HOPPENLY POS PRIVACY POLICY

Privacy Policy

Hoppenly® POS for Android

Effective date: August 27, 2026
Last updated: August 27, 2026

This Privacy Policy is issued by Yehl Ventures LLC, a Texas limited liability company doing business as Hoppenly ("Hoppenly," "we," "us," or "our").

Privacy contact orders@hoppenly.com
Postal address Yehl Ventures LLC d/b/a Hoppenly, 221 Green Pasture, Hutto, Texas 78634, United States
Application Hoppenly® POS for Android (the "Application" or "App")
Payment partner Clover Network, LLC and its affiliates, a Fiserv company ("Clover")

At a glance

  • The Application is an internal checkout tool. It is used only by Hoppenly's own employees, contractors, and field representatives on company-managed Android devices, paired with Clover Go card readers, to sell merchandise in person at events. It is not offered to other businesses and is not available for general download.
  • We never receive or store your card number. Card data is captured, encrypted, and processed end-to-end by Clover. We see only the outcome of a payment.
  • We do not build customer marketing lists from the Application. If you ask for a digital receipt, your email address or mobile number is passed to Clover to send it and is not stored in Hoppenly's records.
  • The Application uses location because the Clover Go card reader software requires it to process card-present payments. We also record where a sale took place so it can be matched to the right event.
  • We do not sell personal information and we do not share it for cross-context behavioral advertising.
  • You can reach a human. Email orders@hoppenly.com with any privacy question or request, including a request to know what we hold about you or to have it deleted.

Contents

1. About this Policy
2. Information we collect
3. Device permissions and why we ask for them
4. How we use information
5. How we share information
6. Data retention
7. Security
8. Your privacy rights and how to exercise them
9. Notice for California residents
10. Notice for residents of Texas and other U.S. states
11. Notice for individuals in the European Economic Area and United Kingdom
12. Our employees, contractors, and field representatives
13. Customers who buy from us at an event
14. Children's privacy
15. Third-party services
16. Where your information is processed
17. Changes to this Policy
18. How to contact us


1. About this Policy

1.1 What this Policy covers

This Policy explains what information the Hoppenly® POS for Android application collects, how we use it, who we disclose it to, and the choices and rights available to you. It applies to the Application and to the information we handle through it.

1.2 How the Application is used

The Application is an internal point-of-sale tool. Hoppenly sells branded merchandise directly to the public at cheer, dance, and spirit events across the United States. Our employees, contractors, and field representatives (together, "Users") run the Application on Android devices that Hoppenly owns and manages, paired over Bluetooth with Clover Go card readers, to ring up and take payment for those in-person sales.

The Application is not published for general download, is not offered to other merchants, and is not used to build customer accounts, profiles, loyalty programs, or marketing lists.

1.3 Who this Policy is written for

Two groups of people are described by this Policy, and different parts apply to each:

  • Users — Hoppenly's own employees, contractors, and field representatives who operate the Application. See Section 12.
  • Customers — members of the public who buy merchandise from us at an event. See Section 13.

1.4 What this Policy does not cover

This Policy does not cover:

  • Clover. Card payments are processed by Clover, which handles your payment information under its own privacy policy, available at clover.com/privacy-policy. We do not control Clover's practices.
  • Our online stores. Yehl Ventures LLC also operates the online stores at hoppenly.com and roserel.com. Purchases and browsing on those sites are covered by the separate privacy policies published on each of them, not by this Policy.
  • Other companies. Any third-party site or service you reach independently of the Application.

This Policy also does not replace or limit any notice or disclosure we are required to give you at the point of sale.


2. Information we collect

2.1 Transaction information

When a sale is completed, the Application records the details of that sale: the items purchased, quantities, unit prices, discounts, taxes, the order total, an order identifier, the date and time, the identity of the User who processed the sale, and the event and venue at which the sale took place.

2.2 Payment card information — handled by Clover, not by us

The Application does not collect, store, transmit, or have access to cardholder data. Payment card information is read, encrypted, and processed end-to-end by the Clover Go card reader and Clover's payment systems.

