Privacy policy
What we collect, why, who else sees it, and how to make us delete it.
Last updated
1. Who we are
Handled ("we", "us") runs this site, a directory where people planning events find and book local vendors. The data controller is [FILL IN: legal entity name], [FILL IN: registered address]. Questions go to Handled@HandledBookings.com.
Vendors listed here are independent businesses, not us. When you send a vendor a request, they become a controller of that information in their own right and their own privacy practices apply to what they do with it.
2. What we collect
When you ask a vendor for a quote
Your name, email address, the type of event, the dates you are considering, guest count, budget range if you give one, and whatever you write in the message. You do not need an account to do this.
We email you a receipt with a private link to the booking, and email you again when the vendor replies, changes the booking's status, or sends you an invoice or contract. You can turn off message emails for a booking from its page. Vendors are emailed about new requests, messages and signed contracts.
When you list a business from your website
If you start from our listing link, you can paste your website address and we will fetch that page once, from our server, and read what is on it — your business name, a contact email or phone number if the page shows one, a description and any social links. It is filled into the form for you to correct, and nothing is saved until you submit it. We fetch only the address you type, we do not store the page, and you can skip this and type everything yourself.
When you create an account
Your first and last name, email address, phone number, and a password (stored only as a hash — we never see it). We ask for a phone number so a vendor can reach you on the day, and a vendor can be reached about a booking. Customers may save a shortlist of vendors. Vendors additionally provide the business details on their listing: trading name, category, city, a starting price if they give one, description, packages, response time, social handles and any photographs they upload.
When a vendor verifies their business
Both parts of this are optional, and a listing works without either.
A vendor can confirm a business email address: we send a six-digit code to it and store the address, a one-way hash of the code, and when it was confirmed. The code itself is not kept, and it stops working after thirty minutes or five wrong tries.
A vendor can also upload a business license — in Washington, a UBI certificate. It goes to private storage that is not served publicly and has no shareable link, and it is read by us to decide whether to show the verified badge. It is never shown on the listing, never given to customers, and a vendor can ask us to delete it at any time, which removes the badge with it.
All the badge tells anyone else is that a listing was verified. The address, the certificate and the date are not public.
When you message a vendor
The messages themselves, and who sent each one. A conversation belongs to one booking and closes if that booking is declined or cancelled.
When a vendor invoices you
Your name, email address and the line items on the invoice. Card details never reach us. Payment is handled by Stripe and settles directly into the vendor's own Stripe account — we are not the merchant and never hold your money. We store only a payment reference, the amount and whether it succeeded.
When you sign a contract
The name you type, the email address you give, the date and time, your IP address and your browser's identifying string, and a fingerprint of the exact contract text. Together these are the record that you signed, and what you signed — which is what makes an electronic signature hold up. They are kept for as long as the contract itself.
When a vendor manages their team
Vendors can record their own staff: names, contact details, pay rates and hours worked. That information belongs to the vendor, who is responsible for it; we store it on their behalf, only they can see it, and we do not use it for anything else.
When a vendor tracks your booking as a project
Vendors can organise a booking as a project, with the details you gave them, their own task list, comments, private notes and files. That is the vendor's working record of their job; only they can see it, and we do not use it for anything else.
When a vendor sends you a file
A file a vendor sends you — in your conversation or by email — is stored with our storage provider and can be opened by anyone who has its link, the same as the link to your booking. Nobody can browse for files they have not been sent. The vendor can delete it.
When a vendor connects a calendar
If a vendor syncs a personal calendar, we store the address of that calendar feed and the dates and titles of events found in it, so their availability here stays accurate. This can include personal entries. Vendors can remove a connected calendar at any time, which deletes what was imported from it.
When a vendor connects Instagram
A vendor can bring photos from their own Instagram account into their gallery, and can let us check that account for new posts. If they do, we store an access token Instagram issues for their account, the username it belongs to, and a copy of each photo they choose to keep. The token lets us read their media and nothing else: we cannot post as them, read their messages, or see anything belonging to anyone else.
Photos are copied rather than linked, because Instagram’s own image addresses expire. A photo a vendor keeps becomes an ordinary gallery image and stays after the post is deleted or the account disconnected. Photos we have fetched but the vendor has not decided about are removed after thirty days.
