Privacy Policy
Cookie Policy, Acceptable Use Policy and Data Processing Agreement: see the Policies page.
Last Updated: September 8, 2026
1. Introduction
This Privacy Policy explains how HIIPE.io SAS ("HIIPE", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our platform. HIIPE is a French company registered under RCS Paris 100 237 593, with its registered office at 60 rue François Ier, 75008 Paris, France.
This Policy applies to all users of our platform, including Creators (individuals or entities who create accounts to capture, import, or connect fan data) and Fans (individuals whose information is submitted through Capture Links, lawfully imported or connected by a Creator, or received because they interact with a Creator's connected Instagram account).
By using HIIPE, you acknowledge that you have read and understood this Privacy Policy.
2. Who Is the Controller, and HIIPE's Two Roles
Understanding "who decides why" matters, because it determines who is responsible.
2.1 Creator Data
HIIPE is the Data Controller for personal data collected from Creators during account registration and platform usage (name, contact, billing, usage data). This Policy governs that data.
2.2 Fan Data, Creators are the Controllers
Creators are the Data Controllers for Fan data collected through their Capture Links, or lawfully imported or connected by them. For that Fan data, HIIPE acts as a Data Processor, processing it only on the Creator's documented instructions, in accordance with our Data Processing Agreement.
2.3 Fan Data, HIIPE's own limited controller role
For a short, closed list of purposes, HIIPE acts as an independent Controller in respect of Fan data, because HIIPE, not the Creator, decides these purposes:
- Securing the Platform and preventing fraud and abuse
- Billing, accounting, and tax
- Producing genuinely aggregate or statistical information that does not identify individual Fans
HIIPE does not use Fan data to market to Fans, does not sell Fan data, and does not combine Fan data across different Creators.
Contact for data protection inquiries: privacy@hiipe.io
3. Data We Collect
3.1 Creator Data
When you create a Creator account, we collect:
- Account information: name (and, for the controller notice, your legal or entity name), email address, phone number, password (hashed), profile image, and country.
- Payment information: billing address and payment method details (processed by our payment provider).
- Usage data: login history, feature usage, Capture Link and Bio Link analytics, messaging history.
- Technical data: IP address, browser type, device information, cookies.
3.2 Fan Data
Fan data may reach the Platform through four routes. In every case it is processed on behalf of the Creator, and in every case HIIPE only makes a Fan messageable on a channel for which per-channel consent evidence exists.
(a) Capture Links. When a Fan submits information through a Creator's Capture Link, we may collect: first name, last name, phone number (required), email address (optional), country (derived from phone number), city (derived from IP or provided), engagement data (which links, opt-in date, per-channel consent, fan tier), and technical data (IP address at time of submission).
(b) Connected Store (e.g. Shopify). Where a Creator connects a store and a customer has given marketing consent in that store, HIIPE may receive that customer's contact details and their separate email and SMS consent states, with their original consent timestamps, to add them to the Creator's fanbase. Email consent enables email only; SMS consent enables SMS only; a consent state that the store cannot vouch for is treated as no consent.
(c) Imports. Where a Creator imports a list they already control, HIIPE receives the contact details together with per-channel consent markers and timestamps, subject to the warranties and the drop rule in the Terms and the Data Processing Agreement.
(d) Connected Instagram account. Where a Creator connects their own Instagram professional account to HIIPE, HIIPE receives from Meta Platforms, through the Instagram API, and only for that Creator's account: the Instagram-scoped user identifier and public username of a Fan who interacts with the Creator's account; the content and identifier of a public comment that Fan leaves on the Creator's content; the content of a message that Fan sends to the Creator's account, and of the replies sent on the Creator's behalf; and the timestamps of those interactions. HIIPE receives this data only after the Creator has explicitly authorised the connection, and only for the interactions listed above. HIIPE does not receive, and does not request, a Fan's email address, phone number, follower list, or any Instagram data unrelated to an interaction with the connected Creator.
Channel rule for Instagram. A Fan who reaches HIIPE through a connected Instagram account is messageable on Instagram only. A comment or a message on Instagram is not consent to receive SMS or email. Such a Fan becomes messageable on SMS or email only where that Fan subsequently gives channel-specific consent, for example by submitting a Creator's Capture Link. The drop rule above applies unchanged.
