Privacy Policy
Last updated: July 2026
1. Who we are
CollabSpace is a collaboration workspace for freelancers, agencies, and their clients. This policy explains what we collect, why we collect it, and what control you have. We are currently in public beta.
2. What we collect
- Account data — your name, email address, and a securely hashed password (we never store your password in plain text). Client portal users may have an account with no password at all.
- Content you create — workspaces, projects, tasks, messages, comments, and files you upload.
- Activity data — a log of actions within a project (task created, file uploaded, member joined) used to power dashboards and the audit log.
- Technical data — standard server logs, including IP address and browser user-agent, used for security and debugging.
We do not sell your data, and we do not use it to train AI models.
3. Cookies
We use a single essential cookie: an httpOnly refresh-token cookie that keeps you signed in. It is not used for advertising or cross-site tracking. Clearing it signs you out.
4. Service providers
We share data only with the providers required to run the service:
- Supabase — PostgreSQL database hosting (stores your account and content data).
- Cloudinary — storage and delivery of files you upload.
- Vercel — hosting for the web application.
- Email delivery (SMTP) — transactional email such as verification, password reset, invitations, and notifications.
5. Security
Data is encrypted in transit using HTTPS/TLS and encrypted at rest by our database provider. Passwords are hashed with bcrypt. Client portal access uses expiring session tokens rather than shared passwords. As a beta-stage product we do not currently hold formal certifications such as SOC 2 or ISO 27001, and we will say so plainly rather than imply otherwise.
6. Your rights
- Export — download all of a workspace's projects, tasks, conversations, and files as a ZIP archive from workspace settings, at any time, without contacting support.
- Deletion — delete a workspace from its settings, which permanently removes its projects, channels, tasks, and files. To delete your user account entirely, contact us.
- Access and correction — your profile and workspace data are editable in-app; contact us for anything you cannot change yourself.
7. Data retention
We keep your data for as long as your account is active. Deleted workspaces are removed from the live database immediately; backups may retain copies for a limited period before rotating out.
8. Changes and contact
We will update this page when our practices change and revise the date above. Questions about privacy or a data request can be sent via our contact page.