Privacy Policy
Last updated: 18 July 2026
Who is responsible
TheSquare is wholly owned and operated by Richmond Capital (Company Registration No. 120251031191, Zambia — www.richmond-afri.com). For the member data a lodge or district keeps in its portal, the lodge or district is the data controller — it decides whose details are recorded and why. Richmond Capital operates the platform as data processor, handling that data only on the tenant’s instructions and as described here. For the small amount of data we collect directly (contact form messages, billing contacts), Richmond Capital is the controller.
What is collected
Account data (name, email, optional phone and profile details); membership records a lodge keeps about its members — including masonic rank, offices held and key dates, which we treat with the sensitivity of the setting; content uploaded to a portal (documents, photographs, filings, dues records); and minimal technical logs (sign-in events, audit trail of administrative actions) kept for security and accountability. We collect the minimum needed to run each feature, and no advertising or cross-site tracking data at all.
Lawful basis and consent
Member records are processed under the tenant’s legitimate administration of its own membership, in line with the Data Protection Act No. 3 of 2021 of Zambia. Statutory filings carry their own consent declarations at the point of filing. Meeting attendance registers — the digital equivalent of the signature book — are kept by each lodge for its own governance and welfare; a governing district sees lodge totals only, with named figures limited to district officers whose appointment carries a duty of attendance. Meeting photographs, where attached, are stored as records only and are never processed for facial recognition. Where a portal displays a member’s contact details to fellow members, that visibility follows the tenant’s own decision as controller; members can ask their lodge secretary to correct or restrict their details at any time.
Where data lives
Data is stored with vetted sub-processors: Supabase (database, authentication and file storage — hosted in the EU), Vercel (application hosting and delivery), Resend (transactional email only — invitations, notifications, sign-in links) and Paddle (payment processing for annual subscriptions). Every lodge’s data is isolated at the database level with row-level security; documents and photographs live in private storage served through short-lived signed links to signed-in members only. Nothing in a portal is public.
Your rights
Under the Data Protection Act you may request access to the personal data held about you, correction of inaccuracies, erasure where retention is no longer justified, and objection to particular processing. Direct requests to your lodge secretary (the controller) in the first instance, or to us via the contact page and we will assist or forward as appropriate. Requests are answered within 30 days.
Retention and export
Data is retained while a tenant’s subscription is active. If a subscription lapses the portal becomes read-only and data is retained for at least 90 days, during which the tenant can export everything with the built-in export tool. Statutory filings are retained as immutable records for as long as the tenant keeps its portal, reflecting their role as the district’s register.
Security
Access is by invitation only; administrative actions are audit logged; administrators can enable two-factor authentication; transport is encrypted end-to-end; storage is encrypted at rest by our sub-processors. If a breach affecting personal data ever occurs we will notify affected tenants and the Data Protection Commissioner without undue delay, as the Act requires.
Cookies
TheSquare uses only the cookies needed to keep you signed in. There are no advertising cookies, no analytics trackers and no third-party marketing scripts anywhere on the platform.
Contact
Privacy questions and rights requests: onthesquare.app/contact. Postal correspondence may be addressed to Richmond Capital, Lusaka, Zambia.