Legal

Privacy Policy

Last updated: 2026-06-15

We recognize that your privacy is very important and take it seriously. This Privacy Policy describes “Hyppo” policies and procedures on the collection, use and disclosure of your information when you use our software, mobile apps, products, services (including GoChat), interact with our websites, or interact with us directly (collectively the “Services”) and tells you about your privacy rights and how the law protects you.

By using our Services, you consent to our use of your information in accordance with this Privacy Policy. We will not use or share your personal information with anyone except as described in this Privacy Policy. Capitalized terms that are not defined in this Privacy Policy have the meaning given them in our Terms of Service.

This Privacy Policy is intended to meet our duties of transparency under the “General Data Protection Regulation”(“GDPR”) and “Health Insurance Portability and Accountability Act “(“HIPAA”).

We will post any modifications or changes to this Privacy Policy on this page.

GDPR & Privacy Review For Hyppo

Information privacy, also known as data privacy or data protection, is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, legal and political issues surrounding them. Privacy concerns exist wherever personally identifiable information or other sensitive information is collected, stored, used, and finally destroyed or deleted – in digital form or otherwise. Improper or non-existent disclosure control can be the root cause for privacy issues. Data privacy issues may arise in response to information from a wide range of sources.

Our Relationship to You

It is important that you identify which relationship(s) you have with Hyppo to understand Hyppo’s data protection obligations and your rights to your Personal Information under this Privacy Policy.

Hyppo has the following relationships:

Your Rights Relating to Your Personal Data

You have the right under this Privacy Policy to:

How to exercise your rights. If you want to exercise any of the rights described above, please contact us using it@Hyppo .io

Typically, you will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, except in relation to Consent Withdrawal, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or, we may refuse to comply with your request in these circumstances. We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Complaints?

If you would like to submit a complaint regarding this Privacy Policy or our practices in relation to your Personal Data, please contact us at: it@hyppo .io with the subject: ‘Data privacy’. We will reply to your complaint as soon as we can. If you feel that your complaint has not been adequately resolved, please note that if you are in the EU the GDPR gives you the right to contact your local data protection supervisory authority.

Who’s Personal Data Do We Collect?

We may process your personal data, if:

When We May Process Your Personal Data

We may process your personal data received directly from You or from other sources. Therefore, your personal data may be processed:

What Personal Data Do We Collect?

Hyppo uses Personal Data we collect to provide the Services, maintain security, monitor aggregate metrics such as total number of visitors, traffic, and demographic patterns, and track user content and users as necessary to comply with the applicable laws. We collect information in three ways: if and when you provide information to us, automatically through operating our services, and from outside sources.

Information You Provide to Us. The amount and type of information depends on the context and how we use the information. Here are some examples:

Information We Collect Automatically

We also collect some information automatically:

Information We Collect from Other Sources

We may also get information about you from other sources. For example, if you connect your account to a third-party service provider (for example: Facebook, Google, Slack..etc), we may receive information from that service. The information we receive depends on which services you authorize and any options that are available. Examples for the information that we may collect: id, name, picture, gender, location, Certain connections of the User such as the Friends, are also available. If the User has made more of their Data public.

Aggregated Data

We may also collect, use and share “Aggregated Data” for any purpose. Aggregated Data may be derived from your Personal Data, but once in aggregated form it will not constitute Personal Data as this data does not directly or indirectly reveal your identity. However, if we combine or connect Aggregated Data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this Privacy Policy.

No Special Categories of Personal Data

We do not collect any “Special Categories of Personal Data” about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sexual orientation, political opinions, trade union membership). Nor do we collect any information about criminal convictions and offences.

Children’s Data

We do not knowingly solicit personal information of children under the age of 16. We do not knowingly collect personal information of and from children under the age of 16. If we learn that a child under the age of 16 has provided us with personal information without parental consent, we will take steps to delete it.

Public Data

Information that you choose to make public can be disclosed publicly. That means, of course, that information like any content that you make public on your website is all available to others. Public information may also be indexed by search engines or used by third parties. Please keep all of this in mind when deciding what you would like to share.

Your Health Information

We may collect information from you that contains health information, the HIPAA requires us to ensure the confidentiality of this information.

