Privacy Policy
Pre-launch draft. Hoopo is not yet open for bookings, and this document has not yet been reviewed by a lawyer. It describes what the app actually does today rather than what a template says it might, and it will be finalised before the first booking is taken.
The short version
- Hoopo holds what it needs to run a rental: who you are, what you lend, what you booked, and what you said to the other person.
- Hoopo never sees your ID document or your full card number. Stripe handles both, and Hoopo is told only the outcome.
- Your exact address is never shown on a listing. A renter sees an approximate area until they have a booking with you.
- Nothing is sold to advertisers. There are no advertising trackers on this website or in the app.
What is collected
| Your account | Name, email address, phone number if you give one, profile photo, and whether you signed in with Google or a password. |
|---|---|
| Your listings | Descriptions, photos, the daily rate, availability, and the postal code of where the item is kept. |
| Location | Your device's approximate location, if you allow it, to show what is near you. It is used at the moment of a search and is not kept as a history. You can decline and pick a city instead. |
| Bookings | Dates, amounts, the service fee, and the state of the handover. |
| Messages | What you send the other person through the app, kept so both of you — and Hoopo, if there is a dispute — can refer back to it. |
| Claims | Photographs and descriptions you submit as evidence of damage or a problem. |
| Device | A push notification token, so the app can tell you a message or booking has arrived, and ordinary technical logs. |
| Identity | Whether you are verified, the name on your document, and Stripe's reference for the check. Nothing else — see below. |
What is deliberately not collected
Stripe Identity captures your identity document and a selfie inside Stripe. Hoopo receives a status, the verified name and a session reference. The images, your date of birth and your document number sit behind a Stripe key that this project does not hold, so they cannot be read from Hoopo even by mistake. Card numbers are the same: Stripe holds the card, Hoopo holds a token that can charge it and the last four digits shown to you.
This is a deliberate design choice. Holding scans of people's driving licences would make Hoopo worth attacking.
Why each thing is used
- To run a booking — matching a renter to a listing, taking payment, holding it until the handover, paying the owner.
- To keep the marketplace honest — identity checks, review of claims, and acting on reports of misuse.
- To tell you things you need to know — booking confirmations, cancellations, pickup reminders, payout notices, and messages from the other person.
- To meet legal and tax obligations — records of transactions, and responses to lawful requests.
Hoopo does not use your data to build an advertising profile, and does not sell it.
What the other person sees
Your name, your profile photo, your rating, your reviews, and whether you are ID verified. Owners see the first name of whoever booked. Neither side sees the other's email address, phone number or payment details unless they choose to share them in a message.
Addresses. A listing shows an approximate area — a shaded circle roughly 700 metres across — to anyone browsing. The precise pickup point appears only once there is a booking between you, because at that point you have already agreed to meet.
Who else processes it
| Google Firebase | Hosting, the database, file storage, sign-in and push notifications. Data is held in Google Cloud, primarily in the United States. |
|---|---|
| Stripe | Payments, payouts to owners, and identity verification. Stripe is the controller of the identity documents it captures. |
| Google Maps | Turning a postal code into coordinates, and drawing the map. A postal code is sent; your identity is not. |
| Resend | Sending transactional email — confirmations, reminders, receipts. |
Each is used for that purpose and no other. Some of them store data outside Canada, which means it can be subject to the laws of the country it is stored in.
How long it is kept
- Your account — until you close it.
- Bookings and payment records — seven years after the rental, which is what Canadian tax record-keeping requires.
- Messages — for the life of the conversation, and longer where they are evidence in an open claim.
- Claim evidence — two years after the claim is closed.
- Waitlist email addresses — until launch, or until you ask to be removed.
Closing your account removes your profile, listings and favourites. Bookings and the messages attached to them are kept for the periods above, because they are also the other person's record of what happened.
What you can ask for
Under PIPEDA you can ask what Hoopo holds about you, ask for a copy, ask for a correction, and complain about how it is handled. Write to privacy@hoopo.ca and expect an answer within 30 days. If you are not satisfied you can take it to the Office of the Privacy Commissioner of Canada.
You can turn off push notifications, and revoke location access, in your phone's settings at any time. The app works without either.
Children
Hoopo is for adults. It is not offered to anyone under 18, and accounts found to belong to a minor are closed.
This website
hoopo.ca sets no cookies and carries no analytics or advertising scripts. The only thing it collects is an email address, and only if you type one into the waitlist form. Fonts and images are served from this domain rather than a third-party CDN, so loading the page tells nobody else that you visited.
Security
Access to production data is restricted to the people who operate Hoopo. Payment and identity data is held by Stripe rather than here, which is the largest single reduction in risk available. No system is perfectly secure; if a breach affects you, you will be told, along with the regulator, as the law requires.
Changes
Material changes are announced in the app and by email before they take effect. The date at the top of this page always reflects the current version.
Contact
Privacy questions and requests: privacy@hoopo.ca. Anything else: help@hoopo.ca.