Hiype, LLC
Privacy Policy
Welcome to Hiype! This Privacy Policy ("Policy," "Privacy Policy,") forms a binding legal agreement between you and Hiype LLC ("Hiype," "we," "us," or "our").
1. Overview
This Privacy Policy ("Policy," "Privacy Policy,") applies to all users (client, coach) and is incorporated by reference into the Terms of Service.
2. Information We Collect
2.1 Account & Registration Data
By using the Platform, you consent to Hiype collecting, storing, processing, and retaining all information and data you provide through the Platform, including but not limited to account registration data, session booking information, session metadata, session transcript, feedback, ratings, communications, and any information shared during onboarding or profile setup. This data may be used to operate and improve the Platform, assess coach performance, match coaches with clients, comply with legal obligations, and for other legitimate business purposes.
2.2 Session Data
To continuously deliver and improve our platform, Hiype tracks and stores data including session durations, transcriptions, core topics, and ratings and feedback on coaches, amongst others. This data allows us to better serve you ("the coach") as well as the individuals learning, while enhancing the overall Hiype experience for everyone.
2.3 Transcripts, AI Processing and Session Data
When you participate in a session, Hiype's technology platform uses tools to process session recordings, metadata, audio feeds, and text inputs to generate transcripts and structured session summaries, amongst other outputs. Our collection and machine processing of this video, audio and text logging are conducted strictly in accordance with the explicit, advance consent you provide under Section 7.2 of the Hiype Terms of Service.
Legal Basis and Consent: In accordance with Section 7.1 and 7.2 of the Terms of Service, all recording and AI processing are performed based on your explicit, affirmative consent provided upon joining the platform and entering a session that says it is being recorded.
2.4 Payment Data
Hiype does not collect or store your full payment card details. Payment processing is handled by our third-party processor, Stripe, Inc. Your payment data is governed entirely by Stripe's Privacy Policy; see Stripe's Privacy Policy for how Stripe handles payment data.
2.5 Google Calendar Data (Coaches)
If you are a Coach and you choose to connect Google Calendar, we process additional Google user data as described in Section 5. Clients cannot connect Google Calendar, and connecting Google Calendar is optional. If you do not connect it, we do not access your Google Calendar.
3. How We Use Information
Your data may be used to operate and personalize the Platform, match Clients with appropriate Coaches, improve the quality of our services, comply with legal obligations, and for other legitimate business purposes. We do not sell your personal data to third parties for their own marketing purposes.
4. Who Can See Your Data
4.1 What Coaches Can See
Coaches will be able to see information about clients like booking history and potentially supporting tools derived from the processing and/or summarization of transcription information.
4.2 What Clients Can See
Clients will be able to see information about coaches like their public profile and potentially supporting artifacts derived from the processing and/or summarization of transcription information.
5. Google Calendar and Google User Data
This Section applies only if you are a Coach and you connect your Google account to Hiype so we can check conflicts and add confirmed Hiype sessions to a calendar you select. Hiype's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.1 What Google User Data We Access
When you connect Google Calendar, you authorize Hiype to access:
- Your Google account identifier and the email address associated with the connected Google account, so we can show you which account is connected and keep one Google account per Coach profile.
- Your calendar list (calendar names, identifiers, primary-calendar flag, and timezone), so you can choose which calendars Hiype should check for conflicts and which one calendar Hiype may write bookings to.
- Event timing and busy/free metadata on the calendars you select for conflict checks (including start and end times, all-day vs timed, busy vs free/transparent, and event type such as out-of-office or focus time), so we can block times that are already busy.
- Permission to create, update, and delete events on the calendar you designate as your Hiype booking calendar, so confirmed, rescheduled, and cancelled Hiype sessions can be reflected there.
We request only the Google Calendar permissions needed for those features: read your calendar list, read free/busy timing, and create/update/delete Hiype session events.
When we read your existing Google events for conflict checks, we request timing and busy status only. We do not retrieve or store the titles, descriptions, locations, attendee lists, or conference links of your existing Google Calendar events.
5.2 How We Use Google User Data
We use Google user data solely to provide and improve the Google Calendar features you turn on:
- Show your connected Google account and the calendars you can select.
- Treat busy times on your selected conflict calendars as unavailable for booking on Hiype.
- After a session is confirmed, create an event on your selected write calendar. The event title identifies it as a Hiype session and includes the client's name. The description includes the offering name and the join link for the session.
- Update that Hiype-created event if the session is rescheduled, and delete it if the session is cancelled.
- Keep the connection healthy (refresh access, detect revoked access, and surface sync errors to you).
We do not use Google user data for targeted or personalized advertising, retargeting, selling to data brokers, credit, lending, building databases unrelated to these features, or developing, improving, or training non-personalized artificial intelligence or machine learning models. Session recording, transcription, and AI summaries described elsewhere in this Policy apply to Hiype session media you consent to on the Platform. They do not use Google Calendar data obtained through Google APIs.
5.3 How We Store and Protect Google User Data
OAuth access and refresh tokens are stored encrypted in our vaulted secret store and are not returned to the browser. Busy times are stored as opaque time ranges (start, end, calendar identifier, and a hashed event identifier) together with connection status. We store calendar names/identifiers you select, your connected Google email, and the Google event identifier of Hiype-created events so we can update or delete them later.
