HandShakeTec

Privacy notice

Built: 2026-10-07 13:34:00 BST

This page explains what information handshaketec.com keeps about you, why it keeps it and what you can do about it.

Who is responsible

This site is run by Matt Oppenheim, who is solely responsible for it and for the data described here — not Lancaster University. For anything about privacy, contact matt@mattoppenheim.com, the same address given on the contact page.

What this site does not do

There is no advertising, no analytics and no tracking on this site. We do not sell or share your information, and we do not build profiles of visitors. Apart from YouTube videos (see below), every page loads only from handshaketec.com and comments.handshaketec.com.

Comments

The comment box on every page is run by Remark42, an open-source comment system that runs on our own server.

When you comment, we keep:

  • The name you use. If you comment anonymously, this is the name you type in. If you sign in with GitHub, it is your GitHub display name. We also keep a copy of your GitHub profile picture and an identifier for your GitHub account.
  • Your comment and when you posted it.
  • A scrambled form of your internet (IP) address. We never store the address itself, only a one-way code made from it, which cannot be turned back into your address. It lets us block someone who is abusing the comments without keeping their address.

We do not ask for your email address.

Comments are public. Anyone who visits the page can read them. Please don’t post anything that identifies a HandShake user or someone who took part in our research, unless it is you and you are happy for everyone to read it.

Signing in with GitHub. If you choose to sign in with GitHub, GitHub knows that you signed in to this site. What GitHub does with that is covered by GitHub’s privacy statement.

Email notifications. When someone posts a comment, the site emails a copy of it, with the commenter’s name, to the site owner so it can be read and moderated. These emails are sent and stored through Google’s Gmail service.

Cookies. Reading comments sets no cookies. When you sign in to comment, comments.handshaketec.com sets two: one keeps you signed in and the other protects your account from forged requests. They last about eight days, or until you sign out, which removes them straight away.

How long we keep it. Comments stay until they are deleted. The comment system makes a backup copy once a day and keeps the last 10, so a deleted comment is gone from the backups after about ten days.

Deleting your comments. You can delete a comment for a few minutes after posting it. After that, contact us and we will remove your comments and the information above.

The configuration and flashing pages

The T-Watch S3 and T-Embed configuration pages build firmware to your settings. To keep your settings separate from other visitors’, the site sets one cookie, called session, when you open one of these pages. It holds a random name for your session and a security code that stops other sites changing your settings, and nothing else. It is deleted when you close your browser.

While your session is active, the server keeps:

  • the settings you choose, such as gestures, sensitivity and keys
  • the MAC addresses you enter, which identify your watch and receiver to each other
  • the firmware built from those settings

A session ends after 2 hours without use. Its settings and firmware are then deleted from the server within a few minutes.

If you upload a firmware file on the Device Flasher page, it is deleted from the server after one hour. Flashing itself happens between your browser and your device: nothing read from the device is sent to us.

Server logs

Like most websites, the server records each request it receives: your IP address, the date and time, the page or file asked for and the type of browser you use. We use these records only to keep the site working and secure, for example to find faults or block attacks. There is no fixed period for keeping them: older records are overwritten as the logs fill up, and the logs are cleared whenever the site is updated. How long that takes depends on how busy the site is and how often it changes, so we can only estimate it, at a few weeks at most.

Videos

Pages with a video use YouTube’s privacy-enhanced player, which does not set cookies until you press play. Playing a video is then subject to Google’s privacy policy, not ours.

Why we are allowed to use this information

UK data protection law requires a lawful basis for using personal data. Ours is legitimate interests: running a public discussion about HandShake, building the firmware you ask for and keeping the site secure. We keep only what those need and for no longer than the times given above.

The session cookie and the comment sign-in cookies are strictly necessary for the features you choose to use, so the site does not ask for consent before setting them.

Where the data is kept

The server is hosted in the United Kingdom by IONOS SE. Comment notification emails are held by Google, which may store them outside the UK under its own safeguards for international transfers.

Your rights

Under UK data protection law you have the right to:

  • ask what personal data is held about you and get a copy of it
  • have inaccurate data corrected
  • ask for your data to be deleted
  • object to how your data is used, or ask for its use to be restricted

To use any of these rights, contact us. We will reply within one month. If you’re not satisfied with the response, you can complain to the UK’s data protection regulator, the Information Commissioner’s Office.

Changes to this notice

If what the site collects changes, this page will be updated first. The date under the title shows when the page was last rebuilt.

Comments

Comments are public. Please don't name anyone who uses HandShake, or say that someone took part in our research, unless it is you and you are happy for everyone to read it. You can comment with just a name, or sign in with GitHub. Our privacy notice explains what is stored.