Privacy Policy

What Hopin collects, why, where it is stored, and what we share with the person you are matched with.

Effective 6 August 2026

This policy covers the Hopin mobile app and this website (hopin.pk), both operated by Hopin from Pakistan. It describes our actual practices. Where a section says we do not do something, that reflects how the product is built, not an aspiration.

1. Information you give us

Account and profile

When you create an account and set up your profile, we store:

Driver verification documents

If you apply to drive, we additionally collect images of your CNIC (front and back), a selfie holding your CNIC, your driving licence (front and back), and your vehicle registration document, along with your CNIC number and your vehicle's make, model, year, colour, registration plate, type and seating capacity.

We also record the outcome of the in-person verification: whether the CNIC matched, whether the vehicle matched its papers, the fuel mileage we measured, the car's condition, and notes from the phone call with you.

Ride and review data

Rides you post or request, pickup and drop-off points, seat counts, prices, the messages you attach to a seat request, cancellations, and the ratings and written reviews you and your counterpart submit after a completed trip.

2. Information collected automatically

We do not collect background or continuous location. The app does not track where you are between trips.

3. Where your data is stored

Account, ride and review data lives in a managed PostgreSQL database. Driver verification documents and profile photos are stored in a private Amazon S3 bucket — the objects are not publicly readable, and there is no public URL for them. When a document needs to be displayed to an authorised reviewer, the server generates a presigned link that expires after five minutes.

Our servers and database are hosted outside Pakistan, so using Hopin involves an international transfer of your data to the hosting regions of the providers listed in section 6.

4. What is shared with other users

This is the part worth reading carefully.

5. Payments

Hopin does not process payments. Passengers pay drivers directly in cash, in the car. We do not operate a wallet, do not hold funds, and never collect or store card, bank or mobile-wallet details. The per-seat figure in the app is a calculated amount shown to both parties — no money moves through us.

6. Third parties we use

ServiceWhat it handles
Amazon Web Services (S3) Private storage for verification documents and profile photos.
Resend Sends verification and password-reset emails. Receives your email address.
Expo push service Relays notifications to your device, forwarding to Google's Firebase Cloud Messaging on Android. Receives your push token and the notification text.
Google Play services App distribution and Android notification delivery.
Hosting and database providers Run the application server and database.

We do not sell your personal data, and we do not share it with advertisers or data brokers.

7. Cookies and advertising

This website sets no cookies. The marketing pages you are reading are static server-rendered HTML with no analytics script, no tracking pixel and no advertising tag. Nothing is written to your browser's storage by visiting hopin.pk.

We intend to display advertising on this website through Google AdSense. When that happens, this section will be updated and the following will apply:

Advertising is a website-only consideration. The Hopin mobile app contains no advertising and no advertising SDK.

8. How long we keep data

9. Your rights

You can request a copy of the personal data we hold about you, correct it, or ask us to delete your account and associated data. Email support@hopin.pk from the address on your account and we will respond within 30 days.

Most profile fields can be edited directly in the app without contacting us. You can also turn off push notifications at the operating-system level at any time.

10. Security

Traffic is encrypted with HTTPS and the site is served with HSTS. Passwords are hashed, never stored in readable form. Document storage is private with short-lived signed access. Access to the administrative dashboard is limited to staff accounts.

No system is perfectly secure. If you believe your account has been accessed without your permission, email support@hopin.pk immediately.

11. Children

Hopin is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a minor has created an account, contact us and we will remove it.

12. Changes to this policy

We may update this policy as the product changes — for example when advertising is introduced, or when a new third-party service is added. The effective date at the top of this page always reflects the current version. Material changes will be announced in the app before they take effect, and continuing to use Hopin after that point means you accept the updated policy.

13. Contact

Questions about this policy, or about the data we hold on you, go to support@hopin.pk. See the contact page for response times.