Skip to content
1sixty8 Manifold
  • Why we built it
  • Modules
  • The Payoff
  • No-Risk Switch
  • Pricing
Sign in Join the First 50

Privacy Policy

Product: 1sixty8 Manifold Operator: 1sixty8 media, inc., a Pennsylvania S corporation Version: 1.3 Effective Date: June 1, 2026 Last Updated: June 1, 2026


Plain-English Summary

This summary describes the key points of our Privacy Policy in plain language. It is provided for convenience. The formal sections that follow govern in the event of any conflict with this summary.

  • We do not sell your data. We do not share your data for advertising or cross-context behavioral advertising. We do not use your data to train third-party AI models unless you explicitly opt in.
  • We process data to run the service, not for our own marketing. Any shop’s end-customer information (names, phone numbers, vehicle records, service history) is handled on the shop’s behalf.
  • Your data is stored in the United States. We do not currently transfer personal information outside the U.S.
  • You can access, correct, or delete your personal information. Requests are answered within 45 days.
  • Deleted data is gone within 60 days. When a shop cancels its subscription, there is a 30-day export window followed by deletion within 60 days of cancellation. Backups are purged within 30 days.
  • We notify affected customers within 72 hours of becoming aware of a security breach involving personal information.
  • We notify customers at least 30 days before adding a new subprocessor. Customers who object can terminate their subscription for a pro-rata refund.
  • Contact: privacy@1sixty8.com for any question about this policy or to exercise your rights.

1. Who We Are

1sixty8 media, inc. (“1sixty8 media,” “we,” “us,” or “our”) is a Pennsylvania S corporation operating 1sixty8 Manifold, a cloud-based software platform for service businesses. Our principal address is:

1sixty8 media, inc. 273 Smith Road Kunkletown, PA 18058

This Privacy Policy explains how we collect, use, share, and protect personal information in connection with 1sixty8 Manifold (the “Service”).

2. Who This Policy Applies To

This policy covers two groups of people whose personal information we handle in different ways. The distinction matters because the law treats them differently, and so do we.

Group A: Shop staff and administrators. The owners, managers, installers, salespeople, and other employees of the businesses that subscribe to 1sixty8 Manifold. Group A members create accounts, sign in to the Service, and use it to run their business. We are the direct service provider for Group A, and we handle their personal information accordingly.

Group B: Your shop’s customers and contacts. When a subscribing shop uses 1sixty8 Manifold to manage its own customers (for example, a driver whose vehicle is serviced), information about those end-customers is stored in our Service. Group B members do not sign in to 1sixty8 Manifold. In most U.S. state privacy laws, the shop is the “business” or “controller” of Group B data, and we act as a “service provider” or “processor.”

Website visitors. This policy also applies to people who visit our public marketing website at manifoldos.co and contact us through it, even if they never become a subscriber. Section 18 describes the limited information we collect in that context.

Throughout this policy, we flag which sections apply to which group.

This policy does not cover the websites or services of any third parties, including the shop’s own website, payment processors, or other services that may be linked to or integrated with 1sixty8 Manifold.

3. Information We Collect

3.1 Information About Group A (Shop Staff)

When a Group A member creates an account or uses 1sixty8 Manifold, we collect:

  • Account identity: first name, last name, username, email address, phone number, role, and status.
  • Authentication credentials: a cryptographically hashed password (stored using the bcrypt algorithm; we never store your plaintext password), and, for staff on trusted terminals, a cryptographically hashed personal identification number (“PIN”).
  • Profile preferences: avatar image (if uploaded), display preferences (such as dark mode), and other user-level settings.
  • Role and permissions: the role assigned to the user and any individual permission grants.
  • Location assignments: which of the shop’s locations the user has access to, if the shop operates more than one location.
  • Session and sign-in activity: login timestamps, IP address used to sign in, browser user agent, and success or failure of each attempt.
  • Password-reset activity: a hashed one-time reset token, its expiration, and the IP address that requested it.
  • Trusted-terminal records: a hashed terminal token, the daily sign-in history on that terminal, and audit records of fast-user-switch events.

