MySquare

Privacy Policy

What we collect, how we use it, and the rights you have over it.

MySquare is run by MyVA LLC, on the same platform and with the same accounts as its workspace product. This document was written for the whole platform: wherever it says “the Service”, that includes MySquare (mysquare.app).

Effective May 12, 2026 · Last updated May 27, 2026 · Version 1.1

1. Who we are

MyVA LLC (“MyVA”, “we”, “us”, “our”) operates the MyVA website and platform at myva.cc. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

2. What we collect

  • Account & contact data: Name, email, username, profile picture, and settings you provide when creating or managing your account. Phone numbers if you provide them.
  • Usage data: Pages visited, features used, basic device/browser information, IP address, timestamps.
  • Content & communications: Messages, files, CRM entries, and other content you create or upload through the platform, plus communications you send to us.
  • Cookies & similar technologies: Small files used for sign-in, session management, preferences, and basic site reliability. See our Cookie Policy.

3. How we use your data

  • Service delivery: Provide, maintain, and secure the platform (authentication, troubleshooting).
  • Improvement: Improve features, performance, and reliability through aggregated insights.
  • Communication: Send service notices, respond to support requests, and deliver transactional emails.
  • Compliance: Comply with applicable laws and enforce our Terms of Service.
  • SMS & email integrations: If you configure SMS or email integrations, we process contact data (including phone numbers) solely to send messages on your behalf.
  • SMS data: If SMS is enabled, we process phone numbers and message content to send and receive text messages related to support, scheduling, and active business communications. We do not sell or share phone numbers or SMS consent data with third parties for marketing purposes.

5. Sharing and disclosure

We do not sell your personal information. We share data only as follows:

  • Service providers: Trusted vendors that help us run the platform (hosting, storage, email delivery, AI, payments). They have to protect your data and only use it on our instructions. See section 6 for the list.
  • Legal requirements: We may share information if the law requires it (court order, subpoena) or to stop harm, fraud, or security threats.
  • Business transfers: If MyVA is bought, merged, or sold, your data goes with it as part of the deal.

6. Service providers we use

We use a small set of well-known providers to run the platform. They process data on our behalf under their own privacy practices and our data-processing terms.

  • Vercel — application hosting and basic usage analytics. Privacy policy
  • Supabase — database, file storage, and realtime features. Privacy policy
  • Resend — transactional email delivery (when we send on our key; you can also bring your own). Privacy policy
  • OpenAI — powers the VAI copilot. You bring your own API key per project; the prompts you send go directly to OpenAI under their terms. Privacy policy
  • Stripe — planned for paid subscriptions and contractor disbursements. Not active for billing today. Privacy policy
  • Twilio — SMS and voice communications provider. Used when you (or your project owner) configure SMS for the project; messages are sent through Twilio under your own Twilio account credentials. Privacy policy

If we add or change a provider, we'll update this list and bump the “Last updated” date at the top.

7. Cookies

We use essential cookies for login, security, and preferences. If we introduce non-essential cookies (e.g., analytics or marketing) in the future, we will update this policy and provide controls. See our Cookie Policy for full detail.

8. How long we keep data

We keep personal data only for as long as we genuinely need it — for as long as your account is active, plus whatever's needed for legal, audit, contract, payment, and security obligations. After that, we delete or anonymise it.

Some records (signed contracts, payment records, tax documents, audit logs) we have to keep longer to comply with the law. We never keep data “just in case.”

9. Security

We implement industry-standard security measures to protect your information, including encryption of sensitive data at rest and in transit, access controls, and regular security reviews. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. See our Security page for more detail.

10. International transfers

Your information may be transferred to and processed in countries other than your country of residence. Where we transfer data outside the EEA / UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or equivalent mechanisms recognised by applicable data-protection authorities.

11. Third-party links & services

Our platform may contain links to third-party websites or integrations with third-party services. We are not responsible for their privacy practices. Read their policies before providing them with your information.

12. Children's privacy

Our platform is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will promptly delete it.

13. Your rights

Depending on your region, you may have the right to:

  • Access, correct, or delete your personal data.
  • Restrict or object to certain processing activities.
  • Request portability of your data in a structured, machine-readable format.
  • Withdraw consent where processing relies on consent.

EEA / UK residents: You may lodge a complaint with your local supervisory authority.

California residents (CCPA): You may request to know or delete your personal information, and opt out of the “sale” or “sharing” of personal information. We do not sell personal information.To exercise any CCPA right — including the right to opt out of the sale or sharing of personal information (the “Do Not Sell or Share My Personal Information” right) — email yourva@myva.cc with the subject line “CCPA Request”. We will confirm receipt within 10 business days and respond within 45 days.

EEA / UK Data Protection Contact: MyVA currently processes a limited amount of personal data of EEA/UK residents on an occasional and small-scale basis. We have not appointed a formal Article 27 Representative. EEA/UK residents may exercise any GDPR right by emailing yourva@myva.cc with the subject line “GDPR Request”. If our processing scale changes, we will appoint a Representative and update this section.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the “Last updated” date at the top of this page and, where appropriate, through in-app notifications or email.

15. Contact us

If you have questions about this Privacy Policy or want to exercise your rights: yourva@myva.cc