Privacy Policy

Last updated: August 7, 2026

Who we are

OfficeHand (“we”, “us”) provides an AI-assisted customer-communication and scheduling service for home-service businesses. This policy explains what we collect and why.

Data we process

How we use it

Exclusively to operate the product for your business: drafting replies, computing availability, escalating decisions to you, and syncing job status back to your lead sources. We do not sell data, use it for advertising, or train shared models on your customers' messages.

Google user data

OfficeHand connects to your Google Calendar to view your existing schedule and automatically propose available booking times to incoming lead requests. Connecting Google is optional; the rest of the product works without it.

With your permission (granted through Google's own consent screen) we request these scopes and use them only as described:

Busy times from your selected calendars are stored in your organization's private area of our database solely to compute availability. We do not sell, rent, or share your Google data; we do not use it for advertising; and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. Google data is never transferred to others except as needed to provide or improve this functionality, to comply with applicable law, or as part of a merger or acquisition with notice to you. No OfficeHand staff read your Google data except with your explicit permission for support, for security purposes, or where required by law.

You can disconnect at any time in Integrations → Google Calendar. Disconnecting immediately revokes our access token at Google and deletes the imported busy times from our database. You can also revoke access at myaccount.google.com/permissions.

OfficeHand's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing

Data is shared only with processors necessary to run the service (hosting, Stripe for payments, the lead-source APIs you connect, and notification channels you configure such as Telegram). Each receives only what its function requires.

Retention & deletion

Your data is retained while your account is active. Deleting your account removes your organization's leads, messages, calendars, and settings within 30 days. You may request export or deletion at any time.

Security

Data is encrypted in transit, access is scoped per organization, and webhook endpoints use unguessable per-tenant URLs with optional HTTP authentication.

Contact

Privacy questions: diego@spartanit.pro