3.2 Information About Group B (Your Shop’s Customers)

On behalf of each subscribing shop, we store:

  • Contact information: first name, last name, email address, primary phone number, alternate phone number, birthday, anniversary, and mailing address.
  • Vehicle information: year, make, model, trim, color, Vehicle Identification Number (VIN), license plate, and vehicle notes. Vehicle information may also feed a universal vehicle registry so service history follows a VIN across shops.
  • Service and transactional history: invoices, work orders, purchase orders, estimates, payments, returns, refunds, and related line items and notes.
  • Communication preferences and consent records: SMS opt-in status, opt-in method (for example, in-store form or chat widget), opt-in and opt-out timestamps, tax-exempt status, and any additional communication preferences set by the shop.
  • Communications content: the content of SMS messages, emails, chat-widget conversations, Facebook Messenger messages, and Instagram direct messages sent through 1sixty8 Manifold to or from the customer, including delivery status and attachments. Inbound messages received by the shop through any of these channels are also stored so the shop can respond. Where a message is routed through a third-party platform (for example, Meta Platforms for Messenger and Instagram), the platform’s own terms also govern the handling of the message on that platform.
  • Photos: images the shop uploads in connection with a work order (for example, vehicle condition at check-in) or in connection with a customer profile. Photos are re-encoded on upload to remove embedded location and device metadata (“EXIF”).
  • Reviews: review content, ratings, reviewer display name and avatar, and reply content, where the shop has enabled the Reviews module and connected its review platforms.
  • Free-text notes: notes the shop types into customer, vehicle, invoice, work-order, or accounts-receivable records. Because these fields are user-authored, their contents are the shop’s responsibility.

3.3 Information About the Subscribing Shop Itself (Business Information)

We also collect information about the business as an entity:

  • Company name, legal or d/b/a name, physical addresses (billing, shipping, storefront), business phone and email, website, logo, timezone, currency, and hours of operation.
  • Tax identification numbers (federal and state), business-entity type, and display preferences for invoices and other documents.
  • Role-contact designations (owner, manager, sales manager, installation manager, office manager) including name, phone, and email for each role.
  • Location records (name, address, phone, email, timezone, bay count) where the shop operates more than one location.
  • Platform configuration (for example, fast-switch idle window and daily cutoff time).

This information is primarily about a business rather than an individual, but because sole proprietors and small businesses are often identified by personal names and contact details, we treat this information with the same care as individual personal information.

3.4 Automatically Collected Information

Regardless of Group, when any user interacts with 1sixty8 Manifold, our servers automatically collect:

  • IP address and approximate network location, captured at authentication events and in the security audit log.
  • Browser user agent (browser name, version, and operating system), captured at authentication events.
  • Session information: a server-side session identifier stored as a cookie in the browser (see Section 12), along with the last-activity timestamp.
  • Application audit events: time-stamped records of security-relevant actions, including credentialed login, PIN-based user switching, PIN lockouts, PIN resets, terminal trust grants and revocations, and related events. Each audit event records the acting user, IP address, user agent, and event-specific context.
  • Diagnostic and operational logs: application error logs, cron job logs, email and SMS delivery status codes, and webhook-processing traces. These logs are used strictly for security, fraud prevention, debugging, and operational integrity.

3.5 Information We Do Not Collect

For clarity, 1sixty8 Manifold does not collect, process, or store:

  • Full payment-card numbers, card verification values (CVV), card expiration dates, or any other cardholder data subject to the Payment Card Industry Data Security Standard (“PCI-DSS”). Payment processing is handled by external payment processors. We store only a reference or token supplied by the processor, together with non-sensitive information such as the payment method, amount, date, and optional reference number.
  • Social Security numbers, driver’s license numbers, or government-issued identification numbers.
  • Biometric information.
  • Health, medical, or genetic information.
  • Precise geolocation of an individual device, beyond what IP-based approximation provides.
  • Information about children under thirteen, to our knowledge (see Section 14).

