Privacy Policy
Last updated:
This policy covers the three markets SkyHoppy serves today — Brazil (LGPD), the United States (CCPA/CPRA) and Canada (PIPEDA). It is written by the team building the product and has not been reviewed by outside counsel.
SkyHoppy is a trip planner that is still being built. This page says, in plain words, what the site collects today and what you can do about it.
What we collect
Signing in is optional. If you sign in with Google, we receive your name, email address and profile picture, plus Google's number for your account. We never receive or keep your Google password, and we do not keep Google's access tokens.
While you are signed in, we keep a record of each signed-in device: when the sign-in started and when it expires. We do not record which device or place it came from.
If you buy a pass, we keep the product, amount, currency, status and the payment provider's reference. Card payments are handled by Lemon Squeezy and Pix payments by Efí; your card and payer details stay with them, not with us.
Your internet address is never stored as is: where we need it (for example, to limit abuse), we keep only a one-way fingerprint of it.
When you follow a booking link to a partner (Viator, GetYourGuide, Travelpayouts or Tripadvisor), we record the click: which partner, when, the market and traveler profile of the page, the itinerary it came from (if any), the campaign tags (UTM) in the link, a one-way fingerprint of your internet address and, if you are signed in, your account. This is how partners credit us a commission; the booking itself happens on their site.
To understand which parts of the product people use, we record short usage events on our servers when you start, build or edit an itinerary, follow a booking link or buy a pass: the event, the market, the traveler profile, the campaign source (or “direct”), the itinerary (if any) and, if you are signed in, your account. No internet address and no personal detail is stored in them.
We send only transactional email, such as payment receipts and the link that confirms an account deletion. It is delivered by Zoho ZeptoMail. We do not send marketing email.
Your rights
When signed in, the “Your data” page (/my/data) shows everything linked to your account, lets you download it as a file and lets you delete your account. If anything there does not work for you, write to [email protected] and we will handle it by hand.
United States — CCPA/CPRA (California)
This section applies to people using SkyHoppy from the United States, under California's CCPA/CPRA and comparable US state privacy laws.
Categories of personal information we collect
Under the CCPA/CPRA's categories, we collect: identifiers (name, email address, profile picture and Google account number, if you sign in); commercial information (the product, amount, currency and status of a pass you buy); and internet or network activity (your signed-in devices, your cookie-banner choice, and, when you follow a booking link, the partner, market, itinerary and campaign tags of that click). We do not collect precise geolocation, biometric, health or financial account information.
Do Not Sell or Share My Personal Information
We do not sell personal information for money, and we do not share it for cross-context behavioral advertising. The only disclosures that happen are to the partner you choose to book with (so they can credit us a commission) and to the service providers listed under “Who else sees your data” below, strictly to run the service. There is nothing to opt out of today; if that ever changes, this page and a clear “Do Not Sell or Share” link will say so first.
Notice at collection
We collect the categories listed above at the point you sign in, buy a pass, answer the cookie banner or follow a booking link, for the purposes described in “What we collect”, and we keep each one for the period shown in the retention table below. We do not use personal information for a purpose incompatible with the one disclosed when it was collected.
Your CCPA/CPRA rights
California residents can ask to know what personal information we hold, correct it, delete it, and limit the use of sensitive personal information (we do not collect sensitive personal information as the CCPA defines it, beyond what a payment needs — and that stays with our payment providers, not with us). The “Your data” page (/my/data) covers access, download and deletion when you are signed in; for any other request, or to verify your identity for one, write to [email protected] from the email address on your account.
Non-discrimination
We will not deny you the service, charge you a different price or give you a different level of quality because you exercised a CCPA/CPRA right.
Commission from booking partners
SkyHoppy is not a travel agency: we never sell, book or take payment for a trip. When you follow a booking link to a partner (Viator, GetYourGuide, Travelpayouts or Tripadvisor), we may earn a commission if you book — at no extra cost to you, and it never changes the price you pay. The booking, the payment and the trip itself happen entirely with the partner, under their terms.
Prices are indicative
Prices shown on SkyHoppy, including in an itinerary's estimated cost, are indicative: they come from partners, can be cached, and can change before you book. The price the partner shows you at checkout is the one that counts — we do not charge you for, or guarantee, any trip price.
The paid pass
An optional paid pass unlocks more than the free use of SkyHoppy for 30 days from purchase; the annual plan covers a full year instead. Card payments are processed by Lemon Squeezy, which acts as the seller of record, and Pix payments by Efí. A pass is a digital service: buying, renewing or not renewing it never books, changes or refunds a trip — that stays between you and the booking partner, under their own terms, with or without a pass.
How long we keep each kind of data
This table comes straight from the code that runs the purge, so the numbers here cannot drift from what actually happens to your data.
- Signed-in session, while inactive
- Signs you out automatically after 30 days without use.
- Signed-in session, absolute cap
- Ends at most 90 days after sign-in, even with continuous use.
- Account, after you confirm deletion
- Your name, email and picture are blanked right away; the account record itself is removed for good 30 days later.
- Cookie-banner consent record
- Kept for 365 days, then deleted.
- Booking-link click record
- Kept for 395 days (about 13 months), so commissions on trips booked up to a year ahead can still be matched.
- Monthly usage counter (free-plan and pass limits)
- Kept for 395 days, then deleted.
- Product usage event (itinerary built, booking-link click, pass bought)
- Kept for 400 days, then deleted. Once you delete your account, the event stays only as an anonymous count.
- Itinerary with no signed-in owner
- Deleted after 90 days with no activity.
- Payment record (tax and accounting)
- Kept while tax law requires it, unlinked from you once your account is deleted. There is no fixed number of days here: a tax retention period is set by law, not by us.
Who else sees your data
We do not sell your data. These are the companies we use to run the service, each limited to what it needs to do its job:
- Zoho ZeptoMail
- Sends our transactional email: payment receipts and the account-deletion confirmation link.
- Lemon Squeezy
- Processes card payments for the pass, as the seller of record, in USD and CAD.
- Efí
- Processes Pix payments for the pass, in BRL.
- Provides the optional sign-in (OAuth); we receive your name, email and profile picture, never your password.
- Viator, GetYourGuide, Travelpayouts and Tripadvisor
- Receive your booking-link click, market and campaign tags when you choose to book, so they can credit us a commission.
Contact
Questions or requests about your data: [email protected].
Read this page for another market
SkyHoppy also serves: