If the two versions differ, the English version prevails.
Privacy Policy
Last updated: September 8, 2026
Helping Hand (“we”, “us”, “our”) respects your privacy. This policy explains what personal information we collect through https://www.cnnehome.com/ (the “Site”), why we collect it, who we share it with, how long we keep it, and the rights you have.
1. Information We Collect
Information you give us
- Account details: name, email address, password (stored only as a salted hash), and optional phone number.
- Order and billing details: shipping and billing address, phone number, items ordered, order value.
- Customer service records: emails, chat messages, order numbers and photographs you send us, including images of products or packaging for warranty and damage claims.
- Marketing preferences: newsletter sign-ups and consent records.
Information collected automatically
- Device and log data: IP address, browser type and version, operating system, referring URL, pages viewed, timestamps, and crash or error logs.
- Cookies and similar technologies: see Section 5.
- Approximate location derived from your IP address, used to calculate applicable tax and shipping options.
Information from third parties
- Payment processors send us transaction status, the last four digits of the card used, and chargeback notices. We never receive or store your full card number.
- Shipping carriers send us tracking status and delivery confirmation.
- Advertising and analytics platforms send us aggregated, de-identified campaign performance data.
2. Smart Home Products and Device Data
The products we sell may connect to mobile applications, cloud services or voice assistants. That connection is generally established directly between your device and the manufacturer’s platform, not with us. Important points:
- We do not operate, host or access the companion apps, cloud recordings, camera feeds, voice recordings, scenes or automation data of the products we sell. That data is governed by the manufacturer’s own privacy policy, which you should read before activating a device.
- We may receive from the manufacturer, or you may provide to us, limited diagnostic information when you request warranty support — typically device model, firmware version, serial number and a description or log of the fault.
- If you return a device, you are responsible for performing a factory reset and unlinking it from your accounts before shipping. We do not access, recover or retain data on returned devices, and we destroy such devices’ storage media or wipe them before resale where technically possible.
3. How We Use Your Information
We use personal information to:
- Process and fulfil orders, including payment authorisation, invoicing, shipping and delivery notifications.
- Provide customer support, handle returns, refunds, exchanges and warranty claims.
- Maintain and secure your account and prevent fraud, chargeback abuse and unauthorised access.
- Comply with legal, tax and accounting obligations, including record retention.
- Send order-related and legally required communications.
- With your consent where required, send marketing emails and measure advertising performance.
- Improve the Site, product range and service quality through aggregated analytics.
We do not sell your personal information. We do not use it to make automated decisions that produce legal or similarly significant effects about you.
4. Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (order processing, delivery, support, returns); legal obligation (tax and accounting records); legitimate interests (site security, fraud prevention, service improvement, direct marketing to existing customers); and consent (newsletters, non-essential cookies and advertising personalisation). You may withdraw consent at any time without affecting prior processing.
5. Cookies and Tracking Technologies
| Category | Purpose | Examples | Necessary? |
|---|---|---|---|
| Strictly necessary | Cart contents, login session, security tokens, checkout state | WooCommerce session and cart cookies | Yes — always on |
| Functional | Remember language, currency and display preferences | WooCommerce UI cookies | Optional |
| Analytics | Understand traffic and page performance in aggregate | Google Analytics 4 | Optional, consent-based |
| Advertising | Measure ad conversions and build audiences | Google Ads, Google Tag Manager | Optional, consent-based |
You can control or delete cookies through your browser settings at any time. Blocking strictly necessary cookies will prevent the cart and checkout from working. Where required by law, we ask for consent before setting non-essential cookies and record your choice.
6. Who We Share Information With
We share personal information only with service providers who need it to perform a function for us, under contractual confidentiality and security obligations:
- Payment processors — to authorise and settle payments. Card data is handled by the processor’s PCI-DSS-compliant environment and is not stored on our servers.
- Shipping carriers and fulfilment partners — name, delivery address, phone number and order contents, to deliver your parcel.
- Hosting and infrastructure providers — who operate the servers on which the Site and its database are stored.
- Email and messaging services — to deliver transactional and marketing messages.
- Analytics and advertising platforms — as described in Section 5, generally in aggregated or pseudonymised form.
