Policies
TERMS OF SERVICE
Last Updated: July 21, 2026
1. Introduction
Welcome to HIIPE.io. These Terms of Service ("Terms") are a legal agreement between you and HIIPE.io SAS ("HIIPE", "we", "us", or "our"), a French company registered under RCS Paris 100 237 593, with its registered office at 60 rue François Ier, 75008 Paris, France.
HIIPE is a fan data capture and direct messaging platform that helps creators build and engage with their fanbase. By accessing or using our platform, you agree to be bound by these Terms.
IMPORTANT: Please read these Terms carefully. By clicking "I Agree", creating an account, or using HIIPE, you confirm that you have read, understood, and agree to these Terms. If you do not agree, do not use HIIPE.
2. Definitions
"Creator" means any individual or entity that creates an account on HIIPE to capture fan data and send direct messages.
"Fan" means any individual who submits their information through a Creator's Capture Link, or whose information a Creator lawfully imports or connects into HIIPE.
"Capture Link" means a unique URL created by a Creator to collect Fan information.
"Direct Messaging" means SMS and/or email communications sent through HIIPE. (Additional channels may be added over time; where a channel is not yet available, it is not covered by these Terms until launched.)
"Credits" means the pay-per-use units required to send Direct Messages.
"Content" means any text, images, links, or other materials uploaded to or sent through HIIPE.
"Connected Store" means a third-party e-commerce store (for example, Shopify) that a Creator connects to their HIIPE Bio Link to display products.
"Imported Data" means Fan data that a Creator uploads to HIIPE from a source they already control (for example, an existing email list).
"Platform" means the HIIPE website, applications, and all related services.
3. Eligibility
You must be at least 18 years old to use HIIPE. By using our Platform, you represent and warrant that you are 18 or older and have the legal capacity to enter into these Terms. HIIPE is not intended for use by anyone under 18.
4. Account Registration
4.1 Creator Accounts
To use HIIPE as a Creator, you must create an account. You agree to:
- Provide accurate, current, and complete information during registration, including the identity information required under Section 7.3 (your legal name or entity name and country), so that Fans can be told who controls their data.
- Keep your account information updated.
- Maintain the security of your password and account.
- Accept responsibility for all activities under your account.
You may register using email/password or through Google Single Sign-On (SSO). If using Google SSO, you authorize us to access basic profile information from your Google account.
4.2 Fans
Fans do not create accounts. When a Fan submits their information through a Creator's Capture Link, they agree to receive Direct Messages from that Creator on the channels they consented to, and acknowledge HIIPE's processing of their data as described in our Privacy Policy and in the Creator's data notice.
5. Our Services
HIIPE provides Creators with tools to:
- Create and share Capture Links to collect Fan information
- Manage their fanbase through a dashboard
- Send Direct Messages (SMS, email) to their Fans, on the channels each Fan has consented to
- Track engagement and analytics
- Display products from a Connected Store on their Bio Link
- Import Fan data they already control, subject to Section 7.4
- (Future) Sell merchandise and tickets through integrated partners
6. Subscriptions, Credits, and Payments
6.1 Subscription Plans
HIIPE offers subscription plans with varying features and limits. Current pricing is available at hiipe.io/pricing. By subscribing, you authorize us to charge your payment method on a recurring basis until you cancel.
6.2 Direct Messaging Credits
Sending Direct Messages requires Credits. Credits are purchased separately from subscriptions and are deducted based on the channel used and message length. Credit pricing is available on our pricing page. Credits are non-transferable between accounts.
6.3 E-commerce: Two Distinct Models
HIIPE supports two different commercial arrangements, and they are treated differently:
(a) Connected Store (display only). Where you connect a third-party store such as Shopify to display products on your Bio Link, all purchases are completed on that third party's checkout. HIIPE does not process, hold, or touch any payment, and HIIPE takes no commission on those sales. The third party is responsible for the transaction, its own terms, and its own consumer obligations.
(b) Sale through the Platform. Where HIIPE provides an integrated checkout for merchandise or tickets sold through the Platform, HIIPE may charge a commission. Commission rates will be displayed before you list items for sale. By using these features, you agree to the applicable commission structure.
6.4 No Refunds
All subscription fees and Credit purchases are non-refundable, except where a refund is required by applicable mandatory law (including consumer withdrawal rights, see Section 14.3). You may cancel your subscription at any time, but you will not receive a refund for any unused portion of your subscription period or unused Credits except as required by such law.
6.5 Price Changes
We may change our pricing at any time. For existing subscribers, price changes will take effect at the start of the next billing cycle following 30 days' notice. Continued use after the price change constitutes acceptance.
