Privacy Policy
HANDORA respects your privacy. This page explains what data we collect, why, where it goes, how long we keep it, and how you control it.
HANDORA is the controller of the personal data described in this policy. We don’t have a dedicated Data Protection Officer at this stage — for any data-protection request or question, contact privacy@myhandora.com and a real person will respond. We don’t sell or share personal data for cross-context behavioral advertising, so there’s no separate “Do Not Sell or Share My Personal Information” process — the rights in Section 5 cover you regardless of where you live.
1. What we collect
Account data
When you sign up we collect your email address, display name, and (if you sign up with Google) the basic profile fields Google sends us. We store this in Firebase Authentication and a private user document in Firestore.
Buying data
When you place an order we collect your shipping address, the contents of the order, and a record of the Stripe payment (we never store your card number — Stripe holds that). Refund requests you submit include the reason and any photos you attach.
Selling data
Creators submit a shop name, story, location, social handles, and bank / tax information through Stripe Connect. Stripe holds your bank account and tax ID directly; HANDORA stores only your Stripe connected-account ID and flags like whether payouts are enabled.
Content you upload
Product photos, shop banners, avatars, review photos, refund evidence, and custom-request references. All stored in Firebase Storage and served from HANDORA URLs.
Messages
Direct messages between buyers and creators are stored on our servers so both parties can read them. Treat anything you send through HANDORA as readable by the recipient and by HANDORA’s support team when responding to abuse reports.
Usage data
Standard server logs (IP address, user agent, request paths, timestamps). We use these for debugging, abuse prevention, and aggregate analytics.
We don’t currently use a third-party analytics or error-monitoring provider. If we add one in the future, we’ll name it here first.
2. Why we use it
- Operate the marketplace — show you orders, conversations, listings, payouts
- Process payments through Stripe (legal basis: contract)
- Detect and prevent fraud, abuse, and illegal listings (legitimate interest)
- Improve the product based on aggregated, anonymous usage patterns
- Send transactional emails — order confirmations, shipment notifications, refund updates, password resets
- Send occasional product announcements (you can unsubscribe at any time)
3. Who we share it with
We share data only with vendors that make HANDORA function:
- Stripe — payments, Connect, refunds. See Stripe’s Privacy Policy.
- Google / Firebase — auth, database (Firestore), storage, hosting. See Firebase’s Privacy Policy.
- Resend — delivers transactional emails (order confirmations, shipping updates, refund notices, sign-in alerts).
Counterparties on a transaction (buyer ↔ seller) see each other’s name and shipping address as needed to fulfill the order. Reviews are public. Aside from those, we don’t sell or share your personal data with third parties for their own marketing.
4. How long we keep it
- Account profile: while your account is open, plus a short period after closure for legal compliance
- Orders, payments, refunds: at least 7 years for tax and accounting
- Messages: until either party deletes them, or 5 years, whichever comes first
- Server logs: 90 days
These are our standard retention periods. Where local law requires a longer minimum for a given record — for example, some jurisdictions require longer tax-record retention than others — we follow whichever period is longer.
5. Your rights
Depending on where you live, you may have the right to:
- See what personal data we hold about you
- Correct inaccurate data
- Ask us to delete data (subject to tax / fraud-prevention retention)
- Take your data with you (data portability)
- Object to or restrict certain processing
- Withdraw consent for marketing emails (use the unsubscribe link in any email)
- Complain to your data-protection authority
To exercise any of these, email privacy@myhandora.com. We’ll respond within 30 days. You can also close your account from Account → Sign-in & security, which deletes your profile + your creator shop profile if applicable — unless you have orders still in progress, an active Stripe dispute, or an unresolved refund or cancellation request, in which case deletion is temporarily blocked until those clear (we’ll tell you exactly why). Past orders and reviews stay on HANDORA for record-keeping.
6. International transfers
HANDORA runs on Google Cloud (Firebase) and Stripe, both global providers that may store and process data in the United States and other countries. Where a cross-border transfer requires a safeguard under your local law, we rely on the mechanisms those providers already offer as part of their standard data-processing terms, such as the EU Standard Contractual Clauses.
7. Children
HANDORA isn’t intended for anyone under 18. If we learn we’ve collected data about someone under that age, we’ll delete it.
8. Cookies and similar tech
We use a small number of strictly-necessary cookies to keep you signed in, remember your cart, and remember your shipping-destination preference. We don’t use tracking cookies for advertising.
9. Changes to this policy
We may update this Privacy Policy. Material changes will be announced via email and an in-app notice at least 14 days before they take effect.
10. Contact
Questions or requests: privacy@myhandora.com.