Privacy Policy
HapHood helps you find time-limited deals from shops near you, and helps those shops fill their quiet hours. To do that we handle some of your information — most importantly your location. This page explains, in plain English, what we collect, why, who sees it, and how to delete it. It applies to the HapHood website (haphood.com), the web app (app.haphood.com), and the HapHood mobile apps.
The short version
- We use your location to show deals near you and to send you nearby-deal alerts. We keep only a short rolling set of recent readings, for no more than 10 minutes — not a movement history.
- Shops never see your name or contact details when you browse, reserve, or redeem. When you reserve a deal, a shop sees a reference number and an estimated walking time — nothing else.
- We ask your date of birth once, when you set up your account, only to confirm you're 18 or over. Shops never see it.
- We don't sell your data, and we don't show third-party ads.
- Payment cards (shops only) go directly to Stripe. Card numbers never touch our servers.
- Analytics runs only if you accept it, and it isn't linked to your name or email.
- You can delete your account — and everything tied to it — yourself, in the app, at any time. See Deleting your account.
Who we are
HapHood ("HapHood", "we", "us") is operated from the United Kingdom, and the business operating it is the data controller for the personal information described on this page. We're an early-stage business; this page will be updated with our registered company details once our UK company registration completes.
For anything privacy-related, contact us at [email protected].
What we collect
Your account
Sign-in is handled by our authentication provider, Logto. When you create an account we receive and store your email address, your name, and (if you set one) an avatar image. Your password is held by Logto — we never see or store it. If you choose to sign in with a third-party provider such as Google or Facebook, we receive your name, email address, and profile picture from that provider through Logto and store them as your account details. We use them only to create and sign you into your HapHood account — we receive no contacts, friend lists, or posts, and we never post on your behalf. You need an email address, a name, and a date of birth to have an account — without them we can't provide the Service; everything on this page marked optional really is optional.
Your date of birth
Setting up your account ends with a date of birth. It is required: HapHood is for people aged 18 or over, and we use your date of birth only to confirm you meet that age and to keep the account blocked if you don't. We store the date on your account, we never show it to shops, and we don't use it for advertising or profiling. You can correct it in Account. This is a self-declaration — we don't ask for ID and we don't verify it against any external record. See Children.
Optional profile details
You can choose to add a gender and phone number to your profile. These are optional — the app works without them — we use them only as part of your profile, and you can remove them at any time.
Your location
If you grant location permission, the app uses your position to show nearby deals and shops. While you're using the app, we store a short rolling set of recent readings for no more than 10 minutes. If you separately switch on Nearby alerts while HapHood is closed, the app can collect those readings in the background so we can avoid sending a nearby-deal alert based on an old or passing location. Older readings are deleted automatically, so we do not build a movement history. There's more detail in Location, in plain terms below.
Your activity
We keep records of what you do on HapHood: deals you reserve and redeem (including a snapshot of the deal so your history stays accurate if the shop later edits it), loyalty stamps and rewards, your favourite shops and deals, points and rank progress, and referral codes you've used or shared.
Shop and business information (merchants)
If you run a shop on HapHood, we store your business details: name, description, category, branch addresses and opening hours, contact details, logo, and photos. For billing, we store a reference to your Stripe customer record and your card's brand and last four digits — the card itself is entered directly with Stripe and never touches our servers. We also keep a record of each confirmed redemption, because that's what your invoices are based on.
Photos and images
Images uploaded to HapHood — shop logos, deal photos, and photos attached to feedback — are stored on our servers and served from public web addresses so they can load quickly in the app. Don't upload images you wouldn't want visible outside the app, and note that images are stored as uploaded, which may include metadata embedded by your camera.
Feedback and support
When you send feedback through the app, we store your message, its category, and any photos you attach, and it's emailed to our support inbox along with your name and email address so we can reply. The same goes for anything you email to [email protected].
Devices and push notifications
If you enable notifications in the mobile app, we store a push token for your device (issued by Google's Firebase Cloud Messaging on Android, or Apple's push service on iOS) so we can deliver alerts. We also log which notifications we've sent you, which lets us cap how many you receive.
Analytics
In the app and on this website, analytics (PostHog, hosted in the EU) loads only if you accept it on the consent banner. It records screens viewed and feature usage — and may record how a screen was used (a "session replay", including interactions and technical logs, kept for 30 days) — all under a random device identifier that we do not link to your name or email. Separately, our servers record a small number of service events (such as an account being created or a deal being redeemed) tied to your account ID — pseudonymous, not your name or email — which we use to understand whether the service is working and to bill shops correctly.
Technical data
Like nearly every online service, our infrastructure (including Cloudflare, which sits in front of our servers) processes IP addresses and standard request logs to serve pages, prevent abuse, and keep the service secure.
How we use your information
- To run the service — showing nearby deals, handling reservations and redemptions, running loyalty cards and rewards, and keeping your history (performance of our contract with you).
