Legal

Privacy Policy

Last updated: 2026-09-09

This Privacy Policy describes how the GoHyppo group collects, uses, shares and protects personal information when you visit our websites, use our products or engage our services. The group is made up of:

In this Policy, “GoHyppo”, “Hyppo”, “we” and “us” refer to either company. Both apply the same privacy and security practices and share a single point of contact: it@hyppo.io. The data controller — or the processor, where we act on behalf of a Customer, as described in section 1 — is the company identified in the corresponding contract, service order or invoice.

Scope. This Policy covers the hyppo.io and gochat.ar websites, the GoChat platform and its dashboard at gochat.hyppo.io, the Customer.io Tracker for Shopify and for Tiendanube apps, and the professional marketing and data services we deliver under contract. Together, the “Services”. Capitalized terms not defined here have the meaning given to them in our Terms and Conditions.

We will publish any changes on this page, with the last-updated date.

1. Our relationship with you

It helps to start by identifying which relationship you have with us, because our obligations and your rights depend on it:

2. What information we collect as controller

When we act as data controller (the User relationship), we collect:

2.1 Aggregated data

We produce statistics and aggregated data that do not allow any individual to be identified. We use them to measure and improve the Services and in our commercial materials. If aggregated data were combined with personal data in a way that allows you to be identified, we treat it as personal data.

2.2 Special categories and children’s data

We do not request and do not wish to receive special categories of personal data — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation — except where a specific written agreement with a Customer provides for it, with appropriate safeguards.

The Services are not directed at people under 18 and we do not knowingly collect their data. If we find that we have received a minor’s data without the appropriate authorization, we delete it. If you believe this has happened, write to it@hyppo.io.

3. What data we process on behalf of our Customers

When a Customer uses the Services, we process their End Users’ personal data on their behalf and under their instructions. Depending on the channels and features the Customer enables, this may include:

The Customer decides what data to upload, for what purpose and for how long, and is responsible for having the legal basis, consents and notices required — including the call recording notice. We do not use that data for our own marketing purposes and we do not sell it.

4. Cookies and similar technologies

We use cookies and similar technologies on our websites. These are the ones currently active:

WhereWhat it isPurposeDuration
hyppo.iohyppo_lang_hint (first-party)Remember that you dismissed the language switch prompt, so it is not shown again180 days
hyppo.ioGoogle Tag Manager (container GTM-WMWVQ5T4)Load and manage our measurement and advertising tagsSet by the tag it loads
hyppo.ioClutch widget (widget.clutch.co)Display our profile and reviews in the site footerSet by Clutch
hyppo.ioGoogle Ads (AW-17672252748; _gcl_* cookies)Measure our advertising campaign conversions and attribute them to the originating campaignUp to 90 days
hyppo.io/lp/Meta Pixel (_fbp, _fbc)Measure the effectiveness of our advertising campaigns and attribute conversionsUp to 90 days
gochat.arGoogle Analytics 4 (G-5K5V8QKD5Y)Usage statistics for the website and the documentationUp to 2 years
gochat.argochat_lang_redirected (first-party)Prevent the automatic language redirect from repeating on every visit30 days
gochat.arGoHighLevel form and scheduler (crm.hyppo.io)Display the contact form and the demo calendarSet by the provider

Enhanced conversions. On our campaign pages, when you submit the contact form we transmit to Google the email address and phone number you entered, in order to attribute the conversion to the campaign that produced it. This is Google Ads’ enhanced conversions feature, which hashes that data. If you would rather it was not transmitted, write to it@hyppo.io or contact us through the other channels published on the site.

You can block or delete cookies from your browser settings. If you block functional cookies, some parts of the site may stop behaving as expected. We load measurement and advertising cookies on the basis of our legitimate interest in measuring and improving our communications; if you are in a jurisdiction that requires prior consent for that kind of cookie and wish to object, write to it@hyppo.io and we will action it.

