1. Information We Collect
We collect information you provide directly to us when setting up an account, updating your profile, submitting a contact request, or configuring workspace components. This may include your name, email address, company name, and role description.
2. How We Use Information
We use collected information to run and secure the Handoff workspace, facilitate team coordination, manage notifications, validate account privileges, and respond to sales or support inquiries.
3. Organization and Workspace Data
Organization data, projects, tasks, comments, and attachments are scoped strictly to the respective organization. We do not inspect or leverage this operational data outside of providing workspace services.
4. Authentication and Account Information
Account creation and authentication are handled securely via cryptographic tokens. Your password is never stored in plain or reversible form — it is one-way hashed (bcrypt) before it touches our database, so even we cannot see or recover it. Password resets use a short-lived, single-use signed link sent to your verified email address. Repeated failed sign-in attempts against an account are automatically throttled.
5. Cookies and Session Data
We use security and session cookies to verify your identity, retain user preferences, and prevent cross-site request forgery. Essential cookies cannot be disabled.
6. AI Features and Workspace Data
When AI features are enabled, Handoff processes only authorized workspace data required to provide the requested feature. AI access is permission-controlled and organization-scoped.
7. Data Sharing and Service Providers
We do not sell customer or workspace data. We share data only with trusted infrastructure providers (e.g., host systems, database providers) required to run the Handoff software.
8. Data Retention
We retain account and operational workspace data only as long as your workspace account is active or as necessary to comply with security requirements.
9. Security Measures
We implement access control lists, row-level security (RLS), and rate limiting (including account-level lockout on repeated failed logins and a dedicated stricter limit on AI usage) to prevent unauthorized database read/write access. Connected third-party integration credentials (e.g. GitHub access tokens) are encrypted at rest (AES-256-GCM) and are never readable through normal application queries. All traffic is served over HTTPS with a strict Content Security Policy and standard hardening headers (HSTS, X-Frame-Options, X-Content-Type-Options).
10. Your Rights and Choices
You may request access to, correction of, or deletion of your personal account information by contacting the workspace administrator or reaching out directly.
11. International Data Transfers
Data is transferred and processed in locations where our server infrastructure resides. By using our service, you acknowledge this data transfer.
12. Changes to This Policy
We update this privacy policy draft as new features or operational requirements are implemented. We will update the effective date accordingly.
13. Contact Information
For questions regarding this draft policy, please contact: