hoocard← Back to Hoocard

THE DETAILS MATTER.

Privacy Policy

Last updated September 16, 2026 · Preview edition

What we collect

When you create an email account, we store your email, a salted password hash (not your readable password), an account identifier, and the creation time. We store hashed session and password-reset tokens with expiration times, and short-lived hashed identifiers used to limit sign-in attempts. Your sign-in email is private unless you add it to your public profile. Existing ChatGPT sign-in accounts use a stable identifier and email supplied by the hosting platform; adding a password from that signed-in account preserves profile ownership.

If you save a profile, we store the name, graduation year, chosen profile link, headline, biography, optional public email and links, publication setting, and update time that you submit. If you upload a résumé, we store the PDF, its filename, and its association with your profile.

How your information is used

We use these details to display your site, protect editing access, serve your selected résumé, and keep the same profile link when your information changes. We do not sell profile information or use it for advertising. Employer logos on the landing page do not mean that employers receive your information from us.

What others can see

A draft profile and its résumé are available only to the account that owns them. Selecting “Publish my site” makes your chosen profile details and résumé available to anyone with your profile link. Published profiles and résumés can be viewed and downloaded without signing in.

Only publish information you intend to share professionally. The Save contact action generates a contact file containing your chosen name, headline, class year, public email, and profile links. Visitors choose whether to import it into their own contacts. People can copy or download information you publish; unpublishing or deletion cannot remove copies already held by others. Profile links are identifiers, not passwords.

Service providers

Vercel serves the public website and forwards account and file requests to the existing backend. OpenAI Sites provides the backend and the original ChatGPT sign-in, and its Cloudflare-backed database and object storage store profile records and PDF files. Providers may process IP addresses, browser information, request times, and service logs for delivery, security, and maintenance. Their own account and infrastructure records are governed by their privacy terms.

Password reset emails are not yet connected in this preview. Once configured, Resend will process your email address and reset message to deliver the requested link. Reset links expire after 30 minutes and become unusable after a successful reset.

Payment and pickup records

Checkout is currently disabled. When enabled, Stripe will process payments on its hosted checkout page. Hoocard will store the selected pickup point, card design, quantity, profile link, payment status, Stripe transaction identifiers, totals, and the email and phone supplied at checkout. These contact details are private and used to coordinate pickup and order support; they are not added to your public profile. We do not store card numbers. Order records are retained as needed for fulfillment, accounting, refunds, and legal obligations. Card links associated with order records must remain reserved to their original owner to prevent someone else from taking over a printed card’s destination.

Retention and deletion

Saved profile information and the current résumé are retained until you remove them using My Hoocard. Replacing a résumé removes the previous stored file after the replacement is saved successfully. You may unpublish a profile, remove its résumé, or delete the profile and résumé entirely. Provider backups and operational logs may remain subject to provider retention schedules. A deleted profile link that is not associated with an order may eventually become available again.

Cookies and analytics

The application does not include advertising pixels or third-party marketing analytics. Hoocard uses an essential, HttpOnly session cookie that expires after 30 days. Signing out revokes the current session; resetting your password invalidates all earlier password sessions. The hosting platform may also use essential authentication and security cookies. Card-builder drafts are stored temporarily in this browser tab’s session storage so they can survive sign-in. They are not customer orders. Saving a page stores your profile in the account database. Closing the tab clears its temporary session draft; a successfully saved draft is also removed from session storage. Assets are served with this site rather than loaded from third-party logo services.

Your choices

Use My Hoocard to access and correct your details, replace or remove your résumé, unpublish your site, or delete your profile. You choose whether to provide optional public contact information. Deleting a profile does not delete its email account. For email-account deletion, contact Jivrajnarula@gmail.com. For the original ChatGPT account or provider-held records, use the hosting provider’s privacy channels.

Children

Hoocard is intended for college students and is not directed to children under 13. Do not create a profile if you are under 13.

Contact and launch details

This is a public prelaunch preview. For privacy requests that cannot be completed in My Hoocard, email Jivrajnarula@gmail.com. The operating business must provide a verified legal identity and privacy contact, finalize retention and rights procedures, and review these terms before a public commercial launch.

Back to Hoocard

Complimentary card orders

When you redeem a temporary promo code, we store your card selection, pickup location, private account email, order reference, and a snapshot of your submitted profile for preparation. With your explicit consent, your page and uploaded résumé become public at your profile link. Order records are separate from your editable profile. Contact Jivrajnarula@gmail.com about order information or pickup updates.