We do not store imported event titles, descriptions, locations, attendees, or raw Google event payloads. Data is transmitted over encrypted connections (HTTPS/TLS). Access is limited to the systems and personnel needed to operate, secure, and support the feature.
5.4 Sharing, Transfer, and Disclosure
We do not sell Google user data. We do not share Google user data with third parties for advertising or for purposes other than providing this feature.
Google user data is processed by our infrastructure and hosting providers (see Section 8) as needed to run Hiype. Clients do not see your Google Calendar, event titles, or busy details; they only see which Hiype times are available to book. Anyone you have already shared that Google Calendar with may see Hiype-created events (including the client name in the event title) in Google Calendar, because those events live on your Google account.
You can disconnect Google Calendar in your Hiype availability settings, or revoke Hiype in your Google Account permissions. Disconnecting removes Hiype's access and deletes our stored tokens and future imported busy ranges. Events Hiype already created in Google Calendar remain in Google unless the related Hiype session is cancelled (in which case we attempt to delete that event) or you delete them in Google Calendar.
5.5 Retention and Deletion
We retain Google connection data and imported busy ranges only while your Google Calendar remains connected and as needed to operate conflict checks (busy times are refreshed over a rolling future window). When you disconnect, or when Google revokes access, we delete stored tokens and future imported busy ranges. We retain Hiype booking records and the Google event identifiers needed to update or delete Hiype-created events for as long as the related booking records are retained under this Policy, unless a longer period is required or permitted by law. To request deletion of Google user data Hiype holds, disconnect Google Calendar in settings and/or contact legal@hiype.io. You may also revoke access at any time via your Google Account.
6. International Data Transfers
If you access the Platform from Canada, the United Kingdom, the European Economic Area (EEA), Australia, or New Zealand, your personal data may be transferred to, stored, and processed in the United States or other jurisdictions where our servers and third-party processors reside. Such transfers are conducted in accordance with applicable data protection law and we ensure appropriate safeguards (such as Standard Contractual Clauses or statutory adequacy mechanisms) are in place to protect your data under applicable global privacy regulations (including GDPR, UK GDPR, PIPEDA, and the Australian Privacy Act 1988) where required.
7. Your Privacy Rights
Depending on your jurisdiction, you may have rights including the right to access, correct, delete, restrict, or port your personal data, or to object to its processing. To exercise these rights, contact legal@hiype.io. We respond in accordance with applicable law.
8. Subprocessors
8.1 Use of Subprocessors
Hiype utilizes trusted third-party service providers and subprocessors to host, operate, secure, and improve our Platform. These vendors process personal data on our behalf and strictly in accordance with our instructions, data protection agreements, and applicable privacy laws.
8.2 Categories of Providers
We share relevant data with providers in the following functional categories to deliver our services:
- Payment Processing Providers: To securely process transactions, manage subscriptions, and handle payouts without Hiype storing your full financial data (e.g., our primary payment processors).
- AI Transcription and Infrastructure Providers: To deliver live audio processing, generate written text logs, compile automated session summaries, and host platform infrastructure.
- Communication and Customer Support Tools: To manage our email updates, send system notifications, and handle user support inquiries.
- Analytics and Performance Vendors: To track platform performance, diagnose software bugs, and optimize user experience metrics.
8.3 Updates
A complete, current list of our specific subprocessors is maintained and available upon request by contacting legal@hiype.io. We review our providers to ensure they maintain strict administrative, technical, and physical safeguards to protect your personal data.
9. Regulatory Compliance
Hiype is committed to compliance with: the General Data Protection Regulation (GDPR) for EEA and UK residents; the UK GDPR; Canada's PIPEDA and provincial privacy laws; Mexico's LFPDPPP; the California Consumer Privacy Act (CCPA/CPRA); Brazil's Lei Geral de Proteção de Dados (LGPD); Australia's Privacy Act 1988; and other applicable data protection laws.
10. Children's Privacy
The Platform is intended solely for users who are at least 18 years old. If we discover that a child under 18 years old has created an account or provided us with personal information, we will take immediate steps to delete that data and terminate the account. If you believe we have inadvertently collected data from a child, please contact us immediately at legal@hiype.io.
11. Changes to this Policy
Hiype reserves the right to update these Terms at any time. We will notify you of material changes via email or platform notification at least 14 days before the changes take effect (or 30 days for EEA/UK users where required by law). Continued use of the Platform after the effective date constitutes acceptance of the updated Terms.
12. General Provisions
- Entire Agreement: This Privacy Policy and the Terms of Service constitute the entire agreement between you and Hiype regarding the Platform.
- Severability: If any provision is unenforceable, the remaining provisions continue in effect.
- Waiver: Failure to enforce any provision is not a waiver of future enforcement.
- Assignment: You may not assign your rights under this policy. Hiype may assign in connection with a merger, acquisition, restructuring of the company, or asset sale.
- Language: This Privacy Policy is in English. Translations are for convenience only; the English version controls.
For questions, contact us at legal@hiype.io.
© 2026 Hiype, LLC. All rights reserved.