Privacy Policy

Effective Date: October 21, 2025

Company: HypeFrame ("we", "us", "our")

Contact / Data Controller: legal@hypeframe.io

This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights. It applies to individuals who visit our website, create accounts, or use our Service.

1. What Data We Collect

A. Account & Registration Data

Name, email address, organization, billing information (payment token or billing contact), role, phone number.

B. User Content

Code, text, files, project data, and other content you upload or generate with the Service.

C. Usage & Technical Data

IP address, device and browser information, operating system, cookies and similar technologies, timestamps, log files, API usage, performance, and error logs.

D. Payment & Transaction Data

Billing address, payment card, or payment processor token (we do not store full card details; processed by third-party payment processors).

E. Communications

Support requests, emails, surveys, and other communications.

F. Derived or Inferred Data

Analytics and usage patterns derived from your interaction with the Service.

10. Children

The Service is not intended for children under 13 (or higher age in certain jurisdictions). We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it.

11. Third-Party Services & Analytics

We use third-party services (e.g., cloud providers, analytics). Those parties have their own privacy practices and may process data under their terms. We recommend reviewing their privacy policies for details.

12. Data Processing Addendum (DPA)

For customers subject to data protection regulations (e.g., GDPR), we offer a DPA that outlines roles, subprocessors, security measures, breach notification commitments, and data subject request support. Contact legal@hypeframe.io to request a DPA.

13. Data Breach Notification

If a security incident affecting your personal data occurs, we will investigate and, as required by law, notify affected individuals and regulators without undue delay.

14. Changes to this Privacy Policy

We may update this Policy. Material changes will be communicated via email or prominent notice. Continued use after the effective date constitutes acceptance.

15. Contact & Complaints

For privacy questions, exercising rights, or complaints, contact: legal@hypeframe.io. You may also lodge complaints with applicable data protection authorities.

2. How We Collect Data

  • Directly from you when you register, use the Service, contact support, or input data.
  • Automatically via cookies, server logs, and analytics.
  • From third parties: payment processors, identity providers (OAuth), third-party integrations you connect to the Service, and public sources where permitted.

3. Purposes of Processing & Legal Bases

We process data for the following purposes:

  • To provide and operate the Service (contractual necessity).
  • Billing and fraud prevention (contractual/legitimate interest).
  • Support and customer service (contractual/legitimate interest).
  • Security, compliance, and abuse prevention (legitimate interest).
  • Improvements and product analytics (legitimate interest).
  • Marketing and communications (consent or legitimate interest where allowed).
  • Legal obligations (to comply with the law).

Where required by law (e.g., GDPR), we will rely on your consent, contract performance, legal obligation, or legitimate interest as the legal basis.

4. Cookies & Tracking

We use cookies and similar technologies for authentication, security, analytics, and preferences. You can manage cookie preferences in your browser; blocking essential cookies may prevent use of the Service.

5. Sharing & Disclosure

We may share personal data with:

  • Service providers: hosting, analytics, payment processors, email providers - who process data under our instruction.
  • Affiliates and successors in case of a corporate transaction (sale, merger, reorganization).
  • Legal requests: to comply with law enforcement, legal process, or to protect rights, safety, or property.
  • With your consent or at your direction.

We do not sell personal data.

6. International Transfers

Data may be processed in countries outside your jurisdiction (including the U.S.). Where required, we use standard contractual clauses, other appropriate safeguards, or rely on applicable transfer mechanisms. By using the Service, you consent to cross-border transfers.

7. Data Retention

We retain personal data as long as necessary to provide the Service, fulfill contractual and legal obligations, resolve disputes, enforce agreements, and for legitimate business purposes. Retention periods may vary by data type; account data is generally retained until you delete your account, plus a reasonable period for backups and legal obligations.

8. Security

We use reasonable administrative, technical, and physical safeguards appropriate to the data classification. These include access controls, encryption in transit, and secure infrastructure. However, no system is impenetrable; we cannot guarantee absolute security.

9. Your Rights

Depending on jurisdiction, you may have rights including:

  • Access to the personal data we hold about you.
  • Rectification of inaccurate data.
  • Deletion ("right to be forgotten") subject to legal exceptions.
  • Restriction or objection to processing.
  • Data portability (to the extent applicable).
  • Withdraw consent where processing is based on consent.
  • Opt-out of marketing communications.
  • For California residents: rights under CCPA/CPRA (right to know, delete, opt-out of sale - note we do not sell personal data).

To exercise rights, contact legal@hypeframe.io. We may require verification.