Language Notice: This Privacy Policy is written in English. The English version is the authoritative, legally binding version. In the event of any discrepancy between this English version and any translation, the English version shall prevail. A French version is available upon request in accordance with the Charter of the French Language (Québec). HoopFrog® is a brand of HoopFrog® Inc.
Privacy Policy
Version 4.0 | Effective Date: April 11, 2026
HoopFrog Inc. ("HoopFrog," "we," "us," or "our") operates the HoopFrog platform ("Service"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have over it.
By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
Our Privacy Officer can be reached at privacy@hoopfrog.com | HoopFrog Inc., 3-11 Bellerose Drive, Suite 312, St. Albert, AB T8N 5C9, Canada.
1. Who We Are and How This Policy Applies
Summary: HoopFrog Inc. is the data controller for all personal data processed through HoopFrog.
Data Controller: HoopFrog Inc., Federal Corporation No. 1467452-9, 3-11 Bellerose Drive, Suite 312, St. Albert, AB T8N 5C9, Canada.
Privacy Officer / DPO Contact: privacy@hoopfrog.com
This policy applies to all users of HoopFrog, regardless of where they are located. Where you are located in the European Economic Area (EEA), the United Kingdom, or Canada, additional jurisdiction-specific rights apply as described in this policy.
We do not have a physical establishment in the EU or UK. We have designated our Privacy Officer as the point of contact for EU and UK data subjects. We are assessing whether formal EU/UK representative designation is required based on processing volumes.
2. Information We Collect
Summary: We collect information you give us directly, information generated by your use of the Service, and limited information from third parties.
a. Information You Provide Directly
- Account details: Email address (stored encrypted), date of birth, password (hashed, never stored in plain text)
- Profile information: Display name, photos, bio, gender identity, pronouns, location (city-level), dating preferences, relationship style, height, interests, and other profile fields you choose to complete
- Special category data: Sexual orientation and gender identity, and your religious or philosophical beliefs (for example, your responses to optional questionnaire items such as religious affiliation and how important religion is to you), as disclosed voluntarily through your profile and questionnaire. This is special category data under GDPR Article 9. We process it only with your explicit consent (see Section 4). You can edit or remove your gender identity, orientation, and religious or philosophical information at any time in your profile and questionnaire settings, and deleting your account permanently removes this sensitive data from our systems.
- Communications: Messages you send to other users (encrypted at rest using industry-standard encryption), voice notes, Opener prompts, and any communications you send to our support team
- Consent records: Records of your consent to these policies and to the processing of your special category data
- Payment information: Subscription details; payment card processing is handled entirely by PayPal, we do not store your full card details
b. Information Generated by Your Use of the Service
- Usage data: Pages visited, features used, discovery feed interactions, connection history, message timing (not content), login timestamps
- Device and technical data: IP address (stored only as a salted, irreversible SHA-256 hash; we retain no full plaintext IP addresses, except that, where we detect child sexual abuse material, we retain the full uploader IP address as legally required evidence preserved for law enforcement. Where an IP is used transiently for rate-limiting it is truncated to the first three octets for IPv4 or first four groups for IPv6), browser type, operating system, device identifiers. We also collect your device's reported time zone and analyze your connection's network type, including indicators that an IP address belongs to a VPN, proxy, or datacenter, to detect location-masking and fraud.
- Location data: City-level location you enter, or approximate location from IP address. No precise GPS unless you explicitly grant permission.
- Photo metadata removal: when you upload a photo, we automatically strip embedded metadata such as EXIF camera information and GPS location coordinates before the photo is stored or shown to other members, so it is not exposed to other users.
- Activity indicators: Last active timestamp (suppressed when Invisible is enabled)
c. Information from Third Parties
- OAuth providers (Apple, Google): Email address and unique identifier. We do not receive your password from these providers.
- Age verification (VerifyMy): Boolean pass/fail result, age band (18+), and anonymised reference token only. We do not receive identity documents. See Section 10.
- Biometric identifiers (facial geometry scores): Collected during selfie age/identity verification. Governed by our separate Biometric Privacy Policy, which establishes retention limits (max 3 years or purpose-satisfied, whichever is sooner), destruction procedures, and your right to revoke consent. Processed under GDPR Art. 9(2)(a) explicit consent and, for Illinois residents, a BIPA § 15(b) signed written release.
Information About People Who Are Not Registered Users
Summary: Sometimes we receive information about people who do not hold a HoopFrog account - for example when a user reports someone, names another person in a message or scam report, or uploads a photo that includes someone else.
Information other members provide about you: after a mutual connection, a member may privately note how they were treated (positive, neutral, or negative). These notes are private. The person rated is never shown the rating or who submitted it, and the notes contribute to an internal safety-and-quality score that is not shown to other members and is used solely for platform safety.
