PrivacyPolicy.
Your trust matters. So here, in plain language, is what data hoppii collects, why, who sees it, and the choices you have, consistent with the Data Privacy Act of 2012.
Who this covers
This policy explains how RackApp IT Solutions (“hoppii”, “we”, “us”) handles personal data in the hoppii apps, such as hoppii fleet, and on this website. It covers people who run a business on hoppii and their staff, and people who contact us through this website.
For data about your customers that you enter into a hoppii app, see section 7: you are responsible for it. Section 8 covers what hoppii itself does when someone visits a shop’s public booking page.
What we collect
Account & business details you give us: your name, email, phone, password (stored hashed, never in plain text), business name and address, staff accounts and roles.
Business data you put into hoppii. In hoppii fleet this includes your customers’ names and contact details, government IDs and driver’s-licence details, photos (including check-in and check-out condition photos), bookings, payments and deposits, vehicles, expenses and notes.
Feedback and rewards. When you send us feedback from a hoppii app, we keep what you send (your message, any screenshots or files you attach, and which account sent it) and our replies. If you let us share praise publicly, we credit it with the name you choose. We also keep a record of the Rewards points your business earns and uses.
Technical data collected automatically: your IP address and browser details, which are kept with your sign-in session and in our server logs, and a record of actions taken in your account (the activity log shown to the shop’s owner). In the hoppii apps we use cookies to keep you signed in and the app working, plus Google reCAPTCHA on some forms (see section 4). We don’t use advertising trackers in the apps, and analytics run only on the sign-in and sign-up pages (see section 3). Booking pages also use the visitor’s own browser storage, as set out in section 8.
This website
Emails to us. When you email us, for example to ask about a plan or to join a waitlist, we receive your email address, your name as your email shows it, and anything else you choose to write, such as your business name, phone number or fleet size. We use it to reply to you and, for a waitlist, to tell you when that app opens.
Analytics. This website uses Google Tag Manager to load analytics tools that help us understand how the site is used, such as which pages are visited. These tools may set cookies in your browser. In the hoppii apps, we use the same tools only on the sign-in and sign-up pages, to count sign-ups and sign-ins; they don’t run on booking pages or inside your account. You can block or delete these cookies in your browser settings.
Bot protection (Google reCAPTCHA)
To keep out spam and automated abuse, the hoppii app’s sign-in, sign-up and password-reset forms, and the request form on shops’ booking pages, use Google reCAPTCHA. reCAPTCHA collects information about your device and browser, such as your IP address and how you interact with the page, and sends it to Google, which may set its own cookies. Google’s Privacy Policy and Terms of Service apply to that information.
Why we use it
We use personal data to:
- provide, maintain and secure the service for you;
- send service messages: verification, password resets, booking and payment notifications, and important notices;
- reply to questions and requests sent through this website;
- provide support, investigate problems, and prevent fraud and abuse;
- review your feedback and add any Rewards points it earns;
- improve hoppii and build new features, including with combined, de-identified statistics that can’t identify you, your business or your customers;
- with your separate consent, send you product news, promotions and tips. You can withdraw this at any time without affecting the service;
- comply with our legal obligations.
We do not sell personal data, and we do not use your business data to advertise to your customers.
Our legal basis
Under the Data Privacy Act of 2012 we process personal data on one or more of these bases: your consent; performance of our contract with you (the Terms of Service); our legitimate interests in running and securing the service, where these don’t override your rights; and compliance with the law.
Data about your customers
When you enter your customers’ personal data into a hoppii app, you act as the personal information controller for that data and hoppii acts as your personal information processor: we only handle it on your instructions to provide the service. You are responsible for having a lawful basis to collect and store that data (for example a rental agreement or your customer’s consent), for giving your customers the required privacy notice, and for honouring their requests. Our processing terms are in the Terms of Service.
- IDs and licences are sensitive. Government-issued identifiers, such as licence and ID numbers, are sensitive personal information under the law. Collect only what you need for the rental, and limit which staff can see it.
- You decide how long to keep it. Keep your customers’ data only as long as you need it for your business or the law, then delete it. You can delete a customer’s records in the app.
- We don’t check it. We don’t review or verify the data you enter, and we don’t contact your customers about it, except to send the messages you set up, such as booking emails.
- Your customers’ requests. If one of your customers asks us about their data, we’ll refer them to you, and we’ll help you answer where it’s reasonable.