7. Creator Responsibilities
As a Creator using HIIPE, you are responsible for:
7.1 Lawful Use
- Complying with all applicable laws, including data protection regulations (GDPR, and equivalent laws in the countries where you operate)
- Obtaining valid, channel-specific consent from Fans before collecting their data and before messaging them on a given channel
- Complying with anti-spam and electronic-marketing laws when sending Direct Messages
7.2 Content Responsibility
- You are solely responsible for all Content you create, upload, or send through HIIPE
- You must comply with our Acceptable Use Policy
- You must not send spam, misleading, or harmful messages to Fans
7.3 Data Controller Obligations and Identity
Under GDPR, you (the Creator) are the Data Controller for Fan data you collect, import, or connect. HIIPE acts as your Data Processor for that data, except for the limited purposes for which HIIPE is an independent controller as set out in Section 11 and in the Data Processing Agreement.
This means you determine why and how Fan data is used, and you bear primary responsibility for compliance. In particular:
- You must provide Fans with the information required by law about who controls their data. HIIPE will help you meet this obligation by generating, on your behalf and from the identity details you provide, a Fan-facing data notice that names you as the controller.
- You must provide accurate identity information (your legal name or entity name, country, and a contact point for data requests) and keep it current. You warrant that this information is accurate.
Fan data is not "owned" by anyone in the property sense, personal data belongs to the Fan as data subject, whose rights override both you and HIIPE. As between you and HIIPE: you are the controller, you decide, and HIIPE does not repurpose Fan data for its own marketing or sell it. See our Data Processing Agreement for details.
7.4 Imported and Connected Data
If you import Fan data into HIIPE, or connect a store or third-party source from which Fan data flows into HIIPE, you represent and warrant that:
- You are the Data Controller for that data, and you are importing or connecting it only to continue your own relationship with those Fans (migration, not transfer). You may not import or connect data that was collected by, or on behalf of, a different controller.
- The data was collected lawfully and each Fan gave valid, channel-specific consent (or another valid legal basis exists) for the purposes and channels you now intend to use.
- Any consent timestamps, channel markers, and provenance information you provide are genuine and accurate.
You agree that HIIPE will only make a Fan messageable on a given channel where per-channel consent evidence is present for that Fan; HIIPE will drop, and not make messageable, any record lacking such evidence.
You agree to indemnify HIIPE (see Section 12) for any claim arising from data you import or connect in breach of this Section.
8. Terms for Fans
8.1 What You Agree To
When you submit your information through a Creator's Capture Link, you:
- Consent to that Creator contacting you, on the channels you selected or that were disclosed to you (currently SMS and/or email)
- Acknowledge that HIIPE processes your data on behalf of the Creator
- Confirm that you are 18 years or older
8.2 Your Rights
You have the right to:
- Unsubscribe from a Creator's messages at any time and per channel, reply STOP to any SMS to stop SMS, or use the unsubscribe link in any email to stop email
- Request deletion of your data by contacting the Creator, or privacy@hiipe.io
- Access your data and exercise your other rights under GDPR as detailed in our Privacy Policy and in the Creator's data notice
8.3 Data Protection
Your data is never sold to third parties. It is used solely by the Creator whose link you used (or who lawfully holds your data), processed through HIIPE's platform. Creators may not sell or share your data with other Creators or third parties, and HIIPE does not combine your data across different Creators.
9. Intellectual Property
9.1 HIIPE's IP
HIIPE and its licensors own all rights to the Platform, including software, design, logos, and documentation. These Terms do not grant you any ownership rights to HIIPE's intellectual property.
9.2 Your Content
You retain ownership of Content you upload to HIIPE. By uploading Content, you grant HIIPE a worldwide, non-exclusive, royalty-free license to use, host, store, and display your Content solely for the purpose of providing the Platform to you.
9.3 Fan Data
As between you and HIIPE, you are the Data Controller for Fan data collected through your Capture Links or lawfully imported or connected by you. HIIPE does not claim any right to use your Fan data for its own marketing, to sell it, or to combine it with other Creators' data. HIIPE's only own-account processing of Fan data is the limited independent-controller processing described in Section 11 and the Data Processing Agreement (security, fraud prevention, billing, and genuinely aggregate statistics that do not identify individual Fans).
10. Acceptable Use
You must comply with our Acceptable Use Policy, which prohibits spam, adult or sexually explicit content, hate speech, harassment or threats, illegal activity, content that exploits or harms minors, intellectual property infringement, and malware, phishing, or fraudulent content. The full Acceptable Use Policy is available at hiipe.io/policies and is incorporated into these Terms by reference.