Where we receive personal data about you from another person rather than from you directly, the categories are typically your name or alias, the content in which you were mentioned, and any image in which you appear. We process this data on the basis of our legitimate interests in keeping the platform safe and in meeting our legal and safety obligations (GDPR Art. 6(1)(f) and, where applicable, Art. 6(1)(c)), and we limit it to what is necessary for those purposes.
This is the information we are required to describe under GDPR Article 14 (information not obtained from the data subject). If you believe you have been mentioned in, or appear in, content on HoopFrog and you are not a user, you may contact us at privacy@hoopfrog.com to exercise your rights of access, rectification, objection or erasure, subject to the limits that apply where disclosure would prejudice an investigation or the rights of another person.
3. How We Use Your Information
Summary: We use your data to operate the platform, keep it safe, communicate with you, and comply with the law. We never sell your data.
- To provide and operate the Service: Compatibility ranking, profile display, messaging, subscription processing
- To keep the platform safe: Automated message scanning, age verification, scam detection, user reporting and banning
- To communicate with you: Transactional emails, safety alerts, platform updates
- To send marketing communications: Only with your consent or as permitted by CASL; unsubscribe at any time
- To improve the Service: Usage analytics, performance monitoring
- To comply with legal obligations: Responding to lawful requests, audit logs, breach notification, legally required retention
- To enforce our Terms: Investigating violations, taking action against accounts violating community standards
We do not sell your personal information to any third party, ever. We do not use your personal data to train external AI models.
4. Legal Basis for Processing (GDPR / UK GDPR)
Summary: For users in the EEA and UK, every processing activity has a specific legal basis. This section maps each one.
For users in the European Economic Area or the United Kingdom, we rely on the following legal bases under GDPR Article 6 and Article 9:
| Processing Activity | Legal Basis | Provision |
|---|---|---|
| Account creation and operation | Contract performance | Art. 6(1)(b) |
| Transactional emails | Contract performance | Art. 6(1)(b) |
| Payment processing | Contract performance | Art. 6(1)(b) |
| Special category data (sexual orientation, gender identity, religious or philosophical beliefs) | Explicit consent | Art. 9(2)(a) |
| Age verification | Legal obligation + Legitimate interest | Art. 6(1)(c) + (f) |
| Automated message scanning for safety | Legitimate interest (platform safety) | Art. 6(1)(f) |
| Anti-ghosting nudge system (timing only, not content) | Legitimate interest | Art. 6(1)(f) |
| Analytics (GTM, Clarity, Mixpanel) | Consent | Art. 6(1)(a) |
| Marketing communications | Consent (or legitimate interest under CASL) | Art. 6(1)(a) |
| Legal requests / law enforcement | Legal obligation | Art. 6(1)(c) |
| Security logging and fraud prevention | Legitimate interest | Art. 6(1)(f) |
| Consent records | Legal obligation | Art. 6(1)(c) |
| Breach notification | Legal obligation | Art. 6(1)(c) |
Where we rely on legitimate interest, we have conducted a balancing test and determined our interests do not override your fundamental rights. You have the right to object at any time (see Section 8).
Where we rely on consent, you can withdraw it at any time without affecting prior processing.
Important, automated message scanning: This is NOT automated decision-making with legal or similarly significant effect within the meaning of GDPR Article 22. Flagged messages require human moderator review before any account action is taken. The system does not make final decisions about your account.
Automated Decision-Making (GDPR Art. 22)
Summary: Some features use automated systems that can affect you. You have the right to request human review.
Some features of HoopFrog use automated systems to make decisions that affect you. Under GDPR Article 22 and equivalent laws, we disclose them here and provide a right to request human review.
Scam-score flagging
We assign every incoming message a risk score based on keywords, link content, attachment patterns, and sender reputation. Messages scoring above our internal threshold are held for human moderator review before delivery. High-confidence scores (crypto pitches, phishing patterns, love-bombing sequences) may auto-hide the message and mark the sender for review.
Consequence: temporary message suppression; possible account suspension if repeated. Your right: request human review via Settings → Privacy → Request human review.
Signup fraud screening
At registration we assess connection and device signals (IP network type and geolocation, and device time zone) to detect location-masking and fraudulent accounts.
Consequence: an account may be held or feature-limited pending manual review. Your right: request human review by contacting our privacy team.
Tier-gate auto-reduction
Free-tier users who exhibit high-risk behavior patterns (mass messaging, flagged photos, reports received) may have new-feature access temporarily restricted pending manual review.
Consequence: feature degradation (fewer suggested profiles per day, delayed messages). Your right: request human review and immediate restore via Settings.
Compatibility (ranking) algorithm
We rank potential connections for you using a geometric-mean compatibility score across questionnaire answers, shared interests, and location proximity.
Consequence: who appears in your Discover feed and in what order. Your right: the algorithm's inputs (your questionnaire, their questionnaire, and your filters) are all user-controlled. Ranking itself is non-final - you still choose whom to connect with.