4. How We Use Information

We use personal information only for the purposes set out below. We do not use personal information for our own marketing, we do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

4.1 To Deliver and Operate the Service

We use the information in Sections 3.1 through 3.4 to:

  • Authenticate users, maintain active sessions, and enforce role-based and per-user permissions.
  • Display customer, vehicle, invoice, work-order, and communication records to authorized shop staff.
  • Send outbound messages (SMS, email, chat-widget conversations, Facebook Messenger messages, and Instagram direct messages) that the shop directs the Service to send.
  • Receive and route inbound messages sent by the shop’s customers through any of those channels.
  • Generate documents (invoices, estimates, purchase orders, work orders, end-of-day reports) and deliver them to recipients selected by the shop.
  • Decode VINs, import review content, and provide the other integrations described on our subprocessors page.

4.2 For Narrow Operational Purposes

We also use information for the following purposes, each strictly limited to what is necessary:

  • Security and fraud prevention: detecting unauthorized access, brute-force attempts, suspicious login activity, and abuse.
  • Diagnostics and debugging: investigating application errors and integration failures.
  • Aggregate metrics that do not identify individuals: measuring platform health, adoption of features, and service-level statistics.
  • Product telemetry: recording which features of the Service are in use at a per-tenant level (not per-customer level), to prioritize product improvements.
  • Legal and compliance purposes: responding to lawful subpoenas or court orders, complying with applicable law, enforcing our Terms of Service, and protecting our rights.

4.3 What We Do Not Do

Consistent with our trust-first posture, we do not:

  • Sell personal information, and we have not sold personal information in the preceding twelve months.
  • Share personal information for cross-context behavioral advertising.
  • Use personal information to market any products or services to a shop’s end-customers (Group B).
  • Use Group B data to train third-party AI models.
  • Make decisions about individuals that produce legal or similarly significant effects using solely automated processing.

If we ever introduce an optional program that would change any of the items above (for example, an opt-in benchmarking program or an opt-in AI-training contribution program), we will introduce it as an explicit opt-in with a version bump to this policy. Your existing data will not be included in such a program unless you opt in.

5. How We Share Information

5.1 Subprocessors

We use a small number of carefully selected third-party service providers (“subprocessors”) to help operate 1sixty8 Manifold. Each subprocessor is bound by contract to process personal information only as needed to provide services to us and only in accordance with our instructions.

A current list of subprocessors, along with the purpose, data categories, and region of processing for each, is published at:

https://manifold.1sixty8.com/legal/subprocessors

Change notifications. We will provide at least thirty (30) days’ advance notice before adding a new subprocessor or materially changing an existing subprocessor’s role. During that notice period, a customer who objects to the change may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused portion of the subscription term.

5.2 Disclosures Required by Law

We may disclose personal information if required to do so in response to a subpoena, court order, or other legal process, or to comply with applicable law. Where we reasonably can, and where it is lawful to do so, we will notify the affected customer before we disclose information so the customer has an opportunity to object.

5.3 Business Transfers

If 1sixty8 media, inc. is involved in a merger, acquisition, reorganization, or sale of all or substantially all of its assets, personal information may be transferred as part of that transaction. We will use reasonable efforts to notify affected customers in advance and to require the successor to honor this policy (or provide equivalent protections) going forward.

5.4 With Your Direction

We may share or transfer personal information at the direction of the shop (for Group A data) or at the direction of the shop on behalf of its end-customers (for Group B data). For example, when a shop configures an integration or initiates an export.

5.5 Aggregated and De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify any individual. For example, we may publish industry benchmarks or use aggregated metrics in marketing material. We do not re-identify this information and we take commercially reasonable steps to prevent re-identification.

6. International Data Transfers

Personal information is stored and processed in the United States. We do not currently transfer personal information outside the United States for storage or meaningful processing.

Some subprocessors operate global edge networks (for example, content delivery, DNS resolution, or bot-protection challenges) that may route network traffic through non-U.S. points of presence for performance reasons. Meaningful processing of personal information remains in the United States.

