Skip to content

Launching soon — we're not yet accepting orders. Register your interest

Privacy Policy

Effective August 27, 2026 · Version 1.1

This Privacy Policy explains how HandCarry Technologies LLC ("HandCarry," "we," "us," "our") collects, uses, shares, and protects personal data when you use the peer-to-peer delivery marketplace at handcarry.app (the "Platform"). It applies to the Platform's website, its application programming interface, and our communications with you. It is incorporated into the Terms of Service.

HandCarry Technologies LLC, a Delaware limited liability company (500 Westover Dr #34619, Sanford, NC 27330, USA), is the data controller — the party responsible for your personal data described here. For anything in this policy, contact [email protected].

We wrote this policy to describe what the Platform actually does — not boilerplate. Where we say we don't do something, we mean it: we do not sell personal data, and we do not run advertising. The one measurement we run is page analytics under the consent model in Section 10 — with consent where the law requires asking first, always with an off switch, and never tied to your identity.

1. Scope and who this covers

This policy covers everyone who uses the Platform: visitors, registered users acting as buyers or travelers, and people who submit our pre-launch interest form. It does not cover the practices of third parties you interact with through the Platform — for example, the payment provider's own collection of your card or bank details (Section 5.2), or another user's handling of information you choose to share with them at a delivery handover. Where those parties act as independent controllers, their own privacy policies apply.

2. Data we collect

We collect only what the Platform needs to run. By category:

2.1 Account data. When you register: first and last name, email address, and a password (stored only as a secure hash — we cannot see your password). Later: your phone number, verified by a one-time SMS code. Phone numbers are used to send verification texts through our SMS provider; message and data rates may apply. We record when you accepted the Terms of Service together with the versions of the Terms and of this Privacy Policy in force at that moment, and likewise the version of the Prohibited Items Policy you acknowledge at each listing, proposal, and checkout.

2.2 Profile data. What you choose to add: a profile photo (uploaded images are re-encoded, which removes hidden metadata such as embedded GPS coordinates), your city and country, a short bio, and languages you speak. Location on HandCarry is city-level only — the Platform never collects GPS or precise location from your device, and no such capability exists in it. Your city comes from a list you pick from, not from tracking.

2.3 Identity verification (KYC) data. To unlock payments, you submit: a government-issued identity document (front and back, or the passport photo page), a self-portrait photograph, your legal name as it appears on the document, the document number, your date of birth, and your country of residence. Verification is reviewed manually by our own trained staff — we use no third-party identity-verification vendor, so your documents are not shared with an outside service. Section 8 describes the unusual care this data receives: document images and document numbers are encrypted at rest, and every single staff view of a document is individually logged.

2.4 Transaction data. When you list, propose, and transact: trip routes and dates, item titles and descriptions, product links, declared values, commissions, offers and counter-offers, order records, amounts paid and refunded, delivery locations you enter (free text — enter only what the delivery needs), proof-of-purchase receipts and item/delivery photos, and the record of how each delivery was confirmed. Order records include payment identifiers from our payment processor — never card numbers: your card details are entered directly with Stripe in your browser and do not touch our servers.

2.5 Payout data (travelers). Your payout account's provider identifier, a masked display label (for example, "Bank account ending 4521"), and the account-holder name reported by the payout provider, which we check against your verified name. Bank identifiers we store are encrypted. The full identity and bank details needed to pay you are collected by Stripe directly during payout onboarding on Stripe's own pages, under Stripe's privacy policy.

2.6 Messages and reviews. Messages you exchange on the Platform, including photo attachments (re-encoded, metadata stripped). Messages are immutable — they cannot be edited or deleted — because conversation threads are the negotiation record and the evidence base for disputes; write them knowing they are permanent. Reviews you write and receive, including scores, comments, and responses.

2.7 Support, dispute, and report data. Support tickets and their attachments, dispute statements and evidence files, and reports you file about listings, conversations, or reviews.

2.8 Data we generate about you. Using the Platform produces records about your account that you did not type in: your rating average and count, completed-delivery count, failed-delivery count, the confirmation class recorded on each delivery, notification records, and internal trust-and-safety records — moderation actions affecting your account, staff notes, and the optional feedback you can give when deactivating. These records exist to run the marketplace's trust systems and support; Section 4 explains which of them other users can see.

2.9 Technical data. IP address and browser information recorded in session records, authentication logs (sign-ins, failures, lockouts, verification events), and the audit trail (Section 8.3). Short-lived server and network operational logs also exist at the infrastructure level (Section 7.1). The Platform sets four first-party cookies, and third-party services run in your browser in specific situations (Section 10). When analytics is allowed to run (Section 10), Google Analytics receives usage data — pages viewed with their campaign tags, and browser and device information — never tied to your account identity. Beyond that we collect no telemetry or behavioral tracking data — no advertising identifiers, no fingerprinting.