11. HIIPE's Roles (Processor and Independent Controller)
To be transparent about the capacity in which HIIPE acts:
HIIPE acts as your Processor, processing Fan data only on your documented instructions, for: storing Fan data, delivering your Direct Messages, operating the Bio Link and CRM, importing data you control, and providing you with analytics about your own fanbase.
HIIPE acts as an independent Controller, for its own limited and necessary purposes, only for: (a) securing the Platform and preventing fraud and abuse; (b) billing, accounting, and tax; and (c) producing genuinely aggregate or statistical information that does not identify individual Fans. HIIPE does not use Fan data to market to Fans and does not sell Fan data.
This division is set out in full in the Data Processing Agreement, which prevails over these Terms on data-protection matters.
12. Limitation of Liability
12.1 Liability Cap
Subject to Section 12.3, and to the maximum extent permitted by applicable law, our total aggregate liability to you for any claims arising from or related to these Terms or your use of HIIPE shall not exceed the greater of (a) the total fees you paid to HIIPE in the twelve (12) months preceding the event giving rise to the claim, or (b) one hundred euros (€100).
12.2 Exclusion of Damages
We are not liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to lost profits, lost revenue, lost data, business interruption, or reputational harm, regardless of whether we were advised of the possibility of such damages.
12.3 Exceptions
Nothing in these Terms limits our liability for: (a) death or personal injury caused by our negligence; (b) fraud or fraudulent misrepresentation; (c) our own breaches of applicable data protection law in our capacity as controller; or (d) any other liability that cannot be excluded or limited under applicable French or EU law.
12.4 Disclaimer of Warranties
The Platform is provided "as is" and "as available" without warranties of any kind, whether express or implied. We do not warrant that the Platform will be uninterrupted, error-free, or secure.
13. Indemnification
You agree to indemnify and hold HIIPE, its officers, directors, employees, and agents harmless from any claims, damages, losses, or expenses (including reasonable legal fees) arising from:
- Your use of the Platform
- Your Content or messages sent to Fans
- Your violation of these Terms or applicable law
- Fan data you imported or connected in breach of Section 7.4, including any inaccurate or fabricated consent records or provenance information
- Any claim by a Fan or third party related to your activities
14. Governing Law and Disputes
14.1 Governing Law
These Terms are governed by and construed in accordance with the laws of France, without regard to conflict of law principles.
14.2 Jurisdiction
Subject to Section 14.3, any disputes arising from these Terms shall be subject to the exclusive jurisdiction of the courts of Paris, France.
14.3 Consumer Rights
If you are a consumer or non-professional in the European Union, nothing in these Terms affects your rights under mandatory consumer protection laws in your country of residence, including any right of withdrawal and any right to bring proceedings in the courts of your place of residence.
Where you purchase digital content or services that begin immediately, you may be asked to acknowledge that performance begins at once and that you thereby waive the 14-day right of withdrawal for that content; that waiver applies only where you have expressly given it.
15. Termination
15.1 By You
You may close your account at any time through your account settings or by contacting support@hiipe.io. Subscription fees already paid are non-refundable except as required by law.
15.2 By HIIPE
We may suspend or terminate your account immediately, without notice, if you violate these Terms or the Acceptable Use Policy. We may also terminate accounts for prolonged inactivity or at our discretion with 30 days' notice.
15.3 Effect of Termination
Upon termination:
- Your right to use the Platform ends immediately
- Your Fan data will be handled as set out in the Data Processing Agreement (exported to you on request, then deleted, save for genuinely aggregate statistics that do not identify individual Fans and any records HIIPE must retain by law or to defend legal claims)
- Unused Credits are forfeited
- Sections that should survive termination (including liability, indemnification, and governing law) will remain in effect
16. Changes to These Terms
We may update these Terms from time to time. If we make material changes, we will notify you via email or through the Platform at least 30 days before the changes take effect. Your continued use after the changes take effect constitutes acceptance. If you do not agree to the updated Terms, you must stop using HIIPE and close your account.
17. General Provisions
17.1 Entire Agreement
These Terms, together with the Privacy Policy, Cookie Policy, Acceptable Use Policy, and Data Processing Agreement, constitute the entire agreement between you and HIIPE.
17.2 Severability
If any provision of these Terms is found invalid or unenforceable, the remaining provisions will continue in full force and effect.
17.3 No Waiver
Our failure to enforce any right or provision of these Terms does not constitute a waiver of that right or provision.
