Privacy Policy

Last updated: August 2026

1. Overview

This policy explains what data Hipzap — the receipt bookkeeping app, which also keeps your membership cards — collects, where it is stored, and the choices you have.

2. What we collect

We collect only what the features need to work:

  • Membership cards — brand name, card number or barcode, and an optional photo of the card.
  • Receipt images — photos you take to record an expense, which are sent to an AI service to extract details.
  • Expense records — amounts, categories, dates, and any notes you add.
  • Preferences — your chosen language and currency.
  • Account — if you bind one, your email address (used for verification codes and account recovery).
  • Shared group content — if you join a shared group, the ledgers, entries, comments, names and photos you share there are visible to the other members of that group.
  • Safety records — if you report a member or block someone, we store the report (your description, up to 1,000 characters, and a copy of the reported content, up to 2,000 characters) and who you have blocked.
  • Health-related information — a receipt from a pharmacy or clinic can reveal health information about you. If you photograph such a receipt, the image and the extracted line items are stored on our servers and the expense may be classified into a medical category. You can always record these expenses manually instead, without a photo.

3. Where your data is stored

As a guest, your cards, expense records, and preferences are stored on your device (local storage) or in your Telegram cloud storage, which is tied to your Telegram account and synced by Telegram — not by us. We do not hold this data on our servers.

Once you bind an email address, your expense records and cards are stored on our servers so they can sync across your devices. A copy also stays on each device, so the app keeps working offline.

4. Third-party services

We share the minimum necessary with a small number of providers:

  • Google Gemini — receipt images you scan are processed to extract merchant, amount, and date. Google processes them outside the UK, under Google’s standard data-protection terms.
  • Email provider — used to send verification codes and account notifications when you bind an email.
  • Cloudflare Web Analytics — loads only after you accept analytics cookies and counts page views anonymously (see section 11).
  • Paddle — processes the payment when you subscribe to Hipzap Plus on the web, and sets the cookies its checkout needs.

5. How we use your data

We use your data solely to run the app — to extract and categorise expenses, store and display your cards, sync bound accounts across devices, and secure your account. We do not sell your data or use it for advertising.

Our legal bases are: performing our contract with you (running the app, syncing your bound account, and taking payment for Hipzap Plus); our legitimate interests (keeping the Service secure, preventing abuse, and handling reports); and your consent where you give it. Where we rely on consent, you can withdraw it at any time.

6. Your rights

You are in control of your data:

  • Delete your account — from your account settings. Your account is deactivated straight away and you are signed out everywhere. If you sign in again within 30 days, everything comes back. After 30 days we permanently delete your expense records, receipt images, cards, budgets and personal ledgers, including the image files in our storage.
  • Access and correct — view and edit your expense records and cards at any time in the app.
  • Guest data — clearing the app or your Telegram cloud storage removes guest data from that surface.
  • Portability, restriction and objection — you can ask for a copy of your data in a portable form, ask us to restrict or stop certain processing, or object to it. Email support@hipzap.net. If you are not happy with our response, you can complain to the UK Information Commissioner’s Office (ico.org.uk).

7. Data retention

Your expense records are kept until you delete them or close your account. Receipt photos are deleted sooner: we keep them for up to 10 days on the free plan and up to 90 days with Hipzap Plus, and there is also a storage limit (50 MB free, 500 MB with Plus) — when either limit is reached, the oldest photos are deleted first. The expense records themselves are not affected. When you close your account there is a 30-day window during which signing in restores it; after that the data is permanently deleted. Entries and comments you wrote inside a shared group stay with that group so the group’s records remain readable to the other members. Guest data lives only on your device or in your Telegram cloud storage for as long as you keep it there.

If you unsubscribe from marketing emails, we keep a record of that choice even after you close your account. We store it as a one-way hash of your email address, not the address itself. Without it, signing up again with the same address would start those emails over — which is the opposite of what you asked for.

8. Children

The Service is not directed at children under 13, and we do not knowingly collect their data.

9. Changes

We may update this policy as the Service evolves. Material changes will be reflected by the “last updated” date above.

10. Contact

Questions or requests about your data? Email support@hipzap.net.

The data controller for the Service is:

Legal name
CODER TECH LTD
Registration number
16353079
Registered office
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Contact
support@hipzap.net

11. Cookies and on-device storage

The web and Telegram versions use a small number of cookies and similar browser-storage techniques, in two groups: strictly necessary ones the app cannot work without, and analytics that runs only with your consent. The iOS and Android apps use no analytics or tracking cookies; signing in inside the apps relies on the same strictly necessary session cookies as the web version, kept by your device’s operating system.

  • Signing in (strictly necessary) — hipzap_session (kept for up to 7 days) and hipzap_refresh (up to 30 days) are HttpOnly cookies that identify your signed-in session and keep you signed in; hipzap_auth and hipzap_tier (up to 7 days) are companion hints so the interface can show the right signed-in state without exposing the session token. Opening Hipzap through an invite or introduction link may also set a cookie for up to 30 days that records which link brought you, so sign-up can honour that link.
  • Preferences and offline data (strictly necessary) — your language (hipzap_locale, kept for up to a year), your cookie choice, display settings, and the on-device copy of your cards and expense records that keeps the app usable offline (see section 3). None of it is used for tracking.
  • Analytics (only after you accept) — anonymous page-view counts via Cloudflare Web Analytics, plus first-party usage events sent to our own servers. No cross-site tracking and no advertising identifiers.

You can change your choice at any time via “Cookie Preferences” in the page footer or on the Policy & Support page, or by clearing site data in your browser.