Privacy Policy
Handro · Version 1.1 · Effective date: August 16, 2026
Changelog — v1.1 (August 16, 2026): removed a sentence identifying the operating legal entity by its corporate name. No other rights, obligations, or defined terms changed; "we"/"us"/"our"/"Handro" continue to refer to the same operating company, and the Privacy Officer contact (info@handro.ca, Section 16) is unchanged. v1.0 is superseded.
Plain-language summary (not a substitute for the policy)
- We're a tool your service company uses. If a plumbing, HVAC, or electrical business manages you as their customer in Handro, that business — not us — decides why your information is collected. We store and process it for them. Contact them first about your data; we'll help them respond.
- What we collect about account holders: name, email, a hashed password, your organization's details, and what you put into the app.
- We don't sell anyone's data, run ads, or use ad trackers. One essential login cookie. No analytics trackers today.
- Your data lives on servers in the United States (and with the providers listed below — hosting, database, payments, email, error monitoring).
- Export is free and built in. Businesses can download all their data as CSV/JSON any time. For deletion, email us — it's a manual process today, and we delete on request.
- Payments are handled by Stripe. Card numbers go to Stripe, never to our database.
- Questions or requests: info@handro.ca. We answer within 30 days.
This policy explains how Handro ("we", "us", "our") handles personal information in connection with our field-service management software (the "Service") and its websites. It covers three groups:
| You are… | Meaning | Sections most relevant |
|---|---|---|
| An Organization user | You or your employer signed up for the Service (owner, admin, or staff) | All |
| An End Customer | A business that uses the Service manages you as their customer (bookings, estimates, jobs, payments) | 2, 3B, 9–11 |
| A visitor | You browse our public pages | 3C, 5 |
1. Who is responsible for your information
For Organization users and visitors, Handro decides how and why personal information is processed — we are the organization responsible (the "controller").
For End Customer information, the Organization that serves you is responsible. It collects your details to run its business; we process them on that Organization's behalf as a service provider (a "processor"), under contract terms that limit our use to providing the Service. If you are an End Customer, please direct questions and requests about your information to the business that serves you — Section 11 explains how we help.
Accountability (PIPEDA / Quebec Law 25). The person in charge of personal information at Handro is our Privacy Officer, reachable at info@handro.ca.
2. What we collect
A. From Organization users
| Category | Details | Source |
|---|---|---|
| Account data | Name, email address, password (stored only as a salted hash), role | You, at signup or via invitation |
| Organization data | Business name, contact details, service types, price book, logo/branding if provided | You |
| Stripe onboarding | We store your Stripe account identifier and onboarding status; identity and banking details you give Stripe go to Stripe, not us | You → Stripe |
| Usage/technical | Log and error data: IP address, browser/device metadata, pages and actions that triggered an error | Automatic (see Sentry, Section 6) |
B. About End Customers (processed for your service company)
| Category | Details | Source |
|---|---|---|
| Contact records | Name, email, phone, service address, notes | The Organization, or you via its public booking form |
| Booking requests | Requested service, preferred date, notes you type | You, via the booking form |
| Job & estimate records | Work descriptions, statuses, line items, approval/decline of estimates via a private link | The Organization; your actions on estimate links |
| Payment records | Amounts, payment status, Stripe transaction identifiers. Card numbers are entered on Stripe-hosted pages and never touch our database. | Stripe |
| Anti-abuse data | The booking form logs the requesting IP address briefly to rate-limit submissions and uses a hidden honeypot field to reject bots | Automatic |
We ask Organizations not to enter special categories of data (health details, government IDs, card numbers) into notes or other free-text fields; the Service is not designed for them.
C. From visitors
Our public pages set no tracking cookies and run no analytics or advertising trackers. Standard web logs at our hosting providers (IP address, user agent, timestamp) are used for security and operations. If you submit a booking form, Section 2B applies.
3. What we use personal information for
- Providing the Service — accounts, tenancy, scheduling, customers, jobs, estimates, memberships, payments, exports.