4.1 Cookies the webchat widget sets on the Customer’s website

When a Customer installs the GoChat webchat widget on their own website, the widget writes a cookie in the visitor’s browser to recognize them across sessions and maintain conversation continuity. That cookie lasts 30 days and is refreshed on each visit; if the visitor does not return within that period, the identifier expires and the next conversation is treated as coming from a new contact. It is a first-party cookie of the Customer’s website: the Customer must declare it in their own cookie policy and obtain consent where their regulations require it.

5. Why we use the information and on what legal basis

PurposeLegal basis
Providing, operating and maintaining the Services; enabling accounts and Workspaces; providing supportPerformance of the contract
Responding to commercial enquiries and booking meetingsPerformance of the contract or pre-contractual steps, and legitimate interest
Invoicing, collection, and accounting and tax compliancePerformance of the contract and legal obligation
Security, fraud and abuse prevention, and access auditingLegitimate interest and legal obligation
Measuring use of the Services and improving them, including our processes, models and algorithmsLegitimate interest
Sending commercial communications and product updatesConsent or legitimate interest, with an opt-out in every message
Processing End Users’ data on behalf of a CustomerThe Customer’s instructions, as data controller
Responding to legal requirements and exercising or defending rightsLegal obligation and legitimate interest

Marketing communications. You can unsubscribe at any time from the link in each email or by writing to it@hyppo.io. Unsubscribing from marketing does not affect the operational and contractual messages we need to send you while you hold an active account or contract.

6. Artificial intelligence and automated processing

7. Who we share information with: sub-processors and providers

We work with providers who process personal data on our behalf so that we can deliver the Services. Before bringing one on board we assess its privacy and security practices and enter into an agreement imposing the applicable obligations. This is the current list:

ProviderPurposeWhere it processes data
SmartLink Pty LtdInfrastructure for the messaging and conversational-agent platform on which GoChat is deliveredAustralia and United States
Customer.io (Customer.io Inc.)Customer data platform and communications automationUnited States or European Union, depending on the region selected
Google LLC / Google Ireland LtdGoogle Cloud and BigQuery (hosting and analytics), Google OAuth (sign-in), Google Workspace — Gmail and Sheets —, Google Tag Manager and Google Ads (conversion measurement)United States and Ireland
Meta Platforms, Inc.Messaging channels (WhatsApp, Messenger, Instagram) and advertising measurementUnited States
Cloudflare, Inc.DNS, content delivery network and attack protectionUnited States and global network
Hetzner Online GmbHServers running our self-managed infrastructure, including dashboards and workflow orchestrationGermany
The Constant Company (Vultr)Hosting of supporting servicesUnited States
Supabase, Inc.Configuration database for the Customer.io Tracker appsUnited States
Stripe, Inc.Payment processingUnited States
PayPal, Inc.Payment processingUnited States
HighLevel Inc. (GoHighLevel)Our commercial CRM, and the forms and calendar embedded in our websitesUnited States
OpenAI, Anthropic, Google, DeepSeek, xAILanguage models for the AI Features, according to the Customer’s configurationUnited States
ElevenLabs, Inc.Voice synthesis and processingUnited States
Slack Technologies, Notion Labs, GitHubClient communication, project management and version control of consulting workUnited States

As the business evolves, this list may change. We will publish updates on this page and, where the agreement with a Customer requires it, notify them with the notice period set out there so they can exercise their right to object.

In addition to these providers, we may share information:

We do not sell personal data. We do not trade or disclose it to third parties for their own advertising or marketing.

7.1 Links and third-party services

Our websites and products link to and integrate third-party services. What those third parties do with your information is governed by their own policies, not by this one. If you choose to connect an external service to the Services, bear in mind that doing so may supply personal information to that third party. We recommend reading their policies before connecting it.

8. Where we process information, and international transfers

GoHyppo LLC is established in the United States and Voxtur Ltd in Saint Kitts and Nevis; our team works primarily from Argentina and Spain. Our infrastructure and that of our providers is located in the United States, Germany, Ireland and other regions, depending on the service, as detailed in the table in section 7. Information may therefore be transferred and processed outside your country of residence, including countries whose data protection laws may differ from those of your jurisdiction.

