Privacy Policy
This Policy explains the information WindowHop handles while operating store pages, booth pages, questions, pull requests, shopper searches, saves, email access, and store subscriptions.
Effective: July 24, 2026 · Version: 2026-07-24-whole-store-discovery
1. Information users provide
WindowHop may collect names, email addresses, store and booth details, public store contact information and social links, private owner contact information, employee invitations, access-recovery requests, booth claims, uploaded photos and descriptions, Store Updates, discounts, private questions and replies, one optional image attached to a private question or reply, pull-request details, optional booth-waiting-list contact information and notes, notification choices, optional practice feedback, support messages, store requests, and other information submitted through the service. Practice-form entries and practice photos remain local to the browser session and are not uploaded as live store or booth content. During store setup, WindowHop may collect a Store Owner’s private verification number. The private owner name, email, and number are available to authorized WindowHop administration for identity, billing, and account-recovery checks and are not intended for public display or ordinary employee access.
2. Information collected automatically
WindowHop may collect basic technical and activity information such as IP address, browser or device type, timestamps, referring page, requested page, security events, store and booth views, searches, saves, shares, and interactions. WindowHop may use cookies or similar browser storage for sessions, saved items, security, and basic product functionality.
3. Payment information
Store subscription payments may be processed by a third-party payment provider. WindowHop may receive customer and subscription identifiers, payment status, billing period, and limited billing details needed to manage the subscription. WindowHop does not intend to store complete payment-card numbers or card security codes.
4. How information is used
WindowHop uses information to operate and secure the service; authenticate users through expiring email links; provide role-based Store Owner, employee, booth-owner, and shopper access; verify access recovery; create and display store and booth pages; build store-defined booth rosters; deliver questions, replies, pull-request status, and requested saved-booth updates; provide an optional private booth waiting list to the relevant store; manage booth claims, store policies, available booths, practice experiences, subscriptions, retention, and support; prevent conflicting actions, spam, and abuse; understand feature usage; communicate service information; and comply with law.
5. Public and private information
After WindowHop approves a store’s initial launch, store names, addresses, public store phone numbers and email addresses, hours, websites, social links, Store Updates, approved store photos and captions, total booth-space counts, photo-ready booth pages, booth-space labels, booth names, categories, descriptions, photos, discounts, and available-booth information may be public. Booth spaces without an approved photo generally remain private from shoppers unless the store advertises them as available. Private booth questions and their optional image attachments, waiting-list names and contact information, secure access links, employee information, the Store Owner’s private name, email, and verification number, billing information, practice feedback, internal dashboard information, and support messages are not intended for public display. Waiting-list information is available to authorized Store Owners and employees of the store whose list the person joined, plus authorized WindowHop administration. Store Views & Trends reports recorded WindowHop activity and does not provide Store Owners or employees with individual shopper identities. Pull-request contact details are used for private status messages and are not displayed to store staff; stores receive the pickup code, booth label, selected photo, item description, price, and status needed to process a booth-owner-approved request.
6. How information is disclosed
WindowHop may disclose information to service providers that support hosting, databases, storage, email delivery, security, analytics, mapping, and payments; to the relevant store or booth owner when needed to provide a requested feature; to comply with legal process or protect rights and safety; or as part of a business transfer. Service providers are permitted to use information only for the services they provide to WindowHop, subject to their agreements and applicable law.
7. No sale of personal information
WindowHop does not sell personal information and does not use personal information for cross-context behavioral advertising. WindowHop may use aggregated or de-identified information that does not reasonably identify an individual.
8. Email communications
WindowHop sends essential transactional messages such as secure access links, invitations, claim notices, access-recovery status, question confirmations, direct-reply notices, store-enabled pull-request decisions and expiration notices, billing and cancellation notices, and support updates. Human-written message emails direct the recipient to the private WindowHop conversation rather than reproducing the message or attachment in email. Recommended operational notices start on for the relevant role but may be changed in Notification settings; account-security and legally required notices may still be sent when necessary. Optional summaries and product updates start off unless the user chooses them. Saved-booth updates are limited to no more than one message per followed booth in 24 hours. Automated messages use a no-reply address; users should use the displayed support address and should not forward secure access links.
9. Retention
When a store ends a booth assignment, the former renter loses access and the next renter receives a clean booth page and inbox. Prior assignment records may remain in a restricted store and WindowHop archive for support, security, policy enforcement, and legal needs. A booth owner may remove a completed private question from their own inbox, but that action hides the thread from that booth-owner view rather than deleting the store’s read-only oversight record or WindowHop’s authorized archive. Booth waiting-list entries remain available to the store while they are active and may be retained after a status change for store records, support, safety, and legal needs until the store or WindowHop deletes them under applicable retention practices. When a store cancels WindowHop, its public store and booth content becomes private and is ordinarily retained for six months so service can be restored without rebuilding the store. After that period, WindowHop may permanently delete the store’s private operational content and personal data, including associated waiting-list records and stored media. WindowHop may retain a minimal internal record needed for legal, accounting, consent, fraud-prevention, and deletion-history purposes, such as the store ID, business name, billing records or processor identifiers, consent history, cancellation date, and deletion date. Limited backups may persist temporarily under backup-rotation practices.
10. User choices and requests
Users may request access to, correction of, or deletion of personal information by contacting WindowHop. WindowHop may verify identity and retain information where an exception or legal obligation applies. Users can adjust available notification choices. Shoppers can remove browser-based saves by clearing local storage, remove a synced booth save, and use available account-deletion tools. Email changes require role-appropriate recovery: the store team may verify booth owners, the Store Owner verifies employees, and WindowHop verifies Store Owners using private contact information.
11. State privacy rights
Depending on residence and whether a law applies to WindowHop, users may have rights to know, access, correct, delete, or obtain a copy of personal information and to appeal certain decisions. WindowHop will not discriminate against a user for exercising an applicable privacy right. WindowHop does not sell or share personal information for behavioral advertising, so there is no sale-based opt-out required for current practices.
12. Security
WindowHop uses reasonable administrative, technical, and organizational safeguards appropriate to the information handled, including access controls and expiring email links. No internet service can guarantee absolute security. Users should protect their email accounts and notify WindowHop of suspected unauthorized access.
13. Children
WindowHop is not directed to children under 13 and does not knowingly collect personal information from them. A parent or guardian who believes a child under 13 submitted personal information should contact WindowHop so it can be reviewed and deleted as appropriate.
14. External links
WindowHop may link to maps, store websites, social media, and other services. WindowHop does not control their privacy practices. Users should review the policies of those services.
15. Policy changes
WindowHop may update this Policy to reflect product, provider, or legal changes. The effective date will be updated, and material changes may be communicated to subscribing stores or users when appropriate.
Contact
Questions about this policy may be sent to luke@windowhop.com.