From Clover we receive only a non-sensitive result: whether the payment was authorized or declined, the payment method type (for example, credit, debit, or contactless), the card brand, the last four digits of the card number, and a payment reference identifier. We never receive the full card number, expiration date, security code, or PIN.

2.3 Digital receipt details

A Customer may choose to be sent a receipt by email or text message. If so, the Application collects the email address or mobile number entered at the point of sale solely to send that receipt.

That detail is transmitted to Clover, which delivers the receipt. It is not stored in Hoppenly's own records, and it is never used for marketing. Clover's retention of that information is governed by Clover's privacy policy.

2.4 Signature

Where a payment requires it, the Application captures a signature drawn on the device screen. A signature is collected only to verify and, if necessary, to defend or dispute the associated payment. It is transmitted to Clover as part of the payment record. Where a copy of a signature is returned to us with a transaction record, it is stored with that transaction record and used for no other purpose.

2.5 Location information

The Application collects the device's geographic location. There are two reasons, and both are disclosed here in full:

1. The Clover Go card reader software requires it. Clover's software development kit requires Android location access in order to process card-present transactions. Location is used by Clover for payment risk assessment and fraud prevention. This is a requirement of the payment software, not a choice Hoppenly made.
2. To attribute a sale to the correct event. We record the approximate coordinates at which a sale was completed on that sale's record, so that sales can be matched to the right event and venue and reconciled afterwards.

Location is associated with a completed sale and with the company-managed device that processed it. It is not used to track a Customer, and it is not used to build any profile of any individual.

2.6 User and account information

The Application collects information identifying the User operating it: their name, the employee or staff identifier assigned to them, their role, and their login credentials for the Application. Each sale is recorded against the User who processed it.

2.7 Device, diagnostic, and log information

The Application collects technical information about the company-managed device on which it runs: the device identifier, model and operating system version, the Application version, network connectivity status, and diagnostic, crash, and error logs generated while the Application is running.

Hoppenly's company-managed devices are also administered using mobile device management software, which may report device configuration, compliance, assignment, and location information to us as described in our internal device policy.

2.8 Camera

The Application uses the device camera only to read product barcodes at checkout. The camera image is processed on the device to decode the barcode. No photograph or video is stored, retained, or transmitted anywhere.

2.9 What the Application does not collect

To be explicit, the Application does not collect:

  • Full payment card numbers, expiration dates, security codes, or PINs;
  • Customer names, postal addresses, dates of birth, or demographic information;
  • Loyalty program data, marketing preferences, or customer survey responses;
  • Photographs, video, or audio recordings;
  • Biometric identifiers, including fingerprints, facial recognition data, and voice recordings;
  • Contacts, calendar entries, call logs, SMS message contents, or files from a device;
  • Health information, government identification numbers, or financial account numbers;
  • Advertising identifiers, and no third-party advertising or analytics software development kit is embedded in the Application.

3. Device permissions and why we ask for them

Android permission Why the Application needs it
Camera To scan product barcodes at checkout. Images are decoded on the device and are never stored or transmitted.
Precise location Required by the Clover Go payment software to process card-present transactions and to support Clover's fraud prevention, and used to record the location of a completed sale so it can be attributed to the correct event.
Bluetooth (connect and scan) To discover, pair with, and exchange data with the Clover Go card reader. No other Bluetooth device is accessed.
Internet and network state To transmit transaction data to Clover and to Hoppenly's business systems, and to detect whether the device is online so sales can be queued when connectivity is lost.

The Application requests no other sensitive permission. It does not request access to contacts, SMS messages, call logs, the microphone, the photo library, or device storage beyond its own application data.


