Privacy
No jargon games. This page lists every kind of information hoopmo holds, what it is used for, and how to have it removed.
Last updated: 20 August 2026 (version 1.1)
The short version. hoopmo holds what an operator needs to run a hostel: accounts, resident records, rent, maintenance. It is stored in India. We do not collect any government ID number, any ID document image, or your location. We do not sell data and we do not run ads. You can delete your account from inside the app, or ask us to — see deleting your data.
This one policy covers all three places hoopmo touches personal data:
If you are filling a QR form and have never used hoopmo, section 4c is the part that describes you.
hoopmo is an app for running hostels, paying-guest accommodations and co-living — rooms and beds, maintenance, resident records and rent. It is operated by Shilpa Kapa, Hyderabad, Telangana 500086, India. To ask anything about this policy, or to exercise your rights under it, write to hello@hoopmo.com.
hoopmo handles two kinds of personal data, and our responsibility is different for each.
| Information | Why we hold it | Where it comes from |
|---|---|---|
| Your name, email address and, if you sign in by phone, your mobile number | To create your account, sign you in, and contact you about the service | You (the operator or staff member) |
| Resident details an operator enters: name, contact number, check-in dates, food preference, vehicle number | To run the tenancy — rooms, beds, rent and communication | The operator, about their residents |
| A checklist of which ID document types were verified (for example "Aadhaar", "college ID") | So an operator can record that identity was checked, without holding the document | The operator, about their residents |
| Rent, deposit and payment records | To keep the tenant ledger and show what is paid and what is due | The operator |
| Photos attached to maintenance tickets | To show staff what needs fixing | Whoever logs the ticket |
| A push notification token for your device | To deliver alerts, such as a ticket assigned to you | Your device |
| Crash reports and anonymous usage events (screens opened, actions completed) | To find bugs and see which parts of the app are used | Your device, automatically |
| Information | Why we hold it | Where it comes from |
|---|---|---|
| Your email address, and an optional note about what you want hoopmo to do | To tell you when hoopmo opens, and to shape what we build | You, if you join the waitlist |
| Cookie-free page analytics: page views, referrer, country, device type | To see which pages are read. No cookies, no cross-site tracking, no profile of you | Your browser, automatically |
| An anti-bot check (Cloudflare Turnstile), which sees your IP address and browser signals | To stop automated spam submissions. We never see or store the IP ourselves | Your browser, when you submit a form |
Waitlist emails are kept in a separate database from the app, so a marketing signup never sits next to anybody's tenancy records. This site sets no advertising or tracking cookies.
Anyone can scan a sticker and submit one of these forms. You do not need an account, and we do not create one for you.
| Information | Why we hold it | Where it comes from |
|---|---|---|
| What is broken, the category, and the room or common area | To create the maintenance ticket the staff will act on | You, on the report form |
| A photo of the problem — optional, and only on the maintenance report form. The enquiry form has no photo field | A picture of the leak or the broken latch tells staff more than a typed description can | You, only if you tap the photo button |
| Your mobile number — optional on a maintenance report, required on an enquiry | So the operator can follow up on your report or your enquiry | You, on the form |
| On an enquiry only: your name, and what you are looking for — gender, sharing preference, move-in date, how long, notes | So the operator can answer your enquiry with a real option | You, on the enquiry form, after you tick the consent box |
| A one-way hash of your IP address — never the address itself | To rate-limit spam. The hash cannot be turned back into your IP | Your browser, automatically |
What you submit goes to the operator of that specific building — the one whose sticker you scanned — and becomes their record to act on. From that point the operator is the Data Fiduciary for it, and hoopmo is the Processor, exactly as described in section 3. A photo is only ever taken if you tap the photo button yourself — the form cannot open your camera on its own. The form asks you to photograph the problem only, not people and not documents, and we ask you to keep to that: the operator and their staff will see what you send.
No government ID number — the app has no field to type one into. No photograph or scan of any ID document. No location: the app never reads your device's position, and "get directions" simply opens your maps app. No access to your contacts, messages, calendar, files, microphone or browsing history. No advertising identifier, no ad networks, no tracking cookies. We do not sell personal data, and we never use it to build a profile of you.
Crash reports carry the type of error and a technical error code — never the text of a database message, because that text could quote a resident's record. Usage events are a fixed list of screen and action names with counts. Neither carries a name, a phone number or any resident detail.
Under the DPDP Act we process personal data on your consent, given when you sign up, when you join the waitlist, or when you tick the box on an enquiry form. Consent is asked for each purpose, and the purposes are the ones listed in section 6 — nothing else.
