Privacy Policy

Privacy Policy

Effective Date: July 9, 2026  ·  Hopscotch is developed by Acorn Designs, LLC. We believe your data is yours. The app is designed to keep your information private and secure. Choose your platform below to read the policy that applies to you.

This policy applies to Hopscotch on iOS and the Hopscotch Apple Watch companion app.

Information Stored on Your Device

When you use Hopscotch, the following information is stored locally on your device using Apple's SwiftData framework:

  • Card information: Store names, barcode numbers, barcode types, and any notes you add
  • Data cards (typed card details): For cards where you store typed details instead of a barcode, the custom field labels and values you enter — which may include membership, insurance, or prescription numbers
  • Category: The category label you assign to each card (e.g., "Coffee," "Gym")
  • Location data: The coordinates and radius you set for each card's geofence
  • Reference photos (optional): If you attach a photo to a card — either from your camera or your photo library — the image is stored locally on your device in the app's sandbox. All location and metadata (EXIF/GPS) is automatically stripped before saving. Photos never leave your device.
  • App settings: Your preferences for how the app behaves

We do not have access to this information. It never leaves your device except in the specific circumstances described below — generating a wallet pass, refreshing your passes and Apple Watch complication, and a one-time app-integrity check.

How Your Information Is Used

Camera and Photos

The camera is used for two purposes:

  • Barcode scanning: The app extracts the barcode number and type in real time — no image is saved or transmitted.
  • Reference photos (optional): You can choose to capture a photo of a card with your camera, or attach one from your photo library, so the card is easier to recognize in your deck. Any photo you attach is stored only on your device in the app's sandbox, with all location and other metadata (EXIF/GPS) automatically stripped before saving. Photos are never transmitted off your device.

Apple's privacy framework classifies camera access as "collected" for transparency purposes. In practice, no camera-captured data or photo data leaves your device.

Location

Hopscotch uses precise location for geofencing:

  • When you set a location for a card, iOS monitors when you enter that area and triggers a local notification. This processing happens entirely on your device — Hopscotch never receives or logs your real-time location.
  • Location coordinates you have set for a card are transmitted off-device only if you later choose to add that card to Apple Wallet (see Wallet Pass Generation below).

Hopscotch requests "Always" (background) location access so it can monitor your saved locations and surface the right card even when the app isn't open. This monitoring happens on your device; your real-time location is never sent to or logged by our servers.

Apple's privacy framework classifies precise location access as "collected" for transparency purposes. Your real-time GPS position is never transmitted to us or stored anywhere outside your device.

You control location permissions in iOS Settings. Geofencing requires location access to function.

Apple Watch Sync

If you use the Hopscotch Apple Watch companion app, your card data syncs between your iPhone and your Watch using Apple's WatchConnectivity framework. This is a direct, encrypted, peer-to-peer connection between your own devices — no server is involved, and no data is sent to us. The Watch receives only the card data already stored on your iPhone; no new data is generated or collected in the process.

Wallet Pass Generation

When you explicitly tap "Add to Apple Wallet" on a card, the following data is sent over HTTPS to our pass generation server (hosted on Vercel at hopscotch-pass-server.vercel.app):

  • A randomly generated, per-card UUID (not linked to your identity or device)
  • Card name (as you typed it)
  • Barcode number and format
  • Card color
  • Category (as you set it)
  • Location coordinates and radius (only if the card has a saved geofence location)
  • For data cards (cards where you store typed details instead of a barcode), the custom field labels and values you entered — which may include membership, insurance, or prescription numbers — so they can be printed on the pass

Our server uses this information solely to generate and digitally sign a .pkpass file, which is returned to your device. We do not store this data. It is processed in real-time and discarded immediately after the pass is returned.

As is standard with any web hosting service, Vercel may collect server access logs including IP addresses and timestamps. These logs are controlled by Vercel under their own data retention policies. See Vercel's Privacy Policy for details.

App Integrity (App Attest)

To protect our pass generation server from abuse, Hopscotch uses Apple's App Attest. The first time your device contacts the server, it generates a cryptographic attestation key and registers that key's public identifier with us. We retain this identifier to verify that future requests come from an unmodified copy of the app. It is a random, per-installation value that cannot be reversed to identify you or your device, is not linked to your identity, your cards, or their contents, and cannot be used to correlate you across other apps or websites. If you reinstall the app, a new value is generated. We store only the public half of the key; the private key never leaves your device's secure hardware.

