Handsom logo

Privacy Policy

Last updated: 17 July 2026 · Draft revision — pending legal review.

This Privacy Policy explains how HANDSOM LTD (company number NI733489), trading as Handsom ("Handsom", "we", "us"), collects, uses, shares, and protects personal data. Handsom is a customer-support tool for merchants: it investigates a support case across a merchant's connected systems (such as their store and helpdesk) and produces a research brief with a recommended action for the merchant's human support agent.

We are the controller of the account, billing, and usage data described in Sections 1.1, 1.2, 1.4 and 1.5. For the personal data we process on behalf of a merchant to provide that service (Section 1.3) — such as the merchant's order and support-ticket data — the merchant is the controller and Handsom acts as processor under our Data Processing Agreement. Our registered address is 18 The Baths Ormeau Avenue, Belfast, United Kingdom, BT2 8HS. You can contact us about privacy matters at [email protected].

Note: If you are a customer of a merchant that uses Handsom (rather than a direct Handsom account holder), the merchant is the controller of your personal data and Handsom processes it on the merchant's behalf. Please contact the merchant directly to exercise your rights; we will assist them as their processor.


1. What Personal Data We Collect

1.1 Account and identity data

When you register for a Handsom account we collect:

  • Name and email address
  • Password (stored as a secure hash — we never store your password in plain text)
  • Profile information you choose to provide
  • Billing name and address for paid subscriptions

1.2 Usage and technical data

When you use the platform we automatically collect:

  • Log data: IP address, browser type and version, pages visited, timestamps, referring URLs
  • Device data: operating system, screen resolution, language settings
  • Session data: how you interact with the Handsom application and its features
  • Performance data: response times, errors, and crash reports (via PostHog)

1.3 Data we process on behalf of merchants (as processor)

When a merchant connects their commerce platform (e.g. Shopify) and helpdesk (e.g. Gorgias, Zendesk, Intercom), Handsom reads data from those systems — on the merchant's instruction — to investigate a support case and produce a research brief for the merchant's human support agent. For this data the merchant is the controller and Handsom is the processor, governed by our Data Processing Agreement. It may include:

  • Commerce data: order details (status, totals, fulfillment, tracking, line items, tags, notes, risk signals), refunds, returns, products, and customer value signals (order counts, amount spent, tags). On Shopify, Handsom operates at Protected Customer Data Level 1 and does not request or store the customer's name, email address, phone number, or postal address.
  • Helpdesk data: support ticket content and the customer identity the merchant already holds in their helpdesk (which may include name and email), to the extent the merchant connects those systems and they are needed to build the brief.
  • Integration credentials: API keys and access tokens you provide to connect these systems (see Section 6), stored encrypted.

We do not contact the merchant's customers, and we do not use this data to make automated decisions about them — Handsom produces a recommendation for a human agent to review.

1.4 Payment data

Payment card details are collected and processed directly by Stripe. We receive only a tokenised reference and limited billing details (last four digits, card type, billing address). We do not store full card numbers.

1.5 Communications data

We collect and retain communications you send to us, including support requests, feedback, and email correspondence.


2. How and Why We Use Your Data

The table below summarises our processing activities, the legal basis for each, and how long we retain the data.

Category of dataPurposeLegal basisRetentionThird parties
Account data (name, email, password hash)Creating and managing your account; authenticationContract performance (Art. 6(1)(b) UK GDPR)Duration of account + 90 days after closureAuth provider (Better Auth)
Billing dataProcessing subscription payments; invoicingContract performance (Art. 6(1)(b))7 years (tax/accounting obligations)Stripe
Usage and log dataPlatform security; fraud prevention; service improvementLegitimate interests (Art. 6(1)(f))12 monthsPostHog (product analytics, session replay, error tracking); infrastructure providers
Merchant commerce & helpdesk data (as processor)Investigating support cases and producing briefs, on the merchant's instructionProcessed for the merchant (controller) under the DPA; the merchant's legal basis appliesLife of the merchant's connection; deleted within 30 days of disconnection/uninstallAWS (EU eu-west-1: hosting, database, storage); Atlas Cloud (AI inference — no training, ≤ 7-day retention)
Credentials/API keysEnabling third-party integrations you configureContract performance (Art. 6(1)(b))Until you remove them or close your accountEncrypted at rest; not shared
Support communicationsResponding to enquiries; improving support qualityLegitimate interests (Art. 6(1)(f))3 yearsInternal only
Aggregated anonymised usage dataPlatform analytics and product developmentLegitimate interests (Art. 6(1)(f))Indefinite (not personal data once anonymised)Internal only

3. Cookies and Tracking

We use cookies and similar technologies to operate the platform, remember your preferences, and understand how the platform is used. You can manage cookie preferences through your browser settings or our cookie banner.