Withdrawing consent is as easy as giving it. Delete your account in the app under Settings, or write one line to hello@hoopmo.com. No form, no phone call, no reason needed. Withdrawing consent means we can no longer provide the service to you, and we stop processing your data except where the law requires us to keep a record.
Where the Act's "certain legitimate uses" apply — for example, responding to a request you made yourself, or complying with a legal obligation — we rely on those instead. We do not claim any other basis.
We do not sell personal data, and we do not share it for anyone else's marketing. The companies below process data for us, under contract, and are not allowed to use it for their own purposes. Each one's privacy policy is linked, because their handling is governed by their terms as well as ours.
| Provider | What it does for hoopmo | Where it processes | Their policy |
|---|---|---|---|
| Supabase | Database, sign-in, file storage and backend functions — the app itself. | India (Mumbai, ap-south-1) | Privacy policy |
| Google (Firebase) | Google sign-in, push notifications, crash reporting and usage analytics. | Outside India | Privacy policy |
| Apple | Sign in with Apple, on Apple devices only. | Outside India | Privacy policy |
| Cloudflare | Hosts hoopmo.com and forms.hoopmo.com, plus the anti-bot check and cookie-free site analytics. | Global network, nearest edge | Privacy policy |
Two other cases. Data an operator enters is visible to that operator's own team, limited by role — that is the point of the product. And we disclose data if the law compels us to. Beyond those, nothing leaves.
If we add or change a provider, we update this table and the date at the top of the page before the change takes effect.
Your records — accounts, residents, rent, tickets, photos — are stored in India (Mumbai) and stay there.
Three things are processed outside India: crash reports and anonymous usage events (Google/Firebase), push notification delivery (Google/Firebase), sign-in verification when you use Google or Apple, and the anti-bot check and site delivery (Cloudflare's global network). The DPDP Act permits transfers abroad except to countries the Government restricts; none of these providers operate from a restricted country today. If that changes, we move the processing or stop it.
No system is perfectly secure, but these are real controls, not intentions.
| What | How long |
|---|---|
| Your account, and the property records inside it | While the account is active. A tenancy ledger is only useful with its history. |
| Everything, after you delete your account | Removed immediately from the live database. Encrypted backups can still hold a copy for up to 7 days, after which the backup expires and the copy is gone. |
| A deletion or rights request sent by email | Acted on within 30 days. |
| The audit log | Kept for the life of the property record, and the entry recording a deletion is kept after it. It is append-only by design — that is what makes it evidence. |
| The hashed-IP spam log on the public forms | Deleted after 2 days. |
| Waitlist email | Until hoopmo launches, or until you ask us to remove it — whichever comes first. |
When you delete your account we remove your access, your device tokens and your membership of every property, and any property you were the sole owner of becomes inaccessible and is removed. We also erase data when you withdraw consent, or when the purpose we collected it for is finished, unless a law requires us to keep it. See deleting your data for the exact steps.
Under the DPDP Act, 2023 you may:
Write to hello@hoopmo.com to use any of these. We answer within 30 days. If you are still not satisfied, you can raise it with the Data Protection Board of India, established under the Act; the Board publishes its own complaint procedure, and the first step is always to have complained to our grievance officer (section 16).
If you are a resident of a hostel or PG and your details were entered by an operator, or you submitted a QR form, please contact that operator first — they decide what is held about you. Write to us if they do not respond and we will help.
hoopmo is business software for adults. It is not directed at children, and we do not knowingly create accounts for anyone under 18. We do not track children, do not profile them, and show nobody advertising of any kind. If an operator needs to record a resident under 18, the DPDP Act requires that operator to have verifiable consent from a parent or guardian first — that duty is theirs, as the Data Fiduciary. If we learn that we hold a child's data without such consent, we delete it.
If personal data we hold is breached, we will notify the Data Protection Board of India and every affected person, as the DPDP Act requires — telling you what happened, what it means for you, and what we have done about it. We will not wait for the story to look better.
hoopmo makes no automated decision that has a legal or similarly significant effect on anyone. There is no profiling, no scoring, no algorithm ranking residents. The app shows an operator what they entered and does arithmetic on it.
As required by the DPDP Act, our grievance officer is Shilpa Kapa, Hyderabad, Telangana 500086, India, reachable at hello@hoopmo.com. Write "Grievance" in the subject line and it gets read first. We acknowledge every grievance, and aim to resolve it within 30 days.
This is version 1.1, effective 20 August 2026. If we change what we collect or why, we will update this page and change the version and date at the top. If the change is significant, we will tell you in the app before it takes effect. Every earlier version is kept, so you can ask us what this page said on any past date.