17.4 Assignment
You may not assign these Terms without our written consent. We may assign these Terms to an affiliate or successor in connection with a merger, acquisition, or sale of assets.
18. Contact Us
If you have questions about these Terms, contact us at:
HIIPE.io SAS
60 rue François Ier
75008 Paris, France
Email: legal@hiipe.io
RCS Paris: 100 237 593
[ End of Terms of Service ]
PRIVACY POLICY
Last Updated: July 21, 2026
1. Introduction
This Privacy Policy explains how HIIPE.io SAS ("HIIPE", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our platform. HIIPE is a French company registered under RCS Paris 100 237 593, with its registered office at 60 rue François Ier, 75008 Paris, France.
This Policy applies to all users of our platform, including Creators (individuals or entities who create accounts to capture, import, or connect fan data) and Fans (individuals whose information is submitted through Capture Links or lawfully imported or connected by a Creator).
By using HIIPE, you acknowledge that you have read and understood this Privacy Policy.
2. Who Is the Controller, and HIIPE's Two Roles
Understanding "who decides why" matters, because it determines who is responsible.
2.1 Creator Data
HIIPE is the Data Controller for personal data collected from Creators during account registration and platform usage (name, contact, billing, usage data). This Policy governs that data.
2.2 Fan Data, Creators are the Controllers
Creators are the Data Controllers for Fan data collected through their Capture Links, or lawfully imported or connected by them. For that Fan data, HIIPE acts as a Data Processor, processing it only on the Creator's documented instructions, in accordance with our Data Processing Agreement.
2.3 Fan Data, HIIPE's own limited controller role
For a short, closed list of purposes, HIIPE acts as an independent Controller in respect of Fan data, because HIIPE, not the Creator, decides these purposes:
- Securing the Platform and preventing fraud and abuse
- Billing, accounting, and tax
- Producing genuinely aggregate or statistical information that does not identify individual Fans
HIIPE does not use Fan data to market to Fans, does not sell Fan data, and does not combine Fan data across different Creators.
Contact for data protection inquiries: privacy@hiipe.io
3. Data We Collect
3.1 Creator Data
When you create a Creator account, we collect:
- Account information: name (and, for the controller notice, your legal or entity name), email address, phone number, password (hashed), profile image, and country.
- Payment information: billing address and payment method details (processed by our payment provider).
- Usage data: login history, feature usage, Capture Link and Bio Link analytics, messaging history.
- Technical data: IP address, browser type, device information, cookies.
3.2 Fan Data
Fan data may reach the Platform through three routes. In every case it is processed on behalf of the Creator, and in every case HIIPE only makes a Fan messageable on a channel for which per-channel consent evidence exists.
(a) Capture Links. When a Fan submits information through a Creator's Capture Link, we may collect: first name, last name, phone number (required), email address (optional), country (derived from phone number), city (derived from IP or provided), engagement data (which links, opt-in date, per-channel consent, fan tier), and technical data (IP address at time of submission).
(b) Connected Store (e.g. Shopify). Where a Creator connects a store and a customer has given marketing consent in that store, HIIPE may receive that customer's contact details and their separate email and SMS consent states, with their original consent timestamps, to add them to the Creator's fanbase. Email consent enables email only; SMS consent enables SMS only; a consent state that the store cannot vouch for is treated as no consent.
(c) Imports. Where a Creator imports a list they already control, HIIPE receives the contact details together with per-channel consent markers and timestamps, subject to the warranties and the drop rule in the Terms and the Data Processing Agreement.
3.3 Enrichment vs. Ingestion
HIIPE may enrich a Fan who already has a consent record on the Platform, for example, adding a purchase or an event attendance to an existing consented Fan of the same Creator. HIIPE does not create a new messageable contact from a source that lacks valid, channel-specific consent, and does not merge or match Fans across different Creators. Enrichment adds attributes to someone you may already contact; it never manufactures permission.
4. How We Use Data
4.1 Creator Data (HIIPE as Controller)
We use Creator data to: provide and maintain your account and access to the Platform; process payments and manage subscriptions; send service-related communications (account alerts, security notices, feature updates); send marketing communications (with your consent); improve and develop our platform; and comply with legal obligations.
4.2 Fan Data (HIIPE as Processor, on the Creator's instructions)
On behalf of Creators, Fan data is processed to: enable Creators to send Direct Messages (SMS, email) to Fans on consented channels; provide Creators with fanbase analytics and engagement metrics; and manage unsubscribe requests and consent records per channel.
4.3 Fan Data (HIIPE as independent Controller, limited)
For the limited purposes in Section 2.3 only, HIIPE processes Fan data to secure the Platform and prevent fraud, to bill and account, and to produce aggregate statistics that do not identify individuals.