4. How we use information

Purpose Information used Why we may do this
Complete a sale and take payment Transaction details, payment result, signature, location To perform the sale you have asked us to complete
Send a digital receipt Email address or mobile number provided at checkout At the Customer's request
Record, reconcile, and account for sales Transaction details, User identity, event, location Our legitimate interest in running the business, and our legal obligation to keep accurate tax and accounting records
Manage inventory and replenish stock at events Items and quantities sold, event Our legitimate interest in running the business
Prevent and investigate fraud, theft, and misuse Transaction details, User identity, device information, location, payment result Our legitimate interest in protecting the business, our staff, and our customers
Troubleshoot, secure, and improve the Application Device information, diagnostic and error logs, Application version Our legitimate interest in keeping the Application working and secure
Administer and secure company-managed devices Device identifiers, configuration, assignment, location Our legitimate interest in protecting company property and data
Comply with legal, tax, and accounting obligations, and respond to lawful requests Any of the above, as required Our legal obligations
Manage our staff and pay them correctly User identity, sales recorded against a User Performance of our contract with the User and our legal obligations as an employer

We do not use the information collected through the Application to profile individuals, to make automated decisions producing legal or similarly significant effects, or for advertising of any kind.


5. How we share information

We disclose information only in the circumstances set out below.

  • Clover. We share transaction and payment information with Clover Network, LLC and its affiliates, as necessary for Clover to process the payment, deliver a receipt, and meet its own legal and payment-network obligations. Clover acts as our payment processor and handles that information under its own privacy policy.
  • Service providers. We use a small number of vendors that support our operations — cloud hosting, business software, mobile device management, accounting and bookkeeping, and professional advisers. They may access information only to provide services to us, must protect it, and may not use it for their own purposes.
  • Professional advisers. Our accountants, auditors, insurers, and attorneys, where necessary for them to advise us.
  • Legal and safety. Where required by law, subpoena, court order, or other legal process, or by a governmental or regulatory request; and where we reasonably believe disclosure is necessary to investigate suspected fraud or unlawful activity, to enforce our agreements, or to protect the rights, property, or safety of Hoppenly, our personnel, our customers, or the public.
  • Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business, subject to the recipient continuing to protect the information consistent with this Policy.

We do not sell your information

We do not sell personal information, and we have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of any individual under sixteen years of age. We do not disclose personal information to data brokers, advertising networks, or list vendors.


6. Data retention

We keep information only for as long as we need it for the purposes described in this Policy, or for as long as the law requires us to keep it. The periods below are the standards we apply.

What we hold How long we keep it
Sales and transaction records, including items, amounts, taxes, event, and the location of the sale At least four years from the end of the year in which the sale occurred, consistent with Texas Tax Code recordkeeping requirements, and generally seven years for accounting, audit, and tax purposes
Payment results — authorization status, card brand, last four digits, payment reference Kept with the transaction record above
Signature, where a copy is returned to us Kept with the transaction record above; the authoritative copy is retained by Clover under Clover's own schedule
Digital receipt email address or mobile number Not retained by Hoppenly. Passed to Clover at the point of sale to send the receipt; Clover's retention is governed by Clover's privacy policy
User account and access records For the duration of the individual's employment or engagement, plus four years, to meet employment, payroll, and tax recordkeeping obligations
Application diagnostic, crash, and error logs Up to ninety days, after which they are deleted or reduced to non-identifying aggregate statistics
Managed-device records, including assignment and configuration For as long as the device is assigned to a User, plus twelve months

At the end of the applicable period, information is deleted or irreversibly anonymized in the ordinary course of business. Where information is subject to a legal hold, an audit, an open dispute, or an ongoing investigation, we keep it until that matter is resolved.

Questions about retention, or a request to delete information we hold about you, should be sent by email to orders@hoppenly.com. We respond to every request as described in Section 8.


7. Security

We use administrative, technical, and physical safeguards designed to protect the information we handle, including:

  • No cardholder data in our systems. All card data is captured and processed by Clover's PCI DSS-compliant payment infrastructure and never enters the Application or our records.
  • Encryption. Card data is encrypted by the Clover Go reader at the point of capture. Information transmitted between the Application, Clover, and our systems is encrypted in transit.
  • Managed devices. The Application runs only on Hoppenly-managed devices, which are enrolled in mobile device management, require a screen lock, and can be locked or erased remotely if lost or stolen.
  • Access controls. Each User has an individual login. Access to sales and business records is restricted by role, so that staff can see only what their job requires. Financial and personnel records are restricted to the business owner.
  • Vendor diligence. We contract with our service providers to require appropriate safeguards.