Content moderation auto-actions
Uploaded photos are automatically scanned for known child sexual abuse material using Microsoft PhotoDNA and Project Arachnid Shield (Canadian Centre for Child Protection), by comparing a non-reversible hash of the image against known-CSAM databases; the image itself is not shared. Photos, voice recordings, and video greetings also run through AWS Rekognition for nudity/violence detection. A CSAM match results in the content being blocked before publication, the account suspended, and the incident logged. We are committed to reporting confirmed CSAM to the appropriate authorities (NCMEC and Cybertip.ca / the Canadian Centre for Child Protection) in accordance with our legal obligations. Nudity matches are held for human review.
Consequence: content rejection or delayed publication. Your right: review via Settings → Privacy → Request human review.
How to request human review
Tap Settings → Privacy → Request human review on an automated action, or email privacy@hoopfrog.com with the affected item's ID. We respond within 30 days per GDPR Art. 12(3).
5. Data Retention
Summary: We keep your data only as long as needed. When you delete your account, most data is erased within 30 days.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (profile, messages, photos) | Until deletion, then 30-day recovery window | Service operation |
| Messages (encrypted) | Duration of account + 30-day recovery, then purged | Service operation |
| Email logs | 90 days | Deliverability and abuse prevention |
| Security event logs | 90 days | Security monitoring |
| Login attempt logs | 90 days | Fraud prevention |
| Rate limit logs | 24 hours | Technical operation |
| Age verification status flag | Duration of account | Legal compliance |
| Consent records (consent_log) | 7 years | GDPR / PIPEDA legal obligation |
| Billing records | 7 years | Canadian tax law (CRA) |
| Incident / breach logs | 24 months minimum (PIPEDA) | Legal obligation |
| DSAR records | 3 years after completion | Legal obligation |
| Encrypted backups | 7 daily, 4 weekly, 6 monthly (approximately 6 months maximum), then overwritten | Disaster recovery |
On hard-delete (after the 30-day recovery window), we delete: profile data, photos, messages, voice notes, connection history, like-and-pass history, discovery actions, event RSVPs, ratings, report history, settings, sessions, and verification records. Consent logs and billing records are retained as required by law.
6. Sharing Your Information
Summary: We share your data only with service providers who help us operate the platform. We never sell your data.
Service Providers (Data Processors)
We use the following third-party service providers, each bound by a Data Processing Agreement (DPA) or equivalent contractual obligations:
- PayPal: Payment processing, Canada / USA
- VerifyMy: Age verification, UK. Returns pass/fail + age band only.
- Google (OAuth, GTM): Sign-in and tag management, USA
- Apple (OAuth): Sign-in, USA
- Mixpanel: Product analytics, EU data residency (consent-gated)
- Microsoft Clarity: Session analytics, USA (consent-gated)
- AWS: Photo moderation, EU (Ireland). Processed under the AWS Data Processing Addendum; SCCs apply to any onward transfer.
- AWS Transcribe: Speech-to-text transcription of voice notes and video greetings for safety moderation and captions, EU (Ireland). Processed under the AWS Data Processing Addendum; data is excluded from AWS AI/ML training.
- Cloudflare: CDN / DDoS protection, USA / EU PoPs
- OVHcloud: VPS hosting (Beauharnois, QC, Canada). DPA in place.
- Slack (Salesforce): Internal admin notifications, USA. Only ticket metadata (ID, subject, timestamp) is sent; no user personal data.
- rsync.net: Encrypted off-site backup storage, USA. Data is AES-256 encrypted at rest; rsync.net has no access to decryption keys.
- Grafana Cloud (Grafana Labs): Infrastructure monitoring and alerting, USA / EU. Receives server metrics only; no user personal data is transmitted.
- Twilio: SMS delivery for two-factor authentication, USA. Receives phone number and OTP message only.
- Mapbox: Map tiles for location-based features, USA. Receives anonymized map tile requests only; no user identity data is shared.
- KLIPY (Kikliko, Inc.): GIF search in messages, USA. Our server sends the words you type in the GIF search box. It does not send your name, account ID, device ID, or IP address. Your device loads the GIF image itself from KLIPY, so KLIPY sees your IP address at that point. Used under KLIPY's API terms and privacy policy.
- Postmark (ActiveCampaign): Transactional email delivery, USA. SOC 2 compliant, EU–US Data Privacy Framework certified. Receives recipient email address and message content for delivery only.
- FreeScout (self-hosted): Helpdesk ticketing system for user support, hosted on GreenGeeks (USA). Processes support ticket data including user name, user ID, and message content. No user email addresses are included in support tickets (GDPR-safe design).
- GreenGeeks Web Hosting: Hosting provider for the FreeScout helpdesk instance (198.72.126.225, USA). Infrastructure-level processor only; does not access ticket content.
- Rspamd (self-hosted): Spam filtering, self-hosted on OVHcloud VPS (Canada). Processes inbound email headers and metadata for security purposes. No data is shared with third parties.
- Firebase Cloud Messaging (Google LLC): Push notification delivery, USA. Receives your device push token and the notification content needed to deliver push notifications to your device.