- Transactional messages — booking confirmations and notifications, estimate links, receipts, and appointment reminders, sent through our email provider on the relevant Organization's behalf. These are not marketing.
- Security and abuse prevention — authentication, tenant isolation, rate limiting, honeypots, investigating incidents.
- Reliability — monitoring errors and fixing bugs.
- Legal — complying with law, enforcing our Terms, establishing or defending claims.
What we do not do: we do not sell or rent personal information; we do not share it for cross-context behavioral advertising; we run no advertising and no profiling that produces legal or similarly significant effects; we do not use Customer Data to train AI models. If any of this ever changes, this policy will change first, with notice (Section 13).
For Canadians: our legal grounding under PIPEDA is your consent (given when you sign up or submit a form, and implied for purposes a reasonable person would consider obvious and appropriate, such as processing a booking you submitted), plus our legitimate business need to secure and operate the Service. You may withdraw consent (Section 11), subject to legal or contractual limits — some withdrawals mean we can no longer provide the Service.
4. Cookies
One cookie. It is essential, so no consent banner is shown.
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| Auth.js session token (JWT) | Keeps you signed in; protects your session | Essential, first-party | Session / 30 days |
No analytics cookies, no advertising cookies, no third-party cookies. If we ever add analytics, we will update this section before doing so.
5. Estimate links — a note on token URLs
Estimates are shared through links containing a long random token. The page shows the estimate's contents (names, addresses, line items, prices) to anyone who has the link. We do not index these pages, and tokens are unguessable, but a forwarded link is a forwarded document — Organizations and End Customers should share estimate links only with people who should see them.
6. Who we share personal information with (subprocessors)
We share personal information only with the service providers that run the Service ("subprocessors"), under contracts limiting their use of it:
| Provider | What it does | What it touches | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting and delivery | All data in transit; web logs | United States |
| Supabase, Inc. (on Amazon Web Services) | PostgreSQL database | All stored Service data | United States (AWS us-west-2, Oregon) |
| Stripe, Inc. / Stripe Payments Canada, Ltd. | Payment processing and Connect onboarding | Payment and identity data you or your customers give Stripe; transaction metadata | United States / global |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Recipient addresses and message contents (bookings, estimates, receipts, reminders) | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | Error events, which may include IP address and browser/device metadata | United States |
| Cloudflare, Inc. | DNS and network edge | Traffic metadata | United States / global |
We also disclose personal information if required by law or legal process (we will notify the affected Organization where lawful), to protect rights and safety, or as part of a merger, financing, or sale of Handro or the Service — in which case this policy continues to apply to the transferred data and we will give notice of any change in responsibility. A current version of this subprocessor list will be maintained at gethandro.com/legal/subprocessors; we will give Organizations advance notice by email before adding a subprocessor that handles Customer Data.
7. Where your information is stored (cross-border transfers)
The Service's data is stored in the United States (AWS us-west-2, Oregon), and our subprocessors process data in the United States. If you are in Canada, your personal information leaves Canada and is subject to US law, including lawful access by US authorities, while stored there. We use contractual and technical safeguards (Section 8) regardless of where data sits.
Quebec residents: personal information about you is communicated outside Quebec (to the United States) for the storage and processing described above.
8. Security
- Encryption in transit (TLS) everywhere; encryption at rest by our database provider.
- Tenant isolation enforced in the database itself — PostgreSQL row-level security on every tenant table, so one Organization's queries cannot reach another's rows.
- Passwords stored only as salted hashes; sessions via signed tokens.
- Role-based access (owner/admin/staff) inside each Organization; least-privilege database roles on our side.
- Rate limiting and honeypots on public forms; error monitoring for anomalies.
No system is perfectly secure; Section 10 describes what happens if safeguards fail.