We are required by law to maintain the privacy of protected health information, to provide individuals with notice of our legal duties and privacy practices with respect to protected health information, and to notify affected individuals following a breach of unsecured protected health information. This section describes how we may use and disclose your health information. If you have any questions about this section, please contact us at it@hyppo .io

How we May Use or Disclose Your Health Information:

Marketing Communications Preferences

You can ask us to stop sending you marketing messages or modify your email preferences at any time through any of the following methods:

Where you opt out of receiving these marketing messages, this will not apply to Personal Data provided to us as a result of emails relating to existing or pending hires, using the Services or consent to direct marketing communications.

How We Use Your Personal Data and Why

We generally use Personal Data for the following: to deliver and improve our Services; to manage our software and provide you with customer and technical support; to perform research and analysis about our software; to verify your identity and prevent fraud or other unauthorized or illegal activity; to enforce or exercise any rights in our Terms of Service;

In respect of each of the purposes for which we use your Personal Data, the GDPR requires us to ensure that we have a legal basis for that use if you are within the EU. The legal bases depend on the Services you use and how you use them. This means we collect and use your Personal Data only where:

We may also rely on your consent as a legal basis for using your Personal Data where we have expressly sought it for a specific purpose. If we do rely on your consent to a use of your Personal Data, you have the right to change your mind at any time (but this will not affect any processing that has already taken place). We have set out below, more detailed examples of relevant purposes for which we may use your Personal Data.

Who We Share Your Personal Data With?

We may share your Personal with third parties in the ways that are described below. We consider this information to be a vital part of our relationship with you.

Business Transfers

In connection with any merger, sale of company assets, or acquisition of all or a portion of our business by another company, or in the unlikely event that Hyppo goes out of business or enters bankruptcy, customer information would likely be one of the assets that is transferred or acquired by a third party. If any of these events were to happen, this Privacy Policy would continue to apply to your information and the party receiving your information may continue to use your information, but only consistent with this Privacy Policy.

With Your Consent

We may share and disclose information with your consent or at your direction. For example, we may share your information with third parties with which you authorize us to do so.

Published Support Requests

If you send us a request (for example, via a support email or one of our feedback mechanisms), we reserve the right to publish that request in order to help us clarify or respond to your request or to help us support other users.

Third Parties Sub-processors

We currently use third party subprocessors to provide our services. Prior to engaging any third party subprocessor, Hyppo performs diligence to evaluate their privacy, security and confidentiality practices, and executes an agreement implementing its applicable obligations.

Hyppo may use the following subprocessors for the purpose described below:

As our business grows and evolves, the Subprocessors we engage may also change. We will endeavour to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here. Please check back frequently for updates.

How Long We Store Your Personal Data

We will retain your information for as long as it is reasonably needed for the purposes set out in How We Use Your Personal Data and Why unless you request that we remove your Personal Data as described in Your Rights Relating to Your Personal Data. We will only retain your Personal Data for so long as we reasonably need to use it for these purposes unless a longer retention period is required by law (for example for regulatory purposes). This may include keeping your Personal Data after the termination of your contract for the period of time needed for us to

pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.

Where We Store Your Personal Data

The Services are maintained in the US. Personal Data that you provide us may be stored, processed and accessed by us, our staff, sub-contractors and third parties with whom we share Personal Data in the US or elsewhere for the purposes described in this policy. We may also store Personal Data in locations outside the direct control of Hyppo (for instance, on servers or databases co-located with hosting providers). By accessing the Services and providing us with your Personal Data, you consent to and authorize the export of Personal Data and its storage and use as specified in this Privacy Policy.

How We Protect Your Personal Data

Hyppo uses industry-standard physical, managerial, and technical safeguards to preserve the integrity and security of your personal information. We limit access to your Personal Data to those employees and other staff who have a business need to have such access. All such people are subject to a contractual duty of confidentiality. We periodically review our policies and procedures to evaluate their effectiveness and ensure that they remain up to date.

We have put in place procedures to deal with any actual or suspected Personal Data breach. In the event that personal information is compromised as a result of such a breach of security, Hyppo will promptly notify those persons whose personal information has been compromised, in accordance with the notification procedures set forth in this Privacy Policy, or as otherwise required by applicable law.

Hyppo cannot ensure that your Personal Data will be protected, controlled or otherwise managed according to this Privacy Policy if you share your login and password information with any third party, including any third party operating a website or providing other services.

Links to Other Websites & Third Party Applications

Our services may contain links to other websites not operated or controlled by Hyppo. We are not responsible for the content, accuracy or opinions expressed in such websites, and such websites are not investigated, monitored or checked for accuracy or completeness by us.