Analytics providers only receive data after you give explicit consent through our cookie consent banner.
Legal Compliance
We review all legal requests for compliance, challenge overbroad requests, disclose only the minimum necessary, and where permitted, notify affected users before complying.
Business Transfers
In a merger or acquisition, your data may transfer. We will notify you at least 30 days before, and you may delete your account before the transfer completes.
What We Never Do
- We do not sell your personal data
- We do not share your data with advertisers for targeted advertising
- We removed Meta Pixel and TikTok Pixel in March 2026 due to the sensitive nature of dating app data
- We never create AI-generated profiles. Every profile on HoopFrog belongs to a real person
7. International Data Transfers
Summary: Some service providers are outside Canada. We have safeguards for all cross-border transfers.
- EU/EEA to Canada: Canada has adequacy status under GDPR Article 45 for PIPEDA-covered organisations.
- Canada/EU to USA: Standard Contractual Clauses (SCCs), EU Commission Implementing Decision 2021/914 (Module 2).
- UK transfers: UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs.
- VerifyMy (UK): Contractual safeguards between Canada and UK.
We implement contractual or other safeguards to protect personal data transferred outside Canada, consistent with PIPEDA, Alberta PIPA, and Québec Law 25. Copies of our SCCs are available upon request from privacy@hoopfrog.com.
International Transfers, Processor Registry (CP-F)
The following table enumerates every processor that receives personal data, the country of receipt, the data categories involved, and the safeguard relied on for cross-border transfer.
| Processor | Country | Data categories | Safeguard |
|---|---|---|---|
| Cloudflare | US | IP addresses, HTTP metadata | SCCs (2021/914 Module 2) |
| Cloudflare R2 | US | Profile photos, voice recordings, video greetings | SCCs |
| AWS Rekognition | EU (Ireland) | Profile photos (content moderation only) | AWS DPA (EU processing); SCCs for onward transfer |
| AWS S3 | US | Media fallback storage | SCCs |
| AWS Transcribe | EU (Ireland) | Voice note & video greeting audio (transcribed for safety moderation and captions) | AWS DPA (EU processing); SCCs for onward transfer |
| Google Gemini API | US | AI-processed bio + conversation text (PII-scrubbed per CP-H) | SCCs |
| VerifyMy | UK | Selfie + facial geometry during age-verify | UK adequacy decision (UK-US Data Bridge when receiver US) |
| Microsoft PhotoDNA | US | Photo hash comparisons against CSAM index | SCCs |
| Postmark (ActiveCampaign) | US | Email addresses + message content | SCCs |
| Twilio | US | Phone numbers, SMS text | SCCs |
| Firebase Cloud Messaging (Google LLC) | US | Device push tokens + notification content | SCCs |
| Grafana Labs (OnCall) | US | System incident metadata (no user PII) | SCCs |
| rsync.net | US | Encrypted backups | SCCs (encrypted at rest) |
All transfers from UK/EU/Canada to processors in third countries rely on Standard Contractual Clauses (2021/914) or equivalent approved safeguards. Current DPA registry available on request to support@hoopfrog.com, or machine-readable at GET /api/v1/compliance/dpa-registry.
8. Your Rights
Summary: You have broad rights over your personal data. Most can be exercised directly in your account settings.
Rights Under GDPR (EU) and UK GDPR
- Right of access (Art. 15): Use "Download My Data" in Settings for instant export.
- Right to rectification (Art. 16): Update your profile in Settings at any time.
- Right to erasure (Art. 17): Use "Delete My Account" in Settings, or submit a formal DSAR.
- Right to restriction (Art. 18): Request we limit how we process your data in certain circumstances.
- Right to data portability (Art. 20): Machine-readable JSON export via "Download My Data" in Settings.
- Right to object (Art. 21): Object to legitimate interest processing. Contact privacy@hoopfrog.com.
- Right to withdraw consent: At any time, without affecting prior processing.
- Right not to be subject to solely automated decisions (Art. 22): Message scanning always involves human review before any account action.
- Right to lodge a complaint: With your national supervisory authority (see Section 12).
