✦ Notice

This privacy policy is a product draft and must be reviewed by qualified legal counsel before production use.

Privacy Policy

Effective Date: [Effective Date]
Last Updated: [Last Updated Date]

1. Information We Collect

We collect information you provide directly to us when setting up an account, updating your profile, submitting a contact request, or configuring workspace components. This may include your name, email address, company name, and role description.

2. How We Use Information

We use collected information to run and secure the Handoff workspace, facilitate team coordination, manage notifications, validate account privileges, and respond to sales or support inquiries.

3. Organization and Workspace Data

Organization data, projects, tasks, comments, and attachments are scoped strictly to the respective organization. We do not inspect or leverage this operational data outside of providing workspace services.

4. Authentication and Account Information

Account creation and authentication are handled securely via cryptographic tokens. Your password is never stored in plain or reversible form — it is one-way hashed (bcrypt) before it touches our database, so even we cannot see or recover it. Password resets use a short-lived, single-use signed link sent to your verified email address. Repeated failed sign-in attempts against an account are automatically throttled.

5. Cookies and Session Data

We use security and session cookies to verify your identity, retain user preferences, and prevent cross-site request forgery. Essential cookies cannot be disabled.

6. AI Features and Workspace Data

When AI features are enabled, Handoff processes only authorized workspace data required to provide the requested feature. AI access is permission-controlled and organization-scoped.

7. Data Sharing and Service Providers

We do not sell customer or workspace data. We share data only with trusted infrastructure providers (e.g., host systems, database providers) required to run the Handoff software.

8. Data Retention

We retain account and operational workspace data only as long as your workspace account is active or as necessary to comply with security requirements.

9. Security Measures

We implement access control lists, row-level security (RLS), and rate limiting (including account-level lockout on repeated failed logins and a dedicated stricter limit on AI usage) to prevent unauthorized database read/write access. Connected third-party integration credentials (e.g. GitHub access tokens) are encrypted at rest (AES-256-GCM) and are never readable through normal application queries. All traffic is served over HTTPS with a strict Content Security Policy and standard hardening headers (HSTS, X-Frame-Options, X-Content-Type-Options).

10. Your Rights and Choices

You may request access to, correction of, or deletion of your personal account information by contacting the workspace administrator or reaching out directly.

11. International Data Transfers

Data is transferred and processed in locations where our server infrastructure resides. By using our service, you acknowledge this data transfer.

12. Changes to This Policy

We update this privacy policy draft as new features or operational requirements are implemented. We will update the effective date accordingly.

13. Contact Information

For questions regarding this draft policy, please contact:

Company: [Legal Company Name]
Address: [Legal Address]
Email: [Privacy Contact Email]