Scope and our privacy roles
This Privacy Policy explains how Gorillo, LLC, doing business as Handout (“Handout,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information. It applies to our website at handout.link, the Handout application, browser extension, APIs, Model Context Protocol (“MCP”) tools, support and business communications, and the infrastructure used to deliver customer-created Handout sites (collectively, the “Services”).
This Policy covers account users, prospective customers, people who communicate with us, recipients whose information a customer enters, and visitors to customer-created sites. It does not govern a customer’s independent practices, a third-party site or service, or information that cannot reasonably be linked to a person.
The role depends on the context
A customer may have its own privacy notice, legal basis, consent obligations, and retention choices. If this Policy conflicts with our data processing terms for information we process for a customer, the data processing terms govern that processing.
Information we collect
Information you or your organization provide
- Account and profile information: name, business email address, password or one-time verification information, profile image, job or company details you choose to add, preferences, authentication records, and, if you choose Google sign-in, Google account identifiers, authorization tokens, and sign-in metadata needed to connect and secure the account.
- Workspace and team information: organization and workspace names, slugs and domains, logos, team memberships, roles, invitee email addresses, invitations, and administrator actions.
- Customer Content: text, layouts, structured editor content, images, logos, GIFs, links, files, videos, embeds, calendar links, variables, design settings, drafts, published versions, and collaborative editing data.
- Recipient and personalization information: recipient name, company, website or domain, customer-defined variable values, public-link codes, and other information a customer chooses to use to personalize a site. Handout is not designed to store recipient email addresses in the canonical recipient record.
- Billing and transaction information: plan, billing interval, seat count, subscription status, transaction references, and Stripe customer, subscription, price, and billing-period identifiers. Stripe collects and processes payment-card and bank details; Handout does not store full payment-card numbers.
- Communications: support requests, feedback, survey responses, security reports, legal requests, and related attachments and correspondence.
- Integrations and automations: webhook configuration, destination host, encrypted endpoint and signing secret, trigger and filter settings, delivery status, and payload snapshots; credentials, authorization grants, and commands for customer-authorized MCP or agent clients; and configuration for optional third-party content.
Information collected automatically from account users
- Device and network information: IP address, browser and operating-system type, user agent, device characteristics, request timestamps, and general network and diagnostic data.
- Usage and security information: authentication and session activity, feature interactions, error and performance data, audit-relevant actions, rate-limit signals, and suspected abuse or security events.
- Local application information: interface preferences, recovery and navigation state, and local offline copies of collaborative documents maintained in browser storage.
Some information is required to create an account, secure access, enter a subscription, or provide a requested feature. If you do not provide it, we may be unable to create the account, process payment, or deliver that feature. Other profile, content, recipient, and integration information is optional and is processed when a user chooses to provide or configure it.
Notice at collection
| Category | Examples | Purposes | Retention |
|---|---|---|---|
| Identifiers and account credentials | Name, business email, account and provider IDs, authentication records, tokens, and profile image | Create and secure accounts, authenticate users, communicate, prevent abuse, and provide support | Account term and a reasonable period for security, disputes, and legal obligations; shorter-lived codes and sessions expire or are revoked sooner |
| Customer records, professional information, and content | Organization, role, workspace, team, sites, recipient context, variables, files, and collaboration data | Provide collaboration, publishing, personalization, support, and customer-directed features | Account or subscription term and a reasonable wind-down, backup, dispute, or legal period |
| Commercial and billing information | Plan, seats, subscription status, invoices, and Stripe references | Checkout, billing, tax, fraud prevention, account administration, and financial records | Subscription term and applicable tax, accounting, chargeback, fraud, and limitation periods |
| Internet, device, usage, and approximate location information | IP address, browser, operating system, timestamps, feature activity, diagnostics, and coarse location | Deliver and secure the Services, troubleshoot, measure performance, enforce limits, and prevent abuse | Only as reasonably needed for the purpose, using the specific analytics periods in Section 12 where applicable |
| Communications and integration information | Support and legal correspondence, webhook settings and delivery records, OAuth grants, and agent commands | Respond to requests and operate customer-authorized integrations, automations, and legal processes | For the request or integration lifecycle and the webhook and legal-record periods in Section 12 |
Information from other sources
We may receive information from your organization’s administrator or team members, payment and email providers, authentication and infrastructure providers, including Google if you choose Google sign-in, security and fraud-prevention sources, public websites a user asks us to access for a company logo or remote asset, and a third-party client that a user authorizes to access Handout. We may combine that information with information described above.
