Privacy
Last updated 14 August 2026
Handled Locator is a store locator you embed on your own website. This page explains what we collect from two different groups of people: customers, who have an account with us, and visitors, who load a locator on a customer's site. The answers are very different.
If you are a visitor to a site using our locator
We do not set cookies on you, we do not track you across sites, and we do not build a profile of you. Loading a locator sends the request our public API needs to answer it: the site identifier of the locator, and the network-level information any web request carries.
If you search by place name, the text you type is sent to a geocoding service to turn it into coordinates. If you allow the browser's location prompt, your coordinates are used in your browser to sort results by distance. We do not store either.
The map itself is served by the site owner's own Mapbox or Google Maps account, under that provider's privacy policy rather than ours.
If you are a customer
We collect and store:
- Your account: email address, name, and the business details you enter.
- Your locations: everything you import or type. Addresses, coordinates, opening hours, contact details, categories and any custom fields.
- Your settings: layout, styling, labels and the map key you provide.
- Product usage: which setup steps you have completed and aggregate counts of how often your locator was loaded. Deliberately narrow: no page URLs, no raw referrers and no free-text campaign data reach your account record.
When you connect Google Sheets
Connecting Google Sheets is optional and separate from signing in to Handled Locator. Google asks you to choose a spreadsheet, and the permission is limited to files you deliberately select for use with Handled. We receive the selected file's identifier, its sheet names and the location data in the selected sheet so we can show a change preview and perform the sync you configure.
Handled requests Google's per-file drive.file permission. Although Google describes that permission as allowing management of selected files, Handled only reads the spreadsheet and never writes back to it. We do not browse other files in your Drive, use Google user data for advertising, or use it to train AI models.
We keep an encrypted Google refresh token for scheduled syncs. Disconnect Google in the Data page to revoke Google access and delete that token, the saved source connection and its synchronization history. Deleting your Google connection does not delete the locations that were already imported into your Handled account.
Handled Locator's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Who else processes it
- Supabase: database, authentication and file storage.
- Amazon Web Services: hosting and content delivery.
- PostHog: marketing-page analytics and the limited setup milestones described below. Dashboard contents, form values and session replays are excluded.
- tawk.to:the live chat on this marketing site. If you open it, the conversation and the page you were on are recorded and stored by tawk.to. It is not on the dashboard, and it is never loaded on a customer's own site.
- Square: subscription payments. Card details go to Square directly and we never receive or store them.
- Mapbox or Google Maps: maps and geocoding, on the key you supply.
- Google Workspace: authorization, file selection and read-only access to a Google Sheet you connect.
- Google Ads: measuring which adverts lead to a trial. It receives the click identifier from the advert you arrived on and a signal that a trial started. It does not receive your name, email address, or anything from your locator.
We do not sell your data and we do not use your locations to build anything other than your locator. We do share one thing with an advertising platform: if you reached us from a Google advert, Google Ads is told that the click led to a trial, so we can tell which adverts are worth paying for. That signal carries no personal detail and nothing from your locations.
How long we keep it
For as long as your account is open. Delete a location and it is soft-deleted first so you can undo the mistake, then removed. Close your account and we delete your data within 30 days, apart from what we have to keep for tax and accounting records.
What you can ask for
Export your locations at any time from the dashboard, as the CSV you put in. You can also ask us for a copy of everything we hold, ask us to correct it, or ask us to delete it. Email hello@handledlocal.com and we will action it within 30 days.
Cookies
On the dashboard we set the cookies needed to keep you signed in. On this marketing site we use privacy-preserving analytics to count visits and call-to-action clicks. If you create an account, an anonymous account identifier joins that marketing journey to setup milestones such as importing locations and installing the widget, so we can understand which campaigns produce working locators rather than just clicks. Dashboard page contents, form values and session replays are not captured, and our own analytics does not follow you to other websites. Since we began advertising, Google's advertising tag also runs on both sites and sets its own cookies, which is how a click on an advert can be matched to the trial it produced. We use it for that measurement only; we do not run remarketing, and we do not build audiences from your visit.
The live chat on this marketing site is provided by tawk.to and sets its own cookies so a conversation survives you moving between pages. It loads after the page is interactive, so it cannot slow the page down, and it is not present on the dashboard. If you never open the chat, you never send tawk.to a message; if you do open it, treat what you type as recorded, because it is.
Contact
Questions about any of this go to hello@handledlocal.com.