← Back to HypeKit

Privacy Policy

Last updated: June 2026

HypeKit (“HypeKit”, “we”, “us”) helps creators and small businesses collect, manage, and display testimonials. This policy explains what we collect, why, and your choices. Questions? Email mahi@gethypekit.com.

Information we collect

Account information — when you sign up, we store your name, email, and a securely hashed password (via our auth provider). If you subscribe, our payment processor handles your card details; we only store billing metadata (plan, subscription status), never card numbers.

Testimonial content you collect — when your customers respond to a form, link, invite, or post-payment request, we process the information they provide on your behalf: their name, optional email, testimonial text, rating, and (for the AI conversation) their chat messages and any private feedback. You are the controller of this data; HypeKit processes it to provide the service to you.

Technical data — to keep the service running and prevent abuse, we process limited technical data such as a salted hash of the IP address for rate limiting. For aggregate, privacy-friendly analytics we use Vercel Web Analytics, which is cookieless, stores nothing on your device, and collects no personally identifying information. We run no advertising trackers.

How we use information

To provide and operate HypeKit: authenticate your account, process subscriptions, send testimonial-request and invite emails, run the AI conversation that drafts testimonials, display your approved testimonials, and protect the service from abuse.

Service providers (sub-processors)

We share data with trusted providers only as needed to run HypeKit:

  • Supabase — database and authentication (account and testimonial data).
  • Vercel — hosting, content delivery, and cookieless Web Analytics (aggregate traffic only, no personally identifying information).
  • Stripe — subscription payments, and Stripe Connect for the optional post-payment auto-collect.
  • Resend — sending transactional and invite emails.
  • Anthropic— powers the AI conversation; the customer’s messages are sent to Anthropic to draft a testimonial. They are not used to train models.

Cookies

HypeKit uses only essential cookies (for example, to keep you signed in). We do not use advertising or analytics cookies — our analytics (Vercel Web Analytics) is cookieless. See our Cookie Policy for details.

Data retention

We keep account and testimonial data while your account is active. When you delete content or your account, we delete the associated data within a reasonable period, except where we must retain it to meet legal or accounting obligations.

Your rights

Depending on where you live (for example, under GDPR or CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these, email mahi@gethypekit.com. If you are a customer who submitted a testimonial, contact the business you submitted it to, or us, and we will help route the request.

Security

We use reputable infrastructure providers, encryption in transit, and access controls. No method of transmission or storage is 100% secure, but we work to protect your data.

Children

HypeKit is not directed to children under 16, and we do not knowingly collect their personal data.

Changes

We may update this policy from time to time. We will revise the “Last updated” date above when we do.