If we ever add a subprocessor or a processing activity that changes the regional footprint of personal information, we will update this policy and provide the thirty-day notice described in Section 5.1.

7. How Long We Keep Information

We keep personal information only as long as we need it to provide the Service or for the limited additional purposes described below.

7.1 While a Shop Is an Active Subscriber

We retain account data and the shop’s records for as long as the shop’s subscription is active, subject to any in-product deletions the shop performs.

7.2 When a Shop Cancels

Upon cancellation or termination of a subscription:

  • A thirty-day export grace period begins, during which the shop may export its data using in-product tools or request assistance from us.
  • No later than sixty days after cancellation, we hard-delete the shop’s live production data from the Service.

7.3 In-Product Deletion by the Shop

When an authorized user inside the Service deletes an individual record (for example, a customer, vehicle, or invoice), that record is soft-deleted and may be recovered from a “trash” view for thirty days. After thirty days, the record is hard-deleted.

7.4 Backups

Operational backups containing personal information are purged within thirty days on a rolling basis. A record that has been hard-deleted as described above will no longer appear in any live or backup copy within thirty days.

7.5 Security Audit Logs

Security audit logs (login, PIN swap, lockout, terminal trust events, and related entries) are retained for twelve months from the event date. These logs are kept for fraud detection, incident investigation, and compliance purposes.

7.6 Aggregated and De-Identified Information

Aggregated or de-identified information that cannot reasonably be used to identify an individual may be retained indefinitely.

7.7 Legal Holds and Compliance Records

Where applicable law requires us to retain certain records longer (for example, tax or accounting records), we will retain those records for the legally required period and no longer than reasonably necessary after that period ends.

8. How We Protect Information

We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Safeguards include:

  • Encryption in transit. All traffic to the Service is served over HTTPS / TLS.
  • Encryption of sensitive values at rest. Third-party OAuth tokens and similar credentials are encrypted at the application layer using authenticated symmetric encryption.
  • Strong password hashing. User passwords are hashed using bcrypt with a work factor suitable for interactive use. We never store plaintext passwords.
  • Session protection. Session cookies are flagged Secure, HttpOnly, and SameSite=Lax, bound to a configurable idle lifetime, and regenerated after key authentication events.
  • Trusted-terminal controls. Fast user switching is gated to browsers that have been explicitly designated as trusted terminals. Terminal tokens are stored as hashes; PINs are stored as hashes; PIN attempts are rate-limited; and a same-day credentials login is required before a user may PIN-swap on a given terminal.
  • Tenant isolation. Every record in our database is scoped to a specific shop by tenant identifier. Application code enforces that users cannot access data belonging to another tenant.
  • Role-based and per-user permissions. Access to sensitive operations (refunds, permission management, admin functions) is restricted to staff with the appropriate role or permission grant.
  • Audit logging. Security-relevant events are recorded in a centralized audit log, including the acting user, the IP address, the user agent, and event context.
  • Photo metadata stripping. Photos uploaded through 1sixty8 Manifold are re-encoded on upload, which removes embedded location and device metadata.
  • Bot protection. Login and password-reset pages are gated by Cloudflare Turnstile to reduce credential-stuffing and brute-force attacks.

No safeguard is perfect. Section 9 describes what happens if one fails.

9. Data Breach Notification

If we become aware of a security incident that has resulted, or that is likely to result, in unauthorized access to personal information, we will notify affected customers without undue delay, and in any event no later than seventy-two (72) hours after becoming aware of the incident.

The notification will describe, to the extent then known:

  • The nature of the incident and the categories of information involved.
  • The approximate number of individuals affected.
  • The measures we have taken or propose to take to address the incident.
  • Recommendations for steps the customer and affected individuals can take to protect themselves.

10. Your Privacy Rights

Depending on where you live, you may have rights with respect to your personal information. We honor the rights described below for all individuals whose personal information we directly hold, regardless of jurisdiction, subject to the exceptions set out in this section.