Visitors to customer-created sites
Customer-created sites may be personalized and may include measurement features chosen by the customer. The particular settings for a site or recipient determine what Handout processes.
Public link and personalization context
When you open a Handout site, the public URL or link code may identify a site and a customer-defined recipient record. Personalized links may contain a recipient name, company, domain, or variable in the path or query string. URLs can be visible to anyone who receives or forwards the link and may be stored in browser history, server or network logs, chat previews, and referrer information handled by third parties. Do not treat a Handout link as an access-controlled data room.
Activity measurement
If the site owner enables activity measurement and any required consent has been obtained, Handout may process a site visit, button or link click, tab change, visit time, active time, session state, and a limited link-preview or bot signal. We may derive a broad browser, operating system, and device category from the user agent and use trusted edge headers to record a coarse city, region, and country.
Handout’s customer-site activity system is designed not to store a raw visitor IP address, persistent device identifier or fingerprint, full visited URL, URL query or fragment, referring URL, arbitrary DOM labels, or a cross-site browsing profile in the customer-facing tracking record. A raw IP address may be processed transiently for security, rate-limiting, customer-configured internal-network suppression, and coarse geolocation, and then discarded from that record. Infrastructure providers may retain network logs for security and service delivery.
Visitor notice at collection
Session replay
A site owner on an eligible plan may enable session replay only after accepting the replay terms and obtaining the visitor’s affirmative consent where Handout presents the choice. Replay may capture a time-ordered, sanitized representation of visible page text and structure, clicks, cursor movements, scrolling, viewport changes, timing, and page changes so the owner can understand the visit.
Handout configures replay to mask values entered into input fields and text areas and to omit placeholders, scripts, embedded frames, designated blocked regions, canvas contents, cross-origin frames, clipboard data, cookies, browser storage, audio, camera, microphone, and raw IP addresses. URL credentials, query strings, and fragments are removed from recorded URLs. Image or font inlining is disabled. These controls reduce risk but cannot guarantee that a customer will never place personal information in otherwise visible page text or misconfigure its content.
Replay is bounded to approximately ten minutes, 20,000 captured events, or 5 MiB of uncompressed event data per recording, whichever limit is reached first. Selecting “decline” prevents consent-gated measurement from starting. Withdrawing through the site’s Privacy choices control stops ongoing consent-gated collection for that browser.
Customer-directed webhooks
A customer may configure Handout to send selected visit or interaction data to an HTTPS endpoint that the customer controls or selects. The destination receives information on the customer’s instructions and is governed by the customer’s and destination provider’s practices. Handout signs deliveries when configured; endpoint and signing credentials are encrypted at rest.
Browser extension, APIs, MCP, and agents
Gmail browser extension
The Handout extension uses browser identity and local-storage permissions and runs on Gmail pages so a signed-in user can select a recipient and insert a Handout link or card into a draft. It reads the primary compose recipient’s email address and displayed name and a compose identifier locally to provide that action. It is designed not to read or transmit the email subject, message body, thread contents, attachments, contacts, or Google access tokens. It transmits information to Handout only when needed for a user-requested Handout action. The extension stores a Handout access token and recent preferences in local browser-extension storage.