2.10 Pre-launch interest form. If you left your email on our pre-launch page, we hold that address to tell you when the Platform launches; email [email protected] to have it removed at any time.

2.11 What we deliberately do not collect. No precise geolocation. No card numbers. No contacts or address books. No device push tokens. No data from data brokers. No social media data (social login is not offered). No biometric templates — the KYC selfie is reviewed by a person, not processed into a faceprint.

3. How we use data, and on what basis

We use personal data for the purposes below. For readers in jurisdictions whose law requires a legal basis for each use, the basis is noted alongside.

3.1 Providing the marketplace (performance of our contract with you). Operating accounts, listings, matching, messaging, orders, payments, payment holds, payouts, and notifications — the Platform's core. Example: when your proposal is accepted, we use your item description, route, and amounts to create the order and charge the buyer.

3.2 Identity and safety verification (contract performance; legal obligations; legitimate interest in a safe marketplace). Email, phone, and identity verification; matching payout-account names to verified names. Example: before you can accept money, we verify who you are, so the person on the other side of a transaction is never anonymous to us.

3.3 Payments and record-keeping (contract performance; legal obligations). Processing charges, refunds, and payouts through our payment processor; keeping the financial records the law requires of a business that handles payments.

3.4 Dispute resolution (contract performance; legitimate interest). Reviewing order evidence, messages, proofs, and confirmation records to decide disputes fairly, and moving money according to the outcome.

3.5 Fraud prevention and enforcement (legitimate interest; legal obligations). Investigating reports, moderating content, enforcing the Terms of Service and Prohibited Items Policy, and maintaining the re-registration denylist (Section 7.4).

3.6 Security (legitimate interest; legal obligations). Authentication logging, lockouts, session management, bot protection on public forms, and the audit trail.

3.7 Communications (contract performance; legitimate interest). Transactional email and in-app notifications about your account and orders, and security alerts. We currently send no marketing email at all.

3.8 Legal compliance (legal obligations). Responding to lawful requests, tax and financial reporting, and meeting record-retention duties.

3.9 Understanding how the Platform is used (consent where the law requires asking first; otherwise our legitimate interest in understanding use of the Platform, always with an off switch). Page analytics through Google Analytics under the model in Section 10: which pages are visited and where visitors come from, so we can see what works and what needs fixing. It is never tied to your identity, and you can turn it off at any time via Cookie settings.

3.10 Automated decisions. Four Platform mechanisms act automatically in ways that can significantly affect you. Each has a human path:

  • Re-registration blocking: attempts to register with the email — or verify the phone number — of an account that was banned and then erased are blocked automatically (Section 7.4). Identity-document matches are never auto-blocked; they are flagged for human review.
  • Payout-name mismatch: a payout account whose holder name does not match your verified name freezes payouts automatically; a human reviews every freeze.
  • Delivery auto-confirmation: if a buyer does not respond for 5 days after a delivery is marked, the order confirms automatically, as the Terms of Service describe; the dispute window is the recourse.
  • Failed-delivery marks: when a paid order fails through the traveler's fault (traveler cancellation, or a missed purchase deadline), a mark is recorded on the traveler's profile automatically under the Terms of Service's rules; if you believe a mark was applied wrongly, contact support.

We do no profiling, scoring, or automated advertising decisions of any kind.

4. What other users can see

The Platform is designed so users learn about each other progressively, as trust is established:

  • Anyone can see your public profile: your display name (first name and last initial — never your full name), your photo, when you joined, your verification badge, your rating average and count, your reviews once revealed, and your completed-delivery count.
  • Only a user who has a paid order with you sees your fuller profile: your city, bio, languages, and transaction statistics — including your failed-delivery count and buyer-side order count.
  • Your phone number is never shown to other users. Delivery confirmation uses the handover code, not contact exchange. After payment, you may choose to share contact details in messages to coordinate handover — that sharing is your decision.
  • Your listings show what you wrote in them, plus your display name, photo, verification badge, and ratings.
  • Reviews become public after the double-blind reveal — reviews are hidden until both sides have written theirs or the review window closes, then published together.
  • Profiles of suspended accounts remain visible; profiles of banned and erased accounts are removed from public view entirely.

Be thoughtful about what you put in free-text fields — bios, listings, messages, reviews, delivery locations. Content you share with another user is visible to them permanently (messages cannot be unsent), and public content is public.

5. Who we share data with

We share personal data only as described here. We never sell it, and we never share it for advertising.

