Last updated: October 2, 2026
This Privacy Policy explains how HoverReel LLC ("HoverReel," "we," "us," or "our") collects, uses, and shares information in connection with the HoverReel service — the HoverReel dashboard (where a business, which we call a "Merchant," manages video content) and the HoverReel embeddable video widget (which a Merchant places on their own website, and which is viewed by that Merchant's own visitors, which we call "Shoppers").
This policy covers two different groups of people, and what we collect differs meaningfully between them:
- Merchants — the businesses who sign up for a HoverReel account, log into the dashboard, and configure video content.
- Shoppers — the anonymous visitors who see a HoverReel-powered video widget on a Merchant's own website. Shoppers never create a HoverReel account and never interact with HoverReel directly — the widget runs on the Merchant's own site.
It also covers visitors to our own website, hoverreel.com (including people who apply for the beta), described in Section 1.4.
If you are a Shopper and have questions about a specific video widget you saw, the Merchant who placed it on their site is the right first point of contact — HoverReel is the technology behind it, not the storefront itself.
1. Information We Collect
1.1 Information Merchants provide directly
When a Merchant's account is created (currently by HoverReel directly, not via public self-signup) and used, we collect:
- Account information: name, email address, and a password (we never store your password itself — only a salted, one-way cryptographic hash of it, using
scrypt). - Content you upload or link: video files or video URLs, product and action information (titles, prices, descriptions, images, destination links), playlists, Player/widget configuration (colors, layout choices, branding), and any custom thumbnail images you upload or capture.
- Brand/appearance settings: logo, color scheme, font choices, and similar customization you configure for your embedded widgets.
- Domain configuration: the list of website domains you authorize your embed to run on.
1.2 Information collected automatically from Merchants
- Session data: a session cookie that keeps you logged into the dashboard. This cookie is essential to the service and is not used for advertising or cross-site tracking.
- Login timestamps: when you last logged in, for our own account- health monitoring.
- Usage/operational data: which dashboard actions you take (e.g. adding a video, creating a Player, publishing an embed) is logged internally so we — and, in a limited read-only summary form, you — can see recent account activity.
1.3 Information collected automatically from Shoppers (via the embedded widget)
The HoverReel widget, once a Merchant places it on their own site, is publicly reachable by anyone who visits that page — it requires no login and does not know a Shopper's real-world identity. It collects the following, entirely to power the Merchant's own analytics about how their video content performs:
- View/engagement events: impressions (a video was shown), views (a video was actually watched for a meaningful amount of time), clicks (on a product/action call-to-action), likes, add-to-cart attempts and their success/failure, and watch-time/completion signals (e.g. reaching 25%/50%/75%/90% of a video).
- A randomly generated, anonymous visitor identifier, stored in the Shopper's own browser (
localStorage/sessionStorage) on the Merchant's domain. This identifier is not derived from and is not linked to any real name, email, or other directly-identifying information we hold — its only purpose is to avoid counting the same visitor's repeat view of the same video multiple times within one browsing session, and to remember (permanently, in that browser) that a "like" was already given so it can't be repeated. - Page context: the page URL and referring page, both reduced to origin + path only — any query string (which can carry things like search terms, order IDs, or email addresses embedded by the Merchant's own site) is deliberately stripped before it is ever stored.
- Device type: a coarse category (e.g. desktop vs. mobile), derived from the browser's own user-agent string.
- IP address, used only transiently to enforce rate limits that protect the service from abuse (e.g. scripted flooding of fake analytics events) — it is not stored as a persistent field tied to analytics events.
We do not collect a Shopper's name, email address, physical address, payment information, or any other directly-identifying information through the widget itself. We have no way to connect a Shopper's anonymous visitor identifier to a real person's identity.
1.4 Information collected on our website, hoverreel.com
Our marketing website is separate from the dashboard and the widget.
- Website analytics (Google Analytics 4): which pages are viewed, how visitors arrived (the referring site, search engine, or a tagged link from one of our posts or emails), approximate location (city/ country level), device and browser type, and on-site actions like clicking "Apply for Beta Access". This is on unless you click Deny in our cookie banner or turn it off later under "Manage consent". Google's advertising features are turned off. Google states that Google Analytics 4 does not log or store IP addresses.
- Search data (Google Search Console): aggregate reports of which Google searches showed our pages. This contains no information about individual visitors.
- Where you came from: a small script on our site remembers, for your current browser tab only, the campaign tags on the link you arrived by, your landing page and the referring website's domain, and adds them to the beta application link if you click it.
- Beta applications: if you apply for the beta, our application form (hosted by Tally) collects what you enter, such as your name, email address, business and website, plus the "where you came from" details above. We use it only to evaluate and respond to your application.
1.5 What we do NOT collect
- We do not collect payment card numbers or bank information — the HoverReel service does not currently process payments from Merchants or Shoppers. Where a Shopper completes a real purchase (through a Merchant's own Shopify "Add to Cart" flow), that transaction happens directly between the Shopper's browser and the Merchant's own Shopify store — HoverReel's servers are never in that data path and never see payment details, shipping addresses, or order contents.
- We do not knowingly collect information from children under 13 (see Section 8).
