Draft for attorney review
Privacy, consent, and data
How Handled.™ handles the information a business and its customers put into the system. Plain language; the legal terms follow review.
Who holds what
Each business on Handled is a separate tenant. A business owns the records it creates: customers, orders, jobs, evidence, reports, and payments. The Lindsey Effect operates the platform, sees system health and plan status, and does not browse a business’s customer records in the ordinary course of operating the service.
Customers see only their own order, its status, decisions waiting on them, and their completion report, through private links.
Consent
Every storefront intake ends with a consent statement the business configures. Customers agree to be contacted about their request and to have their information used to deliver the service. Photos of a customer’s property are collected as proof of work and shown on the completion report the customer receives.
Sensitive access details
Door codes, lockbox and alarm details are marked sensitive. They are shown only to the owner and to the team member assigned to that job, inside the job. They never appear in previews, dashboard cards, notifications, or completion reports.
Storage and security
- Records and uploaded files are stored privately. Application-level encryption at rest (AES-256-GCM) is on when the site’s encryption key is set; the Connections page shows whether it is.
- Passwords are hashed with scrypt and a per-account salt. Sessions end after 24 hours of inactivity and within 30 days.
- Payment card details are never entered into or stored by Handled. Payment happens on the business’s payment provider; Handled records the outcome.
- Every important status and money change writes an audit event with who did it and when.
Export and deletion
A business owner can export every record as JSON from Settings, and can delete the business, which removes its records and files. Deleting a sign-in removes the email and password; businesses the account owns must be deleted or transferred first so nothing disappears by accident. A customer can ask the business to delete their records; the business does so from the customer’s page.
Transactional messages (request received, quote, schedule, report, balance due) are sent on behalf of the business in its brand. Team invitations and password resets come from Handled. Nothing is sent when the site’s email provider is not connected; the Connections page says so.
Questions: danielle@thelindseyeffect.com