5.1 Other users — as Section 4 describes, and as needed to run transactions: a traveler sees the item and delivery details of orders they carry, the parties to a dispute see each other's evidence, and counterparties keep their copy of your shared history (messages, reviews, order records) even if you later leave the Platform.

5.2 Service providers (processors). These companies process data for us to run the Platform. We have data-processing agreements with each, they may use the data only to provide their service to us, and each publishes its own privacy policy:

ProviderWhat they doWhat they receive
Stripe (USA)Payment processing, refunds, traveler payoutsOrder amounts and identifiers, your email for receipts; your card details and (for travelers) identity and bank details are collected by Stripe directly under its own privacy policy
Twilio (USA)Sends phone-verification SMS codesYour phone number
Resend (USA)Sends our transactional emailYour email address, name, and the message content
Cloudflare (USA)Network security and delivery: Platform traffic passes through Cloudflare's global network (proxy/CDN), and its Turnstile service protects our public forms from bots; also DNSConnection data including your IP address; for Turnstile, the bot-check token and your IP
DigitalOcean (USA)Hosts our servers in New York, USAAll Platform data resides on infrastructure they host
Google Workspace (USA)Runs our support mailboxThe content of email you send to [email protected]
Google (USA)Analytics: Google Analytics, loaded through Google Tag Manager, only when analytics is allowed to run (Section 10)Usage data: pages viewed with their campaign tags, browser and device information, and the coarse location Google infers from the connection — never your name, email, or account identity

We add providers only when the Platform needs them, and we update this list before a new provider begins receiving user data.

5.3 Authorities. We disclose data where we believe in good faith that the law requires it — for example, a valid subpoena, court order, or equivalent legal process — or where disclosure is necessary to protect the life or safety of any person, to address fraud or security incidents, or to protect HandCarry's legal rights. Where the law allows and it would not endanger anyone, we tell you before disclosing. We report child sexual abuse material to the authorities without exception.

5.4 Business transfers. If HandCarry is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction. The receiving party remains bound by this policy or one at least as protective, and we will notify you of any change of controller.

5.5 With your direction. Where you explicitly ask us to share something, we share it as you directed.

6. Where data lives; international access

Platform data is stored in the United States — our servers are hosted with DigitalOcean in New York, and our processors listed in Section 5.2 are US companies. Payment data lives with Stripe under its own compliance regime. Because HandCarry connects buyers and travelers across borders, your data is processed in the United States regardless of where you live; by using the Platform you understand your data will be stored and processed there, under this policy's protections. Our staff may access Platform systems from outside the United States (our founder operates from Qatar); all staff access happens under the same role-based access controls and audit logging described in Section 8, wherever the staff member sits.

7. How long we keep data

We keep personal data as long as the purpose it serves requires — no longer, and no shorter than the law demands. Concretely:

7.1 Retention schedule.

DataHow long
Account and profile dataLife of the account; anonymized on account erasure (Section 7.3)
KYC of an active account (approved submission)Life of the account — it is your live identity record
KYC document images after an unfavorable decision (rejected/revoked)10 years from the decision
KYC identity details on a submission (name, document number, date of birth, decision record)Life of the account; removed on the erased-account schedule below
All KYC of an erased account (including the retained profile photo — see 7.3)10 years from erasure (see Section 7.2)
Phone-verification attempt log90 days
Sign-in sessionsExpire after 120 minutes of inactivity; session records pruned shortly after expiry or revocation
Authentication logs (sign-ins, failures, lockouts)12 months
Audit trail of data access and changes10 years
Payment-event records from our processor (webhooks)5 years
Notifications sent to you5 years
Orders, messages, reviews, disputes, support ticketsAs long as necessary for legal obligations, dispute defense, financial records, and the counterparty's own transaction history
Re-registration denylist entries (Section 7.4)As long as necessary for fraud prevention, reviewed periodically
Server and network operational logsShort-lived; kept only for operations and security troubleshooting
Analytics data (Google Analytics, Section 10)14 months, held by Google; aggregated statistics without individual detail persist in reports
Pre-launch interest emailsWhile the pre-launch form is live; removed when it retires or on request

7.2 Why KYC is kept 10 years. We keep identity-verification records well beyond account closure — for ten years — because they are our defense against fraud, money-laundering, and identity abuse, and our evidence in legal claims arising from transactions. This exceeds the retention many services apply, and we disclose it here deliberately so you can weigh it before verifying. The records are encrypted and access-audited for their entire retention life.