Rights Under PIPEDA and Alberta PIPA (Canada)
- Right of access to your personal information
- Right to correction of inaccurate personal information
- Right to withdraw consent for non-essential processing
- Right to complain to the OPC, OIPC Alberta, or OIPC British Columbia
Mexican Users (LFPDPPP)
- You have ARCO rights: Access, Rectification, Cancellation, and Opposition
- We will acknowledge your ARCO request within 5 business days and respond within 20 business days
- You may revoke consent for non-essential data processing at any time
- You may file a complaint with the INAI (gob.mx/buengobierno)
- See our Aviso de Privacidad for the full Mexican privacy notice
Australian Users (Privacy Act 1988 / APPs)
- You have the right to access, correct, and request deletion of your personal information under the Australian Privacy Principles (APPs)
- We will respond to access requests within 30 days
- If we disclose your data cross-border, we take reasonable steps to ensure comparable safeguards are in place (APP 8)
- You may file a complaint with the Office of the Australian Information Commissioner (OAIC) - oaic.gov.au
- Ireland, Data Protection Commission (DPC): dataprotection.ie | Phone: +353 (0)761 104 800 | Email: info@dataprotection.ie
- Iceland, Persónuvernd (Data Protection Authority): personuvernd.is | Phone: +354 510 9600 | Email: postur@personuvernd.is
New Zealand Users (Privacy Act 2020 / IPPs)
- You have the right to access, correct, and request deletion of your personal information under the Information Privacy Principles (IPPs)
- We will respond to access requests within 20 working days
- Cross-border disclosures are made only where comparable privacy protections exist (IPP 12)
- You may file a complaint with the Office of the Privacy Commissioner of New Zealand - privacy.org.nz
Data Subject Access Requests (DSARs)
Submit via your dashboard Settings or email privacy@hoopfrog.com. We respond within 30 days (20 business days for Mexican users under LFPDPPP). Identity verification may be required. No charge for DSARs.
9. Cookies and Analytics
- Necessary cookies: Authentication, session management, cookie consent preference. Cannot be disabled.
- Analytics cookies: GTM, Clarity, Mixpanel. Only activated after explicit consent via our cookie banner.
No advertising or targeting cookies. Manage preferences via the cookie settings link in the footer. See our Cookie Policy.
10. Age Verification (VerifyMy)
Summary: We receive only a pass/fail result from VerifyMy, not your identity documents.
When you complete age verification:
- Your email is encrypted and sent to VerifyMy for background verification
- If background verification is insufficient, you complete VerifyMy's secure flow directly with them
- HoopFrog receives only: a boolean result (verified: yes/no), age band (18+), and an anonymised reference token
- HoopFrog does not receive, store, or have access to your identity documents
- The anonymised reference token cannot be used to reconstruct your identity
VerifyMy's collection, use, and deletion of your identity data is governed by VerifyMy's own privacy policy: verifymy.io/privacy-policy.
Selfie Verification (Profile Verification)
Summary: Optional photo verification to prove your profile is genuine. No selfie images are stored.
What it is: An optional feature that compares a live selfie to your profile photos to verify that your profile is genuine.
How it works: A selfie image is captured and compared to your profile photos using a third-party facial comparison service (Amazon Web Services). The comparison produces a numerical confidence score.
Special category data (GDPR Art. 9): Facial comparison constitutes biometric processing. The lawful basis for this processing is your explicit consent (Art. 9(2)(a)). Consent is obtained before the selfie is taken and can be withdrawn at any time.
Data storage: Selfie images are processed transiently and deleted immediately after comparison. No selfie images or biometric templates are stored permanently by HoopFrog. Only the verification status (verified/not verified) and numerical confidence score are retained.
Third-party processor: Amazon Web Services, Inc. (data processed in the EU - Ireland region). AWS Data Processing Addendum applies. Data is excluded from AWS AI/ML training.
Your rights: You can withdraw consent and remove your verified badge at any time via Settings > Privacy. Upon withdrawal, your verification status and score are deleted.
11. Message Encryption and Scanning
Summary: Messages are encrypted at rest. An automated scanner checks for prohibited content. Flagged messages require human review before any action is taken.
Message Encryption
All messages are encrypted at rest using industry-standard encryption. Decrypted only for delivery to the intended recipient and for safety scanning. We do not read messages for marketing, profiling, or any other purpose.
Photos in Messages
Photos cannot be sent in private messages on HoopFrog; the in-chat photo feature is disabled. Profile and gallery photos that you upload to your account are scanned for known CSAM before publication as described under content moderation.
GIF Messaging
The GIF picker is powered by KLIPY, a service of Kikliko, Inc. (San Francisco, USA). KLIPY replaced Tenor (Google) on July 21, 2026, when Google shut down the Tenor API.
Your app no longer contacts the GIF provider to search. It asks our server, and our server asks KLIPY. Our server sends the words you type in the GIF search box, how many results to load, a page marker for scrolling, our own provider key, a label that names HoopFrog as the app making the request, and a content filter set to "medium" so adult results are held back. It does not send your name, your account ID, your device ID, or your IP address. Because the search comes from our server, KLIPY sees our server's address, not yours.
The GIF image itself is still loaded from KLIPY's servers by your phone or browser, both in the picker and in the chat. At that moment KLIPY receives your IP address and can see which GIF was loaded. KLIPY's privacy policy covers that, and it says KLIPY may use IP address and search history for its own advertising. If you would rather not share that, do not use the GIF button.
Our server keeps GIF results in a short cache for 10 minutes so the same search is not sent twice. The cache is keyed on the search words, not on who searched. We count how many GIF searches an account makes, to stop abuse. We do not keep a record of the words you searched for. The link to a GIF you send stays in the message, like any other message content.
Automated Message Scanning
Our automated content moderation system scans messages for: scam solicitation, financial fraud, romance fraud, requests to move off-platform, phone number harvesting, hate speech, explicit content, and threats. Legal basis: legitimate interest (platform safety).
