Privacy Policy

Last updated: June 2026

1. Who We Are

HanditGo ("we", "us", "our") operates the HanditGo platform at handitgo.com — a peer-to-peer traveler courier marketplace that connects senders who need items delivered internationally with travelers already flying the same route.

This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our platform. By creating an account or using HanditGo, you agree to the practices described here.

Privacy contact: [email protected]

2. Data We Collect

Account data

Name, email address, phone number, and account password when you register. This information is necessary to create and maintain your account.

Identity verification (KYC)

To verify your identity, we collect a government-issued photo ID (passport or national ID) and a real-time selfie. This data is processed by Didit, our identity verification provider. We do not store your ID documents or selfie photos on HanditGo's servers — they are transmitted directly to and stored by Didit under Didit's own privacy policy. We receive only a verification status result (verified / not verified) and a reference ID.

Trip and delivery data

Origin and destination cities or airports, travel dates, available luggage capacity, item descriptions, declared values, photos of items, and any details you submit when creating a trip or delivery request.

Flight verification data

When travelers post a trip, we collect their flight booking confirmation and verify the flight number, date, and route against live aviation databases. The booking document is stored with the trip record and may be retained for fraud prevention, dispute investigation, and legal compliance purposes. We share flight number and date with AviationStack for verification — we do not share the full booking document with AviationStack or any other third party.

Payment data

Transaction amounts, escrow records, collateral amounts, and payout records. Card numbers, CVVs, and banking credentials are handled entirely by PayPal — we never see or store these details.

Messages and communications

In-platform messages exchanged between senders and travelers are stored to enable coordination and as evidence in the event of a dispute. These messages are reviewed by our team only when a dispute is filed or a report is submitted.

Usage data

Pages visited, features used, timestamps, browser type, operating system, IP address, and device identifiers — collected automatically for platform operation, fraud detection, and security monitoring.

3. How We Use Your Data

  • Platform operation: To create and manage your account, match senders with travelers, process escrow payments, and confirm deliveries
  • Identity verification: To confirm you are who you say you are before enabling transactions via the Didit KYC process
  • Flight verification: To confirm traveler trips are real flights before matching with senders
  • Fraud prevention and safety: To detect suspicious activity, protect the trust score system, and prevent abuse of the platform
  • Dispute resolution: To review evidence submitted by both parties and issue binding decisions
  • Transactional communications: To send delivery confirmations, dispute updates, and important account notifications
  • Legal compliance: To fulfil customs documentation requirements, comply with anti-money laundering (AML) obligations, and respond to lawful requests from authorities
  • Platform improvement: To analyze usage patterns and improve features (in anonymized or aggregated form only)
  • Marketing emails: To send platform news and updates (you can unsubscribe at any time from within any email)

4. Data Sharing

We share your data only with the service providers necessary to operate the platform:

  • Didit: Identity verification (KYC) — receives your ID document and selfie for verification processing
  • PayPal: Escrow capture, collateral management, payment processing, and traveler payout transfers
  • AviationStack: Real-time flight database used to cross-check traveler trip details (flight number and date only)
  • Insurance provider: Per-shipment insurance underwriting (item value and route, no personal financial data)
  • Law enforcement and regulators: When legally required by court order, regulatory demand, or to prevent immediate harm

We do not sell your personal data to advertisers or third-party data brokers. Ever.

Our service providers are contractually prohibited from using your data for any purpose beyond the service they provide to us.

5. Data Retention

  • Account data: Retained for the lifetime of your account and for 7 years after account closure, for legal and compliance purposes
  • Transaction records: Retained for 7 years for financial and tax compliance
  • Identity verification data: Governed by Didit's retention policy — we do not control or store your ID documents
  • Flight booking documents: Retained with the associated trip record for as long as the trip is active, and for up to 3 years thereafter for dispute investigation, fraud prevention, and legal compliance
  • Messages: Retained for 3 years after the related transaction completes, then deleted
  • Usage logs: Retained for 90 days for security monitoring

You may request earlier deletion of certain data subject to legal retention requirements (see Section 6).

6. Your Rights

Depending on your country of residence, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your data (subject to legal retention obligations)
  • Objection: Object to processing based on legitimate interests
  • Restriction: Request we limit how we process your data in certain circumstances
  • Portability: Receive your data in a machine-readable format (JSON or CSV)
  • Withdraw consent: Opt out of marketing emails at any time via the unsubscribe link

To exercise any of these rights, email [email protected]. We will respond within 30 days. Note that we may need to verify your identity before fulfilling certain requests.

7. Security

We protect your data with:

  • TLS 1.3 encryption for all data in transit between your browser and our servers
  • AES-256 encryption for sensitive data stored at rest
  • Access controls limiting staff data access to the minimum necessary
  • Regular security audits and penetration testing
  • Incident response procedures to notify affected users of breaches where required by law

No system is completely secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access to your account.

8. Cookies

We use essential cookies required for the platform to function:

  • Session cookies: Keep you logged in between pages
  • Security cookies: CSRF protection and fraud prevention
  • Preference cookies: Remember your language and display preferences

With your consent, we also use Google Analytics and the Meta Pixel to understand how visitors use the platform and measure the performance of our Facebook/Instagram ads. Neither is set until you accept via the cookie banner. To withdraw consent, clear this site's cookies and local storage in your browser settings: clearing local storage makes the cookie banner reappear so you can choose "Essential Only," while clearing cookies removes any analytics or advertising identifiers (such as _ga or _fbp) already stored on your device. The Meta Pixel shares page-visit and conversion events with Meta Platforms for ad measurement and audience building — it does not share your name, email, or other account data. Meta's own privacy policy governs its processing of this data. You can manage cookies in your browser settings — disabling essential cookies will affect your ability to use the platform.

9. International Data Transfers

HanditGo operates globally. Your data may be processed by us or our service providers in countries outside your own. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses (SCCs) where required under applicable data protection law.

10. Children

HanditGo is intended for users aged 18 and over. We do not knowingly collect personal data from children under 18. If we discover that a user under 18 has created an account, we will delete it promptly. If you believe a minor has registered, contact [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. Your continued use of HanditGo after notification constitutes acceptance of the revised policy.

12. Contact

For privacy-related questions, data access requests, or to report a concern: