Legal
Privacy Policy
Last updated: 16 September 2026
This policy explains what personal data Hoopla collects, why it is collected, how long it is kept and what rights you have over it. It covers this website, the enquiry form, and the internal tools Hoopla operates — including tools that access Google user data with the account holder's explicit authorisation.
1. Who is responsible
The data controller is Hoopla LLC, registered in Saint Vincent and the Grenadines ("Hoopla", "we"). You can reach us through the enquiry form on this site; we do not publish a public mailbox, and the form reaches us directly.
2. Data we collect
Enquiries sent through this website
- the name, email address and company or website you enter in the form;
- the content of your message;
- technical data needed to deliver and protect the form: IP address, user agent and timestamp.
Providing this data is voluntary. Without an email address we cannot reply, which is the only reason we ask for it.
Client engagement data
During an engagement we process data belonging to our clients' systems — analytics, search performance, server logs, content. That data is processed on the client's instructions under a separate agreement, and it is never reused for any other purpose, sold, or combined with data from another client.
Website analytics
This site does not use advertising cookies, does not build visitor profiles, and does not share visitor data with advertising networks. Aggregate, non-identifying traffic counts may be collected at the network edge to keep the site available and to detect abuse.
3. Anti-abuse: Cloudflare Turnstile
The enquiry form is protected by Cloudflare Turnstile, which verifies that a submission comes from a person rather than an automated script. Turnstile processes technical signals from your browser for that verification only. It does not require solving a puzzle and it is not used for advertising or cross-site tracking.
4. Google API Services — limited use
Hoopla's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Hoopla operates internal tooling that connects to Google accounts belonging to Hoopla and to its own operators — for example to read and send email on those accounts, and to read search performance and analytics data for properties we are authorised to work on. This access happens only after the account holder has granted it through Google's own consent screen, and it can be revoked at any time from the Google account permissions page.
- What is accessed. Only the scopes shown on the consent screen at the moment of authorisation — in practice: reading and organising messages, and sending messages on behalf of the authorising account.
- What it is used for. Operating that account: finding, reading, organising and replying to correspondence for the account holder.
- What is stored. An OAuth refresh token per authorised account, held encrypted at rest on our own machines. Message content is read on demand and is not copied into a separate archive.
- What is never done. Google user data is never sold, never transferred to third parties except as required by law, never used for advertising, and never used to train generalised artificial intelligence or machine-learning models.
- Human access. No human reads Google user data obtained through these tools other than the account holder, except where required by law, for security investigations, or with the account holder's explicit consent.
5. Why we are allowed to process this data
- Your request. Replying to an enquiry you sent us.
- Legitimate interest. Keeping this site and its form secure and available.
- Consent. Access to a Google account, granted by the account holder and revocable at any time.
- Contract and legal obligation. Client engagements, invoicing and record-keeping.
6. How long we keep it
- Enquiries that do not become projects: up to 24 months, then deleted.
- Client records and invoices: as long as accounting and tax rules require.
- OAuth tokens: until the authorisation is revoked or the tool is retired, whichever comes first.
7. Who else sees your data
We keep the number of third parties deliberately small. The ones involved are our infrastructure and network provider (Cloudflare), our email delivery provider, and Google where an account holder has authorised access as described above. We do not sell personal data, and we do not share it with advertising networks or data brokers.
8. Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Write to us through the form and we will respond within 30 days. If you are in the European Union, you also have the right to lodge a complaint with your national data protection authority.
9. Security
Data in transit is encrypted with TLS. Credentials and tokens are stored encrypted, with access restricted to the individuals who operate the tools. We apply the least access needed for the work and remove it when the work ends.
10. Changes to this policy
If this policy changes materially, the date at the top of the page is updated and the previous version is superseded. Continued use of the site after that date means the current version applies.