No system is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting personal information, we will notify affected individuals and regulators where the law requires it, within the time the law allows.


8. Your privacy rights and how to exercise them

8.1 Rights that may be available to you

Depending on where you live, you may have the right to:

  • Know or access the personal information we hold about you, the categories of sources it came from, the purposes we use it for, and the categories of third parties we disclose it to;
  • Correct inaccurate personal information;
  • Delete personal information we hold about you;
  • Obtain a portable copy of personal information you provided to us, in a readily usable format;
  • Opt out of the sale or sharing of personal information, and of profiling with legal or similarly significant effects — noting that we do none of these things;
  • Limit the use of sensitive personal information — noting that we use it only for the permitted business purposes described in Section 9;
  • Withdraw consent, where we relied on your consent;
  • Appeal a decision in which we decline your request;
  • Be free from discrimination for exercising any of these rights.

These rights are not absolute. In some cases the law permits or requires us to decline a request — for example, where we must keep a record for tax or accounting purposes, or where fulfilling the request would compromise another person's privacy or an ongoing investigation. If we decline, we will tell you why.

8.2 How to make a request

Email: orders@hoppenly.com

Please tell us what you are asking for and give us enough information to find your record — for example, the date and approximate time of your purchase, the event you attended, and the last four digits of the card used.

You may write to us at Yehl Ventures LLC d/b/a Hoppenly, 221 Green Pasture, Hutto, Texas 78634, United States. Because a postal request is slower and gives us no way to reply to you quickly, email is the fastest and preferred method.

8.3 How we handle a request

We acknowledge requests promptly and respond within forty-five days. Where a request is complex or we receive a number of requests, we may extend that period once by a further forty-five days, and we will tell you before we do.

Before we act, we must be reasonably sure you are who you say you are. We may ask you for information to verify your identity, and we will use anything you give us for that purpose only. If we cannot verify your identity, we will tell you and explain why.

An authorized agent may make a request on your behalf. We will ask the agent for written proof of your authorization and may ask you to confirm it directly with us.

Exercising a privacy right is free. If a request is manifestly unfounded or excessive, or repetitive, we may charge a reasonable fee or decline it, and we will tell you why.

8.4 Appeals and complaints

If we decline your request, you may appeal. Reply to our decision, or write to orders@hoppenly.com with the word "Appeal" in the subject line, within forty-five days. Your appeal will be reviewed by someone who did not make the original decision, and we will give you a written answer, with reasons, within sixty days.

If your appeal is denied, you may submit a complaint to your state Attorney General. Texas residents may contact the Office of the Texas Attorney General, Consumer Protection Division, at texasattorneygeneral.gov. Residents of the European Economic Area and the United Kingdom may complain to their local supervisory authority, as described in Section 11.


9. Notice for California residents

This section applies to California residents and supplements the rest of this Policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").

9.1 Categories of personal information

The table below sets out every statutory category of personal information under the CCPA and states whether the Application collects it. Where we collect a category, it is disclosed to the recipients described in Section 5 — principally Clover, our service providers, our professional advisers, and, where required, government authorities. It is retained for the periods in Section 6, and used for the purposes in Section 4.