Instagram’s token lasts sixty days and we renew it while the connection is in use. Disconnecting Instagram, from the Gallery tab of the vendor dashboard, deletes the token and stops all further access; photos already kept can be removed one by one from the same page, and deleting the Handled account removes everything. A vendor can also revoke our access from Instagram’s own settings, under Apps and websites.
Counting visits
We use Cloudflare Web Analytics to see how many people reach each page. It sets no cookie, does not fingerprint your device and cannot follow you to any other site. What it records is the page, the site you came from, and general details of your browser, country and device type — in aggregate, with no identifier that would let anyone pick you out of it or join one visit to the next.
What we do not collect
No advertising pixels, no tag manager, no session recording, no fingerprinting, and no cross-site tracking of any kind. We do not build a profile of you, and we do not sell or rent personal information to anyone.
3. Cookies
This site sets no cookies. It uses your browser's local storage for four things, all of which stay on your device and are never sent to us:
- Saved vendors — your shortlist, if you are not signed in.
- Light or dark theme — your display preference.
- Your sign-in session — only if you have an account.
- An unfinished listing — if you start listing a business and have not confirmed your email yet, so you do not have to type it twice.
All four are strictly necessary or purely a preference you set yourself, so there is no consent banner to click. Clearing your browser data removes them.
4. Who else sees your data
We use a small number of providers. Each processes data on our instructions only.
| Who | What for | What they receive |
|---|---|---|
| Supabase | Database, accounts, file storage | Everything described in section 2 |
| Resend | Sending email | Your email address and the content of each notification, including short message excerpts |
| Stripe | Card payments | Your name, email and card details, given directly to them |
| Cloudflare | Hosting and delivery | IP address, browser, pages requested |
| Cloudflare Web Analytics | Counting visits | Page, referring site, and general browser, country and device type. No cookie, no identifier, not linked to you |
| Google Fonts | The typeface | IP address, when your browser loads the font |
| jsDelivr | A JavaScript library | IP address, when your browser loads the file |
We also disclose information if the law requires it, and if the business is ever sold your data would transfer with it.
5. Why we are allowed to process it (UK/EU)
Quote requests, messages and invoices: to perform a contract, or to take steps you asked for before one exists. Accounts and vendor listings: contract. Security, fraud prevention and keeping the service working: our legitimate interests. The newsletter: your consent, withdrawable at any time by replying to any email or contacting us.
6. How long we keep it
Accounts and listings: while the account exists, then deleted within [FILL IN: e.g. 30 days]. Quote requests and messages: [FILL IN: e.g. 24 months] after the event date, so both sides have a record. Invoices and payment records: [FILL IN: usually 6–7 years], because tax law requires it. Imported calendar data: until the vendor disconnects that calendar. Instagram access tokens: until the vendor disconnects, or sixty days after the last renewal, whichever comes first. Photos fetched from Instagram that the vendor never kept: thirty days.
7. Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop processing it, or object to it. If you are in the UK or EU you may also complain to your data protection authority — in the UK, the Information Commissioner's Office.
If you are in California, you additionally have the right to know what we collect, to delete it, to correct it, and not to be treated differently for asking. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of.
Write to Handled@HandledBookings.com and we will respond within one month.
8. Security
Everything travels over HTTPS. Access to records is enforced at the database level: a vendor can only read enquiries addressed to them, a customer only their own, and uploaded files can only be written into the folder belonging to the account that owns them. Passwords are hashed by our authentication provider and are not visible to us.
Some links act as keys — an invoice link, a conversation link, a file a vendor sent you, a calendar feed address. Anyone holding one can open that single item, so treat them the way you would treat a password and do not post them publicly.
9. Children
This site is for adults arranging events and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.
10. International transfers
Our providers may process data outside the UK and EEA, including in the United States. Where that happens we rely on the providers' standard contractual clauses and their own data processing terms.
11. Changes
If this policy changes materially we will update the date at the top and, where the change matters to you, say so on the site.
12. Contact
Handled@HandledBookings.com · [FILL IN: postal address]