Privacy Policy

Effective date: January 1, 2025

Last updated: August 7, 2026

This Privacy Policy explains how TakeShape Inc. ("TakeShape," "we," "us," or "our") collects, uses, discloses, and retains personally identifiable information / personal data ("Personal Information" or "PII") in connection with our websites, products, and services (the "Services").

Contact: privacy@takeshape.io

1) Scope (B2B services)

TakeShape is a business-to-business (B2B) company. This policy applies when:

  • you visit our website,
  • you create or administer an account,
  • you contact us (sales/support),
  • you receive communications from us, or
  • we process limited personal data in our Services in connection with our business customers.

Where TakeShape processes personal data on behalf of a customer (e.g., customer-managed users), TakeShape acts as a Processor / Service Provider, and the customer is the Controller / Business responsible for explaining processing in their own privacy notices. Our obligations in those cases are governed by contract (including any Data Processing Addendum).

2) What PII we collect (collection)

A. Information you provide

Because we are B2B and limit our data footprint, the primary PII we collect is:

  • Name
  • Email address
  • Business affiliation (e.g., company name, role/title) (optional, if provided)

You may also provide:

  • Support communications (messages and attachments you send to support/sales)

B. Information collected automatically

When you use our website or Services, we may collect:

  • Log and device data such as IP address, browser type, device/OS, timestamps
  • Usage data such as pages viewed, feature usage, and actions taken in the Services
  • Security and audit logs such as authentication events and administrative actions

C. Information from third parties

We may receive:

  • SSO/Identity provider data (typically name and email) if your organization enables SSO
  • Business contact details from business partners or referrals (name/email) where permitted

What we do not intentionally collect

We do not intentionally collect:

  • sensitive personal data (e.g., SSNs, government IDs, health data),
  • payment card data (if payments are used, they are handled by a payment processor),
  • consumer profiling data for targeted advertising.

3) How we use PII (use)

We use PII for the following purposes:

  • Provide and operate the Services (account creation, authentication, administration)
  • Communicate with you about the Services (support responses, service notices, security alerts)
  • Improve reliability and security (monitoring, troubleshooting, abuse prevention, incident response)
  • Manage business relationships (contracts, billing administration, customer success)
  • Comply with legal obligations and enforce our agreements

Marketing: We may send business-related marketing communications (e.g., product updates). You can opt out at any time using the unsubscribe link or by contacting privacy@takeshape.io. We will still send essential service/transactional messages.

TakeShape is based in the United States, but we may have EU/UK customers and users. Where EU/UK data protection laws apply, TakeShape relies on one or more of the following legal bases:

  • Contract (to provide Services to our customers and authorized users)
  • Legitimate interests (e.g., securing our Services, preventing fraud, improving performance)
  • Consent (where required, such as certain cookies/marketing)
  • Legal obligation (e.g., responding to lawful requests)

5) How we disclose PII (disclosure)

We may disclose PII in the following situations:

A. Service providers ("subprocessors")

We share PII with vendors that help us run our business and Services, such as:

  • hosting and infrastructure providers,
  • monitoring/logging and security tooling,
  • email delivery and customer support systems,
  • payment processing (Stripe, which processes payment card data under its own privacy terms),
  • analytics (limited, as needed for service operations).

They are authorized to use PII only to provide services to us and must protect it. A current list of Subprocessors that process customer personal data is available at takeshape.io/legal/subprocessors.

B. Customer organizations

If you use the Services through your employer or organization, that organization may access and manage your account information and activity consistent with their policies.

C. Legal and safety

We may disclose PII to comply with law or legal process, or to protect the rights, safety, and security of TakeShape, our customers, and others.

D. Business transfers

PII may be disclosed in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate protections.

No selling of PII: TakeShape does not sell Personal Information and does not share it for cross-context behavioral advertising.

6) Data retention (retention)

We retain PII only as long as necessary for the purposes described above, including security, compliance, and contractual obligations.

Typical retention (may vary by contract and legal requirements):

  • Account/contact PII (name, email): retained for the duration of the customer relationship or account activity; deleted or de-identified within 90 days after account deactivation/contract termination unless required for legal, security, or audit purposes.
  • Support communications: retained for 24 months to support service quality, track issues, and maintain business records.
  • Security/audit logs: retained for 90 days for detection, investigation, and compliance needs.
  • Backups: retained on a rolling basis for 30 days; PII may persist in backups until overwritten.

We may retain data longer where required by law, to establish or defend legal claims, to prevent fraud/abuse, or under a documented legal hold. We may also retain aggregated or de-identified data longer.

7) Security

We use reasonable administrative, technical, and organizational measures designed to protect PII, including access controls, least privilege, logging/monitoring, and encryption where appropriate. No system is 100% secure.

8) International transfers

PII may be processed in the United States. For EU/UK personal data, we use appropriate safeguards for transfers, such as contractual protections (e.g., Standard Contractual Clauses and/or UK addendum mechanisms) where required.

9) Cookies and similar technologies

We may use cookies and similar technologies to operate our site and Services (e.g., session management, preferences, security, basic analytics). You can control cookies through your browser settings and, where implemented, our cookie preferences tool. Blocking some cookies may affect functionality. See our Cookie Policy for more information.

10) Your rights and choices

Depending on your location, you may have rights to request access, correction, deletion, or restriction of your PII.

  • If you are an end user of a TakeShape customer: please direct requests to your organization (the data controller). We will assist the customer as required by contract.
  • If TakeShape is the controller (e.g., sales/support contacts): email privacy@takeshape.io.

We may need to verify your identity and/or authority before fulfilling requests.

11) Children's privacy

Our Services are intended for business use and are not directed to children. We do not knowingly collect PII from children.

12) Changes to this policy

We may update this policy from time to time. We will revise the "Last updated" date and provide additional notice where required.

13) Contact us

TakeShape Inc.

Email: privacy@takeshape.io

Ready to Transform Your Enterprise Data into Intelligent Agents?

Join forward-thinking organizations that are already leveraging TakeShape to build powerful AI agents with their enterprise data.