Please remember that when you use a link to go from the Services to another website, our Privacy Policy is no longer in effect. Your browsing and interaction on any other website, including those that have a link on our Site, is subject to that website’s own rules and policies. Such third parties may use their own cookies or other methods to collect information about you.

If you’d like to use third party software/services with our Services, please keep in mind that when you interact with them you may provide information about yourself to those third parties. We don’t own or control these third parties and they have their own rules about collection, use and sharing of information. You should review their rules and policies when installing and using any third party software/services.

Customer’s Obligations to Respect Individual End User’s Rights

In connection with using our Services, you may receive and determine what to do with certain personal information from your End Users, such as when communicating with them and entering into transactions with them. This means you process personal information (for example, name, email address, and shipping address) and, to the extent you do so, under EU law, you are an independent controller of data relating to other users that you may have obtained through the Services.

You are responsible for protecting user personal information you receive or process and complying with all relevant legal requirements when you use the Services. This includes applicable data protection and privacy laws that govern the ways in which you can use a user’s information. Such laws may require that you post, and comply with, your own privacy policy, which must be accessible to your users and compatible with this policy and Hyppo’s Terms of Use. For more information on the General Data Protection Regulation, see more resources at https://gdpr-info.eu and http://gdprandyou.ie

As a data controller, to the extent that you process users’ personal information outside of the Services, you may be required under applicable data protection and privacy laws to honor requests for data access, portability, correction, deletion, and objections to processing. Also, if you disclose personal information without the user’s proper consent, you are responsible for that unauthorized disclosure. This includes, for example, disclosures you intentionally make or unintentional data breaches. For example, you may receive an End-User’s email address or other information as a result of entering into a transaction with that End User. This information may only be used for the authorized purpose. You may not use this information for unsolicited commercial messages or unauthorized transactions. Without the End-User’s consent, and subject to other applicable Hyppo policies and laws, you may not add any End User to your email or physical mailing list, use that End-User’s identity for marketing, or obtain or retain any payment information. Please bear in mind that you’re responsible for knowing the standard of consent required in any given instance. If Hyppo and you are found to be joint data controllers of personal information, and if Hyppo is sued, fined, or otherwise incurs expenses because of something that you did as a joint data controller of End-Users’ personal information, you agree to indemnify Hyppo t for the expenses it occurs in connection with your processing of End-Users’ personal information.

Terms of Use for A.I. Purposes

The content and materials provided on this website are not to be used for training, demonstrating, or integrating with any AI assistant or similar purposes. Any attempt to utilise this website’s ‘Hyppo ‘ content for such activities is strictly prohibited. By using this website, you agree to comply with this restriction and acknowledge that unauthorised use of the content in this manner may result in a fine of £10,000 and potential legal action.

Changes to Our Privacy Policy

We reserve the right, in our sole discretion, to change, modify, add, or remove portions of this Privacy Policy at any time. Any changes or updates will be effective immediately upon posting to this page. You should review this Privacy Policy regularly for changes. You can determine if changes have been made by checking the Effective Date at the top of this page. Your continued use of our services following the posting of any changes to this Privacy Policy means you consent to such changes.

Keeping Your Information Safe

customer.io

Customer.io (Customer.io Inc.) Customer.io is a customer engagement and email marketing platform provided by Customer.io Inc. Personal Data processed: email address; first name; last name; Tracker; Usage Data. Processing location: United States – Privacy Policy. Category of personal information collected in accordance with the CCPA: identifiers; internet information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

We use customer.io platform provider. See their privacy policy for details on their data practices.

Google Sheets

Google Sheets is an online spreadsheet and collaboration service provided by Google LLC or Google Ireland Limited, depending on where you access Hyppo.Personal Data processed: e-mail address; first name; surname; Usage Data.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

Category of personal information collected in accordance with the CCPA: identifiers; internet information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

Gmail

Gmail is a service that manages email communication provided by Google LLC or Google Ireland Limited, depending on where you access Hyppo. Such email communication is not scanned by Google for advertising purposes. In addition, Google does not collect or use data within this service for advertising purposes in any other way.Personal Data processed: e-mail address; first name; surname; Usage Data.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

Category of personal information collected in accordance with the CCPA: identifiers; internet information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

