1. Scope & Overview
This Privacy Policy applies to the HPPNIN mobile application (for event attendees), the HPPNIN Host Studio mobile application (for event organizers and door staff), and the website at hppnin.com(collectively, "HPPNIN", "we", "us", or "our").
We are committed to safeguarding your privacy and ensuring your personal data is handled securely, responsibly, and in compliance with applicable Indian data protection laws and the Google Play Developer Distribution Agreement.
2. Personal Data We Collect
We collect only the minimum information necessary to deliver real-time event discovery, ticketing, and social experiences:
- Account & Profile Information: Name, chosen username (@handle), email address, phone number, bio, city, and profile photo when you sign up or edit your profile.
- Location Data (Precise & Coarse): With your permission, we use your device GPS location to show you real-time distance to nearby events, venue drops, and circles in your city. Location is collected when the app is in the foreground and is never tracked passively or sold to advertisers.
- Camera & Biometric Verification:
- Attendee App: Used for optional on-device face gesture liveness verification to establish trusted badges. Raw facial biometric vectors are computed locally via on-device machine learning and are not stored on our cloud servers.
- Host App: Used by event organizers for high-speed camera scanning of attendee QR entry passes at event gates.
- Ticketing & Financial Transactions: When purchasing event passes or receiving host payouts, transactions are processed directly via our RBI-authorized, PCI-DSS certified payment aggregator (Razorpay). HPPNIN stores transaction references (order ID, payment ID, ticket tier, amount paid in INR), but never captures or stores your credit/debit card numbers, CVVs, or UPI PINs.
- Device Identifiers & Push Notifications: Firebase Cloud Messaging (FCM) device push tokens to deliver instant ticket confirmations, gate entry passes, circle updates, and event reminders.
- Media & Storage: Photos you select when creating host event posters or setting your profile avatar.
3. Android Permissions & Why We Need Them
The HPPNIN Android apps request the following runtime permissions strictly for core functionality:
android.permission.ACCESS_FINE_LOCATION&android.permission.ACCESS_COARSE_LOCATION: To calculate precise kilometer distance to events and display local nightlife happening near you.android.permission.CAMERA: To scan digital QR entry passes at event entrances (Host app) and perform on-device identity check gestures (User app).android.permission.POST_NOTIFICATIONS: To deliver real-time drop notifications, RSVP confirmations, and chat alerts.android.permission.READ_MEDIA_IMAGES/READ_EXTERNAL_STORAGE: To allow organizers and attendees to select cover artwork and profile photos from their device gallery.
4. How We Use Your Information
- To authenticate your account via secure 6-digit email OTPs and passwords.
- To issue verifiable, cryptographic QR entry passes and prevent ticket scalping or unauthorized gate access.
- To facilitate discovery of live nightlife drops, circles, and social gatherings in your immediate area.
- To enable hosts to manage guest lists and reconcile ticket revenue in Indian Rupees (₹).
- To protect our community against harassment, fraud, bot creation, and bad actors.
5. Third-Party Service Providers & SDKs
We partner with industry-leading infrastructure providers to operate the service securely:
- Supabase Inc.: Cloud database hosting, row-level security (RLS), and serverless backend functions.
- Razorpay Software Private Limited: RBI-compliant payment gateway for ticket purchases, refunds, and host payouts.
- Google Firebase & Play Services: Push notification delivery (FCM) and Google Maps location indexing.
- Resend / Nodemailer: Delivery of authentication codes and transactional receipts.
We do not sell, rent, or trade your personal information to third-party data brokers or marketing agencies.
6. Data Retention & Security
All communications between the mobile apps and our backend are encrypted in transit using industry-standard TLS 1.3 encryption. Passwords and sensitive authentication tokens are hashed using cryptographic algorithms (bcrypt).
We retain account information for as long as your account is active. Transaction records and order invoices are retained as required by Indian financial and tax compliance regulations.
7. Account Deletion & Data Rights (Google Play Compliance)
You have full control over your personal data. You may request permanent deletion of your account and all associated personal data at any time through either of the following methods:
- In-App Self Service: Open the HPPNIN app → Navigate to Profile → Settings → Tap "Delete Account" and confirm.
- Email Request: Send an email from your registered address to hppninapp@gmail.com with the subject "Account Deletion Request".
Upon receipt of a deletion request, your profile, authentication credentials, active tickets, and chat associations will be permanently purged within 30 days, subject only to mandatory legal and financial accounting retention.
8. Children's Privacy
HPPNIN is designed for nightlife, social drops, and ticketed events, and is strictly intended for individuals aged 18 and older. We do not knowingly collect personal information from minors under the age of 18. If we discover that a minor has created an account, we will promptly delete their data.
9. Changes to this Policy
We may update this Privacy Policy periodically to reflect app updates, new regulatory requirements, or security enhancements. Any material changes will be reflected with an updated "Last updated" date and in-app notice where appropriate.
10. Grievance Officer & Contact Information
If you have any questions, concerns, or grievances regarding our privacy practices or data handling, please contact our support team at:
Email: hppninapp@gmail.com
Platform: HPPNIN Inc. · Bengaluru / Manipal, India
Website: https://hppnin.com