Customer-authorized clients and agents
Handout may expose APIs or MCP tools that let a user-authorized software client or AI agent list, create, read, update, validate, publish, or delete customer content and recipients, or read tracking information. We process the authorization grant, access token, tool input, tool output, and relevant audit or security data required to provide that access. The third-party client or model provider independently processes information the user sends to it under its own terms and privacy policy. Handout does not send Customer Content to an AI model merely because MCP access is available. We do not use Customer Content to train a shared generative-AI model or disclose it to a model provider for that provider’s training unless the customer expressly directs or separately agrees to that use.
How we use personal information
We use personal information to:
- provide, authenticate, operate, maintain, personalize, and support the Services;
- create and manage accounts, workspaces, teams, invitations, sites, recipient links, published versions, previews, integrations, and subscriptions;
- process customer instructions, including consented site measurement, replay, webhooks, and authorized API or agent actions;
- communicate about transactions, verification, password resets, invitations, service changes, support, security, and legal matters;
- send requested product news, events, surveys, or business marketing where permitted, and manage communication preferences and opt-outs;
- provide customer service, diagnose errors, test features, understand aggregate product performance, and improve usability and reliability;
- prevent fraud, spam, malware, unauthorized access, abuse, excessive resource use, and violations of our Terms;
- protect users, visitors, Handout, and the public; enforce agreements; preserve evidence; and establish, exercise, or defend legal claims;
- comply with law, valid legal process, sanctions, accounting, tax, and regulatory obligations; and
- conduct a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction.
We may aggregate or de-identify information and use it for lawful purposes. We will not attempt to re-identify data that applicable law requires us to maintain as de-identified.
Legal bases for processing
Where European Economic Area, United Kingdom, Swiss, or similar law requires a legal basis, our bases depend on the context:
- Contract: processing needed to provide an account or requested Service, administer subscriptions, and respond to requested support.
- Legitimate interests: securing and improving the Services, preventing abuse, communicating with business users, administering our business, and protecting legal rights, balanced against affected individuals’ rights.
- Consent: where we ask for an optional choice, including consent-gated measurement or session replay. Consent may be withdrawn without affecting earlier lawful processing.
- Legal obligation: tax, accounting, compliance, lawful requests, and other obligations imposed by law.
- Legal claims and vital interests: where necessary to protect a person or establish, exercise, or defend claims.
When we act for a customer, the customer determines the legal basis for its processing. Customers must not enable tracking, replay, embeds, personalization, or webhooks unless they have a valid basis and provide all required notices and choices.
How we disclose information
We may disclose personal information to:
- Your organization and workspace: administrators and authorized team members may access and control workspace accounts, content, recipients, tracking, integrations, billing, and audit-relevant activity. If you use an organization email address, we may help the organization verify or administer its relationship with the account.
- The public and link recipients: published sites, assets, recipient-specific content, and generated preview images are available to anyone with the relevant public link and may be cached, copied, indexed if enabled, or shared.
- Service providers and subprocessors: companies that provide hosting, storage, databases, edge delivery, email, payments, security, error diagnosis, and support under contracts limiting their use of the information.
- Customer-directed recipients: webhook endpoints, embedded-service providers, remote asset hosts, MCP or API clients, and other services a customer chooses to connect or display.
- Professional advisers and transaction parties:lawyers, auditors, insurers, lenders, investors, and actual or prospective participants in a corporate transaction, subject to appropriate safeguards.
- Authorities and affected parties: when we reasonably believe disclosure is required by law or valid process, or necessary to protect rights, safety, security, property, users, or the public.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, use it for targeted advertising, or profile people to make decisions producing legal or similarly significant effects. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 18.
Third-party content and customer directions
A customer site may load an image, GIF, video, iframe, calendar, social preview, or other content from a third party such as GIPHY, YouTube, Vimeo, Loom, Calendly, or Cal.com. The editor may also request search results from GIPHY or a company logo from Logo.dev. Loading third-party content can disclose the visitor’s IP address, browser information, referring page, and interaction data directly to that provider and may allow the provider to set its own cookies.