Scanning does not make final decisions. Flagged messages require human moderator review before any account action. This is not automated decision-making within the meaning of GDPR Article 22.
Automated Decision-Making (GDPR Art. 22)
We use automated systems to moderate content shared on our platform. This includes:
- Compatibility scoring: Based on your questionnaire answers, using a research-backed algorithm
- Photo moderation: AI-based content detection using AWS Rekognition, and known-CSAM hash matching using Microsoft PhotoDNA and Project Arachnid Shield (non-reversible image hashes only)
- Trust scoring: Based on your account history and content sharing behaviour
These automated decisions may affect your ability to use certain features. You have the right to request human review of any automated decision that significantly affects you by contacting privacy@hoopfrog.com.
Trust-Based Photo Scanning
We maintain a trust score based on your content sharing history. New accounts and accounts with prior content violations receive additional scrutiny. Established accounts with a clean history may receive reduced automated scanning. This trust score is not shared with other users and is used solely for platform safety purposes.
12. Supervisory Authorities and Breach Notification
Summary: You can complain to your local data protection authority. We will notify you promptly of any breach.
Supervisory Authorities
- Canada (Federal): Office of the Privacy Commissioner of Canada (OPC), priv.gc.ca
- Alberta: OIPC Alberta, oipc.ab.ca
- British Columbia: Office of the Information and Privacy Commissioner for B.C. (OIPC BC), oipc.bc.ca
- Québec: Commission d'accès à l'information (CAI), cai.gouv.qc.ca
- Mexico: INAI - gob.mx/buengobierno
- United Kingdom: ICO, ico.org.uk
- European Union: Your national DPA, edpb.europa.eu
- Australia: Office of the Australian Information Commissioner (OAIC) - oaic.gov.au
- New Zealand: Office of the Privacy Commissioner - privacy.org.nz
Breach Notification
In the event of a breach posing a risk of harm: notify relevant supervisory authority within 72 hours (GDPR / UK GDPR); notify affected users without unreasonable delay where high risk to rights and freedoms; notify OPC if real risk of significant harm (PIPEDA); notify OIPC Alberta without unreasonable delay (Alberta PIPA); notify the OAIC (Australia) within 30 days if likely to result in serious harm (Notifiable Data Breaches scheme); notify the Office of the Privacy Commissioner of New Zealand as soon as practicable if likely to cause serious harm (Privacy Act 2020, Part 6A); maintain breach log for minimum 24 months.
13. PIPEDA and Canadian Privacy Law Compliance
Summary: HoopFrog Inc. complies with PIPEDA, Alberta PIPA, and Québec Law 25 using the 10 Fair Information Principles.
We are subject to PIPEDA, Alberta PIPA, and Québec Law 25. We implement the 10 Fair Information Principles:
- Accountability: Privacy Officer at privacy@hoopfrog.com
- Identifying Purposes: Sections 3 and 4
- Consent: Meaningful consent before collection, use, or disclosure
- Limiting Collection: Collect only what is necessary
- Limiting Use, Disclosure, and Retention: Section 5
- Accuracy: Update in Settings at any time
- Safeguards: Industry-standard encryption, access controls, security audits
- Openness: This policy is publicly available at /legal/privacy
- Individual Access: Settings or DSAR
- Challenging Compliance: privacy@hoopfrog.com or OPC / OIPC
Named Privacy Officer: HoopFrog Inc., 3-11 Bellerose Drive, Suite 312, St. Albert, AB T8N 5C9, Canada | privacy@hoopfrog.com
Québec Residents - Law 25 Right to De-indexation
Summary: If you live in Québec, you can ask us to stop disseminating your personal information and to de-index links to it where the law allows.
Under section 28.1 of Québec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), you have the right to require that we cease disseminating your personal information, or that any hyperlink attached to your name that gives access to that information by a technological means be de-indexed or re-indexed, where the dissemination contravenes the law or a court order, or where it causes you serious injury in relation to your right to privacy or reputation that clearly outweighs the public interest in the information or the right to freedom of expression.
To make such a request, contact our Privacy Officer at privacy@hoopfrog.com or select “Request search-engine de-indexing” in your dashboard’s privacy-request menu. We respond within 30 days.
14. US State Privacy Laws (CCPA / CPRA and Others)
Summary: We comply with US state privacy laws including the California Consumer Privacy Act. We never sell your data.
Although HoopFrog Inc. is a Canadian company, we respect the privacy rights granted to US residents under applicable state laws, including:
- California (CCPA/CPRA): California Consumer Privacy Act, as amended by the California Privacy Rights Act
- Virginia (VCDPA): Virginia Consumer Data Protection Act
- Colorado (CPA): Colorado Privacy Act
- Connecticut (CTDPA): Connecticut Data Privacy Act
- Other US states with consumer privacy legislation
Your Rights Under These Laws
Depending on your state, you may have the right to:
- Know what personal information we collect, use, and share
- Delete your personal information
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
- Non-discrimination for exercising your rights
- Port your data to another service
Our Commitments
- We do not sell your personal information to any third party - ever.