2. How We Use Information
We use the information described above to:
- Operate, maintain, and improve the HoverReel dashboard and widget.
- Authenticate Merchants and keep dashboard sessions secure.
- Generate the analytics (views, click-through, completion rate, etc.) a Merchant sees about their own video content's performance.
- Detect and prevent abuse, fraud, and rate-limit violations.
- Provide customer support and respond to inquiries.
- Understand how people find and use hoverreel.com, which of our posts, articles and emails are useful, and respond to beta applications (Section 1.4).
- Send operational communications about the service (e.g. account or security notices). We do not use Merchant or Shopper data to send third-party marketing or sell it to advertisers.
3. Cookies and Similar Technologies
- HoverReel dashboard (Merchant-facing) sets one essential session cookie, marked
httpOnlyandSameSite=Lax, so it cannot be read by page scripts and is not sent on most cross-site requests. This cookie is required for the dashboard to function and is not an advertising or analytics cookie. - HoverReel widget (Shopper-facing) uses browser
localStorage/sessionStorage— not cookies — to avoid double-counting a view within one session and to remember a "like" permanently in that browser. This storage is scoped to the Merchant's own domain (where the widget script runs), contains only the anonymous identifiers described in Section 1.3, and is never used to track a Shopper across unrelated, unaffiliated websites. - Our website, hoverreel.com, uses Google Analytics cookies (unless you click Deny in our cookie banner), our consent tool's own cookies that remember your choice, and one session-only storage item that remembers which link brought you there. See Section 1.4 and our Cookies Policy.
- We do not use third-party advertising cookies or trackers anywhere, and we use no third-party analytics in the HoverReel dashboard or the widget.
For the exact, current list of every cookie and browser-storage item we use, what each one is named, how long it lasts, and why it exists, see our Cookies Policy.
4. How We Share Information
We do not sell Merchant or Shopper information. We share information only as follows:
- Service providers (subprocessors) who help us operate the service, under obligations to protect the data and use it only to provide their service to us:
- Bunny.net — video hosting, transcoding, and content-delivery (CDN) for uploaded video files.
- Railway — application hosting infrastructure for the HoverReel dashboard and API.
- GitHub — stores automated, encrypted-at-rest database backups (not publicly accessible).
- Google (Google Analytics and Search Console) — website analytics for hoverreel.com only.
- Tally — hosts our beta application form.
- Resend — sends our service emails to Merchants (for example password resets, new sign-in alerts and the weekly summary).
- A Merchant's own Shopify store, only in the specific case where a Shopper clicks "Add to Cart" on a Shopify-connected product — that request is made directly from the Shopper's own browser to the Merchant's Shopify domain and never passes through HoverReel's servers.
- Legal requirements: if required by law, valid legal process, or to protect the rights, property, or safety of HoverReel, our users, or others.
- Business transfers: if HoverReel is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy with comparable protections.
5. Data Retention
- Merchant account and content data is retained for as long as the account is active, and for a reasonable period after closure to allow recovery of an accidentally-deleted account, after which it is deleted.
- Analytics events (Shopper view/click/watch data) are retained to power historical reporting for the Merchant; we may reduce, sample, or aggregate older raw event data over time.
- Temporary, shareable assets (e.g. an image generated when a Shopper uses a "share" feature) are automatically deleted after a short retention window (currently 7 days).
- Backups are retained on a rolling basis and pruned automatically.
- Website analytics (Google Analytics) are retained for 14 months.
- Beta applications are kept while we evaluate and onboard applicants; you can ask us to delete yours at any time.
6. Data Security
We use industry-standard practices to protect information, including: encrypted transport (HTTPS/TLS) for all traffic, salted one-way password hashing (never storing plaintext passwords), signed and time-limited video playback URLs, rate limiting on public endpoints, and a restrictive Content Security Policy on the dashboard. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your Rights and Choices
- Merchants can request access to, correction of, or deletion of their account and content by contacting us at [email protected].
- Shoppers, because the widget does not know their real identity, cannot be individually identified from an analytics event alone — a Shopper who wants their browsing on a specific site not tracked by the widget can clear that browser's
localStorage/sessionStoragefor that site, or use browser settings/extensions that block third-party scripts. - Website visitors can click Deny in our cookie banner, change their choice anytime under "Manage consent", block cookies in their browser, or use Google's opt-out browser add-on.
- Depending on where you live, you may have additional rights under laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA), including the right to access, correct, delete, or restrict processing of your personal information, and the right to non-discrimination for exercising these rights. To exercise any of these rights, contact us at [email protected].
8. Children's Privacy
HoverReel is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at [email protected] and we will take steps to delete it.
9. International Data Transfers
Our service providers may process and store data in the United States and other countries. By using HoverReel, you understand that information may be transferred to and processed in countries other than the one in which you reside, which may have different data protection laws.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date, and for material changes we will make reasonable efforts to notify Merchants directly (e.g. by email or dashboard notice).
11. Contact Us
Questions about this Privacy Policy or how we handle information can be sent to:
HoverReel LLC 5151 Monroe St, Ste 250F Toledo, OH 43623 [email protected]
