Back to handipay

Privacy Policy

Last updated: July 12, 2026

1. Introduction

handipay ("we", "us", "our") runs a payment and invoicing platform for Canadian tradespeople. This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

Where we collect sensitive information, such as your date of birth or banking details, we ask for your consent at the moment we collect it and explain what it is for. For everyday information, like the invoices you create, using the service is your consent to handle it as this policy describes. You can withdraw consent at any time (see Section 7).

2. Information we collect

2.1 Information you provide

  • Account information: your name and email address when you create an account. We sign you in with a secure link sent to your email or through your Google account. If you set a password, we store it in protected (hashed) form.
  • Profile and contact information: phone number, job title, and mailing address, collected while you set up your merchant profile.
  • Business information: business name and address, tax number (GST/HST), business category, website, and support contact details.
  • Identity verification: your date of birth and home address, which we store and share with Stripe to meet know-your-customer rules. If Stripe asks for photos of ID documents, you upload them directly to Stripe; we never see or store them. We record the date and IP address of your acceptance of Stripe's connected account agreement, as Stripe requires.
  • Social Insurance Number: if Stripe needs a Social Insurance Number to verify your identity, you provide it straight to Stripe, inside its own secure verification flow. It never touches our servers, and we never store it.
  • Banking details: your transit, institution, and account numbers go straight to Stripe, inside its own secure flow, so you can get paid. They never touch our servers.
  • Invoice, quote, and job data: customer names and email addresses, descriptions of work, amounts, and any job photos you upload.
  • Photos and images: profile pictures and business logos you upload are publicly visible. Do not upload photos of other people without their permission.

2.2 Information collected automatically

  • Server logs: our hosting and database providers record IP addresses, browser type, and access times in routine server logs.
  • Activity records: we keep a history of actions on invoices, such as when one is sent, paid, or refunded.
  • Cookies: a login session cookie and a cookie that remembers your sidebar preference. See Section 8.
  • Push subscriptions: if you turn on notifications, we store the subscription token your browser or phone gives us so we can deliver them.

We do not use analytics or tracking tools. If that ever changes, we will update this policy before we start.

2.3 Information from third parties

  • Payment Processors: Transaction status and payment confirmation from Stripe
  • Authentication Providers: Basic profile information if you sign in with Google

2.4 If you pay an invoice

When you pay an invoice through handipay, we ask for your email address so we can send you a receipt and payment updates. Your name is optional. We attach your email to the invoice record, and we share it with Stripe so Stripe can process the payment and email your receipt. We share your payment confirmation with the business that billed you. We use Proton Mail to deliver your emails. We do not use your email for marketing. Card and bank details go directly to Stripe and never touch our servers. If you pay by pre-authorized debit, we email you the notices that banking rules require.

3. How we use your information

We use your personal information to:

  • Provide, maintain, and improve our payment and invoicing services
  • Process payments and facilitate transactions between merchants and customers
  • Verify your identity and comply with legal requirements (anti-money laundering, KYC)
  • Estimate applicable sales taxes (GST/HST, PST, QST) on invoices and quotes. Merchants stay responsible for collecting and remitting their own taxes.
  • Send transactional communications (invoices, quotes, receipts, payment confirmations, and security and account notices)
  • Provide customer support and respond to inquiries
  • Detect and prevent fraud, unauthorized access, and other illegal activities
  • Comply with legal obligations and enforce our terms of service

Every email we send is about your account or a transaction: invoices, quotes, receipts, payment updates, and security notices. We do not send marketing email. If we ever want to, we will ask your permission first, and every marketing message will say who we are and include a working unsubscribe link.

4. How we share your information

We may share your personal information with:

4.1 Service providers

  • Stripe (Stripe Payments Canada, Ltd. and affiliates): payment processing, identity verification, and payouts. Canada and the United States.
  • Supabase: database, login, and file storage. Hosted in Canada.
  • Vercel: application hosting. United States.
  • Proton Mail (Proton AG): delivers the emails we send, including invoices, receipts, and sign-in links. Switzerland.

4.2 Business partners

  • Invoice recipients receive your business name, contact information, and invoice details
  • Merchants receive customer names and payment confirmations for their invoices
  • Merchants: when you add a customer's name, email, or photos to handipay, you confirm you have the right to share them with us, and we use them only to provide the service to you.

