1. Who we are and scope
This Privacy Policy explains how the operator of Hypemint (identified on our Contact page) processes personal data when you visit this website, create an account, place an order, make a payment or contact support. We act as the data controller for this processing. We aim to follow the principles of the EU General Data Protection Regulation (GDPR) and comparable data-protection laws that apply to our customers.
2. Data we collect
- Account and contact data: name or display name, email address and, where you provide it, a phone or messaging contact.
- Order data: package, quantity, price, order status, and the public username or public content link you provide as the delivery target.
- Payment data: payment status and transaction references received from our payment providers. We do not store full card numbers; payments are processed by the payment provider shown at checkout.
- Security and technical data: hashed password, session and login records, IP address, browser and device information, and error logs.
- Support data: messages you send through the contact form, live chat or email.
- Preference data: choices such as theme and cookie consent, stored in your browser.
We never request your social-media password or verification codes, and you should never send them to us.
3. Why we process data and legal bases
We process personal data to create and administer your account and orders (performance of a contract); to deliver services to the public target you specify (performance of a contract); to verify payments and prevent fraud and abuse (legitimate interests and legal obligation); to provide customer support (performance of a contract and legitimate interests); to meet accounting, tax and other legal obligations (legal obligation); and to send marketing communications only where you have opted in (consent, which you can withdraw at any time).
4. Sharing and international transfers
We share data only as necessary with hosting, security and infrastructure providers, payment processors, email and support tooling providers, and professional advisers, each limited to their role and bound by appropriate confidentiality and data-processing obligations. We disclose data to public authorities only where legally required. Where data is transferred across borders, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses where the GDPR requires them.
5. Retention
We keep personal data only as long as needed for the purposes above: account data for the life of the account, order and payment records for as long as accounting and consumer-law obligations require, support records for as long as needed to resolve the matter and defend legal claims, and security logs for a limited, risk-proportionate period. Data is then deleted or anonymised.
6. Cookies
We use strictly necessary cookies for sessions and security, and optional analytics only with your consent. Details and controls are described in our Cookie Policy.
7. Your rights
Depending on your location, you may have the right to access your data, receive a copy, correct inaccurate data, request deletion, restrict or object to processing, withdraw consent, and receive data in a portable format. You can exercise these rights through our Contact page or the business email address published there; we will respond within the timeframe required by applicable law. If you are in the EU/EEA or UK, you may also lodge a complaint with your local data-protection authority.
8. Security and changes
We protect data with HTTPS encryption in transit, hashed passwords, access controls, CSRF protection, monitoring and backups. No online service can guarantee absolute security, but we take commercially reasonable measures appropriate to the risk. If we materially change this policy, we will publish the updated version on this page with a new revision date.