Privacy Policy

Last updated 12 August 2026

This policy explains what Fabri Manager does with personal data — whose data we hold, why we hold it, who else can see it, and what you can ask us to do about it. We have written it to be read, not to be skimmed past.

1.Who we are

Fabri Manager is a business-management system for construction and home-service businessesfabrication, carpentry, plumbing, electrical, masonry, roofing and the other trades that work on homes and building sites. It is operated as an independent business by Elkanah Kwaku Donkor, based at GN-0006-3170 (Ghana Post GPS), Accra, Greater Accra, Ghana. We are the data controller for the account data described below, and you can reach a real person at every address on this page.

For questions about this policy or about your data, write to privacy@fabrimanager.com.

2.Two kinds of data, two different roles

This distinction governs everything below, so it comes first.

  • Account data — the details of the business that subscribes to Fabri Manager, and of the people it invites. We decide how this is handled, so we are the data controller.
  • Workspace data — the clients, jobs, quotes, invoices, payments, photos and messages a business records inside its own workspace. The business decides what goes in and why; we only store and process it on their instruction, so we are the data processor and they are the controller.

If you are a customer of a business using Fabri Manager and you want your details corrected or removed, contact that business directly. They control their workspace; we cannot alter their records on our own initiative.

3.What we collect

Account data, collected directly from you:

  • Name, email address and phone number of each invited user.
  • A hashed password — never the password itself — or, if you use Sign in with Google, your Google account identifier, name, email and profile picture.
  • Your business name, and the role and permissions assigned to each user.
  • Subscription plan, billing status and payment references from Paystack. We never see or store your full card number.
  • Sign-in records: the time of each sign-in, kept as an audit trail so unusual access to a workspace can be traced.
  • If you request access through the marketing site, the name, business, phone number and message you submit.

Workspace data, entered by the business using the system:

  • Client contact details, job records, quotes, invoices and payment records.
  • Photographs of work, uploaded to jobs, messages and the showroom.
  • Messages exchanged between a business and its clients through the portal.
  • Stock, expense and report data.

Technical data: standard server logs, and — if you enable them — the browser push-notification subscription needed to deliver alerts to your device.

4.Why we collect it, and on what basis

  • To provide the service — creating your workspace, authenticating you, and running the features you use. Basis: performance of our contract with you.
  • To bill you — taking subscription payments and issuing receipts. Basis: performance of contract, and our legal obligation to keep financial records.
  • To keep the service secure — sign-in audit trails, activity logs and abuse prevention. Basis: our legitimate interest in protecting workspaces from unauthorised access.
  • To contact you — service notices, invitations and password resets. Basis: performance of contract. Marketing email is separate and goes only to people who asked for it; every such message carries a one-click unsubscribe.

We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.

5.Who else processes your data

We use a small number of established providers. Each is bound by contract to process data only on our instructions.

ProviderPurposeLocation
VercelApplication hosting and content deliveryUSA / global edge
NeonManaged PostgreSQL databaseFrankfurt, Germany (eu-central-1)
ResendTransactional and marketing email deliveryEuropean Union
PaystackSubscription billing and payment processingNigeria / Ghana
GoogleOptional 'Sign in with Google' authenticationUSA / global

Your workspace database is hosted in Frankfurt, Germany. Because some providers operate outside Ghana and the European Economic Area, transfers rely on the providers' standard contractual clauses and equivalent safeguards.

6.How your data is separated and secured

  • Every workspace is isolated. One business cannot see another's clients, jobs, invoices or messages.
  • Within a business, access is granted per person and per module. An owner can give a worker access to jobs and stock while keeping payments, profit and reports private.
  • A client signing into the portal sees only their own jobs, quotes, invoices and messages.
  • Passwords are stored as salted hashes and are never recoverable in readable form — not even by us.
  • All traffic runs over HTTPS, and the database is encrypted at rest.
  • There is no public sign-up. An account can only be created where a valid, unexpired invitation exists for that exact email address.

No system is perfectly secure, but if a breach affects your personal data we will notify you and the Data Protection Commission without undue delay.

7.How long we keep it

  • Workspace data is kept for as long as the business holds an active subscription.
  • After cancellation, workspace data is retained for 90 days so the account can be revived, then permanently deleted.
  • Financial and tax records are kept for six years, as Ghanaian law requires.
  • Sign-in and activity logs are kept for 12 months.
  • Access-request enquiries from the marketing site are deleted within 12 months if they do not become accounts.

8.Your rights

Under Ghana's Data Protection Act, 2012 (Act 843) — and, where it applies to you, the GDPR — you may:

  • Ask for a copy of the personal data we hold about you.
  • Have inaccurate details corrected.
  • Ask for your data to be deleted, where we have no legal obligation to keep it.
  • Object to processing based on our legitimate interests.
  • Ask us to export your data in a portable, machine-readable format.
  • Withdraw consent to marketing at any time, without affecting the service you receive.

Write to privacy@fabrimanager.com and we will respond within 30 days. If you are unsatisfied with our response, you may complain to the Data Protection Commission of Ghana at dataprotection.org.gh.

9.Cookies

We use cookies only to keep you signed in and to remember your light or dark theme preference. There are no advertising cookies, no third-party trackers, and no cross-site profiling — which is why you are not being asked to dismiss a consent banner.

10.Children

Fabri Manageris a tool for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child's data has reached us, tell us and we will remove it.

11.Changes to this policy

If we change this policy in a way that materially affects you, we will email every account owner at least 14 days before the change takes effect. The date at the top always reflects the current version.

Still have a question?

A real person answers. See the contact page for every way to reach us, or read the terms of service.