CCPA category Collected? What, specifically
A. Identifiers Yes User name, staff identifier, and login; order and payment reference identifiers; device identifiers. A Customer's email address or mobile number where a digital receipt is requested — passed to Clover, not retained by us
B. Customer records information (Cal. Civ. Code § 1798.80(e)) Yes Signature; the name and contact details of Users; the last four digits of a payment card
C. Protected classification characteristics No Not collected
D. Commercial information Yes Items and quantities purchased, prices, discounts, taxes, and totals
E. Biometric information No Not collected. A signature image is not used for identification and is not processed biometrically
F. Internet or other network activity Yes, limited Application diagnostic, crash, and error logs; network connectivity state; IP address of the device
G. Geolocation data Yes The location of the device when a sale is completed, as described in Section 2.5
H. Sensory or surveillance information Yes, limited A signature image. The camera is used transiently to decode barcodes and no image is stored or transmitted. No audio or video is recorded
I. Professional or employment-related information Yes For Users only: role, staff identifier, device assignment, and the sales recorded against them
J. Non-public education information No Not collected
K. Inferences drawn to create a profile No Not collected. We draw no inferences and build no profiles
Sensitive personal information Yes, limited Precise geolocation of company-managed devices, as described in Section 2.5. No other sensitive category is collected

Sources. We collect this information directly from Users operating the Application, directly from Customers at the point of sale, automatically from the company-managed device, and from Clover in the form of payment results.

9.2 Sale and sharing

We do not sell personal information and have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of consumers under sixteen years of age. Because we do neither, we do not offer a "Do Not Sell or Share My Personal Information" link.

9.3 Sensitive personal information

The only sensitive personal information we collect is the precise geolocation of company-managed devices. We use it solely to process card-present payments through Clover, to prevent fraud, to attribute a sale to the correct event, and to secure and manage our own devices. These are purposes permitted under the CCPA for which a business is not required to offer a right to limit. We do not use or disclose sensitive personal information to infer characteristics about any individual.

9.4 Your California rights

California residents have the rights to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation for exercising any of them. Exercise any of these rights as described in Section 8.2. California employees, applicants, and contractors have the same rights with respect to information collected in the employment context.

9.5 Shine the Light

California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for those third parties' direct marketing purposes. We make no such disclosures.


10. Notice for residents of Texas and other U.S. states

This section applies to residents of Texas, and to residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island.

  • Categories of personal data we process, and the purpose: as set out in Sections 2 and 4.
  • Categories we disclose to third parties, and the categories of those third parties: as set out in Sections 5 and 9.1.
  • Your rights, and how to exercise them: as set out in Section 8, including the appeal process in Section 8.4.
  • Sale of personal data: we do not sell personal data. We do not process personal data for targeted advertising or for profiling in furtherance of decisions producing legal or similarly significant effects. Because we do none of these things, no opt-out is required, but you may still contact us at orders@hoppenly.com with any question.
  • Sensitive data: we do not sell sensitive personal data. We do not process sensitive data without a lawful basis, and the only sensitive category we handle is precise geolocation, as described in Sections 2.5 and 9.3.
  • Biometric data: we do not collect, capture, or use biometric identifiers, and we make no disclosure of biometric identifiers. This includes for the purposes of the Texas Capture or Use of Biometric Identifier Act.

11. Notice for individuals in the European Economic Area and United Kingdom

The Application is operated from the United States and is intended for use in the United States. We do not offer goods or services through the Application to individuals in the European Economic Area or the United Kingdom, and we do not monitor their behavior. Where the General Data Protection Regulation or the UK GDPR nonetheless applies to information we handle, the following applies.

  • Controller. Yehl Ventures LLC d/b/a Hoppenly, 221 Green Pasture, Hutto, Texas 78634, United States, is the controller. Contact: orders@hoppenly.com. Clover acts as our processor for payment processing and as an independent controller for its own regulatory and payment-network purposes.
  • Legal bases. We rely on: performance of a contract, to complete a sale and to manage our relationship with our staff; legal obligation, to keep tax, accounting, and employment records and to answer lawful requests; legitimate interests, to run, secure, and improve our business, prevent fraud, protect our property, and account for our sales, having balanced those interests against your rights; and consent, where we ask for it, which you may withdraw at any time without affecting processing already carried out.
  • International transfers. Information is processed in the United States. Where we transfer personal data out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, and on additional safeguards where they are required.
  • Retention. As set out in Section 6.
  • Your rights. Access, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, data portability, and withdrawal of consent. Exercise them as described in Section 8.2.
  • Complaints. You may lodge a complaint with your local data protection supervisory authority, or in the United Kingdom with the Information Commissioner's Office at ico.org.uk. We would ask you to raise the matter with us first at orders@hoppenly.com so that we can try to resolve it.
  • Automated decision-making. We do not carry out automated decision-making that produces legal or similarly significant effects.

