Privacy policy
Last updated 13 September 2026. This is a working draft written to be readable; it will be reviewed by counsel before general availability. If anything here is unclear, ask us and we will fix the wording rather than explain it away.
What we collect
Account data — the name, email address and company you give us at signup, and what your users do in the application (sign-ins, and the audit trail of changes to records).
Your business data — the customers, items, orders, invoices and documents you put into the service. We process this only to provide the service to you.
Payment data — handled by Stripe. We store a customer identifier and a subscription identifier. We never see or store card numbers.
Site analytics — page views on onhandims.com through Plausible, which is cookieless and does not track individuals across sites. The application itself sets no analytics cookies.
What we do not do
We do not sell your data. We do not share it with advertisers. We do not use your business data to train machine-learning models, ours or anyone else's. We do not use one customer's data to build or improve features for another.
AI features
The in-app assistant, the setup assistant and the support assistant send the text of your question, and a small amount of on-screen context, to Anthropic's API to produce an answer. Anthropic does not train on data submitted through their API. We record the token counts and cost of each call so we can bill and budget; we do not retain the content of the conversation beyond a support ticket you explicitly open.
Sub-processors
| Who | What for | Where |
|---|---|---|
| Stripe | Payments and subscriptions | US |
| Postmark | Transactional email | US |
| Anthropic | AI assistant features | US |
| Plausible | Website analytics (marketing site only) | EU |
We will give 30 days' notice by email before adding a sub-processor that handles customer data.
Retention
Live data is kept while your account is open and for 30 days after it closes, so you can still export. Backups are held seven days for daily archives; nothing survives beyond 90 days. Audit log entries are kept for the life of the account because they are what makes a record trustworthy.
Your rights
Export everything yourself from Settings at any time. To correct or delete something, or to ask what we hold, email privacy@onhandims.com and we will answer within 30 days.
Security
Each customer's data is in its own database schema, and every request is bound to the tenant its access token was issued for. Passwords are stored as bcrypt hashes. Emailed links are single-use, time-limited, and stored only as a hash. Access to production is limited to named people and logged.