HandeeFriend is designed to respect your privacy. We do not operate our own servers and do not store user data ourselves. Here is exactly what happens with your information when you use the app:
1. Information We Do Not Collect
We do not require you to create an account. We do not collect your name, email, phone number, payment information, contacts, or any identifying information. We do not track usage analytics. We do not have a user database.
2. Information Sent To Third Parties
When you use the app's camera, photo-upload, or decision-support analysis features, the following flows directly from your device to third-party services:
- Photos you capture or select — sent to Google Gemini (AI analysis)
- Approximate location (city + country, derived from your device GPS) — sent to Google Gemini for regional pricing and codes
- Text descriptions you enter — sent to Google Gemini as part of the prompt
These transfers are subject to Google's privacy policy. We do not see, store, log, or retain any of this data.
3. Affiliate Tracking
When you tap an Amazon, Home Depot, or Lowe's link in the app, you are redirected to that retailer's website with our affiliate tag attached. The retailer tracks your visit and any purchase through their own cookies/privacy practices. We receive aggregated commission reports that do not identify individual users.
4. Device Permissions
The app requests the following iOS/Android permissions, each of which you can revoke in Settings:
- Camera — for taking photos of walls, fixtures, and contractor quotes
- Photo library — for selecting existing photos
- Location (while in use) — for local pricing and building codes
5. On-Device Storage
The only information stored on your device is your Terms of Service acceptance (the version you accepted and the timestamp). This is kept in the app's local storage and never leaves your device. Deleting the app removes it.
6. Children
HandeeFriend is intended for users aged 18 and over. We do not knowingly collect information from or direct the app at children.
7. Your Rights under PIPEDA / PIPA / GDPR / CCPA
You have the right, under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), to:
- Access any personal information we hold about you;
- Correct inaccurate or incomplete information;
- Withdraw consent at any time, including marketing-communication consent (CASL);
- Request deletion of your personal information (see Section 8 below);
- Port your data in a machine-readable format;
- Complain to your local privacy regulator (Canada: the Office of the Privacy Commissioner at priv.gc.ca) if you believe we've mishandled your information.
Because we store only your Terms-of-Service acceptance and consent audit record on your device (not on our servers for most users), there is often nothing for us to return or delete on our side — but any record that does exist, we will produce or destroy on request. To manage data held by our subprocessor Google, use Google's privacy controls at myaccount.google.com.
8. Data Deletion Request
You can request deletion of any personal information HandeeFriend holds about you — account record, consent audit log, saved renders, saved estimates, PDFs, affiliate-click records, marketing subscriptions — at any time. We will confirm receipt within 48 hours and complete the deletion within 30 days, as required by PIPEDA / PIPA / GDPR.
How to submit a deletion request:
- Email privacy@handeefriend.com with the subject line "Data Deletion Request".
- Include the email address associated with your HandeeFriend account, and whether you want us to (a) delete everything, or (b) delete specific items only.
- We'll reply within 2 business days with a verification step (to make sure it's really you asking), then complete the deletion and send you a written confirmation when it's done.
What we cannot delete: records we're legally required to retain — for example, Stripe payment transaction records for tax / anti-money-laundering purposes (kept 7 years), affiliate-commission reconciliation records (kept 2 years), and Terms-of-Service acceptance logs required to defend against disputes (kept while you have an active account + 6 years after closure, per British Columbia's Limitation Act). Everything else is deleted on request.
Marketing consent withdrawal (CASL): if you only want to stop receiving marketing emails (but keep your account), click the "Unsubscribe" link in any email or email privacy@handeefriend.com — we'll process it within 10 business days, as Canada's Anti-Spam Legislation requires.
9. Changes
We may update this policy from time to time. Material changes will be reflected in a new effective date and communicated via an in-app notice.
10. Contact
Privacy questions? Contact us at privacy@handeefriend.com or hello@handeefriend.com.