The customer selects and controls those resources. Their providers are independent parties governed by their own notices. Handout does not control their collection, security, availability, or use. Site owners must evaluate whether to gate an embed or obtain additional consent.
Our marketing website may load interactive presentation code through Unicorn Studio and the jsDelivr content-delivery network. Those providers may receive ordinary network and browser request information, such as an IP address, user agent, requested asset, and time, under their own practices.
Service providers and subprocessors
The following providers support material parts of the current Services. A provider may process information in the United States and other countries where it or its approved subprocessors operate.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. | DNS, edge security and delivery, Pages/Workers hosting, caching, and private R2 object storage | Network and request data, public content, and encrypted or access-controlled replay/preview objects as applicable |
| Render Services, Inc. | API, background-worker, and scheduled-job hosting in the United States | Account, workspace, content, tracking, automation, and operational data processed by the application |
| Neon, Inc. | Managed PostgreSQL database infrastructure | Account, workspace, content, recipient, tracking, integration, billing-reference, and operational records |
| Resend, Inc. | Transactional email delivery | Email address, name where needed, template variables, delivery and diagnostic data |
| Google LLC | Optional Google account sign-in and authentication infrastructure | Name, email address, Google account and provider identifiers, OAuth tokens, and sign-in metadata |
| Stripe, Inc. | Checkout, subscription, invoicing, tax, fraud prevention, and payment processing | Contact, organization, plan, seat, transaction, payment, and billing information |
| Logo.dev | Customer-requested company-logo lookup | Requested company domain and related network/diagnostic data |
| jsDelivr and Unicorn Studio | Delivery and operation of interactive visuals on Handout’s marketing website | IP address, user agent, requested asset, referring page, timing, and related network/diagnostic data |
GIPHY and customer-selected embed, webhook, or agent providers receive information at the user’s direction and may act as independent controllers rather than Handout subprocessors. We may replace or add providers as our Services evolve. Customers with a DPA receive the subprocessor notice and objection rights described there.
International data transfers
Handout is based in the United States. If you access the Services from another country, information may be transferred to and processed in the United States and other jurisdictions whose laws may differ from yours.
Where required and properly completed, we rely on approved transfer safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, with transfer assessments and supplementary measures as appropriate. The online DPA does not by itself supply party addresses, contact-person details, signatures, dates, or other information a transfer instrument requires. A customer must contact us to complete a transfer schedule before making a restricted transfer unless another lawful mechanism applies. We do not claim participation in a privacy certification or framework unless it is expressly stated on this page. You may request information about the safeguard relevant to your transfer by contacting us.
Retention and deletion
We retain personal information only as long as reasonably necessary for the purposes described here, customer instructions, and legal, security, tax, accounting, dispute, and enforcement needs. Criteria include the account or contract term, configuration selected by a customer, data sensitivity, backup cycles, limitation periods, and the need to prevent abuse or preserve evidence.
| Data | Current operational period | What happens next |
|---|---|---|
| Customer-site activity events and session summaries | Customer-selected 30, 90, 180, or 365 days; 90 days by default | Expired events and related session data are deleted or de-identified through retention jobs, subject to backups and legal holds. |
| Session replay objects and metadata | Customer-selected 7, 14, or 30 days; 14 days by default and 30 days maximum | Objects and metadata are queued for deletion; provider lifecycle and backup copies may persist for a limited period. |
| Webhook message payload snapshots | 7 days after creation, once no delivery is pending | Payload fields are redacted; limited delivery activity may remain. |
| Webhook messages, retired revisions, and delivery activity | 30 days after creation or retirement, once no delivery is pending | Activity is deleted; monthly aggregate usage may be retained for up to 12 months. |
| Customer-site consent choice | Up to 180 days in that site visitor’s browser | Replaced by a new decision or removed when browser storage is cleared. |
| Account, workspace, content, recipients, and billing references | For the account or subscription term and a reasonable period afterward | Deleted, returned, de-identified, or retained only where needed for backup cycles, security, payment, tax, claims, or legal obligations. |
| Terms acceptance records | For the agreement term and applicable contract, claims, audit, and legal limitation periods | A version, timestamp, account identifier, email snapshot, and limited request evidence may be retained after account deletion when reasonably needed to prove or enforce the agreement. |
| Support, security, and legal records | For the time needed to resolve the matter and meet limitation, audit, compliance, or enforcement needs | Deleted or de-identified when the purpose no longer applies. |
Public content or preview images copied, cached, indexed, or shared by recipients or third parties may remain outside our control after a customer unpublishes or deletes it. Local offline editor data may remain on a user’s device until browser data is cleared. Deletion from active systems does not always immediately remove encrypted backup copies; backups remain protected and age out under ordinary cycles unless law requires preservation.