7.3 What deletion keeps. When an account is erased (Section 9.4), personal identifiers are removed or replaced in live systems — your name becomes "Deleted User" to other users, your email and phone are removed from the account, and your city, bio, and languages are cleared. The following survive: the transaction record (orders, reviews, messages) in anonymized form, because your counterparties keep their own transaction history and we keep our financial records; the KYC record for the period in Section 7.1; your profile photo, which is moved out of public view into private retention and kept with the identity record for the same 10-year period, then deleted; and the audit trail.

7.4 The re-registration denylist. When an account that was banned for serious violations is erased, we keep a fraud-prevention record: cryptographic hashes (not the readable values) of the account's email, phone number, and identity-document number, together with the verified name. Attempts to register with a matching email, or verify a matching phone number, are blocked automatically; an identity-document or name match during KYC is flagged to a human reviewer, never auto-blocked. We may also add entries directly when investigating fraud. This is how we prevent erasure from being used to launder a ban. The legal basis is our legitimate interest in keeping removed bad actors removed; the record is the minimum needed for that purpose.

7.5 Backups. We maintain routine backups of Platform data for disaster recovery. Backup copies are retained for a limited period, and data removed from live systems — including erased accounts — may persist in backup copies until those backups cycle out, after which it is gone entirely. Backups are protected with the same care as live data.

8. How we protect data

8.1 Encryption and transport. All traffic to the Platform is encrypted in transit (TLS). The most sensitive stored data is additionally encrypted at rest at the application level: KYC document images (stored as encrypted blobs on private storage, never at public web addresses), KYC document numbers, payout bank identifiers, and delivery handover codes. Passwords are stored only as bcrypt hashes.

8.2 Access control. Staff access is role-based and least-privilege: staff see only the data their function requires, and staff accounts are disabled, never deleted, so the audit trail survives personnel changes. Two categories get extra protection. KYC documents are decrypted only in memory, per viewing, and every view by every staff member is individually logged. Your private messages are not ambiently accessible to staff at all — there is no browse-conversations screen; a permission-gated read-only viewer exists for investigating reports and disputes, and every conversation a staff member opens is logged.

8.3 Audit trail. Changes to significant records and access to sensitive data are written to an append-only audit log kept for 10 years — this is how we can reconstruct who saw and did what, long after the fact.

8.4 Platform security. Sign-in is protected by rate limiting and lockouts (5 failed attempts locks sign-in for 15 minutes), and public forms — sign-up, sign-in, password-reset, phone verification, and the pre-launch interest form — carry bot protection. Changing or resetting your password revokes your other active sessions. Security notifications — password changes, new-device sign-ins — always generate an email to you and cannot be disabled. Uploaded images are re-encoded platform-wide, stripping hidden metadata; private files (KYC, message attachments, order proofs, dispute evidence) are stored on private disks and streamed only to authorized people, never served from public web addresses.

8.5 No system is perfect. No security program eliminates risk, and we make no absolute guarantee. What we promise is the architecture above, and honesty when something goes wrong (Section 11).

9. Your rights and choices

You do not need to live in any particular jurisdiction to exercise these rights — we extend them to all users as Platform policy. To exercise any of them, email [email protected] from your registered email address — that is how we verify a request is really yours; requests from other addresses cannot be actioned.

RightHowTiming
Access / export a copy of your dataEmail us; most data is also visible directly in the appWithin 30 days
Correct your dataEdit in the app; locked fields (Section 9.2) via supportSupport corrections within 30 days
Deactivate your accountSelf-service in account settingsImmediate
Delete your account (erasure)Email us (Section 9.4)Acknowledged within 7 days; completed per Section 9.4
Adjust notificationsIn-app preferencesImmediate
Turn analytics on or offCookie settings in the page footer, or on the Cookie Policy pageImmediate
Object / complainEmail usResponse within 30 days

9.1 Access and portability. You can see most of your data directly in the app. You may also request a copy of the personal data we hold about you; we fulfill export requests by email within 30 days. An export covers the personal data connected to your account — profile and account details, listings, orders, reviews, and messages you sent — in a common readable format.

9.2 Correction. You can edit your profile in the app. Two things are deliberately locked: your email address cannot be changed after registration, and after identity verification your legal name and country are locked to what your documents show — corrections to either go through support, with verification.

9.3 Deactivation. You can deactivate your account yourself in settings at any time (unless an order is in progress — finish or resolve it first). Deactivation hides your profile, closes your active listings, and pauses the account; nothing is destroyed. To return, sign back in and confirm reactivation on the screen that follows — reactivation is a deliberate confirmation, never an automatic side effect of signing in. Listings closed at deactivation stay closed until you republish them, and proposals that were pending will have expired.

