1. Who this covers
Handoff, Inc. (“Handoff”, “we”, “us”) handles personal information in two different roles, and the difference matters for what we can do with it.
Information we collect for ourselves
When you create an account, visit our public pages, or write to us, we decide why and how that information is used. This covers account holders at law firms and visitors to the public site. For this information we act as the controller (or the “business” under U.S. state privacy laws).
Information firms put on the platform
Law firms upload case records so they can refer matters to other firms. Those records describe claimants: people who contacted a firm about a potential legal claim. The firm decides what to upload and whom to share it with. We process it on the firm’s instructions, as its service provider (or processor). We do not use claimant information for our own marketing, and we do not sell it. Section 10 is written for claimants directly.
2. What we collect
Account and firm information
- Name, email address, password (stored as a hash by our sign-in provider), and job title.
- Firm name, address, bar and licensing details, practice areas, logo, and the public profile a firm chooses to publish.
- A record that you accepted the Terms of Service and this policy, with the time you did so.
- Billing details, if your firm is on a paid plan.
Firm Data, including claimant information
Whatever a firm enters or uploads: claimant name and contact details, the state and date of an incident, the type of claim, injuries and conditions described, case notes, uploaded documents, intake criteria, referral agreements, and messages between firms. Some of this is sensitive, and the firm that uploads it is responsible for having the right to share it.
Usage and device information
- Actions taken in the product (a case viewed, a referral sent, an agreement signed), kept in an audit log so firms can see who did what.
- IP address, browser, and device type, from server logs and security tooling.
- On the public site only, page views and traffic sources through the analytics tools listed in section 6.
Information from integrations
When a firm connects an intake system, CRM, Slack workspace, or similar tool, we receive the data that integration sends, which is usually new case records or contact details. The firm chooses what to connect.
3. How we use it
- To run the Service: store cases, route referrals, generate and sign agreements, send notifications.
- To show the right data to the right firm and nobody else.
- To power the AI features described in section 4, for the firm that asked.
- To keep the Service secure, detect abuse, and investigate incidents.
- To send account emails: invitations, verification codes, referral activity, agreement status.
- To support you when you ask for help.
- To understand how the product is used, in aggregate, so we can improve it. We do this with de-identified data wherever we can.
- To comply with law and enforce our Terms.
We do not sell personal information, and we do not share it with third parties for their own advertising.
4. AI features
Some features send information to large language models run by third parties. Today that includes screening an inbound matter against a firm’s criteria, suggesting how to map an imported spreadsheet, drafting a referral memo, reviewing agreement language, and an assistant that answers a firm’s questions about its own cases. Each is labelled in the product, and each runs only when a user at the firm triggers it.
The model providers we use are Anthropic, OpenAI, Google, and xAI. Most requests go through Vercel AI Gateway, which routes the request to the chosen provider and lets us restrict which providers can serve it. Our agreements with these providers prohibit them from using your data to train their models.
Before a request leaves our systems we strip Social Security number patterns from free text, and we send only the fields the feature needs rather than the whole record. Dates of birth, home street addresses, and internal staff notes are not sent to screening features.
The current list of providers, what each feature sends, and how long each provider may retain a request are set out in the AI disclosure in your firm’s company settings. We keep that page current as the controls change, and it is the operative description if this section and that page ever differ. A firm can ask us to turn AI features off for its account.
7. How long we keep it
- Account information is kept while your account is open, and for a reasonable period afterwards to close out the relationship.
- Firm Data is kept while the firm’s account is open and the firm has not deleted it. After an account closes, the firm has 30 days to request an export. We then delete the data from live systems in the ordinary course and from backups on their normal rotation.
- Signed agreements stay in the accounts of both firms that signed them, because each firm has its own record-keeping duties.
- Audit and security logs are kept for as long as they are needed to investigate incidents and demonstrate who accessed what, and then deleted.
- Email we send is retained by our email provider for delivery reporting for a limited period.
We keep information longer where the law requires it or a dispute is ongoing.
8. Security
Data is encrypted in transit and at rest. Access inside Handoff, Inc. is limited to the people who need it to do their jobs, and every firm’s data is separated from every other firm’s so that one firm cannot see another’s cases except through a referral it was sent. Sign-in is handled by a dedicated identity provider, and we log access to case records.
No system is perfectly secure. If we learn of a breach affecting your information we will notify the affected firm without undue delay, and we will help it meet its own notification duties.
9. Your choices and rights
Account holders can view and edit their profile and their firm’s details in settings, control whether the firm appears in the public directory, and close the account. Firms can delete cases they have entered.
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, or to object to certain uses. Residents of California and other U.S. states with privacy laws have those rights under those laws, and we will not treat you differently for exercising them. To make a request, write to hello@casehandoff.com. We will verify that you are who you say you are before acting, and respond within the time the applicable law allows.
Where we hold your information as a firm’s service provider, we will refer your request to that firm and help it respond, since the firm decides how the record is handled.
10. If you are a claimant
You are here because a law firm you contacted about a potential claim uses Handoff to work with other firms. If your matter was referred, the firm that took your details entered them here and chose which firm to send them to. We did not collect your information from you, and we do not contact claimants directly.
The firm you first spoke to remains responsible for your information and for explaining the referral to you. Your questions about why your matter was shared, or requests to correct or delete your information, should go to that firm first. If you cannot reach them or would rather write to us, use hello@casehandoff.com. We will pass your request to the firm and help it respond, and we will act directly where the law requires us to.
11. Children
The Service is for law firms, not for children, and we do not knowingly collect information from anyone under 18 as an account holder. A firm may enter a minor’s details as part of a case; when it does, the firm is responsible for having the authority to do so, and we handle that data as Firm Data under the firm’s instructions.
12. Where data is stored
The Service is hosted in the United States and is built for U.S. law firms. If you use it from outside the United States, your information will be transferred to and processed there.
13. Changes to this policy
We will update this policy when our practices change. For a material change we will email the account owner or show a notice in the product before it takes effect. The effective date at the top of this page is the date of the current version, and earlier versions are available on request.
14. Contact
Privacy questions and requests go to hello@casehandoff.com. Our Terms of Service set out the contract this policy forms part of.