Privacy Policy

Effective date: July 20, 2026. Last updated: July 20, 2026.

This Privacy Policy explains what personal information Handler Labs LLC (“BEO HQ,” “we,” “us,” or “our”) collects through beohq.com and the BEO HQ application (together, the “Service”), how we use and share it, how long we keep it, and the choices and rights you have. We keep it plain because that is how we would want to read it.

1. Who we are

The Service is operated by Handler Labs LLC, the data controller responsible for your personal information. You can reach us at hello@beohq.com or by mail at 5510 NW 38th Terrace, Coconut Creek, FL 33073. We have not appointed a data protection officer because we are not required to; direct all privacy questions to the email above.

2. Scope of this policy

This policy covers three groups of people: visitors to our website, account holders who use BEO HQ to run their catering or events business, and the recipients of documents our account holders send (for example, a client who opens a shared proposal or signs a contract). Where a term differs for one group, we say so.

3. Information we collect

We collect the following categories of personal information:

  • Account and identity information. Your name, email address, and password. Passwords are stored only as salted hashes by our authentication provider; we never see or store your plain-text password.
  • Business content you enter. Your business profile and logo, and the clients, venues, menus, events, and documents you create. This may include information about your own clients that you choose to enter (see Section 6).
  • Payment information. Subscription plan, status, billing period, and a customer identifier from our payment processor. Card numbers and bank details are collected and stored by Stripe, not by us; we never receive your full card number.
  • Signature and approval information. When someone signs or approves a document through a shared link, we collect the signer's name, optional email, the typed or drawn signature, and, for the audit trail, the date and time, IP address, and browser user-agent.
  • Technical and usage data. Standard server logs such as IP address, browser type, pages requested, and timestamps, generated automatically when you use the Service. We also collect aggregate, cookieless site analytics (page views, referrers, and similar statistics) that are not used to identify or profile you; see Section 7.
  • Email address for free-tool delivery. If you ask us to email you a document from the free builder, we collect the email address you provide so we can send it. We use it for occasional product updates only if you tick the optional box saying so, and every such email includes an unsubscribe link.

4. How we use information and our legal bases

We use personal information to provide, secure, and improve the Service. For individuals in the EEA and UK, the legal bases under the GDPR are noted in brackets:

  • To create your account and provide the Service [performance of a contract].
  • To generate, store, and share your documents [performance of a contract].
  • To process subscriptions and prevent payment fraud [contract; legal obligation].
  • To maintain the signature audit trail for documents you send [legitimate interests in providing a reliable e-signature record; contract].
  • To secure the Service, debug, and prevent abuse [legitimate interests].
  • To respond to your support requests [contract; legitimate interests].
  • To send service and transactional emails such as confirmations, password resets, team invites, and documents you ask us to email you [contract]. We send product-update email only to people who opt in, it honors the opt-out requirements of the CAN-SPAM Act (15 U.S.C. s 7704), and you can unsubscribe at any time.
  • To understand, in aggregate, how the site is used (which pages are visited and how often) so we can improve it, using cookieless analytics that do not identify individual visitors [legitimate interests].
  • To comply with law and enforce our Terms [legal obligation; legitimate interests].

We do not use your business or client data to train artificial intelligence models, and we do not sell your personal information.

5. How we share information

We share personal information only with the service providers that run BEO HQ, and only as needed for them to provide their service to us:

  • Supabase (database, authentication, and file storage).
  • Stripe (subscription billing and payment processing).
  • Vercel (application hosting and cookieless, aggregate site analytics) and Cloudflare (DNS and content delivery).
  • Resend (email delivery for the service and transactional emails described above).

We may also disclose information when required by law, to respond to lawful requests or legal process, to protect the rights, safety, and property of BEO HQ, our users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will give notice before your information becomes subject to a different policy). We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

6. Data you enter about other people

When you enter information about your own clients, guests, or vendors into BEO HQ, you control that data and you are its controller (or “business” under the CCPA). We process it only on your behalf and on your instructions, as a service provider and processor, to provide the Service to you. We do not use it for our own purposes. You are responsible for having the right to enter that information and for giving those individuals any notice your own privacy obligations require.

7. Cookies and Do Not Track

We use only strictly necessary cookies to keep you signed in and to keep the Service secure. Our site analytics (provided by Vercel) are cookieless: they count page views and referrers in aggregate, set no cookies, and are not used to identify, profile, or follow individual visitors. We do not use advertising cookies or third-party cross-site tracking, and we do not allow other parties to collect personal information about your online activities over time and across different websites through the Service.

Do Not Track. Because we do not track you across third-party websites in the first place, we treat all users the same whether or not your browser sends a “Do Not Track” signal. We do not respond differently to that signal because we do not perform the cross-site tracking it is designed to limit.

8. How long we keep data

We keep your account and business content for as long as your account is active. If you delete a record, or delete your account, we delete the associated personal data from our live systems within 30 days, except where we must retain limited information to comply with law (for example, tax and payment records), resolve disputes, or enforce our agreements. Routine backups are purged on a rolling schedule. Signature audit-trail records are retained for the life of the related document so the record stays reliable.

9. How we protect data

Data is encrypted in transit (HTTPS) and at rest by our infrastructure providers. Access to your data is restricted by row-level security so that one account cannot reach another account's data. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard measures and to notify you and the appropriate authorities of a breach as required by law.

10. International data transfers

We are based in the United States and our providers process data in the United States and other countries. If you access the Service from outside the United States, you understand your information will be transferred to and processed in the United States. Where we transfer personal data of individuals in the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

11. Your privacy rights

You can review and update most of your personal information at any time from your account settings, and you can export your documents and financial data as PDF, CSV, or a QuickBooks-formatted file. To make any other request, or to ask us to correct or delete information you cannot change yourself, email hello@beohq.com. We will verify your request before acting on it and will not discriminate against you for exercising a right.

12. California residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to:

  • Know and access the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of parties we disclose it to, over the preceding 12 months.
  • Delete personal information we collected from you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
  • Limit the use of sensitive personal information. We do not use sensitive personal information for purposes that trigger this right.
  • Non-discrimination for exercising any of these rights.

The categories of personal information in Section 3 are the categories we collect and disclose to service providers for the business purposes described in Section 4. To exercise a right, email us at the address in Section 16; you may use an authorized agent, and we will take steps to verify the agent's authority.

13. EEA and UK residents (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time where we rely on consent (without affecting processing already carried out). Our legal bases are set out in Section 4. You also have the right to lodge a complaint with your local data protection supervisory authority. We do not use your data for automated decision-making that produces legal or similarly significant effects.

14. Children

The Service is a business tool intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

15. Changes to this policy

If we make a material change to this policy, we will update the effective date above and notify account holders by email or by a notice in the Service before the change takes effect. Your continued use of the Service after a change takes effect means you accept the updated policy.

16. How to contact us

Questions or requests about privacy? Email hello@beohq.com or write to Handler Labs LLC, 5510 NW 38th Terrace, Coconut Creek, FL 33073.