Privacy Policy
How Ehopto handles visitor, client, enquiry, demo project, and payment-related information.
Last updated: September 2026
1. Information we collect
Ehopto may collect names, email addresses, phone numbers, business names, business details, website enquiry messages, project requirements, uploaded content, and information needed to provide website and digital services.
2. How we use information
Information may be used to respond to enquiries, prepare demo websites, create or maintain client websites, manage business tools, process project requests, provide support, improve services, and communicate with clients.
3. Demo websites and project requests
If a potential client requests a website or Ehopto prepares a demo website, we may use the business information provided or publicly available business details to create a reasonable preview. Clients may ask for corrections or removal where appropriate.
4. Client website enquiries
Messages submitted through Ehopto-powered client websites may be stored so that the relevant business can manage, track, and respond to the enquiry.
5. Payments
Payments may be handled through secure third-party payment providers or approved payment channels. Ehopto does not store full card details. Payment providers may process payment information according to their own security and privacy practices.
6. Sharing information
Ehopto does not sell personal information. Information may be shared with the relevant client/business when a visitor contacts that business through an Ehopto-powered website, or with service providers needed to deliver hosting, email, payment, or website services.
7. Security
Ehopto uses reasonable technical and organisational measures to protect information, but no online system can be guaranteed to be completely risk-free.
8. Retention
Information may be retained for as long as needed to provide services, resolve queries, maintain records, support clients, comply with legal requirements, or protect legitimate business interests.
9. The Ehopto app and registry
The Ehopto mobile app is a shell around ehopto.com — everything below applies equally to the website and the app. Registry accounts store the details you choose to give: your name, email address, the contact links you list on your hub, and the posts, websites, and codes you create. Codes are permanent by design; deleting your account never deletes the registry's memory of a code, only your claim on it.
Topic grouping first uses Ehopto's own word rules. When those rules cannot confidently understand the subject, only the title and description — with email addresses and phone numbers removed — may be sent to OpenAI to suggest topic labels. Ehopto requests a one-off response, keeps the resulting labels and token-cost record, and does not send content that you have already grouped yourself.
10. App permissions
Camera is used while you scan. Reading a barcode, a QR code or an Ehopto code happens entirely on your device, and those frames are never uploaded. When you deliberately ask “What is this?”, that one frame IS uploaded: Ehopto first compares it against everything registered, and if nothing matches it is sent to an external AI vision service (Anthropic) to be described. It is not used to train that service, and Ehopto keeps no copy of it except as set out below.
Microphone is used only while you press Listen. A short clip is recorded, turned into an acoustic fingerprint, compared against sounds their owners registered on Ehopto, and then discarded. The clip is never published and never added to your account.
Image checking fingerprints your uploaded file and stores nothing — unless you tick the box offering the photo so Ehopto can learn. Only then is a copy kept, with location metadata stripped: either as an unidentified scan that may later be shown to product owners so the thing can be named, or — when Ehopto did not know the thing and creates a page for it — as that thing's first public picture on its hub and website. Leave the box unticked and no photograph of yours is published or retained. Administrators can delete anything kept.
Location is used only while you run the address radar. Your coordinates are sent once per scan, in the request body, to find registered places near you — they are not saved, not attached to your account, and never placed in a URL.
Bluetooth is used only while you run the shelf radar. The app listens for nearby beacons broadcasting public Ehopto codes and resolves those codes into names. Scanning stops when you leave the radar, press stop, or after 60 seconds — whichever comes first. The app never transmits over Bluetooth and does not use beacons to track you.
None of these permissions are used in the background. Each one activates only for the feature you opened, and each can be declined — the rest of Ehopto keeps working.
11. Social signals
Reactions, follows, reposts, and view counts are shown as public totals on registry entries. Views are counted once per visit and are never shown as a list of who viewed. Follower counts from platforms you link on your hub are fetched from those platforms' official public APIs; a count we cannot verify is a count we do not show.
12. Your account controls
From settings you can take a break (your profile shows as away until the date you pick) or delete your account. Deletion is immediate, requires your password, and removes your login and personal details. Your codes remain in the registry — unclaimed, or hidden from public view if you choose unlist on the way out. Accounts that break the rules can be suspended or banned by moderators.
13. Contact
For privacy questions or correction requests, please contact Ehopto through the official website or business contact channels.