Built for Canadian mortgage compliance from day one.

You handle sensitive client data every day — government IDs, financial documents, personal information. We built HNDL knowing exactly what's at stake. Your clients trust you. You need to trust your tools.

🍁 Data stored in Canada
🔒 Encrypted at rest & in transit
PIPEDA compliant

What we collect, where it lives, who touches it.

HNDL processes personal information, government-issued identification, financial documents, and electronic signatures on behalf of brokers and their clients. We treat every piece of data as if our own mortgage file depended on it.

🍁 Canadian data residency

All client data is stored in Canada (AWS ca-central-1 region via Supabase). This is a Canadian product for Canadian brokers — your clients' PII stays in Canada.

🕒 Data retention

We retain data only as long as your account is active and as needed to provide the service. We don't keep copies of client documents indefinitely. Full details in our Privacy Policy.

🚫 What we don't do

We don't sell your data. We don't share it with advertisers. We don't use it for profiling. We don't use tracking pixels or third-party analytics cookies.

📄 Privacy Policy

Our full privacy policy is available at /privacy. Plain language, no legalese fog.

How we protect your data.

Our infrastructure providers handle the heavy lifting on security. We chose them specifically for their security track records and certifications.

🔒 Encryption at rest

All data is encrypted at rest using AES-256 encryption via Supabase's managed database. Database backups are encrypted with the same standard.

🔐 Encryption in transit

All data in transit is protected by TLS 1.3. Every connection to HNDL is encrypted — no exceptions.

💾 Daily backups

Automated daily database backups via Supabase Pro. Point-in-time recovery available. Your data survives even if something goes wrong.

💳 Payment security

Payments handled by Stripe (PCI Level 1 certified). Credit card numbers never touch our servers — they go directly to Stripe.

Built for Canadian regulatory reality.

We didn't build a generic SaaS platform and hope it fits the mortgage industry. We built for the compliance environment Canadian brokers actually operate in.

Your tools need to work when you need them.

Our infrastructure runs on Vercel's edge network and Supabase's managed database platform — both built for reliability at scale. We're building uptime monitoring so we can publish real numbers, not just targets.

🌐 Edge deployment

Application served from the nearest edge node to you via Vercel's global network. Fast load times whether you're in Toronto, Vancouver, or Calgary.

💾 Managed infrastructure

Supabase handles database reliability with automated failover and backups. Vercel handles application hosting with zero-downtime deployments.

📨 If something goes wrong

We're a small team — if something breaks, we know about it and we fix it. We're building toward a public status page so you can see uptime data for yourself instead of taking our word for it.

When something goes wrong, here's what happens.

We hope we never need this section. But you deserve to know what our obligations are and how we'll handle it.

🔔 Breach notification

If a breach creates a real risk of significant harm, PIPEDA requires us to notify the Privacy Commissioner and all affected individuals as soon as feasible. We will do that — no delays, no spin.

Track record

No data breaches to date. We intend to keep it that way. This page will be updated if that ever changes — transparency isn't optional.

Small team. That's a feature, not a bug.

We're a small team, and that's actually a security advantage. Fewer people means fewer access points, simpler access management, and direct accountability. There's no chain of 14 people between a question and an answer. You can reach the person who built the thing.

For your compliance team.

Need to share our practices with your compliance officer or brokerage? Start here.

Need something else? Email andrew@hndl.app and we'll get you what you need.

Trust is built, not claimed.

We'll keep earning it. Questions? Reach out anytime.

Get in Touch →