5. Legal Basis for Processing (GDPR)
Legal bases apply to the data for which HIIPE is a controller. For Fan data processed on a Creator's instructions, the Creator is responsible for identifying the legal basis (typically the Fan's consent).
For Creator data (HIIPE as controller):
- Contract: processing necessary to provide the platform services to you.
- Consent: for marketing communications to Creators.
- Legitimate interests: securing the platform and preventing fraud.
- Legal obligation: accounting, tax, and responding to lawful requests.
For HIIPE's limited independent-controller processing of Fan data (Section 2.3):
- Legitimate interests: platform security and fraud prevention, and producing aggregate statistics, balanced against Fans' rights, and never used to market to or identify individual Fans.
- Legal obligation: where retention or disclosure is required by law.
6. Data Sharing
6.1 We Do Not Sell Your Data
HIIPE does not sell personal data to third parties. Fan data is never sold, rented, or shared with third parties for their marketing purposes, and is never combined across Creators.
6.2 Service Providers (Sub-processors)
We share data with trusted service providers who help us operate the platform. The current list, with purpose and location, is maintained in our Data Processing Agreement and updated there. It currently includes providers for SMS delivery, email delivery, hosting, payment processing, IP geolocation, and analytics. All are bound by data processing agreements and required to protect data in accordance with applicable law.
6.3 Creators Cannot Share Fan Data
Creators agree in our Terms of Service that they will not sell, rent, or share Fan data with third parties, and will not import or transfer data they do not themselves control. Fan data may only be used by the Creator, through HIIPE's platform, for direct communication with Fans who consented.
6.4 Legal Requirements
We may disclose personal data if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
7. International Data Transfers
HIIPE is based in France (EU). Some service providers are located outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure appropriate safeguards: EU-approved Standard Contractual Clauses (SCCs); reliance on adequacy decisions or the EU-US Data Privacy Framework where applicable; and supplementary measures where required. All providers are contractually bound to protect the data.
8. Data Retention
8.1 Creator Data
We retain Creator account data for as long as your account is active. After account closure, we retain certain data for up to 10 years as required by French accounting and tax regulations.
8.2 Fan Data
Fan data is retained on behalf of the Creator for as long as it remains in active use, and in any event no longer than 3 years from the Fan's last engagement (last message opened, click, submission, or purchase), unless the Fan is re-engaged, after which the period runs afresh, or unless a longer period is required by law. When a Creator closes their account, Fan personal data is deleted in accordance with the Data Processing Agreement.
We may retain pseudonymised or genuinely aggregate statistics that do not identify individual Fans.
8.3 Consent and Message Records
Records evidencing that a Fan consented, and records of Direct Messages sent, are retained for the period necessary to demonstrate compliance and to establish, exercise, or defend legal claims (in France, generally up to 5 years). Where a Fan is erased, we retain only the minimum record needed to prove the sending was lawful, stripped of identifying content.
9. Your Rights
Under GDPR and applicable data protection laws, you have the rights of: access; rectification; erasure; restriction of processing; data portability; objection (including to direct marketing); and withdrawal of consent at any time, per channel, where processing is based on consent.
To exercise these rights over data a Creator controls, you can contact the Creator or contact us at privacy@hiipe.io and we will assist the Creator. For data HIIPE controls, contact privacy@hiipe.io. We will respond within 30 days.
9.1 For Fans
Fans may exercise their rights by:
- Replying STOP to any SMS to unsubscribe from that Creator's SMS
- Clicking unsubscribe in any email to opt out of that Creator's email
- Contacting the Creator, or privacy@hiipe.io, to request data access, correction, or deletion
10. Data Security
We implement appropriate technical and organizational measures to protect personal data, including: encryption of data in transit (TLS/SSL) and at rest; secure password hashing; access controls and authentication; regular security assessments; and incident response procedures.
In the event of a personal data breach, we will notify the relevant parties as required by GDPR: where HIIPE is the controller, we will notify the competent supervisory authority within 72 hours where required, and affected individuals where the breach is likely to result in a high risk to their rights. Where HIIPE is a processor, we will notify the affected Creator (controller) without undue delay so that they can meet their own notification obligations, see the Data Processing Agreement for the processor notification window.
11. Cookies
We use cookies and similar technologies to operate our platform and analyze usage. For details about the cookies we use and how to manage or refuse them, see our Cookie Policy at hiipe.io/policies.