- Product manufacturers — limited details needed to process a warranty claim.
- Professional advisers and authorities — accountants, and law enforcement or regulators where we are legally compelled to disclose.
We may also disclose information in connection with a merger, acquisition or sale of assets, in which case the recipient assumes the obligations in this policy.
7. International Data Transfers
Our Site is operated from United States and hosted on servers that may be located outside your country of residence. If you access the Site from the European Economic Area, the United Kingdom or Switzerland, transfers are made subject to appropriate safeguards, including Standard Contractual Clauses or an adequacy decision where available. You can request a copy of the applicable safeguards.
8. Data Retention
| Data | Retention period |
|---|---|
| Order and transaction records | 7 years after the order, to meet tax and accounting obligations |
| Customer account data | Until you delete the account, or 24 months of inactivity |
| Customer service correspondence | 3 years after the case is closed |
| Warranty and return records | Duration of the warranty plus 12 months |
| Server and security logs | 12 months |
| Marketing consent records | Duration of consent plus 3 years, to evidence the choice made |
When a retention period expires we delete or irreversibly anonymise the data. Some information may persist in encrypted backups until those backups expire on their normal cycle.
9. Data Security
We use TLS encryption for all data in transit, encrypted storage for personal information, hashed password storage, a least-privilege administrative access model, and regular software and plugin updates. Payment card data never touches our servers.
As a business that owns or licenses the personal information of Massachusetts residents, we maintain a written information security programme as required by 201 CMR 17.00 (Standards for the Protection of Personal Information of Residents of the Commonwealth). The programme designates responsible staff, carries out risk assessments, restricts physical and electronic access, requires contractual safeguards from service providers, and is reviewed at least annually and whenever our business changes materially.
If a security breach affects the personal information of Massachusetts residents, we notify the affected residents, the Office of the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation as soon as practicable and without unreasonable delay, in accordance with M.G.L. c. 93H, §3. Where Social Security numbers are involved, we provide at least 18 months of credit monitoring services as required by §3A. No system is perfectly secure, however, and we cannot guarantee absolute security.
10. Your Rights
Depending on where you live, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to processing; withdraw consent; receive your data in a portable machine-readable format; and not be discriminated against for exercising these rights.
To exercise any right, email houke100@gmail.com. We verify your identity before responding — typically by matching your email address and order history, and we may ask for additional information. We respond within 30 days, and may extend by a further 60 days for complex requests, notifying you if we do. You may designate an authorised agent to make a request on your behalf; we may require proof of the agent’s authorisation.
You may also complain to your local data protection authority. EEA and UK residents may contact their national supervisory authority or the UK Information Commissioner’s Office.
11. California Residents — CCPA / CPRA Notice
Over the preceding 12 months we have collected the following categories of personal information about California consumers, from the sources and for the business purposes described above:
| Category (Cal. Civ. Code §1798.140) | Collected | Sold | Shared for cross-context behavioural advertising |
|---|---|---|---|
| Identifiers (name, address, email, phone, IP) | Yes | No | Yes, via advertising cookies where consented |
| Commercial information (products purchased, order history) | Yes | No | No |
| Internet or network activity (pages viewed, interactions) | Yes | No | Yes, via analytics and advertising cookies where consented |
| Geolocation data (approximate, from IP address) | Yes | No | No |
| Audio, visual or similar information (photos you send for support claims) | Yes | No | No |
| Inferences drawn from the above | Limited — used to suggest relevant products | No | No |
We do not sell personal information as “sale” is defined by the CCPA, and we have not sold or shared the personal information of consumers under 16 years of age. You have the right to request, twice in a 12-month period, that we disclose what we have collected, used, disclosed and shared; to request deletion; to request correction; and to opt out of “sharing” for cross-context behavioural advertising. To opt out of sharing, disable advertising cookies via the cookie controls on this Site or contact us. We will not discriminate against you for exercising any CCPA right. California residents may also use an opt-out preference signal where supported.
12. Massachusetts Residents
The Commonwealth of Massachusetts has not, as of September 2026, enacted a comprehensive consumer privacy statute comparable to the CCPA. A data privacy bill has passed both chambers of the Massachusetts Legislature but had not been signed into law as of the date of this policy; if that changes we will update this section.
