Privacy Policy
Last updated: 31 July 2026
1. Who we are
Handover is an AI-assisted customer support platform operated by Squash Media & Marketing. This policy explains what personal data we collect, how we use it, and the choices you have. You can contact us about anything in this policy at support@handover.support.
2. What we collect
- Account details - your name, email address, optional profile photo and a securely hashed password. If you sign in through your organisation's single sign-on (Google, Microsoft, Okta or another OpenID Connect provider), we receive your name, email address and profile picture from that provider.
- Support conversations - messages you send and receive, file attachments, ratings you give to answers, and related metadata such as timestamps and conversation status. You can chat without creating an account; if you provide an email address in an anonymous chat we store it so the conversation can be continued or claimed later.
- Organisation content - documents uploaded by organisations to power their AI agents, and settings such as branding, domains and team membership.
- Billing details - handled by Stripe. We store your subscription status and plan; we never see or store card numbers.
- Technical data - IP addresses and request logs used for security, rate limiting and diagnosing errors.
- Bug reports and errors - if you report a problem, we store what you wrote, an optional screenshot, and the page you were on. We also record unhandled errors automatically, with the technical detail needed to fix them and the account of whoever hit it. Both are filed as issues in our private GitHub repository, so GitHub processes that information on our behalf.
3. How we use your data
- Providing the service - running conversations, routing them to the right team members, showing dashboards and reports to organisation staff.
- Generating AI answers - when you ask a question, your message and relevant excerpts from the organisation's documents are sent to OpenAI to generate a response and to create search embeddings. Under OpenAI's API terms, this data is not used to train their models.
- Notifications - in-app alerts and emails about things like a human agent joining your conversation, your conversation being resolved, or team events for staff.
- Safety and reliability - rate limiting, abuse prevention and error monitoring.
4. Who can see your data
Data is strictly separated per organisation. Your conversations are visible to you and to the staff of the organisation you contacted - and within that organisation, only to the team members assigned to handle the relevant support agent, plus managers and administrators. Internal staff notes are never shown to customers. We do not sell personal data, and no other organisation on the platform can see yours.
5. Service providers we rely on
We share data with these processors only as needed to run the service:
| Provider | Purpose |
|---|---|
| Fly.io | Application hosting (London region) |
| Tigris | File storage (documents, attachments, logos) |
| OpenAI | AI answer generation and document embeddings |
| Stripe | Subscription payments |
| Brevo | Transactional email delivery |
| GitHub | Bug reports and error tracking (private repository) |
6. How long we keep data
Conversations and documents are kept while the organisation's account is active, so support history remains available. If you delete your account, your profile is anonymised immediately and can no longer sign in. If an organisation is deleted, its support portals go offline immediately. For complete erasure of specific data, contact us and we will action it.
7. Security
All traffic is encrypted in transit (TLS). SSO credentials are encrypted at rest. Access to data is controlled per organisation and per role, sign-in is protected against brute force by account locking and rate limiting, and email addresses are verified before password sign-in is allowed.
8. Your rights
Under UK data protection law you can ask for a copy of your personal data, ask us to correct or delete it, object to processing, and ask for it in a portable format. You can export any of your conversations as a PDF at any time from the conversation itself. To exercise any other right, email us. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
9. Changes to this policy
If we make material changes we will update the date at the top of this page and, where the change significantly affects you, tell you by email or in the app.