- We do not share your personal information for cross-context behavioural advertising.
- We do not use your personal data to train external AI or machine learning models.
- We do not use sensitive personal information for purposes beyond what is necessary to provide the Service.
- We do not engage in profiling that produces legal or similarly significant effects without your explicit consent.
Categories of Personal Information
Under CCPA categories, we collect: identifiers (name, email), commercial information (subscription records), internet activity (usage logs, cookies), geolocation (approximate), and sensitive personal information (gender, sexual orientation - provided voluntarily for compatibility-ranking purposes only, with explicit consent).
Exercising Your Rights
To exercise any of these rights, contact our Privacy Officer at privacy@hoopfrog.com or use the Data Export and Account Deletion tools in your dashboard Settings. We will respond within 45 days (or 30 days where required). We will verify your identity before processing requests. You will not be discriminated against for exercising your rights.
Authorized Agents: California residents may designate an authorized agent to submit requests on their behalf. Agents must provide written authorization and we may require identity verification of both the agent and the consumer.
Appeals: If we deny your request, you may appeal by contacting privacy@hoopfrog.com with the subject line “Privacy Rights Appeal.” We will respond within 60 days.
15. Mexico (LFPDPPP)
Summary: We comply with Mexico's federal data protection law. Mexican users have ARCO rights with a 20-business-day response time.
For users in Mexico, HoopFrog Inc. complies with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) and its Regulations.
Your ARCO Rights
Under the LFPDPPP, you have the following rights regarding your personal data:
- Acceso (Access): Request a copy of the personal data we hold about you
- Rectificación (Rectification): Request correction of inaccurate or incomplete personal data
- Cancelación (Cancellation): Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected
- Oposición (Opposition): Object to the processing of your personal data for specific purposes
How to Exercise Your Rights
Submit your ARCO request to our designated personal data department at privacy@hoopfrog.com, or use the Data Export and Account Deletion tools in your dashboard Settings. Your request must include your name, a description of the data in question, and any documents that help verify your identity. We will:
- Acknowledge receipt within 5 business days
- Respond to your request within 20 business days from the date we receive your complete request
- This period may be extended once for an additional 20 business days if justified
Consent
Under the LFPDPPP, we process your personal data based on:
- Express consent: For sensitive personal data (sexual orientation, gender identity) - obtained via our registration consent checkbox
- Tacit consent: For non-sensitive data necessary to provide the Service - implied by your continued use after being informed via this policy and our Aviso de Privacidad
International Transfers
Your data may be transferred to Canada (our headquarters) and to third-party processors in the United States and EU. These transfers are made in compliance with LFPDPPP Articles 36–37 and are governed by data processing agreements that ensure equivalent protection.
Aviso de Privacidad
A complete Aviso de Privacidad in Spanish is available at /legal/aviso-de-privacidad, as required by the LFPDPPP.
Supervisory Authority
If you are not satisfied with our response, you may file a complaint with the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) - gob.mx/buengobierno.
16. Brazil — Lei Geral de Proteção de Dados (LGPD)
Summary: If you are located in Brazil, the LGPD (Law No. 13,709/2018) gives you specific rights over your personal data. This section explains those rights and how we comply.
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018) provides you with specific rights regarding your personal information. This section explains how HoopFrog Inc. complies with the LGPD.
Legal Basis for Processing
We process your personal data on the following legal bases under the LGPD: your explicit consent (Article 7, I) for processing dating preferences and sensitive personal data; the performance of a contract (Article 7, V) for providing the platform services you have requested; and compliance with legal obligations (Article 7, II) where required by applicable law.
Sensitive Personal Data
Dating preferences and information about your relationship interests may constitute sensitive personal data under the LGPD. We process this data solely on the basis of your explicit consent, which you provide during registration. You may withdraw this consent at any time by deleting your account.
Your Rights Under the LGPD
As a Brazilian resident, you have the following rights regarding your personal data:
- Confirmation of the existence of processing and access to your data
- Correction of incomplete, inaccurate, or outdated data
- Anonymisation, blocking, or deletion of unnecessary or excessive data
- Portability of your data to another service provider
- Deletion of data processed with your consent
- Information about third parties with whom your data has been shared
- Information about the possibility of denying consent and the consequences
- Revocation of consent at any time
To exercise any of these rights, contact our Data Protection Officer at privacy@hoopfrog.com. We will respond within 15 days in accordance with the LGPD.
International Data Transfers
Your personal data is stored and processed in Canada. Brazil's National Data Protection Authority (ANPD) recognises transfers to countries with adequate levels of data protection. Canada's PIPEDA provides a comparable level of protection to the LGPD. All transfers are conducted in accordance with LGPD Article 33.