Massachusetts residents are nevertheless protected by three instruments that apply to us:
- 201 CMR 17.00 — the Standards for the Protection of Personal Information of Residents of the Commonwealth, which requires us to maintain a written information security programme, to encrypt personal information in transit and in storage, and to impose equivalent safeguards on our service providers by contract.
- M.G.L. c. 93H — which requires us to notify affected residents, the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation as soon as practicable and without unreasonable delay if a security breach affects residents’ personal information, and to provide at least 18 months of credit monitoring where Social Security numbers are involved.
- M.G.L. c. 93A — the Massachusetts Consumer Protection Act, which prohibits unfair or deceptive acts or practices. Under §9 a consumer may recover actual damages and, where the court finds wilful or knowing conduct, double or treble damages plus reasonable attorneys’ fees. Section 9(3) generally requires a written demand letter at least 30 days before filing suit.
To exercise a privacy right, request a copy of your data, or ask how we protect Massachusetts residents’ personal information, email houke100@gmail.com or call +1 774-421-6931. Massachusetts residents may also contact the Office of the Massachusetts Attorney General directly.
13. Children’s Privacy
The Site is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us with personal information, contact us and we will delete it. Certain smart home devices, including cameras and voice-controlled products, may capture audio or video in the home; we recommend that adults configure these devices and review the manufacturer’s privacy settings.
14. Third-Party Links
The Site may link to manufacturer websites, marketplaces or content we do not control. This policy does not apply to them, and we are not responsible for their practices.
15. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. The “Last updated” date at the top shows the current version. For material changes we will post a notice on the Site or email affected customers before the change takes effect.
16. Contact Us
Helping Hand
3569 Kennedy Court, Charlestown, Massachusetts 02129, United States
Email: houke100@gmail.com
Phone: +1 774-421-6931
[…] a complete description of our data handling practices, please review our Privacy Policy. Privacy rights for non-California residents are governed by applicable laws in their respective […]
[…] For complete details about our data collection, use, and protection practices, please read our full Privacy Policy. […]
[…] Privacy Policy: Explains data collection, usage, and protection measures […]
[…] Privacy Policy […]
[…] reaches our California customers. For details on our data handling practices, please refer to our Privacy Policy; for service terms, see our Terms of […]
[…] physical microphone mute switches, data encryption methods, and transparent privacy policies. Our Privacy Policy explains how we handle user […]
[…] Privacy Policy: Explains how we collect, use, and protect your personal information, as well as your data protection rights. […]
[…] For comprehensive details covering all aspects of our data practices, please review our full Privacy Policy […]
[…] To protect both your devices and your home network, we strongly recommend the following measures: keep the companion app and device firmware updated to the latest versions; set unique access credentials for each device that differ from your router administrator password; change default passwords immediately after initial setup; and consider placing smart devices on a separate guest network to isolate them from your primary computing devices. After setup is complete, remove any temporary test networks or configurations that are no longer needed. These precautions help reduce the risk of unauthorized access and protect your personal data. For more information on how device data is collected, stored, and protected, please review our Privacy Policy. […]
[…] support end-to-end encryption, local processing options, and firmware update mechanisms. Our Privacy Policy outlines our data handling […]
[…] Compliance and Safety page. For information on how personal health data is handled, please see our Privacy Policy. Information is current as of September 2026 and subject to official […]
[…] Our catalog currently includes 205 smart home products across eight categories, with prices ranging from $49 to $2,999 (USD). Compatibility capabilities may vary across different product categories and price tiers, so please verify the compatibility notes for each specific product you are considering. For information on how device data is collected, processed, and protected during these interactions, please review our Privacy Policy. […]
[…] All payment transactions processed through cnnehome.com are transmitted via industry-standard encrypted channels. We do not store your complete payment card numbers, bank account credentials, or other sensitive financial data on our servers. Payment processing is handled by PCI-DSS compliant third-party payment processors who specialize in secure transaction management. For comprehensive details about how we collect, use, protect, and retain your personal and transactional data, please review our Privacy Policy. […]