This policy covers the Hopin mobile app and this website (hopin.pk), both operated by Hopin from Pakistan. It describes our actual practices. Where a section says we do not do something, that reflects how the product is built, not an aspiration.
1. Information you give us
Account and profile
When you create an account and set up your profile, we store:
- Email address — your login identifier. Verified with a six-digit code.
- Password — stored only as a salted hash. We cannot read it.
- Full name, shown to drivers and passengers you are matched with.
- Phone number — see section 4 for exactly when it is revealed.
- Profile photo, if you upload one.
- Gender — used to operate women-only rides, which are visible only to female users.
- Home city.
- Emergency contact name and phone number. This is stored on your profile and is never shown to drivers or passengers.
Driver verification documents
If you apply to drive, we additionally collect images of your CNIC (front and back), a selfie holding your CNIC, your driving licence (front and back), and your vehicle registration document, along with your CNIC number and your vehicle's make, model, year, colour, registration plate, type and seating capacity.
We also record the outcome of the in-person verification: whether the CNIC matched, whether the vehicle matched its papers, the fuel mileage we measured, the car's condition, and notes from the phone call with you.
Ride and review data
Rides you post or request, pickup and drop-off points, seat counts, prices, the messages you attach to a seat request, cancellations, and the ratings and written reviews you and your counterpart submit after a completed trip.
2. Information collected automatically
- Push notification token. If you allow notifications, the app registers a device push token with us, along with a per-install device identifier so we can replace a stale token from the same device. You can revoke this at any time in your phone's notification settings.
- Session tokens. Signing in issues a short-lived access token (15 minutes) and a refresh token (30 days). Logging out blocklists the refresh token server-side so it cannot be reused.
- Server logs. Standard request logs from our hosting provider, used for debugging and abuse investigation.
We do not collect background or continuous location. The app does not track where you are between trips.
3. Where your data is stored
Account, ride and review data lives in a managed PostgreSQL database. Driver verification documents and profile photos are stored in a private Amazon S3 bucket — the objects are not publicly readable, and there is no public URL for them. When a document needs to be displayed to an authorised reviewer, the server generates a presigned link that expires after five minutes.
Our servers and database are hosted outside Pakistan, so using Hopin involves an international transfer of your data to the hosting regions of the providers listed in section 6.
4. What is shared with other users
This is the part worth reading carefully.
- Before a request is approved, a driver sees the passenger's name, profile photo, rating and the message attached to the request. A passenger sees the driver's first name, rating, vehicle details, pickup and drop-off points, and price.
- Phone numbers are exchanged only when a seat request is approved. Until the driver accepts, neither side has the other's number. This is enforced in the API, not just hidden in the interface.
- Email addresses are never shared between users.
- Your emergency contact is never shared with any other user.
- Verification documents are never shared with other users. They are visible only to Hopin staff performing the verification.
- Reviews you write are visible to the person reviewed, and your rating average is visible to users considering a ride with you.
5. Payments
Hopin does not process payments. Passengers pay drivers directly in cash, in the car. We do not operate a wallet, do not hold funds, and never collect or store card, bank or mobile-wallet details. The per-seat figure in the app is a calculated amount shown to both parties — no money moves through us.
6. Third parties we use
| Service | What it handles |
|---|---|
| Amazon Web Services (S3) | Private storage for verification documents and profile photos. |
| Resend | Sends verification and password-reset emails. Receives your email address. |
| Expo push service | Relays notifications to your device, forwarding to Google's Firebase Cloud Messaging on Android. Receives your push token and the notification text. |
| Google Play services | App distribution and Android notification delivery. |
| Hosting and database providers | Run the application server and database. |
We do not sell your personal data, and we do not share it with advertisers or data brokers.
7. Cookies and advertising
This website sets no cookies. The marketing pages you are reading are static server-rendered HTML with no analytics script, no tracking pixel and no advertising tag. Nothing is written to your browser's storage by visiting hopin.pk.
We intend to display advertising on this website through Google AdSense. When that happens, this section will be updated and the following will apply:
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this or other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to our site and other sites on the internet.
- You can opt out of personalised advertising by visiting Google's Ads Settings.
- You can opt out of third-party vendors' use of cookies for personalised advertising at aboutads.info/choices.
- Google's practices are described in its advertising policies and partner-site policy.
Advertising is a website-only consideration. The Hopin mobile app contains no advertising and no advertising SDK.
8. How long we keep data
- Account and profile data — for as long as your account exists, and afterwards only where we must (see below).
- Verification documents — retained while you are an active driver, because they evidence the check we performed.
- Ride and review records — retained after an account closes, because a ride and its reviews involve a second person whose record we cannot unilaterally erase. Where this happens the record is detached from your identifying details.
- Email verification and password-reset codes — expire after ten minutes and are single-use.
- Push tokens — marked inactive as soon as the notification service reports the device is unreachable.
9. Your rights
You can request a copy of the personal data we hold about you, correct it, or ask us to delete your account and associated data. Email support@hopin.pk from the address on your account and we will respond within 30 days.
Most profile fields can be edited directly in the app without contacting us. You can also turn off push notifications at the operating-system level at any time.
10. Security
Traffic is encrypted with HTTPS and the site is served with HSTS. Passwords are hashed, never stored in readable form. Document storage is private with short-lived signed access. Access to the administrative dashboard is limited to staff accounts.
No system is perfectly secure. If you believe your account has been accessed without your permission, email support@hopin.pk immediately.
11. Children
Hopin is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a minor has created an account, contact us and we will remove it.
12. Changes to this policy
We may update this policy as the product changes — for example when advertising is introduced, or when a new third-party service is added. The effective date at the top of this page always reflects the current version. Material changes will be announced in the app before they take effect, and continuing to use Hopin after that point means you accept the updated policy.
13. Contact
Questions about this policy, or about the data we hold on you, go to support@hopin.pk. See the contact page for response times.