- If something goes wrong. If we become aware of a breach affecting your customers’ data, we’ll tell you without undue delay. As the controller, you decide whether and how to notify your customers and the National Privacy Commission, and we’ll help.
hoppii fleet: people who visit a booking page
Each shop on hoppii fleet can publish a public booking page. When a renter sends a request through it, the details they give go to that shop, which is the personal information controller; hoppii processes them for the shop as described in section 7. The shop shows its own privacy notice on the request form.
Visit counts. To show a shop how its page is doing, we count visits as a single daily total per shop. The visit count itself stores no IP address or other identifier. A session cookie stops the same browser being counted twice in a day, and link-preview bots and staff signed in to that shop aren’t counted. Like every page on hoppii, the booking page uses a session, and our servers keep a short-lived session record that includes the visitor’s IP address and browser details, for security.
Details remembered on the renter’s device. After a request is sent, the renter’s name, mobile number and email are saved in their own browser so the form is filled in next time. They stay on that device and aren’t sent to us again until the renter sends another request. The renter can remove them with “Not you? Clear it” on the form, or by clearing their browser data.
Chat and social buttons. A shop can add buttons for Messenger, Viber, WhatsApp, Facebook and Instagram. Tapping one opens that service, and its own privacy policy applies. hoppii doesn’t receive those conversations.
Who we share it with
We share personal data only with:
- service providers who help us run hoppii, such as hosting, storage, email delivery, error monitoring, payment processing, bot protection (Google reCAPTCHA) and website analytics, under confidentiality and data-protection terms;
- authorities or others when required by law or court order, or to protect rights and safety;
- a successor entity if hoppii is involved in a merger or acquisition, with notice to you.
Payments
Payments you record. hoppii fleet records the payments your customers make to you (cash, e-wallets, bank transfers, cards) for your bookkeeping. It does not process or hold those funds, so we don’t collect your customers’ card or bank credentials.
Paying for your plan. When you pay us for a plan, the payment is handled by our payment provider on its secure checkout page. We receive a confirmation and a payment reference, never your card details.
Where it’s stored, and for how long
Personal data is stored on cloud infrastructure that may be located outside the Philippines; where that happens we use appropriate safeguards. We keep your data while your account is active. When it ends, you have at least 30 days to export your records, as set out in our Terms of Service. After that we delete or anonymise it, except where we’re required to keep certain records longer, or need them to resolve disputes or enforce our agreements. Copies in our backups can take a little longer to clear. You can download your bookings, payments, expenses and other records as spreadsheet (CSV) files from the app at any time, and email us for a copy of anything else. You can delete your account or your business from the app, or ask us to delete your data.
How we protect it
Connections to hoppii are encrypted (HTTPS). We restrict access to staff who need it, hash passwords, keep logs, and keep backups. No method of transmission or storage is perfectly secure, so we can’t guarantee absolute security. Keep your own credentials and devices safe, and tell us promptly if you suspect a problem.
If a breach affects personal data we control, we’ll notify the National Privacy Commission and the people affected when and as the law requires. If it affects your customers’ data, we’ll tell you as set out in section 7.
Marketing choices
We only send marketing and promotional messages if you’ve given us separate, opt-in consent, for example by ticking the marketing box when you sign up. This is never required to use hoppii. You can withdraw consent at any time by emailing hello@rackappsolutions.com, and we’ll stop. You’ll still receive essential service messages about your account.
Your rights
Subject to the law, you have the right to be informed, to access your data, to object to or restrict processing, to correct inaccurate data, to erasure or blocking, to data portability, and to be indemnified for damage from unlawful processing. Some you can do yourself in the app, such as updating your details, downloading your records or deleting your account. For anything else, email us. If a request is about your customers’ data, it’s handled through your account, since you’re the controller of that data.
If you believe your rights have been violated you may also complain to the National Privacy Commission of the Philippines.
Children
hoppii is a tool for businesses and isn’t directed at children. We don’t knowingly collect personal data from anyone under 18 for their own use; if you believe a child has given us data, contact us and we’ll remove it.
Changes to this policy
We may update this policy as hoppii changes. We’ll post the new version here with a fresh “last updated” date and, for material changes, give you reasonable notice (for example by email or an in-app notice).
Contact us
RackApp IT Solutions operates hoppii from the Philippines and is the personal information controller for the data this policy describes, except the data about your customers covered in section 7. For privacy questions or to exercise your rights, email hello@rackappsolutions.com.
See also our Terms of Service and the hoppii fleet terms.