12. Our employees, contractors, and field representatives

The Application is a workplace tool. Information about Users is collected and used in the context of their employment or engagement with Hoppenly and is handled in accordance with our internal policies.

Users should understand that Hoppenly-managed devices and the Application may be monitored, audited, logged, and remotely managed to the extent permitted by law, for the purposes of securing company property, preventing fraud and theft, accounting accurately for sales, and meeting our legal obligations. Users should have no expectation of privacy in their use of the Application or of a company-managed device.

Users who are residents of California, Texas, or another state granting privacy rights hold those rights with respect to information collected in the employment context, and may exercise them as described in Section 8.2.


13. Customers who buy from us at an event

Customers interact with the Application only at the point of sale. We use the Application to ring up a sale and take payment. We do not create customer accounts, customer profiles, loyalty records, or marketing lists through the Application, and we do not add anyone to a mailing list as a result of buying from us at an event.

The only information a Customer provides directly is a signature, where a payment requires one, and — if they ask for a digital receipt — an email address or mobile number, which is passed to Clover to send the receipt and is not retained by us.

Card information is handled by Clover, not by us. A Customer with a question about how their payment card information is handled should also review Clover's privacy policy at clover.com/privacy-policy.

Any Customer may contact us at orders@hoppenly.com, to exercise the rights described in Section 8.


14. Children's privacy

The Application is a workplace tool and is not directed to children. Users must be of legal working age.

We do not knowingly collect personal information from children through the Application. We do not ask a Customer their age and we do not knowingly collect personal information from a child under thirteen. If we learn that we have inadvertently collected personal information from a child under thirteen, we will delete it. A parent or guardian who believes we hold information about their child should contact orders@hoppenly.com and we will act promptly.

We do not knowingly sell or share the personal information of any individual under sixteen years of age.


15. Third-party services

  • Clover Network, LLC and its affiliates (a Fiserv company). Provides the Clover Go card reader hardware, the payment software embedded in the Application, payment processing, and digital receipt delivery. Clover handles that information under its own privacy policy at clover.com/privacy-policy. We do not control Clover's practices, and this Policy does not apply to information Clover collects directly.
  • Google. The Application runs on the Android operating system. Google's handling of information on an Android device is governed by Google's own policies.
  • Mobile device management provider. Administers and secures Hoppenly-managed devices under contract with us and may process device information on our behalf.
  • Cloud hosting and business software providers. Store and process our sales and business records on our behalf, under contract, and may not use the information for their own purposes.

The Application contains no third-party advertising software, no analytics software development kit, and no social media tracking software.


16. Where your information is processed

Hoppenly operates from the United States. Information collected through the Application is processed and stored in the United States, where privacy laws may differ from those of your own country. Section 11 describes the safeguards we apply to transfers from the European Economic Area and the United Kingdom.


17. Changes to this Policy

We may update this Policy from time to time to reflect changes to the Application, to our practices, or to the law. The Last updated date at the top of this Policy shows when it was last revised, and we keep the effective date of the current version alongside it.

If we make a material change, we will give notice before it takes effect — to Users through the Application or by ordinary company communication, and to everyone else by posting the revised Policy at the address where you are reading it. Your continued use of the Application after a change takes effect constitutes acknowledgment of the revised Policy.


18. How to contact us

For any question about this Policy or our privacy practices, or to exercise any right described in Section 8:

Email — the fastest and preferred method:
orders@hoppenly.com

Mailing Address:
Yehl Ventures LLC d/b/a Hoppenly
Attn: Privacy
221 Green Pasture
Hutto, Texas 78634
United States

We aim to acknowledge every email promptly and to answer substantively within forty-five days, as described in Section 8.3.