Privacy Policy

Your privacy matters to us. This policy explains how H0p collects, uses, and protects your personal information in compliance with applicable data protection laws.
Last Updated: 2025-11-11

H0p is committed to protecting your privacy and being transparent about how we handle your personal data. This Privacy Policy explains what information we collect, how we use it, your rights, and how we comply with the General Data Protection Regulation (GDPR) and French data protection laws.

Data Controller
H0p (France)
contact@h0p.co
Supervisory Authority
CNIL (Commission Nationale de l'Informatique et des Libertés)
https://www.cnil.fr
01

Data Controller

H0p operates as an independent URL shortening service based in France. For any questions regarding your personal data or this privacy policy, you can contact us at contact@h0p.co.

02

Information We Collect

We collect different types of information depending on how you interact with our service.

Account Information

When you create an account, we collect

  • Email address (required for registration and login)
  • Name and profile information (optional)
  • Password (encrypted using industry-standard hashing, never stored in plain text)
  • Google account information (email, profile picture) if you choose to sign in with Google

Payment Information

For paid subscriptions

  • Payment information is processed securely by Stripe (our payment processor)
  • We do not store your full credit card details on our servers
  • Stripe may collect billing address, card details, and transaction history
  • Please refer to Stripe's Privacy Policy for more information

Link and Usage Data

When you create and use shortened links

  • Original URLs and shortened link codes you create
  • Custom domains and branded short links
  • QR code configurations and settings
  • Link metadata (titles, descriptions, preview images)
  • Creation and modification timestamps

Click Analytics Data (Anonymized)

When someone clicks on your shortened links, we collect anonymized analytics

  • Click timestamps and frequencies
  • Geographic location (country, city, region) provided by Cloudflare
  • Device type (desktop, mobile, tablet)
  • Operating system and browser type
  • Referrer information (where the click came from)
  • This data is anonymized and cannot be linked to individual identities
  • Analytics data is retained for a maximum of 2 years

Technical and Session Data

To provide and secure our service

  • IP address (used only for session security and fraud prevention, not stored with analytics)
  • Browser type and version
  • Device information
  • Language preferences
  • Session cookies (strictly necessary for authentication)
  • Analytics cookies (with your consent, via Rybbit analytics)
04

How We Use Your Information

We use the collected information for the following specific purposes.

Service Provision

  • Create and manage your H0p account
  • Generate, manage, and redirect shortened URLs
  • Provide real-time click analytics and statistics
  • Process subscription payments via Stripe
  • Authenticate users via email/password or Google Sign-In
  • Send transactional emails (account confirmation, password reset, billing notifications)

Service Improvement and Analytics

  • Analyze aggregated usage patterns to improve features
  • Monitor service performance and uptime
  • Develop new functionality based on user needs
  • Conduct A/B testing for UI improvements

Communication

  • Send essential account-related notifications
  • Respond to support requests and inquiries
  • Send newsletter updates (only with your explicit consent)
  • Notify you of important service changes or security alerts

Security and Fraud Prevention

  • Detect and prevent fraudulent activity and abuse
  • Maintain session security using IP verification
  • Protect against spam and automated attacks
  • Enforce our Terms of Service and Acceptable Use Policy
05

Data Storage and Security

We take the security of your data seriously and implement robust measures to protect it.

Data Storage Location

  • All user data is stored on secure servers hosted by Scaleway in France
  • Your data remains within the European Union (EU)
  • Payment data is handled by Stripe (refer to Stripe's data practices)
  • CDN and geolocation services provided by Cloudflare (refer to Cloudflare's data practices)

Data Retention Periods

  • Active account data is retained while your account exists
  • Inactive accounts are automatically deleted after 2 years of inactivity
  • Click analytics data is stored anonymously for a maximum of 2 years
  • IP addresses for session security are not stored permanently (session duration only)
  • Billing records are retained for 10 years to comply with French accounting law
  • Deleted accounts and associated data are permanently erased within 30 days

Security Measures

  • HTTPS/TLS encryption for all data in transit
  • Password hashing using bcrypt algorithm (passwords never stored in plain text)
  • Secure session management with HTTP-only cookies
  • Regular security updates and patches
  • Access controls and limited employee access to personal data
  • Automated backups with encryption at rest
06

Data Sharing and Third-Party Processors

We do not sell your personal data to third parties. We only share data with trusted service providers necessary to operate our service.