TypeName / providerPurpose
EssentialSession cookieKeeps you logged in; required for the platform to function
EssentialCSRF tokenSecurity: prevents cross-site request forgery attacks
EssentialConsent cookieStores your cookie banner choice so we do not re-prompt you
AnalyticsPostHog (EU)Product analytics, session replay, and error tracking; only active if you accept on the cookie banner

4. Sharing Your Data

We do not sell your personal data. We share data only in the following circumstances:

4.1 Infrastructure and service providers

We share data with the following sub-processors who provide infrastructure to operate the platform:

ProviderLocationPurpose
Amazon Web ServicesEU (eu-west-1)All application hosting and infrastructure: application servers (ECS Fargate), managed PostgreSQL database (Aurora), file storage (S3), content delivery (CloudFront CDN), load balancing, messaging (SQS), secrets management, and logging. All data is stored in the EU.
OpenRouterUSAAI model routing for the optional memory feature; routes to underlying model providers only when that feature is enabled
GoogleUSA / GlobalOAuth sign-in for users who choose to sign in with Google
Atlas CloudUSAAI inference provider (self-hosted DeepSeek models) used to investigate customer-support cases; does not train on content; content retained ≤ 7 days
PostHogEU (eu.i.posthog.com, Frankfurt)Product analytics, session replay, and error tracking
StripeUSAPayment processing and subscription management
ResendUSATransactional email delivery
Better AuthSelf-hosted on AWS (eu-west-1)Authentication and session management

4.2 Legal disclosures

We may disclose personal data to law enforcement, regulatory authorities, or courts where required by applicable law or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Handsom, our users, or others.

4.3 Business transfers

If Handsom is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.


5. International Transfers

Our core infrastructure and data storage are located in the European Union (Amazon Web Services, eu-west-1). Some sub-processors — for example, our AI inference, payment, and transactional-email providers — are based in the United States. Where we transfer personal data outside the UK or EEA, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (the UK IDTA) or the European Commission, or we rely on the adequacy decisions where applicable.

A list of our sub-processors and the transfer mechanisms in place is available on request at [email protected].


6. Credentials and API Keys

When you connect a third-party service (such as your store, helpdesk, Stripe, or email provider), the API keys, tokens, and secrets you provide are:

  • Encrypted at rest using industry-standard encryption (AES-256-GCM)
  • Handled at the platform infrastructure layer and not exposed to the AI agent or to other users
  • Used only to call the connected services on your instruction — to investigate support cases and build briefs
  • Never used for any purpose other than providing the Services to you

You are responsible for ensuring that credentials you provide are scoped appropriately (minimum required permissions) and are rotated regularly.


7. Data Retention

We retain your personal data only for as long as necessary to provide the platform services and to comply with our legal obligations. The key retention periods are:

  • Account data: retained for the duration of your account, plus 90 days after closure to allow data export
  • Billing records: retained for 7 years to comply with tax and accounting obligations
  • Usage logs and error data: retained for 12 months
  • Support communications: retained for 3 years
  • Merchant commerce and helpdesk data processed on the merchant's behalf (Section 1.3): retained for the life of the merchant's connection and deleted within 30 days of disconnection or uninstall (see the Data Processing Agreement)
  • Anonymised, aggregated usage data: retained indefinitely (this is not personal data)

After the applicable retention period, your data is securely deleted or irreversibly anonymised.


8. Your Rights

Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:

RightWhat it means
AccessYou can request a copy of the personal data we hold about you.
RectificationYou can ask us to correct inaccurate or incomplete personal data.
ErasureYou can ask us to delete your personal data in certain circumstances, including where it is no longer necessary for the purpose for which it was collected.
RestrictionYou can ask us to restrict processing of your personal data in certain circumstances, such as while we investigate an accuracy dispute.
PortabilityYou can request your personal data in a structured, machine-readable format for transfer to another service.
ObjectionYou can object to processing based on legitimate interests. We will stop processing unless we have compelling legitimate grounds that override your interests.
Withdraw consentWhere processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at [email protected]. We will respond within one month. We may need to verify your identity before processing your request. You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data lawfully.


9. Children

The platform is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will delete that data promptly. Please contact us at [email protected] if you believe we may have collected data from a child under 13.


10. Security

We implement technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These include:

  • Encryption of data in transit (TLS) and at rest
  • Access controls limiting staff access to personal data on a need-to-know basis
  • Secure credential handling through platform infrastructure (credentials are not exposed to AI agents)
  • Error monitoring and alerting via PostHog (EU-hosted)
  • Regular security reviews of our infrastructure and third-party integrations

No security measure is absolute. In the event of a personal data breach, we will notify affected users and the ICO as required by the UK GDPR (within 72 hours of becoming aware of the breach where required).


11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the platform at least 14 days before the changes take effect. The current version is always available at handsom.ai/privacy-policy.


12. Contact Us

For any questions about this Privacy Policy or to exercise your rights, contact us at:

HANDSOM LTD (trading as Handsom) Company number: NI733489 18 The Baths Ormeau Avenue, Belfast, United Kingdom, BT2 8HS Privacy enquiries: [email protected] Website: handsom.ai