12. Children's Privacy
HIIPE is not intended for individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through the platform at least 30 days before the changes take effect. The "Last Updated" date indicates when it was last revised.
14. Supervisory Authority
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. In France:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Website: www.cnil.fr
You may also complain to the supervisory authority in your country of residence.
15. Contact Us
HIIPE.io SAS
60 rue François Ier, 75008 Paris, France
Email: privacy@hiipe.io
RCS Paris: 100 237 593
[ End of Privacy Policy ]
COOKIE POLICY
Last Updated: July 21, 2026
1. Introduction
This Cookie Policy explains how HIIPE.io SAS ("HIIPE", "we", "us", or "our") uses cookies and similar technologies on our website and platform at hiipe.io.
This policy tells you which cookies we use, what they do, and how you can control or refuse them through your browser.
2. What Are Cookies
Cookies are small text files placed on your device when you visit a website. They help websites work efficiently and provide information to site owners. Cookies can be "session cookies" (deleted when you close your browser) or "persistent cookies" (remaining for a set period or until deleted).
3. Cookies We Use
3.1 Essential Cookies
These are necessary for the platform to function and cannot be disabled. They include:
- Authentication cookies: keep you logged in during your session
- Security cookies: protect against fraud and unauthorized access
- Preference cookies: remember your settings and preferences
3.2 Analytics Cookies
We use Google Analytics to understand how visitors use our platform so we can improve it. It collects data about page views, session duration, and interactions. You can refuse or remove these cookies through your browser settings (see Section 5), and you can opt out of Google Analytics specifically using the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
4. Cookie Details
The following cookies are used on our platform:
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
| hiipe_session | Essential | Maintains user login session | Session |
| hiipe_csrf | Essential | Security token to prevent cross-site request forgery | Session |
| hiipe_prefs | Essential | Stores user preferences | 1 year |
| _ga | Analytics | Google Analytics: distinguishes users | 2 years |
| _ga_* | Analytics | Google Analytics: maintains session state | 2 years |
5. Managing Cookies
Most browsers let you control cookies through their settings. You can refuse cookies or delete existing ones. Disabling essential cookies may affect how the platform works.
- Chrome: https://support.google.com/chrome/answer/95647
- Firefox: https://support.mozilla.org/en-US/kb/cookies
- Safari: https://support.apple.com/guide/safari/manage-cookies
- Edge: https://support.microsoft.com/en-us/microsoft-edge/manage-cookies
You can also opt out of Google Analytics using the add-on linked in Section 3.2.
6. Changes to This Policy
We may update this Cookie Policy to reflect changes in the cookies we use or for operational, legal, or regulatory reasons. The "Last Updated" date indicates when it was last revised.
7. Contact Us
HIIPE.io SAS
60 rue François Ier, 75008 Paris, France
Email: privacy@hiipe.io
[ End of Cookie Policy ]
ACCEPTABLE USE POLICY
Last Updated: July 21, 2026
1. Introduction
This Acceptable Use Policy ("AUP") governs your use of the HIIPE platform, including your account, Capture Links, Content, imported or connected data, and Direct Messages (SMS, email). It is incorporated into our Terms of Service. By using HIIPE, you agree to this AUP.
2. Prohibited Content
You may not use HIIPE to create, upload, or send:
- Illegal content: content that violates any applicable law or regulation; promotion of illegal activities or substances; content that facilitates fraud, identity theft, or financial crime.
- Hate and harassment: hate speech targeting race, ethnicity, religion, gender, sexual orientation, disability, or other protected characteristics; harassment, bullying, or intimidation; content glorifying self-harm or suicide.
- Adult and explicit content: pornography or sexually explicit material; adult content not suitable for general audiences.
- Child safety: any content that exploits, harms, or endangers minors; child sexual abuse material (CSAM) of any kind.
- IP infringement: content that infringes copyrights, trademarks, or other intellectual property rights; use of others' content without proper authorization.
- Deceptive content: content intended to deceive; impersonation of other individuals, brands, or organizations; phishing or attempts to collect credentials or sensitive information through deception.
3. Prohibited Activities
You may not:
- Spam and unsolicited messaging: send unsolicited bulk messages; message Fans without their proper, channel-specific consent; purchase, rent, harvest, or otherwise use contact lists you did not lawfully collect and do not control; import or transfer data collected by or on behalf of a different controller; or send messages that do not include a clear per-channel unsubscribe mechanism.
- Technical abuse: crawl or perform automated data collection without authorization; circumvent security measures or access controls.
- Platform misuse: create multiple accounts to evade enforcement; resell or sublicense HIIPE services without authorization; use the platform for purposes other than legitimate fan engagement.
