avatar image, and designated role (Owner, Staff, Client, or User) upon registration.
- Project & Workspace Communications: Chat messages, system activity feeds, reply threads, forwarded updates, and emoji reactions.
- Uploaded Creative Assets: Media files uploaded to the Vault or shared in chat, including high-resolution images (PNG, JPEG, SVG), video cut reels (MP4, WebM), audio voice notes, briefs (PDF), and ZIP deliverables.
- Time-Coded & Coordinate Annotations: Feedback entries containing second-level timestamps for video reels and normalized (x, y) coordinates for design canvas pins.
- Milestones & Task Status: Completion timestamps, checklist states, assigned milestone categories, and start/deadline dates.
3. How We Use Information
We utilize the collected information strictly for the following operational purposes:
Enabling instant sync across agency and client tabs for chats, milestone checks, and media review annotations.
Enforcing fine-grained visibility rules so clients only access their designated workspaces and private files.
Maintaining an immutable history of who approved, checked off, or requested revisions on deliverables.
Authenticating user sessions, verifying authorization tokens, and preventing unauthorized workspace access.
4. Creative Assets & Intellectual Property
Handshake claims zero ownership or intellectual property rights over any creative work, raw assets, logos, video reels, design files, or feedback uploaded to the platform. All intellectual property remains exclusively between the agency and the respective client as governed by their mutual contracts.
We do not sell, rent, or monetize your assets, nor do we train public AI models on your private creative media, briefs, or project chat histories.
5. Data Storage & Security Controls
Handshake implements defense-in-depth security measures to protect your data:
- Row Level Security (RLS): Every database query is verified at the PostgreSQL kernel level. Users can never query or manipulate rows belonging to workspaces they are not members of.
- Private Object Storage: Assets uploaded to the
handshake-vaultstorage bucket are private by default and require authenticated user tokens to download or stream. - Transport Encryption: All communications between your browser and our servers are encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
- Zero AI Badge/Sparkle Injections: Handshake never alters, scans, or injects promotional AI badges into your creative deliverables.
7. User Rights & Data Retention
You retain full control over your personal and workspace information:
- Access & Export: You can download your files, view tasks, and export conversation transcripts at any time.
- Workspace Deletion: Workspace Owners have the authority to permanently delete a workspace. Deleting a workspace cascades and removes all associated tasks, chat logs, files, and annotations.
- Account Closure: You may request the complete deletion of your account and personal profile by contacting our privacy team.
8. Contact & Privacy Inquiries
If you have questions regarding this Privacy Policy, your rights, or data practices, please reach out directly:
