Handover · Privacy

Privacy Policy

Handover lets a business read and reply to the conversations its own n8n chatbot has with customers. This policy explains what data the extension handles and where it goes.

Effective date25 September 2026 PublisherNamiciLab Contactnamicilab@gmail.com
The short version

We do not receive, store or have access to any of your data.

Handover has no server of its own. It connects only to the Supabase project and n8n webhook that you configure, and everything it handles moves between your browser and those two services.

No serverNothing passes through Namici.
No analytics or trackingNo telemetry, cookies or crash reports.
Never sold or sharedNot used for advertising, ever.
Your databaseConversations stay in your Supabase.

What the extension handles

DataWhyWhere it goes
Connection settingsYour Supabase project URL, Supabase publishable key, n8n webhook URL and webhook secret WhyTo connect to your services Where it goesStored in your browser's extension storage (chrome.storage.local)
Your sign-in sessionSupabase access and refresh tokens, and your email address WhyTo keep you signed in Where it goesStored in your browser's extension storage. Your password is sent only to your Supabase project to sign in and is never stored.
ConversationsCustomer names, handles or phone numbers, message text and images WhyTo show your inbox and let you reply Where it goesRead from and written to your Supabase project. Replies are also sent to your n8n webhook for delivery. Not stored by the extension beyond what is on screen, except a per-conversation timestamp used to avoid repeat notifications.
Images you send WhyTo deliver them to the customer Where it goesUploaded to the chat-media storage bucket in your Supabase project

What we do not do

  • We do not collect analytics, telemetry, crash reports or usage data.
  • We do not use cookies or tracking technologies.
  • We do not sell, rent or share data with anyone, and we do not use it for advertising, credit decisions or any purpose other than the extension's single purpose described above.
  • The extension does not read the web pages you visit.

Permissions

storage

Keeps your settings, session and notification state on your device.

alarms

Checks for new messages once a minute so the badge and alerts stay current.

notifications

Shows a desktop alert when a customer sends a new message.

sidePanel

Shows the inbox in Chrome's side panel.

Host access (optional)

Requested only for the Supabase URL and n8n webhook address you enter, at the moment you click Save & grant access.

Your data and control

The customer conversations belong to you, the business, and live in your own Supabase project, under your own retention and deletion policies. We have no copy.

To remove everything the extension stores on your device: click Sign out in the side panel, and uninstall the extension. Uninstalling deletes all extension storage.

If you are a customer of a business that uses Handover, your messages are held by that business. Contact them to access or delete your data.

Security

The extension only accepts a Supabase publishable (or legacy anon) key — it refuses secret and service role keys — and access to conversations is controlled by the row level security policies in your own database. Connections to Supabase use HTTPS.

Children

Handover is a business tool and is not directed at children under 13.

Changes

If this policy changes, we will update the effective date above and publish the new version at this address. Material changes will also be noted in the extension's release notes.

Contact

Questions about this policy: namicilab@gmail.com

Questions about your data?

Email us and a real person will answer. We'll never ask for your keys or passwords.