Skip to content

Legal

Privacy Policy

How personal information is collected, used, disclosed, retained, and controlled across PopHops and PopHops-powered experiences.

Effective date: August 28, 2026

Who this Policy covers. This Policy is organized by interaction so visitors, consumer users, builders, organization administrators, merchants, scanner and event staff, white-label users, and people whose information is supplied by a PopHops customer can find the sections relevant to them.

1. Scope and how to use this Policy

This Privacy Policy explains how PopHops collects, uses, discloses, retains, and protects personal information across PopHops-operated websites, builder and merchant workspaces, consumer mobile applications, scanner tools, APIs, support experiences, and PopHops-powered public or white-label experiences (together, the “Services”).

The information and responsible party can vary by context. PopHops may determine why and how information is used for its own accounts, security, billing, product operations, and direct relationships. An organization, merchant, venue, or experience operator may determine why and how information is used in its workspace or branded experience, with PopHops processing that information on its behalf. Contact the identified organization when its notice controls the interaction; contact PopHops for PopHops-controlled processing.

2. Information visitors and consumer users provide

Depending on the feature, we may collect:

  • Account and profile information such as name, username, email address, phone number, photo, language, time zone, preferences, and authentication details.
  • Purchase, pass, ticket, coupon, reward, transfer, check-in, redemption, review, follow, message, support, and account-deletion information.
  • Content you upload or submit, such as photos, comments, reviews, messages, reports, and support attachments.
  • Payment and transaction details. Full payment-card data is generally handled by a payment provider rather than stored directly by PopHops.
  • Information you choose to provide when joining a waitlist, responding to a form, entering a promotion, or communicating with PopHops or an experience operator.

3. Information builders, organizations, and merchants provide

We may collect business contact details, organization and merchant profiles, workspace roles, campaign and experience configuration, destination and catalog content, customer or audience records, invitations, integrations, subscription and billing information, fulfillment activity, support requests, and audit history.

If an organization supplies information about customers, members, employees, invitees, or other people, that organization is responsible for providing required notices and having authority to use and share the information. PopHops uses it to provide the configured Services and for the other purposes described in this Policy and applicable agreements.

4. Scanner and event-operation information

Scanner and event workflows may collect activation-link details, organization and venue authorization, device information, scan results, redemption status, timestamps, error and fraud signals, and operational logs. Scanner access should be assigned only to authorized staff and used only for the applicable event or venue purpose.

5. Information collected automatically

When you use the Services, we may collect device, browser, app, network, and usage information, including IP address, device and advertising identifiers where permitted, operating system, language, pages and screens viewed, clicks, referring URLs, crash and diagnostic data, session identifiers, and timestamps.

Web experiences may use cookies, local storage, pixels, and similar technologies for authentication, security, preferences, analytics, performance, and—where permitted and enabled—communications or marketing. Available consent controls depend on the site, device, and applicable law.

6. Device permissions and sensitive features

Some features request device-level permission at the time they are used:

  • Precise or approximate location may support nearby discovery, navigation, check-ins, weather, or location-based eligibility.
  • Camera and photo-library access may support QR or barcode scanning, profile or content uploads, and media capture.
  • Notifications may support tickets, pass updates, messages, reminders, security alerts, and operational communications.
  • Calendar or sharing access may support an action you request.

You can generally change permissions in device settings. Disabling a permission may limit the related feature. We do not treat permission to use one feature as consent for unrelated marketing or data use.

7. Sources of information

We receive information directly from you; from organizations, merchants, venues, event operators, invite senders, and other users; automatically from devices and use of the Services; and from service providers or integrations such as identity, payment, mapping, media, communications, analytics, fraud-prevention, and support providers.

8. How we use information

We use personal information to:

  • Create and secure accounts, authenticate users, manage roles, and prevent fraud and abuse.
  • Build, publish, deliver, purchase, own, transfer, check in to, scan, redeem, support, and measure experiences.
  • Process transactions, subscriptions, billing, fulfillment, refunds, and related records.
  • Personalize language, preferences, discovery, notifications, and account experiences.
  • Communicate about the Services, transactions, safety, security, support, and—with the required choice—marketing.
  • Operate analytics, diagnose failures, improve accessibility and performance, develop features, and understand aggregate usage.
  • Moderate content, investigate reports, enforce terms, protect people and property, and comply with law.

Where law requires a legal basis, the basis may include performance of a contract, consent, compliance with legal obligations, protection of vital interests, or legitimate interests such as securing and improving the Services. The basis depends on the context and jurisdiction.

9. AI-assisted features

When you use AI-assisted features, we may process prompts, source materials, generated drafts, edits, approvals, provenance, validation results, and related usage information. We use this information to provide the feature, maintain safety and quality, troubleshoot, and improve the Services as allowed by applicable agreements and settings. Do not submit personal, confidential, or regulated information unless you are authorized and the feature is intended for it.

10. How information is disclosed

We may disclose information:

  • To the organization, merchant, venue, organizer, or authorized staff responsible for the relevant workspace, transaction, experience, check-in, or redemption.
  • To vendors that provide hosting, databases, authentication, payments, maps, media, email, notifications, analytics, customer support, security, fraud prevention, and other operational services.
  • At your direction, including when you publish content, share a pass, connect an integration, transfer an item, or interact with another user.
  • In connection with a merger, financing, acquisition, reorganization, sale of assets, or similar business transaction.
  • To comply with law, legal process, or valid requests, or to protect rights, safety, property, users, and the Services.

Public profiles, published experiences, reviews, comments, and other designated public content may be visible to others. Review the audience and publication state before submitting or publishing.

We do not sell personal information for money. Certain analytics, advertising, or cross-context sharing practices may be treated as a “sale” or “sharing” under some laws; where applicable, we provide required notices and choices.

11. Retention

We retain information for as long as reasonably needed for the purposes described here, including providing accounts and owned experiences, honoring entitlements and redemption history, maintaining published or purchased snapshots, resolving disputes, preventing fraud, keeping audit and transaction records, and meeting legal obligations. Retention varies by record type, relationship, and legal requirement.

Account deletion removes or de-identifies information where appropriate, but it may not erase records that must be retained, information another user or organization independently controls, public content that must be handled separately, or transaction, entitlement, fraud, safety, and legal records.

12. Security

We use administrative, technical, and organizational safeguards designed to protect personal information. No system is completely secure. Protect your credentials and devices, use authorized scanner links only, and notify us if you suspect unauthorized access.

13. International processing

PopHops and its providers may process information in countries other than where you live. Where required, we use recognized safeguards for cross-border transfers. Laws and government-access rules may differ between countries.

14. Your choices and rights

Depending on your location and relationship, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, opt out of certain marketing or sharing, or appeal a decision. You can manage many profile, privacy, notification, and account-deletion choices in the applicable app or workspace.

Requests may require identity verification. If an organization controls the information, we may direct the request to that organization or assist it in responding. Authorized agents may submit requests where law permits. You may also complain to the applicable privacy or data-protection authority.

15. Children

The Services are not directed to children under 18, and we do not knowingly collect personal information from children under 18. If you believe a child has provided information, contact us so we can review and take appropriate action.

16. Changes and contact

We may update this Policy. We will post the revised version, identify its effective date, and provide additional notice when required.

Privacy questions and requests may be sent to info@pophops.co. If your request concerns an organization-operated or white-label experience, include the organization or experience name so it can be routed appropriately.