When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to third countries without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, and on any applicable supplementary measures. You can ask us about those mechanisms by writing to it@hyppo.io.

9. How long we keep information

We keep personal data for as long as necessary for the purposes described, and then delete or anonymize it. These are the specific periods:

WhatHow long
Conversation history sent by the End User or by a human agent, across all channels6 months
Conversation history sent by the bot3 months
WhatsApp media files30 days. If the Customer connects their own S3 storage, the same period as the conversation history
Contact profiles and custom attributesWhile the Workspace is active, or until the Customer deletes them
Workspace after cancellation30 days in read-only mode for export; deletion thereafter
Account dataWhile the account is active, and up to 12 months after closure
Billing data and invoicesThe period required by applicable accounting and tax obligations
Commercial enquiries and leadsUp to 24 months from last contact, unless it becomes a contractual relationship
Technical and security logsUp to 12 months
BackupsPurged in their normal rotation cycle, up to 35 days after deletion in production

The product’s current limits and periods are published and kept up to date in the GoChat documentation on data and retention.

An important warning about synced tables. When a Customer syncs a table from their own database into the Platform, the sync is not two-way: if the Customer deletes a record or a table at the source, the synced copy is not automatically removed from the Platform. The Customer must delete it there as well. We flag this because it directly affects their ability to honour an End User’s deletion request.

We may keep data for longer where necessary to comply with a legal obligation, respond to a request from an authority, or exercise or defend rights in a claim.

10. How we protect information

We apply reasonable technical, administrative and physical measures, appropriate to the state of the art, to preserve the confidentiality, integrity and availability of information: encryption in transit, encryption at rest for credentials and configuration data, secrets management, access control on a least-privilege basis, strong authentication on critical systems, access logging, regular backups, and review of the providers we bring on board. We limit access to personal data to personnel who need it for their role, subject to confidentiality obligations.

No system is completely secure and we cannot guarantee absolute security. In the event of a personal data breach, we will notify the authorities and affected individuals where applicable regulations require it, and our Customers without undue delay where it affects data we process on their behalf, with the information they need to meet their own obligations.

11. Your rights

Depending on where you live, you may have the right to:

11.1 Applicable frameworks

11.2 How to exercise them

Write to it@hyppo.io. We generally do not charge for handling your request. We may ask for additional information to verify your identity, as a security measure to avoid disclosing personal data to someone not entitled to receive it. We respond to legitimate requests within one month; if the request is particularly complex or if you have made several, we may extend that period and will let you know. We may charge a reasonable fee, or decline to act, where a request is manifestly unfounded, repetitive or excessive; this does not apply to withdrawal of consent.

11.3 Complaints

If you want to complain about this Policy or about our practices, write to it@hyppo.io with the subject “Data privacy”. We will respond as soon as possible. If you believe your complaint has not been adequately resolved, you may take it to the supervisory authority for your jurisdiction.

12. Our Customers’ obligations towards their End Users

If you are a Customer, you are the data controller for your End Users’ data and it is therefore your responsibility to:

We will reasonably assist you in meeting these obligations. If you need a data processing agreement, the applicable one is our Data Processing Agreement; to execute it, write to it@hyppo.io.

13. Annex A — Customer.io Tracker for Shopify

App: Customer.io Tracker · Contact: it@hyppo.io

Overview

Customer.io Tracker is a Shopify-native application that connects a merchant’s store to the merchant’s own Customer.io workspace. The merchant is the data controller and the owner of the Customer.io account; we act as a conduit and processor on the merchant’s behalf. We do not sell personal data and do not use it for any purpose other than delivering it to the merchant’s configured Customer.io workspace.

What we collect through Shopify’s APIs

When a merchant enables server-side tracking, the app receives the following webhook events and forwards them to the merchant’s Customer.io workspace:

We do not retain this data. Each payload is held only in memory for the duration of the request while it is forwarded to the merchant’s workspace. Application logs record only the event topic, shop domain, a message identifier and the delivery outcome — never personal data.

What we collect from the merchant

These are stored in our database (Supabase), encrypted at rest and accessible only via a server-side service-role credential.