3.3 Enrichment vs. Ingestion
HIIPE may enrich a Fan who already has a consent record on the Platform, for example, adding a purchase or an event attendance to an existing consented Fan of the same Creator. HIIPE does not create a new messageable contact from a source that lacks valid, channel-specific consent, and does not merge or match Fans across different Creators. Enrichment adds attributes to someone you may already contact; it never manufactures permission.
4. How We Use Data
4.1 Creator Data (HIIPE as Controller)
We use Creator data to: provide and maintain your account and access to the Platform; process payments and manage subscriptions; send service-related communications (account alerts, security notices, feature updates); send marketing communications (with your consent); improve and develop our platform; and comply with legal obligations.
4.2 Fan Data (HIIPE as Processor, on the Creator's instructions)
On behalf of Creators, Fan data is processed to: enable Creators to send Direct Messages (SMS, email, and Instagram messages) to Fans on consented channels; provide Creators with fanbase analytics and engagement metrics; and manage unsubscribe requests and consent records per channel.
Where a Creator uses Instagram automation, Instagram interaction data is processed to identify the comments and messages the Creator has chosen to respond to, to send the reply the Creator has configured on their behalf, and to add the Fan to the Creator's fanbase under the channel rule in Section 3.2. Every automated Instagram message sent through HIIPE opens by stating that it is an automated message sent on the Creator's behalf, and closes with a "Powered by HIIPE" line linking to the Creator's data notice and to this Policy. HIIPE does not use the content of Instagram comments or messages for profiling, scoring, advertising, or for any purpose other than supporting the Creator's reply and the Creator's own relationship with that Fan. Instagram data is never combined across Creators.
4.3 Fan Data (HIIPE as independent Controller, limited)
For the limited purposes in Section 2.3 only, HIIPE processes Fan data to secure the Platform and prevent fraud, to bill and account, and to produce aggregate statistics that do not identify individuals.
5. Legal Basis for Processing (GDPR)
Legal bases apply to the data for which HIIPE is a controller. For Fan data processed on a Creator's instructions, the Creator is responsible for identifying the legal basis (typically the Fan's consent).
For Fans who interact with a Creator's connected Instagram account: the Creator's legal basis for the automated reply is its legitimate interest in answering a Fan who has publicly addressed it, by a comment or a message, within the windows Meta allows (a private reply within 7 days of a comment; a reply within 24 hours of a Fan's message). That basis covers the reply on Instagram and nothing else: SMS and email require the Fan's separate, channel-specific consent.
For Creator data (HIIPE as controller):
- Contract: processing necessary to provide the platform services to you.
- Consent: for marketing communications to Creators.
- Legitimate interests: securing the platform and preventing fraud.
- Legal obligation: accounting, tax, and responding to lawful requests.
For HIIPE's limited independent-controller processing of Fan data (Section 2.3):
- Legitimate interests: platform security and fraud prevention, and producing aggregate statistics, balanced against Fans' rights, and never used to market to or identify individual Fans.
- Legal obligation: where retention or disclosure is required by law.
6. Data Sharing
6.1 We Do Not Sell Your Data
HIIPE does not sell personal data to third parties. Fan data is never sold, rented, or shared with third parties for their marketing purposes, and is never combined across Creators.
6.2 Service Providers (Sub-processors)
We share data with trusted service providers who help us operate the platform. The current list, with purpose and location, is maintained in our Data Processing Agreement and updated there. It currently includes providers for SMS delivery, email delivery, hosting, payment processing, IP geolocation, analytics, and, where a Creator connects an Instagram account, Meta Platforms as the source of Instagram interaction data and the carrier of Instagram messages. All are bound by data processing agreements and required to protect data in accordance with applicable law.
6.3 Creators Cannot Share Fan Data
Creators agree in our Terms of Service that they will not sell, rent, or share Fan data with third parties, and will not import or transfer data they do not themselves control. Fan data may only be used by the Creator, through HIIPE's platform, for direct communication with Fans who consented.
