HDHandyDeskSign in to HandyDesk

A plain-language explanation of how HandyDesk handles operator, customer, and connected-service data.

OverviewInformation we collectGoogle, Gmail & CalendarOther connected servicesHow we use dataSharingRetention & deletionYour choicesCookies & trackingSecurityContact

Your business stays your business

Privacy Policy

This policy explains what HandyDesk collects, why we use it, who may process it, how long we keep it, and how you can control or delete it.

Last updated: August 16, 2026

1. Overview

HandyDesk provides field-service business software for independent operators and small trade businesses. References to “HandyDesk,” “we,” “us,” or “our” mean the provider of the HandyDesk service at handydesk.app and app.handydesk.app.

Operators control the customer and business information they place in HandyDesk. We process that information to provide the service, follow the operator's instructions, secure the platform, and meet legal obligations. We do not market to, cross-sell to, or compete for an operator's customers.

2. Information we collect

  • Account and business data: name, email, phone, business name, business settings, service area, team members, preferences, and authentication information.
  • Operator-provided customer data: client and lead contact details, addresses, messages, notes, jobs, visits, estimates, invoices, payments, photos, attachments, and related records.
  • Connected-service data: information you authorize us to access from services such as Google, Gmail, Google Calendar, payment providers, and communications providers.
  • Usage and technical data: device and browser information, IP address, log data, feature activity, diagnostics, security events, and support communications.
  • Public-site submissions: information submitted through a free-trial or other contact form.

3. Google, Gmail, and Google Calendar

Connecting a Google account is optional. HandyDesk requests only the Google permissions shown on Google's consent screen and uses them only for the connected features you choose.

What we may access

  • Google identity: your name, email address, profile image, and Google account identifier for connection and authentication.
  • Gmail: message headers, participants, timestamps, labels, message bodies, threads, and attachments needed to display and organize business communications, identify leads or customer context, draft replies, and send messages you direct or approve. The precise access depends on the permissions you grant.
  • Google Calendar: calendar names and settings, events, attendees, locations, descriptions, availability, and related identifiers needed to show availability and synchronize visits or appointments. If you grant write access, HandyDesk may create, update, or delete calendar events when you direct the related action in HandyDesk.

How Google data is used

We use Google data only to provide or improve visible, user-facing HandyDesk features: connecting your account, displaying relevant email or calendar information, organizing leads and customer records, synchronizing schedules, drafting operator-requested content, and completing actions that you direct or approve.

When Leo processes Google data, it does so only to provide a HandyDesk feature requested by or presented to the operator. HandyDesk does not use Gmail or Calendar data to train generalized artificial-intelligence models, build advertising profiles, serve ads, determine creditworthiness, or market to your customers.

Storage and protection

HandyDesk may store encrypted OAuth access and refresh tokens, connection identifiers, synchronization state, and the Google-derived records needed to provide connected features. Google content imported or saved into a HandyDesk client, lead, job, visit, or communication record becomes part of that operator's HandyDesk business record and is protected using the same tenant isolation and access controls as other HandyDesk data.

Sharing and transfer

We do not sell Google user data, use it for advertising, or disclose it to data brokers. We may transfer the minimum necessary data to contracted infrastructure, security, communications, and AI service providers only to provide or secure the user-facing HandyDesk feature, under confidentiality and data-protection obligations. We may also disclose information when legally required or with your explicit direction. Human access is limited to support, security, abuse prevention, or legal needs and only when reasonably necessary.

Retention, deletion, and disconnecting Google

OAuth tokens are retained while the Google connection remains active and are deleted or rendered unusable after the connection is disconnected, subject to short operational delays. Temporary synchronization data is kept only as long as reasonably needed to complete and troubleshoot synchronization.

Disconnecting Google stops future Gmail and Calendar access and synchronization. It does not automatically delete business records previously imported, copied, sent, created, or saved in HandyDesk, because those records may be part of the operator's client, job, communication, or accounting history. You can delete those records in HandyDesk where available or request deletion through the contact methods below. Deleting your HandyDesk account includes deletion of stored Google connection credentials and Google-derived data associated only with that account, except information we must retain for legal, fraud-prevention, security, payment, dispute, or backup-integrity purposes.