10.1 Rights We Honor

  • Right to access and know. You may request a copy of the personal information we hold about you and information about how it is processed.
  • Right to correct. You may request correction of inaccurate personal information.
  • Right to delete. You may request deletion of your personal information, subject to narrow exceptions described in Section 10.6.
  • Right to portability. You may request a copy of your personal information in a machine-readable format.
  • Right to non-discrimination. We will not discriminate against you for exercising any of these rights. We will not deny you service, charge you a different price, or provide a different quality of service because you exercised a right under this policy.
  • Right to appeal. You may appeal any denial of a request (see Section 10.5).

10.2 Rights That Do Not Apply to Our Service

Some rights are provided by applicable law conditionally. We make the following declarations so that the conditions resolve cleanly:

  • Opt-out of sale or sharing. We do not sell personal information and we do not share personal information for cross-context behavioral advertising. No opt-out is necessary. We nonetheless honor Global Privacy Control (“GPC”) signals to the extent applicable, and we will not treat a GPC signal as a request to take any action we would not otherwise take.
  • Opt-out of profiling and automated decisions with legal or similarly significant effects. We do not make decisions about individuals that produce legal or similarly significant effects using solely automated processing. No opt-out is necessary.

10.3 How Requests Are Handled

Group A (shop staff). Requests from a Group A member about the Group A member’s own personal information are handled by us directly. Submit the request as described in Section 10.4. We will authenticate you before acting on the request.

Group B (shop’s end-customers). If you are a customer of a shop that uses 1sixty8 Manifold, we are a service provider to that shop. The shop is the primary decision-maker for your personal information. If you contact us directly, we will forward your request to the shop without undue delay and confirm to you that we have done so. The shop will then process your request using the in-product tools we provide for that purpose. If you are not sure which shop holds your information, we will do our best to help you identify it.

10.4 How to Submit a Request

Send your request to privacy@1sixty8.com. Include enough information for us to identify you and the shop (if applicable). We may ask you to verify your identity before acting on certain requests; the verification method will be proportionate to the sensitivity of the request.

You may also authorize an agent to submit a request on your behalf. We will require written proof of the agent’s authority and may, where the law permits, also verify your identity directly.

10.5 Response Times and Appeals

We will respond to a valid request within forty-five (45) days of receipt. If we need more time due to the complexity or number of requests, we may extend the response period once by up to an additional forty-five days and will notify you of the extension within the initial response period.

If we decline your request in whole or in part, we will explain why and inform you of your right to appeal. To appeal, reply to the response notice or email privacy@1sixty8.com with the word “Appeal” in the subject line. We will complete the appeal within a reasonable time and inform you of the outcome. If you remain dissatisfied, you may contact the attorney general of your state.

10.6 Exceptions to the Right to Delete

We may retain certain information after a deletion request for the limited purposes and limited duration required to:

  • Complete a transaction you initiated, provide a good or service you requested, or perform a contract.
  • Detect and respond to security incidents, fraud, or illegal activity.
  • Comply with a legal obligation.
  • Maintain security audit logs as described in Section 7.5.
  • Enable solely internal uses reasonably aligned with your expectations based on your relationship with us.

When we retain information under an exception, we retain only the minimum necessary for the exception’s purpose, and we delete it when the exception no longer applies.

11. California-Specific Disclosures

If you are a California resident, the following additional disclosures apply under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”):

  • Categories of personal information collected. Identifiers (name, email, phone, IP address, account identifiers), customer records (billing and contact information), commercial information (invoice and transaction history), internet or other electronic network activity (session and audit log entries), geolocation (approximate, IP-based), and inferences drawn from any of the above to the limited extent they exist.
  • Sources of personal information. Directly from you, from the shop that uses 1sixty8 Manifold (for Group B data), from our subprocessors, and automatically from your device.
  • Business or commercial purposes for collection. The purposes described in Section 4 of this policy.
  • Categories disclosed to third parties. The categories above may be disclosed to the subprocessors listed on our subprocessors page for the purposes described there. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
  • Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under CCPA/CPRA.
  • Retention. As described in Section 7.