4. Direct Messaging Guidelines
When sending Direct Messages through HIIPE, you must:
- Only message Fans who have opted in to receive communications from you on the channel you are using
- Identify yourself clearly in your messages
- Honor unsubscribe requests promptly, per channel
- Comply with applicable anti-spam and electronic-marketing laws in the countries where your Fans are located
5. Enforcement
We may take enforcement action for violations, including: issuing warnings; removing or disabling content; temporarily suspending account access; permanently terminating accounts; and reporting illegal activity to law enforcement. We may act with or without notice depending on severity.
6. Reporting Violations
To report a violation, contact abuse@hiipe.io with: a description of the violation; the URL or identifier of the content (if applicable); and any supporting evidence.
7. Contact
HIIPE.io SAS
60 rue François Ier, 75008 Paris, France
Email: abuse@hiipe.io
[ End of Acceptable Use Policy ]
DATA PROCESSING AGREEMENT
Addendum to Terms of Service. Last Updated: July 21, 2026.
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between HIIPE.io SAS ("HIIPE", "Processor") and you ("Customer", "Controller") for the provision of the HIIPE platform services.
This DPA reflects the parties' agreement regarding the processing of Personal Data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws. By accepting the Terms of Service, you also accept this DPA.
2. Definitions
- "Controller" means you, the Customer, who determines the purposes and means of processing Fan Data.
- "Processor" means HIIPE, which processes Personal Data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Fan Data" means Personal Data of Fans collected through the Customer's Capture Links, or lawfully imported or connected by the Customer, and processed through HIIPE.
- "Sub-processor" means any third party engaged by HIIPE to process Personal Data.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
- "Security Incident" means any unauthorized access to, or acquisition, use, or disclosure of, Personal Data.
3. Scope of Processing
3.1 Subject Matter
HIIPE processes Fan Data on behalf of the Customer to provide the platform services, including fan data management, Direct Messaging (SMS, email), and analytics.
3.2 Nature and Purpose
The nature and purpose of processing includes: collection and storage of Fan contact information; delivery of Direct Messages on the Customer's behalf, to channels the Fan has consented to; processing of per-channel opt-in and opt-out requests; generation of analytics and engagement reports; location detection for geographic targeting; and receiving Fan Data from a Connected Store (e.g. Shopify) or from a Customer-controlled import, subject to Section 5.3.
3.3 Categories of Data Subjects
Fans who submit their information through the Customer's Capture Links, or whose data the Customer lawfully imports or connects.
3.4 Types of Personal Data
First name, last name; phone number; email address (optional); city and country; per-channel consent status and timestamps; IP address (at time of submission); and, where a Connected Store is used, purchase-related attributes.
3.5 Duration
Processing continues for the duration of the Customer's use of the HIIPE platform, plus any retention period required by law or as set forth in Section 10.
3.6 HIIPE's Two Roles
This DPA governs HIIPE's processing of Fan Data as Processor, on the Customer's documented instructions. Separately, and outside the scope of the instructions in this DPA, HIIPE acts as an independent Controller for a limited, closed set of purposes: securing the Platform and preventing fraud and abuse; billing, accounting, and tax; and producing genuinely aggregate or statistical information that does not identify individual Fans. HIIPE does not use Fan Data to market to Fans, does not sell Fan Data, and does not combine Fan Data across Customers. HIIPE's independent-controller processing is described in the Privacy Policy.
4. Processor Obligations
HIIPE shall:
- Process Fan Data only on documented instructions from the Controller, unless required by applicable law (and, in that case, inform the Controller unless legally prohibited)
- Immediately inform the Controller if, in HIIPE's opinion, an instruction infringes GDPR or other data protection law
- Ensure that persons authorized to process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational security measures (Section 7)
- Engage Sub-processors only under Section 6 and under a written contract with equivalent obligations
- Assist the Controller, taking into account the nature of processing, in responding to Data Subject requests (Section 9)
- Assist the Controller with security, breach notification, and data protection impact assessment obligations
- Delete or return Personal Data upon termination, at the Controller's choice (Section 10)
- Make available information necessary to demonstrate compliance and allow for audits (Section 12)
- Enforce the per-channel consent rule: make a Fan messageable on a channel only where per-channel consent evidence exists, and drop records that lack it
5. Controller Obligations
5.1 General
The Customer shall: ensure its collection and use of Fan Data complies with applicable data protection laws; obtain valid, channel-specific consent from Fans before collecting their data and before messaging them on a channel (or ensure another valid legal basis); provide Data Subjects with the required privacy information; ensure its instructions comply with law; and respond to Data Subject requests (with HIIPE's assistance where applicable).