You may revoke HandyDesk's Google access through HandyDesk connection settings when available or through your Google Account connections page. Revocation at Google invalidates HandyDesk's authorization but does not itself delete records already saved in HandyDesk. Contact us if you also want those records reviewed for deletion.

Google API Limited Use disclosure

HandyDesk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Other connected services and lead platforms

Connected services and lead platforms may provide lead, contact, project, and message data when an operator authorizes the connection. HandyDesk uses that data only to manage the operator's workflow and complete actions the operator directs or approves.

Disconnecting a platform stops future access. Business records previously imported or saved in HandyDesk remain subject to HandyDesk's normal retention and deletion controls.

5. How we use information

  • Provide, operate, maintain, personalize, and improve HandyDesk and Leo.
  • Connect leads, clients, jobs, visits, communications, schedules, estimates, invoices, and payments.
  • Authenticate users, manage accounts and subscriptions, and provide support.
  • Detect fraud, abuse, security threats, technical failures, and policy violations.
  • Comply with law, enforce agreements, and protect operators, customers, HandyDesk, and the public.
  • Contact people who request a free trial or support. We do not add form submitters to unrelated marketing without an appropriate choice or permission.

6. How information is shared

We share information only as needed to operate HandyDesk, follow an operator's instructions, complete a transaction, protect the service, or comply with law. Categories may include cloud hosting and storage, authentication, communications, payment processing, analytics and diagnostics, customer support, security, and AI-processing providers.

Operators may choose to send or share information with their clients, team members, vendors, payment providers, or connected services. Those actions are controlled by the operator and may be subject to the recipient's own privacy terms.

We do not sell raw customer or operator-level data. We do not share personal data for cross-context behavioral advertising.

7. Retention and deletion

We retain account and business records while an account is active and afterward only as reasonably necessary to provide requested exports or recovery, complete deletion, meet tax, accounting, payment, dispute, security, fraud-prevention, and legal obligations, and maintain limited backups. Retention varies by record type and legal need; we avoid keeping personal information longer than needed for the disclosed purpose.

Deletion requests are verified to protect the account. Active data approved for deletion is removed from normal production use. Residual copies may remain in encrypted backups until those backups cycle out and are not restored except for disaster recovery, security, or legal necessity. Some transaction, consent, audit, or dispute records may be retained where required or reasonably necessary.

8. Your choices and rights

Depending on where you live and applicable law, you may ask to access, correct, export, or delete personal information, or object to or restrict certain processing. You may disconnect integrations, change permissions, or close your account. We may need to verify your identity and authority before completing a request.

Operators are responsible for responding to their own customers' requests concerning data the operator controls. HandyDesk will reasonably assist operators with those requests as appropriate.

See our Data Requests & Deletion page for clear request and Google-disconnection steps.

9. Cookies and public-site tracking

HandyDesk may use strictly necessary browser storage, cookies, request logs, and similar technologies to deliver pages, protect forms, maintain sessions, prevent abuse, and diagnose failures. The public HandyDesk website does not use personal information for cross-context behavioral advertising.

If we introduce non-essential advertising or tracking technology, we will update this notice and provide choices where required by law.

10. Security

We use administrative, technical, and organizational safeguards designed for the sensitivity of the data, including tenant isolation, access controls, encryption in transit, protected credential storage, logging, backups, and security monitoring. No system can guarantee absolute security. Operators must protect their credentials, devices, team access, and connected accounts.

Read the public Security Overview for more detail and responsible-reporting instructions.

11. Contact and support

For privacy questions, Google-data questions, access or deletion requests, or support:

  • Email: info@handydesk.app. Use “Privacy request” or “Google data request” in the subject line.
  • Public visitors: you may also use the HandyDesk contact form and identify the request in the message.
  • Existing operators: use Help & Feedback inside HandyDesk so we can verify the requesting account.

We may update this policy as HandyDesk changes. Material changes will be posted here and, when appropriate, presented inside the service before new uses of connected data begin.

© 2026 HandyDesk. Built from the field up.

HomeLegal & TrustPrivacyTermsSecurityData RequestsSign In