To exercise California rights, submit a verifiable consumer request as described in Section 10.4.

12. Cookies and Similar Technologies

The Service uses cookies and limited browser storage as described below. We do not use cookies for advertising or analytics.

12.1 Cookies We Set

  • pos_session (or an equivalent name configured for the deployment). First-party. Strictly necessary for authentication. Flags: Secure, HttpOnly, SameSite=Lax. Lifetime configurable per deployment; typically one hour of idle inactivity.

12.2 Third-Party Resources Loaded by the Service

  • Cloudflare Turnstile on login and password-reset pages, and on our marketing website’s contact form, for bot and abuse protection. Turnstile may set a challenge-scoped cookie on Cloudflare’s domain during verification. The signals it uses are strictly necessary for distinguishing real people from automated abuse and are not used for advertising or tracking.
  • Google Fonts on authenticated application pages, to provide the typeface. Google receives the visitor’s IP address when the font file is fetched. No cookies are set by this request.
  • jsDelivr CDN for chart rendering libraries on reporting pages. CDN asset fetch; no tracking cookies.

12.3 Browser Local Storage

The Service uses localStorage in limited circumstances for user-interface state (for example, the last-chosen size of an assistant panel) and for in-progress work recovery (for example, recovering a physical-inventory scan that was interrupted). These entries are first-party and contain no identifiers.

12.4 Do Not Track

Our Service does not currently respond to “Do Not Track” browser signals because there is no consensus standard for how a service provider should respond. We honor Global Privacy Control signals as described in Section 10.2.

13. Google API Services User Data Policy

This section describes how we collect, use, store, and share data we receive from Google APIs in connection with the Reviews module’s Google Business Profile integration. It is included to satisfy Google’s transparency requirements for restricted-scope OAuth applications and is in addition to (not in place of) the rest of this Privacy Policy.

1sixty8 Manifold uses Google API Services to integrate Google Business Profile reviews into the Reviews module. The Service’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes used. When a Customer connects a Google Business Profile account, the Service requests the following OAuth scope: https://www.googleapis.com/auth/business.manage. This scope grants the Service permission to read and reply to reviews of the Customer’s verified Business Profile listing on the Customer’s behalf.

Google data we access and store. Review content, star ratings, reviewer display name, reviewer profile photo URL, reply content, reply timestamps, the Customer’s Business Profile account and location identifiers, and the Customer-authorized OAuth refresh and access tokens. OAuth tokens are encrypted at rest as described in Section 8.

How we use Google data. We use Google data solely to provide the Reviews module’s user-facing features: display the Customer’s reviews, allow authorized staff to compose and post replies, send push notifications about new reviews to staff who opt in, and surface aggregate review metrics in the Customer’s dashboard.

What we do not do with Google data. We do not transfer Google data to third parties except as necessary to provide or improve the user-facing features described above, comply with applicable law, or as part of a merger or acquisition with notice as described in Section 5.3. We do not use Google data for advertising, including retargeting, personalized advertising, or interest-based advertising. We do not allow humans to read Google data except (a) with the Customer’s affirmative consent for specific items, (b) as necessary for security purposes including investigation of abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations. We do not use Google data to train, improve, or develop generalized AI or machine-learning models.

Retention and disconnect. When a Customer disconnects the Google integration from /reviews/settings, we revoke the OAuth refresh and access tokens with Google and delete them from our database. Review content and replies that were ingested while the integration was active remain in the Customer’s account and are deleted on the cancellation timeline described in Section 7.2 unless the Customer requests earlier deletion.

14. Children’s Data

1sixty8 Manifold is not directed to children. We do not knowingly collect personal information from anyone under the age of thirteen, and we do not sell or share personal information of anyone under the age of sixteen without affirmative consent.

If you believe we have collected information from a child under thirteen, please contact privacy@1sixty8.com. We will delete the information promptly upon verification.