9. How long we keep information
| Data | Retention |
|---|---|
| Account and Organization data, Customer Data | For the life of the Organization's account; deleted on request — see below (Terms of Service, s. 12.5) |
| Error events (Sentry) | Our error-monitoring provider's standard retention period |
| Email delivery logs (Resend) | Our email provider's standard log-retention period |
| Backups | Rolling database backups; deleted data ages out on our database provider's normal backup-rotation schedule |
| Breach records | Minimum 24 months (PIPEDA requirement), longer if needed for legal claims |
| Legal/financial records | As required by tax and corporate law |
Organizations control the records inside their tenant and may correct or delete individual records (for example an End Customer's file) at any time in the app; deletions propagate to backups on the rotation above.
Account-level deletion is on request. When an Organization's account is terminated, or when someone asks us to delete their personal information under Section 11, we delete it. Today that is a manual process we complete within a reasonable time, ordinarily within 30 days of the request, rather than an automated pipeline.
10. If something goes wrong (breach notification)
If a breach of security safeguards involving personal information creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as PIPEDA requires (and the Commission d'accès à l'information for Quebec residents, per Law 25). We keep records of all breaches for at least 24 months. Where the affected data is Customer Data, we will notify the affected Organization without undue delay so it can meet its own obligations to its customers, and we will cooperate with its response. US state breach statutes are addressed through the same process.
11. Your rights and choices
We honor these rights for everyone — Organization users, End Customers, and visitors — regardless of where you live, even where no statute requires it:
- Access / know: get confirmation we hold personal information about you, a copy of it, and an account of how it's used and to whom it's been disclosed.
- Correction: fix inaccurate or incomplete information.
- Deletion: ask us to delete your personal information.
- Portability: receive your information in a structured, machine-readable format (Organizations: the built-in CSV/JSON export answers this instantly, free, any time).
- Withdraw consent (Canada), subject to legal/contractual limits.
- No discrimination for exercising rights.
How to exercise them: email info@handro.ca from the address associated with your information (or with enough detail for us to verify you — we verify to protect you, and we may decline requests we cannot verify). We respond within 30 days. If we refuse a request, we will say why and what law permits the refusal, and you may complain to us, to the Office of the Privacy Commissioner of Canada, to the Commission d'accès à l'information du Québec (Quebec residents), or to your state attorney general (US residents). If a future state-law obligation applies to a request we deny, you may appeal by replying to our decision; we will answer the appeal within 45 days.
If you are an End Customer, the business that serves you controls your records, so we will refer your request to that Organization and help it respond (its staff can view, correct, export, or delete your records in the app). If the Organization is unreachable or no longer exists, we will handle your request directly.
Authorized agents may submit requests with proof of authority.
12. Email: what we send today, and marketing later
Today, transactional only: booking confirmations and notifications, estimate links, payment receipts, and appointment reminders — messages required to deliver the Service, triggered by you or the Organization serving you. These are sent even without marketing consent because the Service doesn't work without them; each identifies the business it concerns.
Marketing, when it starts (none is sent today): we will follow CASL — express, opt-in consent collected separately (never a pre-checked box), sender identification (including a mailing address), and a working unsubscribe honored within 10 business days — and CAN-SPAM for US recipients (accurate headers, physical address, functioning opt-out). Consent records will be retained. Organizations that use the Service to contact their customers are responsible for their own compliance with these laws (Terms of Service, s. 7).
13. Children
The Service is business software and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or the age your local law protects). If you believe a child's information has been submitted, contact us and we will delete it.
14. Do Not Track and Global Privacy Control
We do not track visitors across sites, sell data, or share it for targeted advertising, so there is nothing for a Do Not Track or Global Privacy Control (GPC) signal to opt you out of. We treat GPC-enabled browsers the same as everyone else: no sale, no sharing, no ad tracking.
15. Changes to this policy
We may update this policy as the Service evolves. Material changes (a new data category, a new subprocessor handling Customer Data, a new purpose) take effect no sooner than 30 days after we email account owners and post an in-app notice; non-material clarifications take effect on posting. Every version is dated and archived, and the changelog at the top of this document records what changed.
16. Contact
Handro Person in charge of personal information / Privacy Officer · info@handro.ca
Complaints: we investigate every complaint. Unresolved concerns can go to the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Commission d'accès à l'information du Québec (Quebec), or your state attorney general (US).