Privacy Policy
This is a generic template for an SSO / identity provider. Have counsel review and customize it (including regional requirements such as GDPR or CCPA) before relying on it in production.
1. Who we are
hnndl (“we”, “us”) operates a single sign-on and authentication service. This policy explains how we handle personal data when you use our websites and Service.
2. Data we collect
- Account data — such as email address and password (stored as a secure hash), and optional profile or security settings you configure (for example two-factor methods).
- Authentication data — sign-in events, session identifiers, device/browser metadata, IP address, and timestamps used to operate sessions and protect accounts.
- Integration data — identifiers needed to connect your account to Relying Parties that use hnndl SSO (for example client or redirect configuration associated with a sign-in).
- Communications — messages you send us (support or legal requests).
- Technical logs — server and security logs that may include IP addresses and request metadata.
3. How we use data
We use personal data to create and secure accounts, authenticate you, provide SSO to Relying Parties you choose, prevent abuse and fraud, improve reliability, comply with law, and communicate service-related notices.
4. Cookies and similar technology
We use cookies or similar storage for essential purposes such as keeping you signed in, maintaining session security, and remembering security preferences. These are required for the Service to function. We do not use advertising trackers on the authentication Service.
5. Sharing
We share data only as needed to run the Service:
- Relying Parties — when you sign in to an integrated site, that site may receive authentication results and limited identity attributes required for SSO.
- Service providers — hosting, email delivery, or infrastructure vendors under contractual obligations to protect data.
- Legal — when required by law, legal process, or to protect rights, safety, and security.
We do not sell your personal information.
6. Retention
We keep account and authentication data for as long as your account is active and as needed for security, dispute resolution, and legal obligations. Logs are retained for a limited operational period unless a longer period is required for investigations or compliance.
7. Security
We apply administrative and technical measures appropriate to an authentication service, including encrypted transport, hashed passwords, and optional two-factor authentication. No method of transmission or storage is completely secure; see also our Security page.
8. Your choices
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Contact us to make a request. You may close your account through available account tools or by contacting us. Some data may remain in backups or logs for a limited time.
9. Children
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children.
10. International transfers
If you access the Service from another country, your data may be processed where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers.
11. Changes
We may update this policy by posting a revised version with a new “Last updated” date. Material changes may also be communicated through the Service when practical.
12. Contact
Privacy questions or requests: privacy@hnndl.com.