Essential Service Providers (GDPR Article 28 Processors)

  • Scaleway (France): Server hosting and data storage
  • Stripe: Payment processing (PCI-DSS compliant)
  • Google: Authentication via Google Sign-In (optional)
  • Cloudflare: CDN, DDoS protection, and geolocation services
  • Email service provider: Transactional emails and newsletters

Legal Disclosures

We may disclose your information if required by law

  • Compliance with valid legal requests (court orders, subpoenas)
  • Protection of our legal rights and property
  • Investigation of fraud or security incidents
  • Enforcement of our Terms of Service
  • Protection of user safety and public interest

Public Information

  • Shortened URLs you create are publicly accessible by design
  • Anyone with the shortened link can access the destination URL
  • Link metadata (title, description, image) may be visible in link previews
  • Aggregate and anonymized statistics may be published or shared

International Data Transfers

  • Your data is primarily stored in France (Scaleway)
  • Some third-party processors (Stripe, Google, Cloudflare) may transfer data outside the EU
  • These processors comply with GDPR and use Standard Contractual Clauses (SCCs) or adequacy decisions
  • Refer to each processor's privacy policy for details on international transfers
07

Cookies and Tracking Technologies

We use cookies to provide functionality and improve your experience. You have control over optional cookies.

Strictly Necessary Cookies

These cookies are essential for the service to function and cannot be disabled

  • Authentication and session management (keeping you logged in)
  • Security and CSRF protection
  • Cookie consent preferences
  • Load balancing and performance

Analytics Cookies (Require Consent)

These cookies help us understand how you use our service

  • Rybbit analytics for usage statistics and feature tracking
  • Page views and navigation patterns
  • Aggregated performance metrics
  • You can opt-out via our cookie consent banner

Managing Cookies

  • You can control cookie preferences through our consent banner
  • Browser settings allow you to block or delete cookies
  • Blocking strictly necessary cookies will prevent login and core functionality
  • You can withdraw consent for analytics cookies at any time
08

Your Privacy Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data.

Right of Access (Article 15)

  • Request a copy of all personal data we hold about you
  • Receive information about how we process your data
  • Contact us at contact@h0p.co to exercise this right

Right to Rectification (Article 16)

  • Update your account information directly in your dashboard
  • Request correction of inaccurate or incomplete data
  • We will update your data within 30 days of your request

Right to Erasure / Right to be Forgotten (Article 17)

  • Request deletion of your account and associated personal data
  • Data will be permanently erased within 30 days
  • Some data may be retained for legal obligations (e.g., billing records)
  • Contact contact@h0p.co to request account deletion

Right to Data Portability (Article 20)

  • Request your data in a structured, machine-readable format (JSON/CSV)
  • Export your link data and analytics
  • Contact us to request a data export

Right to Restriction of Processing (Article 18)

  • Request temporary suspension of data processing
  • Applicable while we verify data accuracy or legitimate interests

Right to Object (Article 21)

  • Object to processing based on legitimate interests
  • Opt-out of marketing communications (unsubscribe links in emails)
  • Withdraw consent for analytics cookies

Right to Withdraw Consent (Article 7.3)

  • Withdraw consent for newsletters anytime via unsubscribe link
  • Withdraw analytics cookie consent via cookie settings
  • Withdrawal does not affect lawfulness of prior processing

Right to Lodge a Complaint (Article 77)

  • You have the right to file a complaint with the French data protection authority (CNIL)
  • CNIL website - www.cnil.fr
  • We encourage contacting us first so we can address your concerns
09

How to Exercise Your Rights

To exercise any of the rights listed above, please contact us.

Email
contact@h0p.co

Send a detailed request with your account email

Response Time
Within 30 days

We will respond to your request within one month as required by GDPR

Identity Verification
Required for security

We may ask for proof of identity to prevent unauthorized access

10

Children's Privacy

H0p is not intended for use by children under the age of 16.

  • We do not knowingly collect personal data from children under 16 years old
  • If you are under 16, please do not register for an account or provide personal information
  • If we discover we have collected data from a child under 16, we will delete it immediately
  • Parents or guardians can contact us at contact@h0p.co to request deletion of their child's data
11

Automated Decision-Making and Profiling

We want to be transparent about any automated processing of your data.

  • H0p does not use automated decision-making or profiling that produces legal effects
  • We do not use AI or algorithms to make decisions that significantly affect you
  • Fraud detection systems may automatically flag suspicious activity, but final decisions involve human review
12

Data Breach Notification

In the unlikely event of a data breach affecting your personal data.

  • We will notify the CNIL within 72 hours of becoming aware of a breach (GDPR Article 33)
  • If the breach poses a high risk to your rights, we will notify you directly within 72 hours (GDPR Article 34)
  • Notifications will include the nature of the breach, likely consequences, and measures taken
  • We have implemented security measures to minimize the risk of data breaches
13

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

  • The "Last Updated" date at the top will be revised whenever we make changes
  • For significant changes, we will notify you via email or prominent notice on our website
  • Continued use of H0p after changes constitutes acceptance of the updated policy
  • Material changes affecting your rights will require your explicit consent
  • You can review previous versions by contacting us
14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us.

Email
contact@h0p.co

For all privacy-related inquiries

Response Time
Within 7 business days

We aim to respond to all inquiries promptly

Supervisory Authority
CNIL - www.cnil.fr

You can also contact the French data protection authority

Questions About Your Privacy?

We're committed to protecting your data and respecting your rights. Contact us for any privacy-related questions.