15. Changes to This Policy

We may update this Privacy Policy from time to time.

  • Minor updates. Typographical corrections or clarifications that do not change our commitments will be recorded in the Change Log (Section 19) and reflected as a minor version bump (for example, 1.0 to 1.1). These updates do not require any action from you.
  • Material updates. Changes that materially affect our commitments or your rights will bump the major version (for example, 1.x to 2.0) and will be announced to active customers in advance. Active users of the Service will be prompted to re-accept the updated policy at their next sign-in.

The version number and effective date appear at the top of this document. The full history of changes is at the bottom (Section 19).

16. Contact Us

For any question about this policy, to exercise a right described in Section 10, or to report a suspected privacy incident, contact:

1sixty8 media, inc. Attn: Privacy 273 Smith Road Kunkletown, PA 18058 Email: privacy@1sixty8.com

The same email address is the designated contact for inbound breach notifications from any subprocessor that is obligated to notify us of a security incident.

17. Governing Law

This policy is governed by the laws of the Commonwealth of Pennsylvania, without regard to its conflict-of-laws principles. Nothing in this section limits any right you may have under the law of the state in which you reside.

18. Our Marketing Website and Contact Form

This section describes the information we collect through our public marketing website at manifoldos.co, separately from the Service itself. It applies to anyone who visits that site, whether or not they become a subscriber.

18.1 Information you submit. If you fill out our contact form, we collect what you choose to provide: your name, your business or company name, your email address, your website, and the contents of your message. We use this only to respond to you, to evaluate whether 1sixty8 Manifold is a fit for your business, and to follow up about the product. We do not sell it and we do not use it for advertising. If you use a link on our site to schedule a call, that booking is handled by a third-party scheduling provider under its own privacy terms.

18.2 Information collected automatically. Like most websites, our hosting provider records standard server logs (which may include your IP address, browser type, the pages you request, and the date and time of your visit) to operate and secure the site. The marketing website does not set advertising or cross-site tracking cookies, and we do not run third-party analytics on it.

18.3 Bot protection. Our contact form is protected by Cloudflare Turnstile, as described in Section 12.2. The signals it processes are strictly necessary for security and are not used to track you.

18.4 How long we keep it. We keep contact-form submissions as long as needed to respond and follow up, then for a reasonable period for our business records, after which we delete or anonymize them. You may ask us to delete your submission anytime by emailing privacy@1sixty8.com.

19. Change Log

Version 1.0 (April 22, 2026): Initial policy published.

Version 1.1 (April 23, 2026): Clarifying edit before adoption: Section 3.2 and Section 4.1 extended to identify Facebook Messenger and Instagram direct messages as communication channels through which Group B message content is sent, received, and stored. No change to data-handling commitments; this edit makes the pre-existing Meta messaging integration explicit alongside SMS, email, and chat-widget conversations.

Version 1.2 (May 1, 2026): Added new Section 13, “Google API Services User Data Policy,” disclosing the business.manage OAuth scope, the Google Business Profile data accessed and stored, the Limited Use commitments, and the token revocation behavior on disconnect. Required for Google’s restricted-scope OAuth verification of the Reviews module integration. Existing Sections 13 through 17 renumbered to 14 through 18; cross-references updated accordingly.

Version 1.3 (June 1, 2026): Added Section 18, “Our Marketing Website and Contact Form,” disclosing the information collected through the public marketing site at manifoldos.co (contact-form fields, server logs, and Cloudflare Turnstile bot protection) and confirming the marketing site sets no advertising or tracking cookies. Section 2 updated to note coverage of marketing-website visitors; Section 12.2 updated to note Turnstile also protects the contact form. Change Log renumbered from Section 18 to Section 19.

1sixty8 Manifold

The Operating System For Your Business

Product

  • Pricing

Resources

  • Documentation
  • FAQ
  • Changelog

Company

  • Contact
  • Facebook

Legal

  • Privacy
  • Terms
© 2026 1sixty8 Manifold. All rights reserved.