6.4 Legal Requirements
We may disclose personal data if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
7. International Data Transfers
HIIPE is based in France (EU). Some service providers are located outside the European Economic Area (EEA). When we transfer personal data outside the EEA, we ensure appropriate safeguards: EU-approved Standard Contractual Clauses (SCCs); reliance on adequacy decisions or the EU-US Data Privacy Framework where applicable; and supplementary measures where required. All providers are contractually bound to protect the data. Meta Platforms, Inc., which supplies Instagram interaction data and delivers Instagram messages where a Creator connects an Instagram account, is certified under the EU-US Data Privacy Framework.
8. Data Retention
8.1 Creator Data
We retain Creator account data for as long as your account is active. After account closure, we retain certain data for up to 10 years as required by French accounting and tax regulations.
8.2 Fan Data
Fan data is retained on behalf of the Creator for as long as it remains in active use, and in any event no longer than 3 years from the Fan's last engagement (last message opened, click, submission, or purchase), unless the Fan is re-engaged, after which the period runs afresh, or unless a longer period is required by law. When a Creator closes their account, Fan personal data is deleted in accordance with the Data Processing Agreement.
We may retain pseudonymised or genuinely aggregate statistics that do not identify individual Fans.
8.3 Consent and Message Records
Records evidencing that a Fan consented, and records of Direct Messages sent, are retained for the period necessary to demonstrate compliance and to establish, exercise, or defend legal claims (in France, generally up to 5 years). Where a Fan is erased, we retain only the minimum record needed to prove the sending was lawful, stripped of identifying content.
8.4 Instagram Data
Access tokens for a connected Instagram account are deleted when the Creator disconnects the account, when the Creator's account is closed, or when Meta revokes the authorisation. The content of comments and messages processed to produce an automated reply is deleted 30 days after it is received. After that, only the Fan record and the record of the interaction that created it are retained, under Sections 8.2 and 8.3.
9. Your Rights
Under GDPR and applicable data protection laws, you have the rights of: access; rectification; erasure; restriction of processing; data portability; objection (including to direct marketing); and withdrawal of consent at any time, per channel, where processing is based on consent.
To exercise these rights over data a Creator controls, you can contact the Creator or contact us at privacy@hiipe.io and we will assist the Creator. For data HIIPE controls, contact privacy@hiipe.io. We will respond within 30 days. Step-by-step deletion instructions, for Fans and for Creators, are at hiipe.io/data-deletion.
9.1 For Fans
Fans may exercise their rights by:
- Replying STOP to any SMS to unsubscribe from that Creator's SMS
- Clicking unsubscribe in any email to opt out of that Creator's email
- Contacting the Creator, or privacy@hiipe.io, to request data access, correction, or deletion
- If you interacted with a Creator on Instagram: blocking or restricting that Creator's account on Instagram stops any further interaction with it. To have data already collected deleted, contact the Creator, write to privacy@hiipe.io, or follow the instructions at hiipe.io/data-deletion
10. Data Security
We implement appropriate technical and organizational measures to protect personal data, including: encryption of data in transit (TLS/SSL) and at rest; secure password hashing; access controls and authentication; regular security assessments; and incident response procedures.
In the event of a personal data breach, we will notify the relevant parties as required by GDPR: where HIIPE is the controller, we will notify the competent supervisory authority within 72 hours where required, and affected individuals where the breach is likely to result in a high risk to their rights. Where HIIPE is a processor, we will notify the affected Creator (controller) without undue delay so that they can meet their own notification obligations, see the Data Processing Agreement for the processor notification window.
11. Cookies
We use cookies and similar technologies to operate our platform and analyze usage. For details about the cookies we use and how to manage or refuse them, see our Cookie Policy at hiipe.io/policies.
12. Children's Privacy
HIIPE is not intended for individuals under 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through the platform at least 30 days before the changes take effect. The "Last Updated" date indicates when it was last revised.
14. Supervisory Authority
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. In France:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Website: www.cnil.fr
You may also complain to the supervisory authority in your country of residence.
15. Contact Us
HIIPE.io SAS
60 rue François Ier, 75008 Paris, France
Email: privacy@hiipe.io
RCS Paris: 100 237 593
[ End of Privacy Policy ]