5.2 Fan Notice
HIIPE will generate, from the identity details the Customer provides, a Fan-facing data notice naming the Customer as Controller. The Customer remains responsible for the accuracy of those details and for ensuring Fans receive the notice.
5.3 Imported and Connected Data
Where the Customer imports Fan Data, or connects a source from which Fan Data flows into HIIPE, the Customer represents and warrants, and confirms in the Data Import Attestation (see the separate Attestation document), that:
- The Customer is the Controller of that data and is bringing it in only to continue its own relationship with those Fans (migration, not transfer); the Customer will not import or connect data collected by or on behalf of a different controller.
- The data was collected lawfully and each Fan gave valid, channel-specific consent (or another valid legal basis exists) for the purposes and channels now intended.
- All consent markers, channel indicators, and timestamps provided are genuine and accurate.
HIIPE will apply the drop rule (Section 4) to imported and connected data. The Customer indemnifies HIIPE for any claim arising from data imported or connected in breach of this Section.
6. Sub-processors
6.1 Authorization
The Customer provides general authorization for HIIPE to engage Sub-processors. HIIPE ensures Sub-processors are bound by data protection obligations no less protective than this DPA.
6.2 Current Sub-processors
As of the date of this DPA:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure and hosting | United States |
| Vercel | Application hosting | United States |
| Conecteo | SMS message delivery | France / EU |
| Twilio SendGrid | Email delivery | United States / EU |
| Stripe | Payment processing | United States |
| MaxMind | IP geolocation | United States |
| Google Analytics | Website analytics | United States |
| Shopify (where connected by the Customer) | Source of consented customer data | United States / EU |
6.3 Changes to Sub-processors
HIIPE will notify the Customer of intended changes to Sub-processors by email and through the Platform, and by maintaining the current list in this DPA. The Customer may object to a new Sub-processor within 30 days on reasonable data-protection grounds. If the objection cannot be resolved, either party may terminate the affected services.
7. Security Measures
HIIPE implements and maintains appropriate technical and organizational measures, including: encryption in transit (TLS 1.2+) and at rest (AES-256); access controls and authentication; regular security assessments and vulnerability testing; employee security training and confidentiality obligations; and incident response and business continuity procedures.
8. Security Incident Notification
HIIPE will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting the Customer's Fan Data. The notification will include: the nature of the incident; categories and approximate number of Data Subjects affected; likely consequences; and measures taken or proposed.
9. Data Subject Requests
HIIPE will assist the Customer in responding to Data Subject requests under GDPR (access, rectification, erasure, restriction, portability, objection), taking into account the nature of processing. If HIIPE receives a request directly from a Data Subject regarding Fan Data, HIIPE will promptly redirect it to the relevant Customer unless legally prohibited.
10. Termination and Data Deletion
Upon termination of the Customer's account or upon the Customer's request, HIIPE will:
- Provide the Customer with an export of their Fan Data in a standard format upon request, before deletion
- Delete all Fan Data within 30 days, unless retention is required by applicable law or to establish, exercise, or defend legal claims
- Certify deletion in writing upon request
HIIPE may retain genuinely aggregate or pseudonymised data that does not identify individual Fans, and the minimum consent/message records needed to demonstrate that past sending was lawful.
11. International Data Transfers
Where Personal Data is transferred outside the EEA to countries not recognized as adequate, HIIPE ensures appropriate safeguards through EU-approved Standard Contractual Clauses incorporated into its agreements with Sub-processors, plus supplementary technical and organizational measures where required. By entering into this DPA, the Customer authorizes such transfers subject to these safeguards.
12. Audit Rights
HIIPE will make available all information necessary to demonstrate compliance with Article 28 GDPR and allow for audits, including inspections, by the Customer or an authorized auditor. The Customer shall give at least 30 days' prior written notice, conduct audits during normal business hours no more than once per year (unless required by a supervisory authority), and subject to reasonable confidentiality obligations.
13. General Provisions
13.1 Conflicts
In the event of any conflict between this DPA and the Terms of Service, this DPA prevails on data-protection matters.
13.2 Liability
The limitations of liability in the Terms of Service apply to this DPA.
13.3 Governing Law
This DPA is governed by French law. Disputes are subject to the exclusive jurisdiction of the courts of Paris, France, without prejudice to mandatory consumer protections.
14. Contact
HIIPE.io SAS
60 rue François Ier, 75008 Paris, France
Email: privacy@hiipe.io
[ End of Data Processing Agreement ]