17. SMS / Phone Number Processing
Summary: We collect your phone number for account verification and two-factor authentication. It is encrypted at rest and processed via Twilio. You can opt out at any time.
What We Collect
When you provide a mobile phone number during account registration, enable SMS-based two-factor authentication (2FA), or request identity verification for a privacy rights request, we collect and process your phone number. Your phone number is:
- Encrypted at rest using AES-256-GCM encryption
- Hashed using SHA-256 for lookup and deduplication purposes
- Never displayed to other users or shared for marketing
Purpose of Processing
Your phone number is used exclusively for:
- Account verification: A one-time SMS code to verify your phone number during registration
- Two-factor authentication (2FA): A one-time SMS code to verify your identity when logging in from an untrusted device
- Identity verification: A one-time SMS code to confirm your identity when submitting a Data Subject Access Request (DSAR) or other privacy rights request
We do not send marketing, promotional, or recurring campaign messages via SMS.
SMS Message Types and Frequency
Message frequency varies based on your usage. You will only receive SMS messages when you initiate an action requiring verification. Typically this includes 1 message per registration, 1–5 messages per month for 2FA logins, and rarely for DSAR verification.
Message and data rates may apply. Standard messaging rates from your mobile carrier apply.
Data Processor - Twilio
SMS messages are delivered via Twilio Inc. (101 Spear Street, San Francisco, CA 94105, USA), which acts as a data processor under a Data Processing Agreement (DPA) with HoopFrog Inc. For EU/UK users, the DPA includes Standard Contractual Clauses (SCCs) for international data transfers. Twilio processes your phone number solely to deliver SMS messages.
Retention
- Phone number (encrypted): Retained while your account is active, plus 30 days after account deletion
- Phone number hash: Retained for 90 days after account deletion (anti-fraud), then permanently deleted
- SMS delivery logs: 90 days, then permanently deleted
- Verification codes: Expire after 10 minutes and are not stored after use
Opt-Out
You may stop receiving SMS messages at any time by:
- Replying STOP to any message from +1 (587) 805-1506
- Disabling SMS 2FA in your account settings
- Contacting support@hoopfrog.com
If you opt out, you may switch to authenticator app (TOTP) based 2FA as an alternative.
For complete SMS disclosures including TCPA, CASL, CTIA, GDPR, Australian, New Zealand, Mexican, and Brazilian compliance details, see our SMS / Messaging Terms & Conditions.
18. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption in transit and at rest, secure password storage, access controls, regular security audits, and encrypted backups.
Report security concerns to security@hoopfrog.com or /.well-known/security.txt.
19. Children's Privacy
HoopFrog is strictly an adult platform. Accounts found to belong to minors are immediately terminated and data deleted. Contact safety@hoopfrog.com if you believe a minor has used the Service. See our Child Safety Policy.
20. Changes to This Policy
Material changes will be notified in-app at least 30 days before taking effect. Previous versions available from privacy@hoopfrog.com.
22. Account Deletion Timeline
When you delete your account:
- Immediately: your profile is hidden from all other users. You cannot log back in.
- Within 30 days: hard deletion of your profile, photos, messages, questionnaire answers, and all personal data from our primary database.
- Within 90 days: encrypted backups containing your data are rotated out. Of our facial/photo processors, only VerifyMy may hold biometric data, which is deleted per its retention policy and our deletion requests; AWS Rekognition operates statelessly and retains no facial geometry or biometric templates from our requests, and the CSAM hash-matching providers (Microsoft PhotoDNA and Project Arachnid Shield) process non-reversible image hashes only and hold no biometric data.
- Permanently retained (pseudonymised): non-identifying consent records for CASL/GDPR proof; anonymized fraud signals for scam-ring detection; financial records required by tax law (7 years).
21. Contact Us
- Privacy Officer: privacy@hoopfrog.com
- Security: security@hoopfrog.com
- General Support: support@hoopfrog.com
- Mailing Address: HoopFrog Inc., Privacy Officer, 3-11 Bellerose Drive, Suite 312, St. Albert, AB T8N 5C9, Canada
Children's Code (UK Age Appropriate Design Code)
HoopFrog is an 18+ service. We do not knowingly accept users under 18. We follow the UK Information Commissioner's Office (ICO) Age Appropriate Design Code (the "Children's Code") standards:
- Age-gate on every signup: VerifyMy age estimation plus user-declared date of birth plus a selfie check.
- No default-off data collection: all optional telemetry requires explicit user opt-in.
- Minimum data retention: see the Retention section of this policy.
- No geolocation tracking beyond approximate city.
- No profiling for commercial purposes targeting presumed minors.
- Clear, plain-language privacy policy (you're reading it).
- Parental contact channel: If you believe an account under 18 is active on our service, contact support@hoopfrog.com with details. We respond within 24 hours.
Nightly automated audits cross-check every active user's declared date of birth; any account that would put the user under 18 is suspended immediately and reviewed by our safety team. Accounts flagged as under 13 are hard-deleted within 48 hours in line with COPPA.