Legal · ClearHandshake

Privacy Policy

Effective date: July 19, 2026

This Privacy Policy explains how ClearHandshake (“ClearHandshake,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use our commercial risk reporting product at https://clearhandshake.co and related app surfaces (the “Service”).

Plain summary: we collect the contact details and contract text you submit so we can run a commercial risk report, attach free full-report allotments to your email, and (if you opt in) notify you about Pro features. We do not sell personal data. Scan text is intended for short retention (~7 days). This product provides commercial insights only — not legal advice.

1. Who we are

Controller / operator: ClearHandshake. Privacy and support contact: nessykalvo@gmail.com.

2. Information we collect

Information you provide

  • Contact details for lead capture and free-report allotment: first name, last name, work email, and role/title.
  • Contract or SOW text you paste for analysis.
  • Waiver acknowledgements (for example, B2B commercial scope and “not legal advice” certification).
  • Pro waitlist details if you ask to be notified when paid unlocks or Pro features launch (email and optional name/role).
  • Support messages you send to us.

Information collected automatically

  • Standard technical logs such as IP address, user agent, approximate location derived from IP (used for region messaging), timestamps, and request metadata from our hosting provider.
  • Security and abuse-prevention signals needed to operate the Service, including bot-check outcomes (for example Cloudflare Turnstile), disposable-email blocks, and rate-limit events.
  • Hashed network identifiers (SHA-256 of IP address plus a server secret) used only for abuse rate limits and founder ops counters. We aim not to store raw IP addresses in application databases for this purpose.

We do not intentionally collect special-category data (health, biometrics, precise geolocation beyond coarse IP, etc.). Do not paste personal data that is not needed for a commercial B2B contract review.

3. How we use information

  • Provide commercial risk scoring and report generation.
  • Enforce free full-report allotments per email and lock premium fields server-side.
  • Operate Pro waitlist notifications when billing features launch.
  • Maintain security, prevent abuse, debug failures, and improve model/heuristic quality.
  • Comply with law and enforce our Terms of Service.
  • Contact you about the Service, including transactional messages related to your scan or waitlist request.

We do not use submitted contracts to provide legal advice, establish an attorney-client relationship, or train public foundation models under this policy’s ordinary product path.

4. Legal bases (EEA/UK users)

Where GDPR/UK GDPR applies, we rely on:

  • Contract / steps prior to contract — processing contact + contract text to deliver the report you request.
  • Legitimate interests — securing the Service, preventing abuse, product analytics limited to operating the Service, and Pro waitlist product planning, balanced against your rights.
  • Consent — where required for optional marketing messages or non-essential cookies/pixels (we aim to avoid non-essential tracking on the core app unless separately disclosed and consented).
  • Legal obligation — when we must retain or disclose information to comply with law.

5. AI / automated analysis

Contract text may be processed by automated systems, including third-party large language model providers (when configured), and deterministic commercial heuristics. Outputs are commercial risk insights only. You should not rely on them as legal conclusions. Do not submit secrets, passwords, or unnecessary personal data inside contract paste fields.

6. Sharing

We share data only with processors needed to run the Service, for example:

  • Hosting and edge infrastructure (for example Vercel).
  • Database and backend infrastructure (for example Supabase / Postgres).
  • Model inference providers when the OpenAI (or successor) path is enabled.
  • Email delivery providers if transactional or waitlist email is configured.
  • Bot-check / CAPTCHA providers (for example Cloudflare Turnstile) when enabled on scan submit.
  • Payment processors if/when Stripe billing is enabled (not required for free allotment use).

We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required).

We do not sell personal information and we do not share personal information for cross-context behavioral advertising as those terms are commonly defined under US state privacy laws.

7. International transfers

We may process data in the United States and other countries where our providers operate. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) offered by those providers.

8. Retention

  • Scan / contract text rows: designed for short retention, targeting automatic cleanup on the order of ~7 days after creation, unless a longer period is required for security, dispute, or legal reasons. Scan rows may include a hashed IP for rate limiting during that window.
  • Abuse-control event logs (for example CAPTCHA failures, disposable-email blocks, rate-limit hits, OpenAI ceiling blocks): designed for short retention on the order of ~30 days, then deleted.
  • Global model-usage counters (daily aggregates, not contract text): retained as needed to enforce cost ceilings and review spend.
  • Contact fields tied to scans: retained with the scan record for the same window, and may be retained in aggregate lead form only as needed to enforce free allotments and communicate about the Service.
  • Pro waitlist: retained until you ask to be removed or the waitlist program ends.
  • Server logs: retained for a limited operational period.

9. Security

We use industry-standard safeguards appropriate to a small SaaS product (TLS in transit, access-controlled infrastructure, server-side enforcement of locked report fields). No method of transmission or storage is 100% secure.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data; object to or restrict certain processing; withdraw consent; and lodge a complaint with a supervisory authority. To exercise rights, email nessykalvo@gmail.com. We may need to verify your request.

California residents: we do not sell or share personal information for cross-context behavioral advertising. You may still request know/delete/correct rights as applicable under the CCPA/CPRA.

11. Children

The Service is for business users age 18+ (or the age of majority). We do not knowingly collect data from children.

12. Cookies and similar technologies

The core app uses cookies or local storage as needed for basic functionality (for example theme preference) and security. If we later enable non-essential analytics or advertising pixels, we will update this Policy and, where required, present a consent mechanism.

13. Changes

We may update this Policy by posting a new version with a revised effective date. Material changes will be highlighted in-product or by email when appropriate.

14. Contact

Privacy questions: nessykalvo@gmail.com. General support: nessykalvo@gmail.com.

These pages are operational disclosures for product transparency. They are not a substitute for attorney-drafted terms tailored to your entity structure. Have counsel review before large-scale advertising or regulated-market expansion.