Thanks @sticky-night-20812. Just so I understand how to do this:
1. Go to Roles. Create two roles, "User" (this already exists by default) and "Manager". No need to check the box of 'Can read/modify all data' (screenshot 1)
2. Go to Permissions. Click on 'Add permission' for the table
3. There, create a permission with the Manager role selected, and let them read, update, create records. Also tick the 'delete' box (screenshot 2)
4. Create another permission with the User role selected, and let them only read and update
5. Go to the profile page, and for the Edit button, in the 'Edit Conditions' select the Record is the current user's People Profile (screenshot 3)
6. On the profile page again, only make the Delete button visible to Managers (screenshot 4)
Is that correct?