- To personalise what you see — your activity on HapHood can change which deals are visible to you (some deeper-discount deals may be limited to active customers), and repeated no-shows automatically reduce how many holds you can place for a while. These adjustments are automated; if you think one is wrong, contact us and a person will review it (performance of contract and legitimate interests).
- To send notifications you control — deal alerts near you and favourite-shop alerts, which you can switch off in the app at any time (your notification choices govern these; we log what we've sent so we can cap volume — legitimate interests).
- To email you about your account — a welcome when you finish setting up, team invitations and join-request updates, a notice if a deal you've reserved is cancelled, billing notices for shops, and a confirmation when you delete your account (performance of our contract with you — or, when a shop invites someone who doesn't yet have an account, our and the shop's legitimate interest in getting the invitation to them). Account emails can be switched off; service messages can't — see Notifications and email.
- To bill shops — counting confirmed redemptions and invoicing through Stripe (performance of contract, legal obligations for accounting records).
- To improve HapHood — analytics that runs only with your consent, and pseudonymous service events under legitimate interests, as described above.
- To keep the service safe — preventing abuse, enforcing our Terms, and moderating content (legitimate interests and legal obligations).
- To reply to you — support and feedback (legitimate interests).
We don't sell personal information, we don't share it with data brokers, and we don't use it for third-party advertising.
Location, in plain terms
Location is the heart of HapHood, so here is exactly what happens when you grant location permission:
- Nearby deals: your coordinates are used to work out which deals and shops are within walking distance. Queries like this are answered on the spot.
- Your recent position: while the app is in use, it periodically updates our servers with your current position. If you separately opt into Nearby alerts while HapHood is closed, these updates can continue in the background. We keep the readings for no more than 10 minutes and use at least two recent, accurate readings to check that you are still near a shop rather than simply passing it. We skip the alert when the readings are stale, inaccurate, moving too quickly, or outside walking distance.
- Walking-time estimates: when you reserve a deal, we may use your position at that moment to estimate your walking time to the shop. The shop sees the estimate — never your coordinates.
- Operations dashboard: a small number of authorised HapHood operators can see a live map of recent user positions, shown under pseudonymous reference codes (not names or emails), on an internal, access-controlled dashboard. We use it to understand where HapHood is active. These views aren't stored as a history.
- Map and address services: to draw the map, the app loads tiles from CARTO (or OpenStreetMap as a fallback), which means those services see your IP address and the area of the map you're viewing. To turn coordinates into a readable place name — or to help merchants type an address — coordinates or address text may be sent to the Photon geocoder (Komoot, Germany) and postcodes.io (UK).
You can use HapHood without granting location permission — you can browse the map manually. Background collection is off unless you choose to enable it, and you can switch it off in Account → Preferences or revoke the permission in your device settings at any time.
Who sees your information
- Shops you visit: shops never see your name, email, or contact details when you browse, reserve, or redeem. When you reserve a deal, the shop sees a reference number and an estimated walking time. When you redeem, the shop scans a code — the till knows a valid customer redeemed, not who you are. Your loyalty progress at a shop is likewise shown to the shop only in aggregate. The one exception is when you introduce yourself: if you ask to join a shop's team, the shop sees the name and email you provide.
- Other users: nothing. HapHood has no public profiles.
- Service providers: we use a small set of providers to run HapHood — hosting, authentication, payments, email, push delivery, analytics, and maps. Each one is listed, with what it does and what it processes, on our Subprocessors page. Providers that handle personal information on our behalf do so only on our instructions, under contracts requiring them to protect it to at least the standard described in this policy.
- Authorities: we may disclose information if the law requires it, or to protect the rights and safety of our users, shops, or the public.
Where your information lives
Our servers are hosted in Europe, and our analytics is hosted in the EU. Some of our providers (such as Stripe for payments, Resend for email, and Google for push delivery) operate globally, including in the United States. Where personal information leaves the UK, we rely on our providers' UK GDPR–compliant safeguards, such as the UK International Data Transfer Agreement or Addendum and equivalent standard contractual clauses.
How long we keep it
- Your account and activity: for as long as you have an account. Delete your account and it goes with it — see below.
- Location: recent readings are stored for no more than 10 minutes and then deleted automatically. They are also deleted if you switch off background nearby alerts or delete your account.
- Billing records (shops): invoicing runs through our payment processor, Stripe, which retains invoice records under its own legal accounting obligations even after a HapHood account is deleted.
- Email delivery records: we keep a record of each email we've sent (recipient, subject, delivery status, and whether it bounced) for 90 days, after which it is deleted automatically. Your email preferences — including the personal unsubscribe token in the link at the bottom of each account email — are kept while you have an account and removed when you delete it.
- Invitations before you have an account: if a shop invites you to its team before you have an account, we store your address so we can send the invitation and honour an unsubscribe from those emails; we delete that record after 180 days unless you unsubscribed, in which case we keep the address on our do-not-email list until you ask us to remove it.
