HoppleTerms of Service

Privacy Policy

Last updated: 28 August 2026

Applies to: the Hopple mobile application and hopple.me

1. Who we are

Hopple is operated by Hopple Technologies Private Limited (CIN U62099CH2026PTC047024), #442, Sector 20-A, Chandigarh 160020, India ("Hopple", "we", "us").

For the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we are a Data Fiduciary. For the EU/UK GDPR, where it applies, we are a data controller.

Grievance Officer (DPDP Act s.13): Sai Nirmit, team@hopple.me, #442, Sector 20-A, Chandigarh 160020, India. We respond within 30 days.

2. What this policy covers

Hopple is a shopping assistant. You describe what you are looking for, we search a catalogue of independent brands, and you can save products, group them into collections ("universes"), and request a hand-curated capsule wardrobe. This policy explains what we collect while you do that, why, who else sees it, and how you get rid of it.

3. What we collect

3.1 Information you give us

DataWhenWhy
Email addressAccount creationIdentifies your account; account recovery; service notices
Name, profile imageIf you sign in with Apple or Google, or add themDisplays your account
HandleIf you set oneLabels your content in the app
Authentication identifier from Apple or GoogleSign-inLets you sign in without us holding a password for that method
PasswordOnly if you create an email accountStored hashed, never in readable form

If you use Sign in with Apple and choose to hide your email, we receive Apple's private relay address and never see your real one.

3.2 What you create in the app

  • Chat messages — everything you type describing what you want.
  • Saved products and universes, including any name you give a universe.
  • Capsule wardrobe requests — occasion, free-text notes and comments (up to 2,000 characters each), travel dates, and a budget range.
  • Reports and blocks, if you use those controls.

3.3 What we derive

  • A style vector ("persona embedding") — a numeric representation of your preferences computed from your activity, used to rank results. It is not readable text and is not shared.
  • A style profile — occasion, budget band, vibe, category.

3.4 What we collect automatically

Technical data needed to run the service: IP address, device and OS version, app version, timestamps, and error diagnostics.

We do not use third-party advertising or analytics SDKs. We do not track you across other companies' apps or websites, and we do not sell or share personal data for advertising.

4. Two things you should know specifically

These are stated plainly because they are the parts people do not expect.

4.1 A human being reads your capsule brief

A capsule wardrobe is assembled by a person, not a machine. When you submit a request, a Hopple curator can read your occasion, notes, dates, budget and comments, together with your email address, so they can build the capsule and contact you if something needs clarifying.

Do not put anything in those fields you would not want a member of our team to read.

4.2 Your chat text is processed by OpenAI

To understand a request we send the text of your message, and the context of that conversation, to OpenAI for processing. We do not send your email, name or account identifier with it.

We use OpenAI's API under terms which, as at the date above, state that API data is not used to train their models. If that changes we will update this policy before continuing.

5. Why we process it, and on what basis

PurposeGDPR legal basis
Creating and running your accountPerformance of a contract
Answering your requests and showing resultsPerformance of a contract
Fulfilling a capsule wardrobe requestPerformance of a contract
Keeping the service secure, preventing abuse, handling reportsLegitimate interests
Improving search quality and fixing faultsLegitimate interests
Complying with lawLegal obligation

Under the DPDP Act we process personal data on the basis of your consent, given when you create an account and accept this policy, and for the "legitimate uses" that Act permits.

You may withdraw consent at any time (section 9). Withdrawal does not affect processing already carried out.

6. Who else sees your data

We do not sell personal data. We share it only with processors who run parts of the service for us, under contract, and only what each needs:

ProcessorWhat it receivesPurposeLocation
OpenAIChat message text and conversation contextUnderstanding requests, generating repliesUnited States
PineconeNumeric embeddings and product metadataSearchUnited States
Google FirebaseAuthentication identifiersSign in with Google and AppleUnited States
MongoDB AtlasAll stored account and content dataDatabase hostingIndia (Mumbai)
RenderData in transit through our serversApplication hostingUnited States (Oregon)
Hopple curatorsCapsule brief and your emailBuilding your capsuleIndia

We also disclose data where the law requires it, and to a successor if the business is transferred — in which case this policy continues to apply until you are given notice of any change.

7. International transfers

Some processors above are outside India and outside the EEA. Where the GDPR applies, those transfers rely on the European Commission's Standard Contractual Clauses. Where the DPDP Act applies, transfers are made to countries not restricted by the Central Government.

8. How long we keep it

DataRetention
Account recordUntil you delete your account
Chat messages, saves, universesUntil you delete them, or you delete your account
Capsule requests and deliveriesUntil account deletion, then 90 days in backups
Reports of content2 years after resolution, so repeat behaviour can be recognised
BlocksUntil you remove them, or account deletion
Server logs90 days

Backups are overwritten on a rolling 90-day cycle. Data may persist there for up to 90 days after deletion, and is not restored to live systems.

9. Your rights

Whoever you are, you can:

  • Access the personal data we hold about you
  • Correct anything inaccurate
  • Delete your account and its content
  • Withdraw consent
  • Complain to us, and then to a regulator

Where the GDPR applies you also have the right to restrict or object to processing, and to data portability. Where the DPDP Act applies you may nominate another person to exercise your rights if you die or become incapacitated.

Deleting your account: Settings → Delete Account, inside the app. This removes your account record, chats, saves and universes from live systems immediately, subject to the backup window in section 8. You do not need to email anyone, and we will not ask you to.

For anything else, write to team@hopple.me. We respond within 30 days.

Regulators. India: the Data Protection Board of India. EU/UK: your local supervisory authority.

10. Children

Hopple is not for people under 18.

The DPDP Act treats everyone under 18 as a child and requires verifiable parental consent before processing their data. We do not have a mechanism for obtaining that consent, so we do not knowingly allow under-18s to create an account, and the App Store age rating reflects this.

If we learn that an account belongs to someone under 18, we delete it. If you believe a child has created one, write to team@hopple.me and we will act within 7 days.

11. Security

Traffic is encrypted with TLS. Passwords are hashed. Access to production data is restricted to those who need it. Curator access is limited to the capsule briefs assigned to them.

No system is perfectly secure. Where a breach is likely to result in risk to you, we will notify you and the relevant regulator as the law requires — under the DPDP Act, the Data Protection Board and every affected person.

12. Changes

If we change this policy materially, we will notify you in the app before the change takes effect. Continuing to use Hopple after that means you accept the updated policy.

13. Contact

  • Hopple Technologies Private Limited — CIN U62099CH2026PTC047024
  • #442, Sector 20-A, Chandigarh 160020, India
  • team@hopple.me
  • Grievance Officer: Sai Nirmit, team@hopple.me
Back to hopple.me