Privacy Policy

Last updated: September 4, 2026

This Privacy Policy explains how HoverReel LLC (“HoverReel,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the HoverReel service — the HoverReel dashboard (where a business, which we call a “Merchant,” manages video content) and the HoverReel embeddable video widget (which a Merchant places on their own website, and which is viewed by that Merchant's own visitors, which we call “Shoppers”).

This policy covers two different groups of people, and what we collect differs meaningfully between them:

  • Merchants — the businesses who sign up for a HoverReel account, log into the dashboard, and configure video content.
  • Shoppers — the anonymous visitors who see a HoverReel-powered video widget on a Merchant's own website. Shoppers never create a HoverReel account and never interact with HoverReel directly — the widget runs on the Merchant's own site.

If you are a Shopper and have questions about a specific video widget you saw, the Merchant who placed it on their site is the right first point of contact — HoverReel is the technology behind it, not the storefront itself.

1. Information We Collect

1.1 Information Merchants provide directly

When a Merchant's account is created (currently by HoverReel directly, not via public self-signup) and used, we collect:

  • Account information: name, email address, and a password (we never store your password itself — only a salted, one-way cryptographic hash of it, using scrypt).
  • Content you upload or link: video files or video URLs, product and action information (titles, prices, descriptions, images, destination links), playlists, Player/widget configuration (colors, layout choices, branding), and any custom thumbnail images you upload or capture.
  • Brand/appearance settings: logo, color scheme, font choices, and similar customization you configure for your embedded widgets.
  • Domain configuration: the list of website domains you authorize your embed to run on.

1.2 Information collected automatically from Merchants

  • Session data: a session cookie that keeps you logged into the dashboard. This cookie is essential to the service and is not used for advertising or cross-site tracking.
  • Login timestamps: when you last logged in, for our own account-health monitoring.
  • Usage/operational data: which dashboard actions you take (e.g. adding a video, creating a Player, publishing an embed) is logged internally so we — and, in a limited read-only summary form, you — can see recent account activity.

1.3 Information collected automatically from Shoppers (via the embedded widget)

The HoverReel widget, once a Merchant places it on their own site, is publicly reachable by anyone who visits that page — it requires no login and does not know a Shopper's real-world identity. It collects the following, entirely to power the Merchant's own analytics about how their video content performs:

  • View/engagement events: impressions (a video was shown), views (a video was actually watched for a meaningful amount of time), clicks (on a product/action call-to-action), likes, add-to-cart attempts and their success/failure, and watch-time/completion signals (e.g. reaching 25%/50%/75%/90% of a video).
  • A randomly generated, anonymous visitor identifier, stored in the Shopper's own browser (localStorage/sessionStorage) on the Merchant's domain. This identifier is not derived from and is not linked to any real name, email, or other directly-identifying information we hold — its only purpose is to avoid counting the same visitor's repeat view of the same video multiple times within one browsing session, and to remember (permanently, in that browser) that a “like” was already given so it can't be repeated.
  • Page context: the page URL and referring page, both reduced to origin + path only — any query string (which can carry things like search terms, order IDs, or email addresses embedded by the Merchant's own site) is deliberately stripped before it is ever stored.
  • Device type: a coarse category (e.g. desktop vs. mobile), derived from the browser's own user-agent string.
  • IP address, used only transiently to enforce rate limits that protect the service from abuse (e.g. scripted flooding of fake analytics events) — it is not stored as a persistent field tied to analytics events.

We do not collect a Shopper's name, email address, physical address, payment information, or any other directly-identifying information through the widget itself. We have no way to connect a Shopper's anonymous visitor identifier to a real person's identity.

1.4 What we do NOT collect

  • We do not collect payment card numbers or bank information — the HoverReel service does not currently process payments from Merchants or Shoppers. Where a Shopper completes a real purchase (through a Merchant's own Shopify “Add to Cart” flow), that transaction happens directly between the Shopper's browser and the Merchant's own Shopify store — HoverReel's servers are never in that data path and never see payment details, shipping addresses, or order contents.
  • We do not knowingly collect information from children under 13 (see Section 8).

