1. Who we are
HANDL is a trading name of HANDL Auto Ltd, a company registered in England and Wales (“HANDL”, “we”, “us”). We are the data controller for the personal data we process about our customers. Our registered address and full contact details are at the end of this policy.
2. Data we collect
We collect data you give us directly and data generated as you use HANDL:
- Account details — name, email, phone number and password.
- Booking details — service address, vehicle information, appointment times and any notes you provide.
- Payment data — handled by Stripe; we receive confirmation, the last four digits of your card and billing references, but not your full card number.
- Usage data — device, browser, IP address and how you interact with our platform.
- Communications — messages to our support team, ratings and reviews.
- Location — service location and, with your consent, approximate device location to find nearby detailers.
3. How we use your data
We use your data to provide and improve the service, including to: create and manage your account; match you with detailers and arrange bookings; take payment and issue VAT receipts; send service messages and updates; provide customer support; ensure safety and prevent fraud; meet legal obligations; and, where you have opted in, send marketing about HANDL.
4. Legal bases (UK GDPR)
We rely on: performance of a contract to deliver bookings you request; legitimate interests to run, secure and improve our service; consent for optional cookies and marketing (which you can withdraw at any time); and legal obligation for tax, accounting and compliance.
6. Payments via Stripe
Card payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Your card details are sent directly to Stripe over an encrypted connection and are not stored on HANDL’s own servers. Stripe processes this data as an independent controller and processor in accordance with its own privacy policy, which we encourage you to read.
8. Data retention
We keep personal data only as long as necessary for the purposes above. Booking and transaction records are typically retained for up to six years to meet UK tax and accounting requirements. Account data is deleted or anonymised within a reasonable period after you close your account, subject to any legal retention obligations.
9. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and vetted, instructed processors. No system is perfectly secure, but we work hard to safeguard your information and will notify you and the regulator where required if a breach occurs.
10. Your rights
Under UK GDPR you have the right to access your data; to correct inaccuracies; to request erasure; to restrict or object to certain processing; to data portability; and to withdraw consent at any time where processing is based on consent. To exercise any of these, email privacy@handlauto.com. We respond within one month.
11. International transfers
Some of our processors operate outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place — such as UK adequacy regulations or the International Data Transfer Agreement — so your data receives an equivalent level of protection.
12. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows the latest version, and we will give reasonable notice of material changes — for example by email or an in-app notice.
13. Contact & complaints
For any privacy question, contact our data protection team at privacy@handlauto.com or write to HANDL Auto Ltd, London, United Kingdom. If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk — though we’d always appreciate the chance to put things right first.