4.3 Legal requirements

We may disclose information when required by law, including:

  • Court orders or subpoenas
  • Tax authorities (CRA) for tax compliance
  • Law enforcement for fraud investigation
  • Regulatory bodies for financial services compliance

5. Data security

We implement appropriate technical and organizational measures to protect your data:

  • Access controls: every database table is protected by row level security, so users and team members only see the records their role allows.
  • Payment security: card numbers go from your browser straight to Stripe and never touch our servers. Stripe is a certified PCI DSS Level 1 provider, and our integration follows the PCI DSS requirements for platforms that fully outsource card handling.
  • Bank details and identity information: when you connect a bank account, or when Stripe asks for identity information such as a Social Insurance Number, those details go straight to Stripe, inside its own secure flow, and never touch our servers.
  • Encryption: our hosting and database providers encrypt data in transit (TLS) and at rest.
  • Activity records: we keep records of payment and account activity so we can investigate problems.

6. Data retention and deletion

How long we keep things:

  • Account and profile information: while your account is open, then deleted or anonymized after closure as described below.
  • Invoices, quotes, receipts, and payment records: at least six years, as Canadian tax law requires.
  • Identity verification records: as long as Stripe and financial regulations require.
  • Server and email delivery logs: kept by our providers for their standard periods.
  • Sign-in recovery tokens: 24 hours.
  • Push subscription tokens: until you turn notifications off or close your account.

To close your account, email us at privacy@handipay.ca. Once your account is closed, we delete or anonymize the personal information we no longer need, normally within 30 days of closure, except records the law requires us to keep, such as tax, transaction, and identity verification records, and we will tell you what we kept and why. Information held by Stripe is kept under Stripe's own retention rules.

7. Your rights

You have the right to:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Withdrawal of consent: withdraw your consent for uses that are not required by law. If you withdraw consent for information we need to run your account, such as identity verification, we may have to close the account. Records the law makes us keep, we keep.
  • Deletion: ask us to close your account and delete the personal information we no longer need.
  • Portability (Quebec): ask for your computerized personal information in a structured, commonly used technological format.

To use any of these rights, email privacy@handipay.ca. We may ask you to confirm your identity first. We respond within 30 days. If we need more time or have to refuse part of a request (for example, records the law makes us keep), we will explain why and tell you what you can do next. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'accès à l'information.

8. Cookies

We use cookies and similar technologies for:

  • Essential Cookies: Authentication and session management (required for the service to function)
  • Preference Cookies: Remembering your settings and preferences

We do not use third-party advertising cookies or sell your data to advertisers. You can configure your browser to reject cookies, but this may affect your ability to use our services.

Specifically: cookies that keep you signed in, set by our login provider, and one cookie that remembers whether your sidebar is open.

9. Where your information is processed

Your account information is stored with our database provider in Canada. Some of our service providers process your information in the United States: Stripe (payments and identity verification) and Vercel (application hosting). Our email provider, Proton AG, processes your information in Switzerland. While your information is in another country, the courts, police, and national security authorities of that country can require access to it under that country's laws. Our contracts with each provider require them to protect your information to a standard comparable to this policy.

10. Children's privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

11. If something goes wrong

If a breach of our security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, and the Commission d'accès à l'information du Québec where Quebec law applies. Our notice will tell you what happened, what information was involved, and what you can do. We keep a record of every breach of security safeguards, as the law requires.

12. Quebec residents

The founder of handipay is our person in charge of the protection of personal information. You can reach them at privacy@handipay.ca. You can ask for a copy of the computerized personal information we hold about you in a structured, commonly used technological format. Stripe screens payments automatically to detect fraud, which can block a payment; if a decision about you is ever made entirely by automated means, we will tell you and you can ask a person to review it. Before we send personal information about Quebec residents outside Quebec, we assess whether it will receive adequate protection. You may complain to the Commission d'accès à l'information du Québec at www.cai.gouv.qc.ca.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. If a change means we would use your information for a new purpose, we will ask for your consent before we do it.

14. Contact us

If you have questions about this Privacy Policy or our privacy practices, please contact our Privacy Officer:

Our Privacy Officer is the founder of handipay. They are responsible for how handipay handles personal information.

handipay
Email: privacy@handipay.ca

You may also contact the Office of the Privacy Commissioner of Canada:
www.priv.gc.ca