Security
We use administrative, technical, and organizational safeguards designed for the nature of the Services and information, including transport encryption, access controls, tenant-aware authorization, secret and credential protection, private object storage for replay data, rate-limiting, log redaction, security monitoring, backup and recovery measures, and software testing. We review safeguards as risks and the Services evolve.
No service, network, or storage method is completely secure. Customers are responsible for strong credentials, account access, team roles, endpoint security, link sharing, connected services, and promptly reporting suspected compromise. Email us immediately if you believe an account, public link, or integration has been compromised.
Your privacy rights
Depending on where you live and subject to exceptions, you may have the right to request access, confirmation, correction, deletion, portability, or restriction of personal information; object to processing; withdraw consent; opt out of certain sales, sharing, targeted advertising, or profiling; obtain information about or a list of recipients where applicable; and appeal a denied request. You may also complain to your local data-protection authority.
Email hello@handout.link with the subject “Privacy Request.” Describe the right and context, and provide enough information for us to locate the relevant account or visit. For a customer-site visit, include the public site address, approximate date and time, and site owner if known. Avoid emailing passwords, full payment details, or other sensitive information.
If Handout processed the information only for a customer, we may direct the request to that customer and assist it as required. We may verify your identity and authority using information proportionate to the request. An authorized agent may submit a request where law permits; we may require proof of authorization and direct verification with the individual. We will not discriminate against you for exercising a right.
To appeal a decision, reply to our response with “Privacy Appeal” and explain your concern. We will respond within the period required by applicable law and provide any regulator contact required after a denied appeal.
You may opt out of optional marketing at any time through the unsubscribe mechanism in the message or by contacting us. We may still send transactional, security, billing, and legal communications needed for the account or Services.
United States state privacy disclosures
This section supplements the Policy for residents of California and other states with comprehensive privacy laws. In the preceding 12 months, depending on the person and features used, we collected the categories below. The examples are descriptive and do not mean we collect every item about every person.
| Category | Examples | Sources and recipients |
|---|---|---|
| Identifiers | Name, business email, account ID, IP address, session token, public-link code, device or integration identifier | You, your organization, devices, customers, and providers; disclosed as described in Sections 8 and 10. |
| Customer-record and commercial information | Organization, subscription, plan, seat count, invoices, payment references, support and transaction history | You, organization administrators, and Stripe; disclosed to business providers and advisers. |
| Internet or electronic activity | Authentication, app use, customer-site interactions, clicks, scrolling, session timing, replay, browser and device category | Devices and service interactions; disclosed to the applicable customer and infrastructure providers. |
| Approximate geolocation | Coarse city, region, and country derived from trusted network headers | Network and edge provider; disclosed to the applicable customer and service providers. |
| Professional or employment-related information | Business affiliation, role, customer-entered recipient company, or profile details | You, your organization, customers, and public/business sources at a user’s direction. |
| Visual or interaction information | Profile images, uploaded assets, public content, and sanitized session-replay representations; no replay audio | Users, customers, and consented visitor interactions; disclosed to authorized workspace users and processors. |
| Inferences | Broad browser, operating-system, or device category inferred from user agent | Technical signals; disclosed to the applicable customer and providers. We do not use these for significant automated decisions. |
| Sensitive personal information | Account credentials and precise access tokens; content a customer improperly submits may contain other sensitive information | Users and customers; used only for permitted service, security, and compliance purposes, not to infer characteristics. |
We collect and use these categories for the business and commercial purposes in Section 6 and retain them using the criteria in Section 12. We do not use or disclose sensitive personal information for purposes requiring a California right to limit. We do not offer financial incentives for personal information.