What buyers’ browsers send

When the merchant enables the storefront tracker, Customer.io’s analytics.js — served by Customer.io’s CDN — runs in the buyer’s browser and sends page views and identify events directly to the merchant’s Customer.io workspace. This data does not pass through our servers.

How we use the data

Solely to deliver Shopify events to the merchant’s own Customer.io workspace so the merchant can run their own lifecycle marketing and automations. We do not profile buyers, make automated decisions about them, or share data with any third party other than the merchant’s own Customer.io endpoint.

Retention

Sub-processors, data location and certifications

This app’s sub-processors, distinct from the general list in section 7:

Sub-processorRoleSecurity posture
Google Cloud RunApp backend hosting (US region)ISO 27001, SOC 2/3
SupabaseMerchant configuration storage (US region)SOC 2 Type II
Customer.ioDestination workspace owned by the merchant (US or EU per merchant selection)ISO 27001, SOC 2 Type II, HIPAA

The merchant’s destination (Customer.io) maintains ISO 27001, SOC 2 Type II and HIPAA certifications and an annual external penetration test. The app backend and its configuration store run on Google Cloud Run and Supabase, both independently certified. The app itself stores no buyer data, as set out under Retention. These certifications belong to the providers named, not to GoHyppo LLC or Voxtur Ltd.

If the merchant operates in or serves the EEA or the UK, they should ensure appropriate transfer mechanisms are in place for any data leaving that region.

Buyer data rights

We honour Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Because we do not store buyer personal data, data subject access and erasure requests are fulfilled by the merchant within their own Shopify admin and Customer.io workspace.

14. Annex B — Customer.io Tracker for Tiendanube

App: Customer.io Tracker (Tiendanube) · Contact: it@hyppo.io

Overview

The app connects the merchant’s Tiendanube store to the merchant’s own Customer.io workspace, to which it forwards purchase events. The merchant authorizes the app via OAuth and enters their Customer.io write key in the embedded admin panel. As with the Shopify app, the merchant is the data controller and we act as a conduit and processor.

The app is server-side only. Since 27 July 2026 it injects no storefront script and performs no browsing analytics: it does not record page views, product views, cart activity or checkout behaviour.

Which events it sends

Each person is identified by their email address, which is the identifier used to create or update the profile in Customer.io.

What data is transmitted

On receiving the webhook, the app fetches the order from the Tiendanube API and forwards it exactly as Tiendanube returns it, without renaming or deriving fields, together with the customer data associated with the order. Depending on what the store collected, this may include name, email address, phone number and billing and shipping addresses, in addition to the order details. Unlike Shopify, Tiendanube does not redact phone or address, so those fields are transmitted to the merchant’s workspace.

We do not retain that data. It is held in memory for the duration of the request, only as long as needed to forward it. Application logs record the event, the store identifier, the order identifier and the delivery outcome.

What we collect from the merchant

These are stored in our database (Supabase, East US region), encrypted at rest and accessible only from the server.

Retention and removal

Sub-processors

Google Cloud Run (backend, US region), Supabase (merchant configuration, US region) and Customer.io (the merchant’s destination workspace). The app runs in GoHyppo’s Google Cloud project.

Buyer data rights

Because we do not store buyer personal data, access, rectification and erasure requests are fulfilled by the merchant from their Tiendanube admin and their Customer.io workspace.

15. Changes to this Policy

We may change this Policy at any time. The current version, with its last-updated date, is published on this page. Where a change is material and affects your rights, we will notify you through the dashboard or by email with reasonable advance notice. Use of the Services after the effective date constitutes acceptance of the updated version.

16. Contact

GoHyppo LLC · Miami-Dade County, Florida, United States
Voxtur Ltd · Reg. 0014565 · Suite 5, Horsford’s Business Centre, Long Point Road, Charlestown, Nevis KN0801
Privacy, rights requests and complaints: it@hyppo.io
Commercial and product enquiries: hello@hyppo.io

×
Hi! 👋

How can we help you today?

Please write a message first.