Notifications and Pass Updates

Geofence notifications are generated entirely on your device and no notification content is sent to any server. Separately, to refresh your Apple Wallet passes and Apple Watch complication when you approach a saved location, the app registers a push token with our server and includes the random card identifiers involved. These are used to send a single push and are not stored; no card names, barcode values, or field contents are included.

Platform Analytics (Aggregate)

Apple App Store Connect provides anonymized aggregate analytics to developers — installs, sessions, active devices, retention curves, country/metro distribution, crashes. These are shared with us only if you have opted in via iOS Settings → Privacy & Security → Analytics & Improvements → Share with App Developers. We see aggregate numbers only; we cannot identify individual users or devices. This data is collected and anonymized by Apple under their own privacy policy.

Website Forms (Early Access and Product Survey)

This section applies if you use the optional forms on hopscotch.city — the early-access email signup or the one-question product survey on the "For businesses" page. These are website features and are separate from the app.

Early-Access Email Signup

When you submit your email address on the website, the following is sent over HTTPS to a Cloudflare Pages Function and stored in a Cloudflare D1 (SQLite) database operated by Acorn Designs, LLC:

  • Email address (as you typed it)
  • Source tag: which form you used (e.g., the business notify on the homepage or the For Businesses page) and the platform we detected from your browser (iPhone, Android, or unknown)
  • Timestamp

We use your email address solely to notify you when Hopscotch for businesses is coming to your city. We do not sell, share, or trade it, and we do not enroll you in any marketing lists.

Product Survey

When you submit a vote in the "If you ran a rewards program, how would you want customers to redeem rewards?" survey, the following is sent over HTTPS to the same Cloudflare Pages Function:

  • Your vote choice (one of five options)
  • Timestamp

Survey votes are stored in a separate database table from email addresses, and the two are never linked. Votes are fully anonymous. We use survey results in aggregate to prioritize what we build first.

Retention and Deletion

  • Email addresses: retained until you request deletion, or up to 18 months from collection — whichever comes first.
  • Survey votes: retained indefinitely as anonymous aggregate counts; not tied to any individual.

To remove your email from the early-access list, email hello@hopscotch.city with the subject "Delete my data" and we'll remove it within 7 days.

Cloudflare Infrastructure

The Cloudflare Pages Function and D1 database run on Cloudflare's infrastructure. Cloudflare may collect server access logs (IP addresses, timestamps) under their own retention policies. See Cloudflare's Privacy Policy.

Information the App Does Not Collect

Aside from the optional website forms described above, Hopscotch does not collect:

  • No user accounts: The app does not require registration, login, or authentication
  • No analytics or tracking: We do not use analytics SDKs, advertising networks, Firebase, Crashlytics, Sentry, Mixpanel, or any other third-party behavioral tracking service. The app runs with zero external code dependencies — no analytics SDK of any kind
  • No crash reports sent to us: The app does not use a crash reporting SDK. Any crash data collected by Apple's platform-level reporting (only if you've enabled "Share with App Developers" in iOS Settings) is governed by Apple's policies and surfaced only as aggregate data in App Store Connect
  • No personal information: We do not collect your name, email address, phone number, or any other personally identifying information
  • No browsing or usage patterns: We do not track how you use the app
  • No location history: Geofence processing happens on-device; we never receive or log your real-time location
  • NSPrivacyTracking: false — the app performs no cross-app or cross-site tracking

External Links

The app's Settings screen contains links that open in your browser or mail client: a support page, this privacy policy, and a voluntary "Buy Me a Coffee" tip link. Tapping these hands off to Safari or Mail. We do not collect any data from these interactions.

Data Storage and Security

  • Local storage: All card and location data is stored on your device using Apple's SwiftData framework
  • No cloud sync from Hopscotch: The app does not actively sync data to iCloud or any cloud service. (If you have iCloud Backup enabled on your device, Hopscotch's local data is included in your encrypted device backup by default — managed and encrypted by Apple. We never see it.)
  • Server communication: The only outbound server call occurs when generating a wallet pass. All connections use HTTPS
  • Device security: Your data is protected by your device's passcode, biometric authentication, or screen lock

Third-Party Services

The app uses the following external services:

  • Vercel (pass generation server): When you add a card to Apple Wallet, your card data is sent to a Vercel-hosted server to generate the pass. Vercel may collect server access logs (IP addresses, timestamps). See Vercel's Privacy Policy.
  • Cloudflare Pages (website hosting): Our website hopscotch.city is hosted on Cloudflare Pages. Cloudflare provides aggregate web analytics — page views, country/region, referrers — which we view in their dashboard. No cookies, no fingerprints, no per-user identifiers. See Cloudflare's Privacy Policy.

