Effective: July 20, 2026
One account, limited service dataAccount, security, payment-method summaries, receipts, and support records may be shared across the platform. Each service otherwise collects and uses only the data needed for its own job.
1. Privacy rules for every service
Information you provide
We collect account details such as name, email address, authentication records, service choices, support messages, and content you intentionally submit. Payment providers send us customer identifiers, transaction status, card brand, last four digits, and expiration; Handlebe does not receive or store full card numbers or CVV values.
Operational and security data
We process request times, device and browser details, network identifiers, session and API-key records, audit events, and error details needed to operate the platform, secure accounts, prevent abuse, enforce limits, and investigate failures. Secrets are stored only in protected or one-way forms where the feature permits.
How information is used
We use information to provide enabled services, authenticate users, process usage and billing, answer support, prevent fraud and abuse, maintain safety, improve reliability, and meet legal obligations. We do not move one service's private content into another service merely because both share an account.
When information is shared
Information may be shared with infrastructure, email, security, storage, and payment providers that process it for Handlebe; when you direct us to share it; during a lawful business transfer; or when reasonably necessary to comply with law or protect rights and safety. Providers receive only the information needed for their work.
Security and retention
We use administrative and technical safeguards, but no system can promise perfect security. Account deletion begins a 15-day recoverable period. Afterward, personal data is removed while billing records and anonymized security evidence may remain when required for legal, fraud-prevention, or accounting purposes.
2. Short Links data
Short Links stores the destination, public path, lifecycle state, safety decisions, plan snapshot, optional targeting rules, webhook configuration, subdomain, and reviewed content needed to publish and operate a route.
- Visits may record time, referrer, browser, operating system, coarse geography, and protected network evidence for safety and aggregate analytics.
- Exact city and coordinate data is removed after 30 days.
- Restricted raw IP data is removed after 90 days.
- Country, region, browser, operating system, timestamps, and irreversible visitor identifiers may remain as long-term aggregates.
- Destination safety checks may resolve hosts and send the minimum needed destination information to Google Cloud Web Risk.
5. New and future services
The platform-wide practices above apply to future services. Before a new service collects a materially different kind of content or uses it for a materially different purpose, its focused notice will explain that change. New services keep separate capabilities, usage records, and private content unless you deliberately connect them.
6. Your choices and rights
Depending on where you live, you may ask to access, correct, delete, restrict, object to, or receive a portable copy of personal information. Some records may be retained when law or fraud prevention requires it. The service is not intended for children under 13, and we remove a child's personal information when we learn it was collected without required consent.
Use the Support page and choose “Privacy request.” We may verify your identity before acting on an account request. We may update this policy as services change; the effective date above identifies the current version.