- Do-not-send list: if an address hard-bounces we keep it on a do-not-send list for 180 days; if you report one of our emails as spam we keep it there until you delete your account or ask us to remove it.
- Moderation and deal-audit trails: where action has been taken on a deal or account, we keep a minimal record of who did what (including a snapshot of the acting user's email and, for deal actions, name) even after that account is deleted, for as long as the related decision remains relevant.
- Backups: where we maintain backups, residual copies of deleted data are purged from them within 14 days.
Deleting your account
You can permanently delete your HapHood account yourself, from inside the app:
- Open the app and go to Account → Delete account.
- The app first shows you exactly what will be deleted. If you're the only admin of a business, the business — its branches, deals, and team memberships — is deleted with you, and the preview warns you about this before you confirm.
- On confirmation we delete your reservations, redemption history, loyalty progress, favourites, referrals, feedback, and device tokens; your sign-in identity at Logto (including any Google or Facebook sign-in connection); the images of any business deleted with your account; and, for shops, your Stripe billing profile (which removes your saved card at Stripe).
- We then send one confirmation to your email address and remove your email preferences, your unsubscribe token and any do-not-send entry for that address. Nothing further is sent to it.
A few narrow records survive deletion, exactly as described in the retention section above: billing records held by Stripe, email delivery records (including the deletion confirmation itself) until their 90-day routine deletion, copies of messages you've already sent to our support inbox, and minimal moderation audit entries.
You can also request deletion without using the app: email [email protected] from your account's email address and we'll delete your account and its data for you — this works whether or not the app is installed. If you signed in with Google or Facebook, deleting your account removes the connection on our side; you can additionally revoke HapHood's access in your Google or Facebook account settings.
Deleting some of your data without deleting your account
You don't have to delete your whole account to delete data. You can remove optional profile details (like your phone number or gender) yourself in Account, and you can email [email protected] from your account's email address asking us to delete specific data — for example feedback you've sent or photos you've uploaded — while keeping your account. We'll act on the request within one month, and the same narrow retention exceptions listed above apply.
Your rights
Under UK data protection law, you have the right to:
- access a copy of your personal information;
- correct it if it's wrong;
- delete it (the in-app deletion above honours this, or ask us);
- restrict or object to how we use it, including any use based on legitimate interests;
- take your data with you in a portable format; and
- withdraw consent at any time where we rely on it (for example, analytics or location permission).
To exercise any of these, email [email protected]. We'll respond within one month. If you're unhappy with how we've handled your information, you can complain to the UK Information Commissioner's Office at ico.org.uk.
Notifications and email
HapHood can send two kinds of push notification: alerts about deals near you — including when a shop broadcasts a deal or a reserved slot nearby frees up — and alerts when a deal you've favourited goes live. When you enable notifications on your device, both are on; each has its own toggle in Account, switching one off stops those alerts immediately, and you can also turn notifications off entirely in your device settings. Because these alerts promote shops' deals, you always have the right to object to them — one tap on the toggle is all it takes, and we honour it straight away.
Emails from us are transactional or about your account. For example: a welcome when you finish setting up, team invitations and join-request updates, a notice if a deal you've reserved is cancelled, billing notices for shops (card saved, payment failed), and a confirmation when you delete your account. If a shop invites you to its team before you have an account, we store your address so we can send the invitation and honour an unsubscribe from those emails.
Account emails can be switched off in Account → Preferences, or with the unsubscribe link at the bottom of each one — one click, honoured immediately. Service messages — billing notices, a cancelled booking, and the deletion confirmation — are always sent, because they're about something that has already happened to your account.
We keep a delivery record for each email (recipient, subject, delivery status, and whether it bounced) for 90 days, then delete it automatically. The unsubscribe link carries a personal token that identifies your preferences; it's personal data, and it's removed along with your preferences. When you delete your account we send one confirmation to your address and then remove your email preferences.
Security
All traffic to and from HapHood is encrypted with TLS. Our production data is stored on encrypted volumes, access to systems is restricted and authenticated, and payment card data is handled entirely by Stripe. No online service can promise perfect security, but we design for the minimum: shops don't get your identity when you reserve or redeem, location readings are kept for no more than 10 minutes, and we collect nothing we don't use.
Children
HapHood is not directed at children and is only for people aged 18 or over. We ask for your date of birth when you set up your account, and an account that declares an age under 18 cannot finish setup or use the app. That is a self-declaration, not verified identity checking. We set the floor at 18 because of what the app itself does — it asks for your location and can send you push notifications — not because of what any particular shop sells. Shops remain responsible for age checks in store for age-restricted goods, exactly as they would for any other sale, as set out in our Terms. If you believe someone under 18 has created an account, contact us and we'll delete it.
Cookies
What we store in your browser and on your device — and the consent choices you have — is covered separately in our Cookie Policy.
Changes to this policy
When we change this policy, we'll update the date at the top. If a change meaningfully affects your rights or how we use your information, we'll tell you in the app or by email before it takes effect.