Paypal

PayPal (PayPal Inc.) PayPal is a payment service provided by PayPal Inc. Personal Data processed: email address; first name; last name; payment information. Processing location: United States – Privacy Policy. Category of personal information collected under the CCPA: identifiers; financial information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

Hetzner

Hetzner (Hetzner Online GmbH) Hetzner is a hosting and infrastructure service provided by Hetzner Online GmbH. Personal Data processed: various types of Data as specified in the service’s privacy policy. Processing location: Germany – Privacy Policy. Category of personal information collected in accordance with the CCPA: internet information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

Google OAuth

Google OAuth is a registration and authentication service provided by Google LLC or Google Ireland Limited, depending on the location of access to Hyppo, and is connected to the Google network.Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy; Ireland – Privacy Policy.

Category of personal information collected in accordance with the CCPA: internet information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

Cloudflare

Cloudflare is a traffic optimization and distribution service provided by Cloudflare Inc. The way Cloudflare is integrated means that it filters all traffic through Hyppo, that is, the communication between Hyppo and the User’s browser, while allowing the collection of analytical data from Hyppo.Personal Data processed: various types of Data as specified in the privacy policy of the service.

Place of processing: United States – Privacy Policy.

Category of personal information collected in accordance with the CCPA: internet information.

This processing constitutes a sale based on the CCPA definition. In addition to the information in this clause, the User can find information on how to opt out of the sale in the section detailing the rights of Californian consumers.

Vultr Hosting

Vultr may work through geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.

This type of service is intended to host Data and files that allow Hyppo to function and be distributed, as well as provide an infrastructure ready to run specific features or parts of Hyppo.

Some of the services listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where Personal Data is stored.

Google Cloud

We use Google Cloud Platform with all the data allocated in US. See their privacy policy for details on their data practices.

Google account permissions

Customer.io Tracker (Shopify app)

App: Customer.io Tracker  Contact: it @ hyppo (.) io

Overview

Customer.io Tracker is a Shopify-native installation mechanism that connects a merchant’s Shopify store to the merchant’s own Customer.io workspace. The merchant is the data controller and the owner of the Customer.io account; we act as a conduit and processor on the merchant’s behalf. We do not sell personal data and do not use it for any purpose other than delivering it to the merchant’s configured Customer.io workspace.

What we collect through Shopify’s APIs

When a merchant enables server-side tracking, the app receives the following webhook events and forwards them to the merchant’s Customer.io workspace:

We do not retain this data. Each payload is held only in memory for the duration of the request while it is forwarded to the merchant’s Customer.io workspace. Application logs record only the event topic, shop domain, a message identifier, and the delivery outcome — never personal data.

What we collect from the merchant

These are stored in our database (Supabase), encrypted at rest, accessible only via a server-side service-role credential.

What buyers’ browsers send (client-side tracking)

When the merchant enables the storefront tracker, Customer.io’s Analytics.js (served by Customer.io’s CDN) runs in the buyer’s browser and sends page views and identify events directly to the merchant’s Customer.io workspace. This data does not pass through our servers.

How we use the data

Solely to deliver Shopify events to the merchant’s own Customer.io workspace so the merchant can run their own lifecycle marketing and automations. We do not profile buyers, make automated decisions about them, or share data with any third party other than the merchant’s own Customer.io endpoint.

Retention
Sub-processors, data location, and security certifications

This app’s sub-processors (note: distinct from the broader Hyppo sub-processor list, which covers other services):

Sub-processorRoleSecurity postureGoogle Cloud RunApp backend hosting (US region)ISO 27001, SOC 2/3SupabaseMerchant configuration storage (US region)SOC 2 Type IICustomer.ioDestination workspace owned by the merchant (US or EU per merchant selection)ISO 27001, SOC 2 Type II, HIPAA

The merchant’s destination (Customer.io) maintains ISO 27001, SOC 2 Type II, HIPAA, and an annual external penetration test. The app backend and its configuration store run on Google Cloud Run and Supabase, both independently certified. The app itself stores no customer data (see Retention).

If you operate in or serve the EEA/UK, ensure appropriate transfer mechanisms are in place for any data leaving that region.

Buyer data rights and GDPR

We honor Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Because we do not store buyer personal data, data-subject access/erasure requests are fulfilled by the merchant within their own Shopify admin and Customer.io workspace.

Changes

We will update this policy as the app’s data practices change and revise the “Last updated” date above.

×
Hi! 👋

How can we help you today?

Please write a message first.