Privacy Policy

1. Introduction

This Privacy Policy describes how HopToDesk and Begonia Holdings LLC ("Company," "we," "us," or "our") handle information in connection with the HopToDesk software, website, and related services (collectively, the "Service"). Privacy is a core principle of HopToDesk, and we are committed to collecting as little information as possible. By using the Service, you agree to the practices described in this Policy.

The Service consists of three parts. What we collect differs between them, and where a section of this Policy applies to only one part, it is identified:

  • The Website, our public marketing site at www.hoptodesk.com.
  • The App, the HopToDesk remote desktop software you install on a device.
  • The Dashboard, our optional account and device-management web application at dashboard.hoptodesk.com.

Neither the Website nor the App requires an account. The Dashboard is optional, and the device information described in Section 2 is collected only for devices you enroll in it.

This Policy should be read together with our Terms of Service and End User License Agreement.

2. Information We Collect

HopToDesk is designed so that you can use the remote desktop software without providing personally identifiable information. Connection identifiers are generated automatically to route sessions between devices. If you choose to create an optional account or contact us for support, we collect only the information you voluntarily provide, such as your email address.

When you visit the Website

We collect the following when you visit www.hoptodesk.com:

  • Aggregate usage statistics. Daily totals of page views, referring sites and file downloads. These are counts only and are not associated with an individual visitor.
  • A daily visitor identifier. Used to estimate the number of unique visitors. It is generated as a one-way hash of the date, your IP address and your browser user agent, and is regenerated each day, so it cannot be used to recognize you on a later visit.
  • Error records. Where a request to the Website returns an error, we record the requested path, the response status, the referring page, your browser user agent and your IP address, in order to diagnose and resolve technical faults. These records are retained for 90 days.

We do not set advertising cookies on the Website and we do not track your browsing across other websites.

When you use the App

The App generates a connection identifier so that sessions can be routed between devices. Unless you link the App to a Dashboard account, it does not send us information about your device.

We do not collect, store or have access to the content of your remote sessions. The video stream, keystrokes, chat messages and file transfers exchanged during a session are transmitted directly between the connected devices using end-to-end encryption.

The App stores diagnostic logs locally on the device it runs on and retains them for 31 days. These logs are not transmitted to us, and the App does not include crash reporting.

When you use the Dashboard

If you create a Dashboard account, we collect the following. Information about a device is collected only for devices you choose to enroll.

  • Account information. Your email address, your name or username, and your organization name.
  • Device information. For each device you enroll, its device identifier, operating system type and version, computer name, IP and MAC address, hardware details such as processor, memory and storage, and time zone.
  • Device health information. For devices you manage, processor, memory and disk usage, uptime and battery level, used to report device status in the Dashboard.
  • Usage information. Connection timestamps and duration, and feature usage statistics.
  • Payment information. For paid plans, your billing country and the card brand and last four digits provided to us by our payment processor. We do not receive or store full card numbers.

If you use the Dashboard to manage a device, an administrator of that device's account can request recent service log entries from it. Such requests are recorded in the account's activity history.

3. End-to-End Encryption (the App)

Connections between devices are end-to-end encrypted by default. We cannot view, monitor, or record the contents of your remote sessions, including your screen, files, keystrokes, chat messages, or transferred data. We make no distinction between personal and business use, and we do not monitor user activity.

4. Cookies and Tracking

The Website does not set advertising cookies and does not track your browsing across other websites. The App does not use cookies.

The Dashboard uses cookies and analytics so that we can operate the application, keep you signed in, understand how it is used, and measure our own advertising:

  • Product analytics and session replay. We use Fullstory to understand how users interact with the Dashboard and with the pricing and get-started pages on our website, such as pages viewed, clicks, and navigation, and JavaScript errors, so that we can diagnose issues and improve the product. Password fields are not captured.
  • Advertising measurement. We use conversion tracking from Reddit Ads to measure the performance of our advertising. For accounts created from one of our Reddit ads, Reddit receives its own click identifier and a hashed email address at sign-up and at purchase, plus a hashed IP address and the browser type at sign-up and the order amount at purchase, to attribute both to the ad. We do not sell your personal information and we do not allow it to be used for unrelated third-party advertising.
  • Payments and email. Optional paid plans are handled by our third-party payment provider, and account and support messages are delivered through our third-party email provider.

You can limit this collection through your browser's privacy settings.

The Service may also contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their policies.

5. How We Use Information

Any information you voluntarily provide is used to operate and maintain the Service, respond to your inquiries, manage optional account or billing functions where applicable, and, as described in Section 4, understand and improve the Dashboard and measure our own advertising. Other than measuring the performance of our own advertising, we do not use your information for third-party advertising or profiling, and we do not sell it.