We do not use any advertising networks, analytics platforms, or other third-party tracking services.

Children's Privacy

Hopscotch does not collect personal information from any user, regardless of age. Because we do not collect, store, or process personal information, COPPA and similar children's privacy laws do not apply — there is no personal data to govern. If you have questions, contact us at hello@hopscotch.city.

Your Rights

Because all data is stored locally on your device:

  • Access: You can view all your data within the app at any time
  • Delete: You can delete individual cards, or delete all data by uninstalling the app
  • Export: There is currently no export feature (may be added in future versions)

If you have questions about data processed through our wallet pass server, contact us at hello@hopscotch.city.

Changes to This Policy

We may update this privacy policy from time to time. If we make significant changes, we will update the effective date at the top of this document and may display a notice within the app.

Data Retention

  • On your device: Data persists until you delete individual cards or uninstall the app
  • On our wallet pass server: We retain only an anonymous App Attest key identifier — a random, per-installation anti-fraud token that cannot be reversed to identify you or your device, is not linked to your identity, your cards, or their contents, and cannot be used to correlate you across other apps or websites (see App Integrity above). It is used solely to confirm requests come from a genuine copy of the app. No card data, pass contents, location, or push token is ever stored — pass generation and push requests are processed in real time and discarded
  • Early-access email addresses (website): Retained until you request deletion, or up to 18 months from collection — whichever comes first
  • Survey votes (website): Retained indefinitely as anonymous aggregate counts; not linked to any individual

European Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following applies:

Legal basis for processing. When you generate a wallet pass, we process your card data based on your explicit request (performance of a contract — you initiated the action). Because we do not retain that data, there is no ongoing processing to govern. When you submit your email address to the early-access list on hopscotch.city, we process it based on your consent (Article 6(1)(a) GDPR); you may withdraw consent at any time by emailing us. Survey votes are stored without any identifier and are not personal data under GDPR.

Data transfers. Our wallet pass server is hosted on Vercel, which may process data in the United States and other regions. Vercel complies with GDPR data transfer requirements via Standard Contractual Clauses.

Your rights under GDPR. In addition to the rights listed above, you have the right to:

  • Restriction of processing: Request that we limit how your data is used
  • Data portability: Receive your data in a portable format (all data is already on your device)
  • Object to processing: Object to data processing based on legitimate interest
  • Lodge a complaint: File a complaint with your local data protection authority

Aside from email addresses submitted to our early-access list, we do not retain personal data on our servers. Most data subject requests are fulfilled by the fact that all your app data is on your device and under your control. To exercise any rights — including requesting deletion of your email address from the early-access list — contact us at hello@hopscotch.city.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the following applies:

Categories of personal information collected. When you generate a wallet pass, your card data (name, barcode, format, color, category, a random UUID, and optionally coordinates) is transmitted to our pass server and immediately discarded — it is not stored or retained by us. When you submit your email address to our early-access list on hopscotch.city, we collect and retain your email address along with the form source and a timestamp (see "Website Forms" above).

Sale or sharing of personal information. We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

Your rights. You have the right to know what personal information is collected, to request deletion, and to opt out of sale or sharing. To request deletion of your email address from the early-access list, see "Retention and Deletion" above. Card data is stored entirely on your device and under your control.

To submit a request, contact us at hello@hopscotch.city.

International Users

The app is developed and operated in the United States. The wallet pass server is hosted on Vercel's infrastructure, and the website (hopscotch.city) plus its early-access and survey backend run on Cloudflare's global network. Both providers may process data in various regions. By using the app or website, you acknowledge that data may be transferred to and processed in the United States.

Contact

If you have questions about this privacy policy or how Hopscotch handles your information:

Acorn Designs, LLC
Email: hello@hopscotch.city

Summary

  • Your cards and locations are stored only on your device
  • We use your location only for geofencing, processed entirely on your device
  • We use your camera only to scan barcodes — no images saved or transmitted
  • Apple Watch sync is direct, device-to-device — no server involved
  • We send card data to our server only when you explicitly tap "Add to Apple Wallet," and we don't store it
  • The app uses no analytics, advertising networks, or tracking SDKs
  • On the website, if you submit your email or vote in the survey, those go to our Cloudflare D1 database. Email and votes are never linked; votes are anonymous. You can request email deletion anytime.
  • We don't sell, share, or trade your data
  • You can delete all your data by deleting the app

This app is built to be private by design.