
Last updated: 17 July 2026 · Draft revision — pending legal review.
This Privacy Policy explains how HANDSOM LTD (company number NI733489), trading as Handsom ("Handsom", "we", "us"), collects, uses, shares, and protects personal data. Handsom is a customer-support tool for merchants: it investigates a support case across a merchant's connected systems (such as their store and helpdesk) and produces a research brief with a recommended action for the merchant's human support agent.
We are the controller of the account, billing, and usage data described in Sections 1.1, 1.2, 1.4 and 1.5. For the personal data we process on behalf of a merchant to provide that service (Section 1.3) — such as the merchant's order and support-ticket data — the merchant is the controller and Handsom acts as processor under our Data Processing Agreement. Our registered address is 18 The Baths Ormeau Avenue, Belfast, United Kingdom, BT2 8HS. You can contact us about privacy matters at [email protected].
Note: If you are a customer of a merchant that uses Handsom (rather than a direct Handsom account holder), the merchant is the controller of your personal data and Handsom processes it on the merchant's behalf. Please contact the merchant directly to exercise your rights; we will assist them as their processor.
When you register for a Handsom account we collect:
When you use the platform we automatically collect:
When a merchant connects their commerce platform (e.g. Shopify) and helpdesk (e.g. Gorgias, Zendesk, Intercom), Handsom reads data from those systems — on the merchant's instruction — to investigate a support case and produce a research brief for the merchant's human support agent. For this data the merchant is the controller and Handsom is the processor, governed by our Data Processing Agreement. It may include:
We do not contact the merchant's customers, and we do not use this data to make automated decisions about them — Handsom produces a recommendation for a human agent to review.
Payment card details are collected and processed directly by Stripe. We receive only a tokenised reference and limited billing details (last four digits, card type, billing address). We do not store full card numbers.
We collect and retain communications you send to us, including support requests, feedback, and email correspondence.
The table below summarises our processing activities, the legal basis for each, and how long we retain the data.
| Category of data | Purpose | Legal basis | Retention | Third parties |
|---|---|---|---|---|
| Account data (name, email, password hash) | Creating and managing your account; authentication | Contract performance (Art. 6(1)(b) UK GDPR) | Duration of account + 90 days after closure | Auth provider (Better Auth) |
| Billing data | Processing subscription payments; invoicing | Contract performance (Art. 6(1)(b)) | 7 years (tax/accounting obligations) | Stripe |
| Usage and log data | Platform security; fraud prevention; service improvement | Legitimate interests (Art. 6(1)(f)) | 12 months | PostHog (product analytics, session replay, error tracking); infrastructure providers |
| Merchant commerce & helpdesk data (as processor) | Investigating support cases and producing briefs, on the merchant's instruction | Processed for the merchant (controller) under the DPA; the merchant's legal basis applies | Life of the merchant's connection; deleted within 30 days of disconnection/uninstall | AWS (EU eu-west-1: hosting, database, storage); Atlas Cloud (AI inference — no training, ≤ 7-day retention) |
| Credentials/API keys | Enabling third-party integrations you configure | Contract performance (Art. 6(1)(b)) | Until you remove them or close your account | Encrypted at rest; not shared |
| Support communications | Responding to enquiries; improving support quality | Legitimate interests (Art. 6(1)(f)) | 3 years | Internal only |
| Aggregated anonymised usage data | Platform analytics and product development | Legitimate interests (Art. 6(1)(f)) | Indefinite (not personal data once anonymised) | Internal only |
We use cookies and similar technologies to operate the platform, remember your preferences, and understand how the platform is used. You can manage cookie preferences through your browser settings or our cookie banner.
| Type | Name / provider | Purpose |
|---|---|---|
| Essential | Session cookie | Keeps you logged in; required for the platform to function |
| Essential | CSRF token | Security: prevents cross-site request forgery attacks |
| Essential | Consent cookie | Stores your cookie banner choice so we do not re-prompt you |
| Analytics | PostHog (EU) | Product analytics, session replay, and error tracking; only active if you accept on the cookie banner |
We do not sell your personal data. We share data only in the following circumstances:
We share data with the following sub-processors who provide infrastructure to operate the platform:
| Provider | Location | Purpose |
|---|---|---|
| Amazon Web Services | EU (eu-west-1) | All application hosting and infrastructure: application servers (ECS Fargate), managed PostgreSQL database (Aurora), file storage (S3), content delivery (CloudFront CDN), load balancing, messaging (SQS), secrets management, and logging. All data is stored in the EU. |
| OpenRouter | USA | AI model routing for the optional memory feature; routes to underlying model providers only when that feature is enabled |
| USA / Global | OAuth sign-in for users who choose to sign in with Google | |
| Atlas Cloud | USA | AI inference provider (self-hosted DeepSeek models) used to investigate customer-support cases; does not train on content; content retained ≤ 7 days |
| PostHog | EU (eu.i.posthog.com, Frankfurt) | Product analytics, session replay, and error tracking |
| Stripe | USA | Payment processing and subscription management |
| Resend | USA | Transactional email delivery |
| Better Auth | Self-hosted on AWS (eu-west-1) | Authentication and session management |
We may disclose personal data to law enforcement, regulatory authorities, or courts where required by applicable law or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Handsom, our users, or others.
If Handsom is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
Our core infrastructure and data storage are located in the European Union (Amazon Web Services, eu-west-1). Some sub-processors — for example, our AI inference, payment, and transactional-email providers — are based in the United States. Where we transfer personal data outside the UK or EEA, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (the UK IDTA) or the European Commission, or we rely on the adequacy decisions where applicable.
A list of our sub-processors and the transfer mechanisms in place is available on request at [email protected].
When you connect a third-party service (such as your store, helpdesk, Stripe, or email provider), the API keys, tokens, and secrets you provide are:
You are responsible for ensuring that credentials you provide are scoped appropriately (minimum required permissions) and are rotated regularly.
We retain your personal data only for as long as necessary to provide the platform services and to comply with our legal obligations. The key retention periods are:
After the applicable retention period, your data is securely deleted or irreversibly anonymised.
Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
| Right | What it means |
|---|---|
| Access | You can request a copy of the personal data we hold about you. |
| Rectification | You can ask us to correct inaccurate or incomplete personal data. |
| Erasure | You can ask us to delete your personal data in certain circumstances, including where it is no longer necessary for the purpose for which it was collected. |
| Restriction | You can ask us to restrict processing of your personal data in certain circumstances, such as while we investigate an accuracy dispute. |
| Portability | You can request your personal data in a structured, machine-readable format for transfer to another service. |
| Objection | You can object to processing based on legitimate interests. We will stop processing unless we have compelling legitimate grounds that override your interests. |
| Withdraw consent | Where processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. |
To exercise any of these rights, contact us at [email protected]. We will respond within one month. We may need to verify your identity before processing your request. You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data lawfully.
The platform is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will delete that data promptly. Please contact us at [email protected] if you believe we may have collected data from a child under 13.
We implement technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These include:
No security measure is absolute. In the event of a personal data breach, we will notify affected users and the ICO as required by the UK GDPR (within 72 hours of becoming aware of the breach where required).
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the platform at least 14 days before the changes take effect. The current version is always available at handsom.ai/privacy-policy.
For any questions about this Privacy Policy or to exercise your rights, contact us at:
HANDSOM LTD (trading as Handsom) Company number: NI733489 18 The Baths Ormeau Avenue, Belfast, United Kingdom, BT2 8HS Privacy enquiries: [email protected] Website: handsom.ai