Handsent Privacy Policy
Effective September 1, 2026
Handsent is operated by Buildnode Inc. ("Buildnode", "we"), 2015 Main St, Vancouver, BC, Canada. Contact: hello@buildnode.io.
This policy explains what Handsent collects, how it uses it, and the specific way it handles data from your Google account.
1. What Handsent is
Handsent sends personalized email campaigns from a Gmail or Google Workspace account you connect, to contacts you supply, and reports replies. It is a tool you operate; you are the sender and the data controller for your contacts.
2. Information we collect
- Account: your name, email address and profile picture from Google Sign-In; your organization name and members.
- Google user data (only after you connect an inbox and grant the permissions listed in section 3): an OAuth refresh token for that account; the email address of the inbox; message headers, snippets and thread membership for threads Handsent itself created; the subject and body of a Gmail draft you select as a template; the contents of spreadsheets you connect as a list.
- Contacts and content you provide: recipient addresses and merge fields (from a sheet, a CSV upload, or the API), templates, campaign settings.
- Operational records: every message Handsent sent (recipient, subject, time, Gmail message and thread ids), delivery outcomes, an audit log of actions taken in your workspace and by whom, webhook deliveries, and standard server logs (IP address, user agent, timestamps).
3. Google user data: permissions, use, storage, sharing
Handsent's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
| Google permission (scope) | What Handsent does with it | What it does not do |
|---|---|---|
Send email on your behalf (gmail.send) | Sends the campaign emails, follow-ups, test emails and daily summaries you set up, from your inbox. | Never sends anything you did not create and start. |
View your email messages and settings (gmail.readonly) | Reads the messages in threads Handsent started, to detect replies, bounces, out-of-office auto-replies and unsubscribe requests; reads the Gmail draft you selected as a template. | Never reads, indexes, stores or searches the rest of your mailbox. Message bodies of replies are not stored; only a short snippet and the classification (replied / bounced / unsubscribed). |
See, edit, create and delete your spreadsheets (spreadsheets) | Reads the spreadsheet you connected as a list; writes a status, last-sent time and note into three columns of that same sheet. | Never opens spreadsheets you did not connect, and never deletes anything. |
Storage. OAuth tokens are stored encrypted at rest in our database on AWS (us-west-2) and are used only to make the API calls above. Thread ids, message ids, snippets and classifications are stored to run your campaigns and show you results.
Sharing. We do not sell Google user data, do not share it with third parties, do not use it for advertising, do not use it to build profiles, and do not use it to train machine-learning models. It is processed only by Buildnode's own infrastructure (AWS) to provide the features above. No person at Buildnode reads your Google data unless you ask us to for support, or it is required for security investigation or to comply with the law.
Retention and deletion. Disconnecting an inbox deletes its tokens immediately. Deleting your workspace deletes all Google user data, contacts and campaign records within 30 days (backups are retained for a further 30 days and then expire). You can also email hello@buildnode.io to request deletion. You can revoke Handsent's access at any time at myaccount.google.com/permissions.
4. How we use other information
To operate the service, keep it secure, show you your own history and audit log, respond to support requests, and send you service messages about your account. We do not use your contacts' data for any purpose other than sending the campaigns you start.
5. Your contacts
You are responsible for having a lawful basis to email each contact (for example consent, an existing business relationship, or a published business address under CASL) and for honoring unsubscribe requests. Handsent records unsubscribe requests and bounces and prevents further sends to those addresses automatically.
6. Service providers
Amazon Web Services (hosting and encrypted backups, us-west-2) and Google (APIs described above). We do not use analytics or advertising trackers on the app.
7. Security
Encryption in transit (TLS) and at rest (encrypted volumes and backups), least-privilege access, org-scoped API keys, signed webhooks, and an audit log of every action. Report security issues to hello@buildnode.io.
8. Your rights
Access, correction, export and deletion of your data on request; users in the EU/UK and Canada have the rights provided by GDPR/UK GDPR and PIPEDA respectively.
9. Changes
We will post changes here and update the effective date; material changes are announced in the app.