9.4 Deletion (erasure). You may request permanent erasure of your account. The process:

  1. Email [email protected] from your registered address asking for account deletion. We acknowledge within 7 days.
  2. We check whether anything legally or financially blocks erasure: an order in progress, an open payment dispute with a card issuer, a payout still processing, or a recent charge still inside the card networks' 120-day chargeback window. These conditions exist because we must be able to resolve chargeback and fraud claims about transactions you were part of.
  3. If nothing blocks it, erasure completes within 30 days of your request. If something blocks it, we tell you what, and complete the erasure promptly once the blocking condition clears — for the chargeback window, at most 120 days after your last charge. A worked example: if you request erasure 20 days after your last purchase, the erasure completes about 100 days later, when that charge leaves the chargeback window.
  4. Erasure anonymizes your account as Section 7.3 describes. We confirm completion by reply to the email address you wrote from.

You can cancel a pending erasure request by writing from the same address before it is processed.

9.5 Notifications. You can adjust notification preferences in the app. Security notifications (Section 8.4) always send. We currently send no marketing email at all; if that ever changes, marketing will be opt-in with a working unsubscribe.

9.6 Objection and complaint. You may object to a processing activity or raise any privacy concern at [email protected]; we respond within 30 days. If you are in a jurisdiction with a data-protection authority, you also have whatever right to complain to it your law gives you — though we would appreciate the chance to resolve the issue first.

10. Cookies and tracking

The Platform sets exactly four first-party cookies, all functional: a session cookie (keeps you signed in; expires after 120 minutes of inactivity), a security token cookie (prevents request forgery), an optional persistent sign-in cookie ("remember me", up to 400 days), and hc_consent, which remembers your analytics choice for 12 months.

Analytics runs under a regional consent model. In the European Economic Area and the United Kingdom, whose law requires asking first, analytics stays off until you actively agree — a banner asks, with Reject exactly as prominent as Accept. Everywhere else, analytics is on from your first page view, disclosed by a notice with an equally visible "Turn off". In every region, a browser Global Privacy Control signal counts as "off" automatically, and an explicit choice you make yourself always wins. To decide which experience applies, we read the visitor country our network provider (Cloudflare) attaches to each request; it is used for that decision in the moment and is not stored. Your choice can be changed at any time via Cookie settings in the page footer or on the Cookie Policy page.

When analytics is allowed to run, Google Analytics (loaded through Google Tag Manager) sets its measurement cookies (_ga and _ga_…, about 2 years) and receives usage data. What it receives is deliberately limited: page addresses are cleaned so only the page path and recognised campaign tags are sent, no account identity is ever sent, Google's advertising features (Google Signals, ad personalisation) are switched off, and Google retains the data for 14 months. Turning analytics off also deletes Google's cookies from your browser.

Two further third-party services run in your browser, both functional:

  • Cloudflare Turnstile, a bot-protection check on our public forms — sign-up, sign-in, password-reset, phone verification, and the pre-launch interest form. It connects to Cloudflare to distinguish humans from bots.
  • Stripe.js, which loads only on payment pages to embed Stripe's secure card form. It connects to Stripe and sets Stripe's fraud-prevention cookies (__stripe_mid, about 1 year, and __stripe_sid, about 30 minutes) under Stripe's privacy policy — this is the mechanism that keeps your card number off our servers entirely.

That is the complete list. No advertising, retargeting, or cross-site tracking cookies exist on the Platform. We honour the Global Privacy Control signal as described above; the older "Do Not Track" signal has no separate effect beyond it. When we introduced analytics (version 1.1 of this policy), we kept the sequence this policy always promised: both policies were updated first, in the same release as the change, with consent asked for where required. Full details: the Cookie Policy.

11. Data breaches

If a breach of security affects your personal data in a way that creates a risk to you, we will notify you and the authorities the law requires, without undue delay and consistent with applicable law, and tell you what happened, what data was involved, and what we are doing about it.

12. Children

The Platform is for adults: you must be 18 or older to use it (Terms of Service, Section 3.1). We do not knowingly collect personal data from anyone under 18. If we learn we hold data of a person under 18, we delete it; if you believe a minor has an account, tell us at [email protected].

13. Changes to this policy

When we change this policy materially — new data categories, new sharing, new retention — we will give at least 14 days' notice by email and in the Platform before the change takes effect, identifying the new version. Non-material clarifications may take effect on posting. Every version is numbered and dated, and prior versions are preserved in our records.

14. Contact

HandCarry Technologies LLC
500 Westover Dr #34619, Sanford, NC 27330, USA
[email protected]

We use analytics cookies (Google Analytics) to understand how the site is used. You can turn this off at any time. Cookie Policy