2. How We Use Information

We use the information described above to:

  • Operate, maintain, and improve the HoverReel dashboard and widget.
  • Authenticate Merchants and keep dashboard sessions secure.
  • Generate the analytics (views, click-through, completion rate, etc.) a Merchant sees about their own video content's performance.
  • Detect and prevent abuse, fraud, and rate-limit violations.
  • Provide customer support and respond to inquiries.
  • Send operational communications about the service (e.g. account or security notices). We do not use Merchant or Shopper data to send third-party marketing or sell it to advertisers.

3. Cookies and Similar Technologies

  • HoverReel dashboard (Merchant-facing) sets one essential session cookie, marked httpOnly and SameSite=Lax, so it cannot be read by page scripts and is not sent on most cross-site requests. This cookie is required for the dashboard to function and is not an advertising or analytics cookie.
  • HoverReel widget (Shopper-facing) uses browser localStorage/sessionStorage — not cookies — to avoid double-counting a view within one session and to remember a “like” permanently in that browser. This storage is scoped to the Merchant's own domain (where the widget script runs), contains only the anonymous identifiers described in Section 1.3, and is never used to track a Shopper across unrelated, unaffiliated websites.
  • We do not use third-party advertising cookies or trackers anywhere in the service.

For the exact, current list of every cookie and browser-storage item we use, what each one is named, how long it lasts, and why it exists, see our Cookies Policy.

4. How We Share Information

We do not sell Merchant or Shopper information. We share information only as follows:

  • Service providers (subprocessors) who help us operate the service, under obligations to protect the data and use it only to provide their service to us: Bunny.net (video hosting, transcoding, and content-delivery/CDN for uploaded video files); Railway (application hosting infrastructure for the HoverReel dashboard and API); GitHub (stores automated, encrypted-at-rest database backups, not publicly accessible).
  • A Merchant's own Shopify store, only in the specific case where a Shopper clicks “Add to Cart” on a Shopify-connected product — that request is made directly from the Shopper's own browser to the Merchant's Shopify domain and never passes through HoverReel's servers.
  • Legal requirements: if required by law, valid legal process, or to protect the rights, property, or safety of HoverReel, our users, or others.
  • Business transfers: if HoverReel is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy with comparable protections.

5. Data Retention

  • Merchant account and content data is retained for as long as the account is active, and for a reasonable period after closure to allow recovery of an accidentally-deleted account, after which it is deleted.
  • Analytics events (Shopper view/click/watch data) are retained to power historical reporting for the Merchant; we may reduce, sample, or aggregate older raw event data over time.
  • Temporary, shareable assets (e.g. an image generated when a Shopper uses a “share” feature) are automatically deleted after a short retention window (currently 7 days).
  • Backups are retained on a rolling basis and pruned automatically.

6. Data Security

We use industry-standard practices to protect information, including: encrypted transport (HTTPS/TLS) for all traffic, salted one-way password hashing (never storing plaintext passwords), signed and time-limited video playback URLs, rate limiting on public endpoints, and a restrictive Content Security Policy on the dashboard. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Your Rights and Choices

  • Merchants can request access to, correction of, or deletion of their account and content by contacting us at [email protected].
  • Shoppers, because the widget does not know their real identity, cannot be individually identified from an analytics event alone — a Shopper who wants their browsing on a specific site not tracked by the widget can clear that browser's localStorage/sessionStorage for that site, or use browser settings/extensions that block third-party scripts.
  • Depending on where you live, you may have additional rights under laws such as the EU/UK GDPR or the California Consumer Privacy Act (CCPA), including the right to access, correct, delete, or restrict processing of your personal information, and the right to non-discrimination for exercising these rights. To exercise any of these rights, contact us at [email protected].

8. Children's Privacy

HoverReel is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at [email protected] and we will take steps to delete it.

9. International Data Transfers

Our service providers may process and store data in the United States and other countries. By using HoverReel, you understand that information may be transferred to and processed in countries other than the one in which you reside, which may have different data protection laws.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new “Last updated” date, and for material changes we will make reasonable efforts to notify Merchants directly (e.g. by email or dashboard notice).

11. Contact Us

Questions about this Privacy Policy or how we handle information can be sent to:

HoverReel LLC
5151 Monroe St, Ste 250F
Toledo, OH 43623
[email protected]