We use information to:

  • Provide and maintain the Service
  • Facilitate connections between devices
  • Improve and optimize the Service
  • Detect, prevent, and address technical issues
  • Provide customer support
  • Send important notices and updates
  • Comply with legal obligations

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We share it only in the following circumstances:

  • With IT professionals (the Dashboard). When you accept an invitation to have your device managed, basic device information may be shared with the IT professional who manages it.
  • Service providers. We may share limited information with trusted third-party providers who help us operate the Service, such as payment processors for optional paid features, and only to the extent necessary.
  • Legal requirements. We may disclose information where required by law, in response to valid legal requests, or to protect our legal rights.
  • Business transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred.
  • AI processing (the Dashboard). We use Anthropic as a processor for four purposes. Order details and the fraud signals described in Section 12 are sent for automated risk scoring when an order is placed on a paid plan. The application name, branding text and icon submitted for a custom build are sent so the build can be screened against our Terms of Service before it is produced. The photo, display name and organization name uploaded for Technician Identity are sent so the photo can be screened before it can appear on a connection prompt. The content of an account's support tickets is sent only where that account has enabled the optional AI Assistant or ticket triage, both of which are disabled by default. None of this data is used to train third-party models.

7. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • End-to-end encryption for remote sessions
  • Secure data transmission protocols
  • A documented register of security decisions and accepted exceptions, reviewed at least annually
  • Access controls and authentication

However, no method of transmission over the Internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. Details of our hosting, encryption, and sub-processors are published on our Trust and Security page.

8. Data Retention

We retain information only for as long as necessary to provide the Service and to meet our legal obligations. You can delete your account and the information you provided with it from your account settings in the Dashboard, or by contacting us.

The retention periods that follow apply to the Dashboard. If you create an account and never confirm your email address, we delete that account 30 days after it is created. Limited security records are kept separately so that we can detect abuse: sign-in and invitation attempts for 90 days, and a log of the emails we sent for 180 days.

9. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • The right to access your personal data
  • The right to rectify inaccurate data
  • The right to erasure, also known as the right to be forgotten
  • The right to restrict processing
  • The right to data portability
  • The right to object to processing

To exercise any of these rights, please contact us through our contact form.

10. Children's Privacy

The Service is not directed to children under the age of 13, or the minimum age required in your jurisdiction, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us so we can remove it.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where the primary database for the United States data region is located. Dashboard accounts created in the European Union data region keep their account, device, ticket, and configuration data, including file storage and backups, only on infrastructure under European Union jurisdiction; support access, checkout payments, and optional AI features may still involve processing in the United States. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical and organizational measures. A copy of the relevant safeguards can be requested through our contact form.

12. Additional Information for EEA, UK, and Swiss Users (GDPR)

Controller and processor roles. For personal data of dashboard account holders and website visitors, Begonia Holdings LLC is the data controller. Where a business customer uses the Service to manage its own devices, technicians, and end users, that customer is the controller of the data it puts into the Service and HopToDesk acts as its processor. We offer a Data Processing Agreement under Article 28 GDPR, including the Standard Contractual Clauses, to every business customer on any plan, including the free plan. It is published at hoptodesk.com/dpa and applies where we act as your processor, with no need to request or sign a separate copy.

Legal bases. We process personal data on the following legal bases: performance of a contract (Article 6(1)(b), providing the Service you signed up for); our legitimate interests (Article 6(1)(f), securing the Service, preventing fraud and abuse, and improving the product); your consent (Article 6(1)(a), where required, for example for certain analytics or marketing, which you may withdraw at any time); and compliance with legal obligations (Article 6(1)(c)).

Your GDPR rights. In addition to the rights listed in Section 9, you have the right to withdraw consent at any time, without affecting processing carried out before withdrawal, and the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of an alleged infringement. We ask that you contact us first through our contact form so we can try to resolve your concern directly.

Automated decision-making. This applies to the Dashboard only. When an order is placed on a paid plan, we score it automatically for fraud risk. The score combines deterministic signals, such as a mismatch between the billing and connection country, the age of the account and any previous fraud flags, with an assessment by an AI model where those signals are inconclusive. A high score can temporarily block further checkout attempts from the same address and email for 24 hours. The score alone never cancels an existing subscription or issues a refund, and any suspension or termination of an account is decided by a person. Custom builds and Technician Identity photos are screened in a comparable way. A photo that passes that screening is approved automatically, and a build or photo flagged by it is held for manual review rather than being refused automatically. If an automated block affects you, contact us through our contact form and we will review it manually. We do not otherwise make decisions about you based solely on automated processing.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be published on our website and are effective upon posting. Your continued use of the Service after any changes indicates your acceptance of the updated Policy.

14. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us through our contact form.