Because we do not sell or share personal information for cross-context behavioral advertising, we do not provide a sale/share opt-out link. We do not respond to browser-based opt-out preference signals as a sale/share request where no such processing occurs. We will honor any legally required signal if our practices change.
We do not change ordinary first-party service processing in response to the legacy browser “Do Not Track” signal because Handout does not use that processing to follow a person across unrelated services over time. Customer-selected embeds and other third-party resources described in Section 9 may receive data directly and apply their own signal practices.
In the preceding 12 months, we disclosed the categories in the table above to service providers and contractors for the business purposes in Sections 6 and 10. We did not sell or share those categories and do not have actual knowledge that we sold or shared personal information of anyone under 16.
We do not disclose personal information to third parties for their own direct-marketing purposes as contemplated by California’s “Shine the Light” law. California residents may still contact us with a request about that practice.
Children
The Services are business tools and are not directed to children under 18. You must be at least 18 to create or use an account. Customers may not use Handout to intentionally collect personal information from children under 13 in the United States, under 16 in the EEA or United Kingdom where consent rules apply, or under the corresponding minimum age in another jurisdiction, without our prior written approval and all legally required parental authorization.
If you believe a child provided personal information to us contrary to this section, contact us so we can investigate and take appropriate action.
Sensitive and regulated information
Handout is not designed for protected health information subject to HIPAA, payment-card data subject to PCI DSS beyond use of Stripe’s payment interface, nonpublic consumer financial information governed by GLBA, biometric identifiers, precise geolocation, genetic data, education records, government identifiers, account passwords, or other highly sensitive or specially regulated data in Customer Content, recipient variables, replay-visible content, or webhook payloads.
Do not submit that information unless Handout has expressly agreed in writing to the processing and any required addendum. We do not sign a HIPAA Business Associate Agreement through standard online acceptance. Customers remain responsible for determining whether their content, visitors, recipients, and intended use are appropriate for the Services.
Additional regional information
EEA, United Kingdom, and Switzerland
Handout is the controller for the account and operational processing identified in Section 1. You may contact us about our legitimate-interest assessment or transfer safeguards. You may lodge a complaint with the supervisory authority where you live, work, or believe a violation occurred. If applicable law requires Handout to appoint a local representative for processing within its territorial scope, we will make the representative’s contact details available here or on request.
Canada
You may request access to or correction of personal information and ask about our service providers outside Canada. We rely on consent or another basis permitted by applicable federal or provincial law and use contractual and other measures for transferred information.
Australia, Brazil, and other jurisdictions
We honor rights required by applicable law, including access, correction, deletion, information about processing and sharing, portability, revocation of consent, and review of automated decisions where relevant. Handout does not currently use personal information for solely automated decisions with legal or similarly significant effects.
Changes to this Policy
We may update this Policy to reflect changes in law, providers, technology, or the Services. We will post the revised version and update the date above. If a change materially reduces protections or introduces a materially different use of personal information, we will provide additional notice or seek consent where required. Earlier versions may be requested by email.
Contact us
Questions, privacy requests, and complaints may be sent to:
Gorillo, LLC, doing business as HandoutAttn: Privacy
Email: hello@handout.link
Please use “Privacy Request” in the subject line. If your request concerns a customer-created site, identify that site and its owner if possible so we can route the request without unnecessary delay.