Privacy

Third-party services

A practical inventory of external services used to operate Handigo. Last reviewed September 20, 2026.

Handigo sends only the information needed for each function. OAuth access and identity tokens are handled during authentication; provider account identifiers are retained so the login remains linked. Infrastructure libraries that do not receive Handigo data are excluded from this processor list.

Provider
Apple
Purpose
Sign in with Apple and Apple Push Notification service
Data disclosed
Apple account identifier, verified or relay email, name on first authorization, signed identity token, and notification token/content.
Used by
iOS, Android, web authentication, and iOS push delivery
Provider
Google
Purpose
Google sign-in, address geocoding, and Firebase Cloud Messaging
Data disclosed
Google account identifier, verified email/name; address or coordinates submitted for geocoding; Android notification token/content.
Used by
Web authentication, backend geocoding, Android push delivery
Provider
Meta
Purpose
Facebook sign-in
Data disclosed
Facebook account identifier, email, and public profile name approved during sign-in.
Used by
Web authentication
Provider
Expo
Purpose
Mobile build/runtime services and push-notification relay
Data disclosed
Expo project/device push token, notification title/body, notification identifier, and build diagnostics supplied through Expo tooling.
Used by
iOS and Android
Provider
Cloudinary
Purpose
User-uploaded file and image storage
Data disclosed
Profile images, verification documents, message attachments, file metadata, and generated asset identifiers/URLs.
Used by
Backend uploads used by web and mobile
Provider
Resend
Purpose
Transactional email delivery
Data disclosed
Recipient email address and the contents of verification, password-reset, and service emails.
Used by
Backend email worker
Provider
Sentry
Purpose
Production error and performance monitoring when configured
Data disclosed
Error stack traces, route and request metadata, browser/device details, release information, and performance spans. Handigo does not intentionally attach message bodies, passwords, or authentication tokens.
Used by
Web, edge, and HTTP server

Review controls

A provider must be reviewed before it is added or materially expanded. The review covers necessity, data fields, retention, authentication or secret handling, user disclosure, deletion, platform permissions, and a documented owner. This inventory is reviewed for every release that changes an SDK or external data flow and at least every six months.