Privacy policy

Last updated July 24, 2026

Who this policy covers

Handit is a business collaboration service operated by Handit LLC. This policy covers the Handit website, product, demo-request forms, browser extension, connected integrations, support, and business outreach. It applies to site visitors, prospects, customers, workspace members, and people whose business contact details we use to introduce Handit.

Our role and your organization’s role

A customer organization generally controls the asks, attachments, messages, and other content its people submit to a Handit workspace. For that content, Handit acts as a processor or service provider on the organization's instructions. The organization is responsible for telling its people how it uses the workspace and for handling requests about company content.

Handit acts independently as a controller or business for website, account-administration, demo, sales, support, security, and service- operations information. If you are unsure which role applies, contact us and we will help route your request.

Information we collect

  • Identity and access. Name, verified work email, profile image, organization membership, role, function label, invitation details, and authentication identifiers. Clerk handles sign-in; Handit does not receive or store your password.
  • Workspace content. Ask text, requester and owner, due dates, status history, clarification notes, attachments, links, source labels, and timestamps needed to create and close a handoff.
  • Demo and support. Name, email, company or team, availability or notes entered in a demo request, and messages you send us. Demo-request details are stored in Handit and sent to the operator through Resend so we can reply.
  • Business outreach. A prospect's name, job title, business email, employer, source, campaign and reply history, and—when enabled—delivery, open, or link activity. We may obtain these details from the person directly, referrals, public company sites, professional or business networks, public sources, or business-data providers. Instantly helps us manage outreach and opt-outs.
  • Operational data. Authentication and security events, browser or device information, IP-derived information recorded by our providers, error reports, email delivery, bounce, complaint, failure, and suppression events, and content-free activation milestones such as whether a workspace created or completed its first ask.

Workplace and email capture

If an organization enables Slack, Handit receives the Slack workspace and user identifiers needed to map the workspace, the invoking person's work email, the selected owner's email, channel name, message text used for the ask, and a message permalink when available. Handit does not import a workspace's general Slack history.

If an organization enables Microsoft Teams, Handit receives the Entra tenant, Teams user, and conversation identifiers needed to connect the tenant and deliver cards, the invoking person's verified work email and display name, and the selected Teams message text and link used to create an ask. Handit does not import general Teams chat history, mail, SharePoint files, or a Microsoft directory.

If a member forwards an email to Handit, we process the sender address, subject, the instruction written above the forward, and a bounded excerpt of the forwarded sender, subject, and opening text—rather than storing the entire forwarded mailbox message as the ask. Resend, or an enabled inbound-mail provider such as Postmark, transports that message.

Chrome extension data

The Handit extension reads the active page URL and title when you explicitly open its side panel. If you choose the Handit context-menu action, it may also capture the selected text or link you invoked it on. Selection text is limited to 1,200 characters and the page title to 160 characters. The capture is stored in Chrome's local extension storage until it is overwritten or you clear extension data. It is sent to Handit only when you submit an ask, where it becomes that ask's source context.

The extension uses access to Clerk authentication cookies only to share your signed-in session with Handit. It has no content script, does not scan pages in the background, does not collect general browsing history, and does not use captured page data for advertising or unrelated profiling.

Cookies and local storage

Handit and Clerk use essential browser storage and cookies for sign-in, security, and session continuity. Handit also stores your theme choice, and a short list of recent recipient identifiers for ranking. Handit does not currently use advertising cookies or a third-party behavioral analytics service. Blocking essential storage may prevent sign-in or product features from working.

Why we use information

We use the information described above to:

  • provide, authenticate, secure, and support the service;
  • create asks, enforce workspace permissions, and deliver notifications;
  • operate user-enabled Slack, Teams, email, and browser-extension features;
  • respond to demo requests, support questions, and privacy requests;
  • diagnose failures, prevent abuse, and improve reliability; and
  • introduce Handit to relevant business contacts and honor opt-outs.

Where privacy law requires a legal basis, we rely on performance of a contract, legitimate interests in operating and responsibly introducing a business service, consent for optional features where required, and compliance with legal obligations. You can object to direct marketing at any time.

Business outreach choices

We limit outreach to business purposes and assess whether the recipient and message are permitted under applicable direct-marketing rules. Where consent is required, we will not send without it. Each campaign message identifies Handit and provides a way to opt out. You can also reply with “unsubscribe” or email hello@handit.to. We keep the minimum address and suppression record needed to make sure we do not contact you again.

When people at Handit may access content

We do not routinely read workspace content. Access is limited to the minimum necessary when you ask for support or authorize access, an automated process fails and requires intervention, we investigate a security or abuse issue, or law requires it. Anyone authorized to access production data must keep it confidential and use it only for that limited purpose.

Service providers and disclosure

We disclose information to providers that help operate Handit, only for the relevant service, and to connected services at your organization's direction. Our current provider list and purposes are on the subprocessors page. We may also disclose the minimum necessary to comply with valid legal process, prevent harm, or complete a business transfer subject to this policy or advance notice where practicable.

We do not sell personal information, share it for cross-context behavioral advertising, use workspace content for targeted advertising, or use customer content to train machine-learning models. We do not use a customer's name, logo, or testimonial in marketing without permission.

Retention and deletion

  • Account and workspace content is retained while the workspace is active. After a verified workspace-closure request, content becomes inaccessible and is scheduled for deletion from active systems within 30 days and from rotating backups ordinarily within 90 days.
  • Demo-request and prospect records are retained while a conversation is active and normally for no more than 24 months after the last meaningful interaction, unless a longer period is required for a contract, legal obligation, or dispute.
  • A minimal marketing-suppression record may be kept as long as needed to honor an opt-out. Delivery, error, security, and activation records are kept only as long as needed to operate, troubleshoot, protect, and audit the service, then deleted or aggregated.
  • Local extension captures remain on the device until overwritten or cleared. Deleting browser data is controlled through your browser.

We may preserve limited information when law requires it, to protect the service, or to resolve a dispute. Backups are isolated from ordinary use and are not restored except for disaster recovery.

International processing

Handit and its primary providers process data in the United States and other places where the providers operate. When applicable law requires a transfer mechanism, we use recognized safeguards such as adequacy decisions or contractual protections, including provider standard contractual clauses where available. Organizations that need a DPA or transfer details can contact hello@handit.to before using Handit for regulated production data.

Your privacy rights

Depending on where you live, you may have rights to know, access, correct, delete, restrict, object to, or receive a portable copy of personal data; withdraw consent; opt out of marketing; appeal a denied request; and make a complaint to a privacy regulator. We do not discriminate against people for exercising privacy rights and do not use solely automated decisions that produce legal or similarly significant effects.

Start with your workspace admin for requests about company-controlled workspace content. For information Handit controls, email hello@handit.to. We may verify your identity and authority before acting. An authorized agent may submit a request with written permission; we may confirm the request directly with you. If we deny a request, you may ask us to review the decision. EU and UK residents may also complain to their local data protection authority.

Children

Handit is a workplace product for people who can enter a business agreement. It is not directed to children under 18, and we do not knowingly collect their personal information.

Changes and contact

We will update the date above when this policy changes. For a material change, we will provide reasonable notice by email, in the service, or on the website before the change takes effect when practicable. Privacy questions and requests can be sent to hello@handit.to.