Privacy Policy
Effective Date: July 30, 2026
Last Updated: July 30, 2026
1. Introduction
This Privacy Policy describes how Hotshot Inc. (“we,” “us,” or “our”), collects, uses, and shares your personal information when you use our services. This policy applies to all users of our platform, including both individual end-users and business customers.
For EU/EEA/UK Residents: This policy also serves as our privacy notice under the General Data Protection Regulation (GDPR) and UK GDPR. We are the data controller for the personal data we collect about you. Please see the contact information at the bottom of this privacy notice if you would like to contact us.
For Business Customers (B2B): If you are using Hotshot as part of a business or enterprise subscription, any personal data we process on your behalf in the course of providing our services is governed by our Data Processing Agreement (“DPA”), which is incorporated into our Subscription Agreement with you. The DPA outlines each party’s roles and responsibilities regarding personal data processing (for example, that your organization is the data controller and we are the data processor) in compliance with applicable data protection laws. Where we are the data processor, please contact the business or enterprise with any inquiries or to exercise your privacy rights (aka “data subject rights”) and we will collaborate with the business or enterprise to fulfill them to the business’ or enterprise’s instructions.
2. Information We Collect
Personal Information from End-Users (B2C)
We collect the following personal information from individual users:
- Identity Information: First name, last name, email address
- Account Information: Hashed password
- Usage Information: Course progress, usage metrics
Personal Information from Business Contacts (B2B)
We collect the following information from business customer contacts:
- Contact Information: First name, corporate email address
- Professional Information: Job title, company name
- Billing Information: Billing details for invoicing
Information We Do Not Collect
We do not knowingly process special categories of personal data/sensitive personal data, children’s data, or direct payment card numbers (Stripe tokenizes payment information on our behalf). We do not collect or process precise geolocation data.
Hotshot does not use or sell your personal information to train Large Language Models (LLMs).
3. How We Use Your Information
We use different types of personal information for the purposes described below, in accordance with the lawful bases for processing:
| Information Collected | Use | Lawful Purpose |
|---|---|---|
| Basic identifiers (e.g., name, job title, company) | Service delivery & security | Consent; Performance of contract |
| Chat content | Sales & customer support | Consent; Performance of contract |
| Email address | Transactional communications | Consent; Legitimate interest (service reliability) |
| Billing details (name, address, payment info) | Payment processing | Consent; Performance of contract; Legal obligation |
| Pseudonymized usage events | Product analytics & improvement | Consent; Legitimate interest (product improvement) |
| Third-party data (name, email shared with permission) | Sales & customer support | Consent; Legitimate interest (commercial purposes) |
| System logs and traces | Security & incident response | Consent; Legitimate interest (security) |
| Inferred data (derived from above categories) | Product improvement & marketing | Consent; Legitimate interest (product improvement, commercial purposes) |
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our platform to provide, secure, and improve our services. Some cookies are strictly necessary for the website to function (for example, to enable logins, maintain your session, and ensure security). With your consent, we also use non-essential cookies—such as analytics cookies to understand how users engage with our site, and functionality cookies to remember your preferences (e.g., video playback position). We will not place non-essential cookies unless you have given consent through our cookie banner or preference center, and you may withdraw your consent at any time. For more details about the cookies we use and how you can manage your preferences, please see our Cookie Policy.
5. Information Sharing and Third-Party Processors
We share your information with third-party service providers that help us operate our services. We do this only after providing you notice (like in this Privacy Policy) or obtaining your consent, as appropriate. These third parties process data on our behalf and are contractually obligated to safeguard your information.
We may also share your data if we enter into, or intend to enter into, a business transaction that alters the structure of our business, such as a merger, acquisition, bankruptcy, or sale. In such cases, we would share personal data with third parties, such as the buyer or target (and their agents and advisors), to facilitate and complete the transaction. We also share personal information where we are legally required to and with our legal advisors or auditors to establish, exercise, or protect our legal rights. We also share your personal data if you consent to the sharing. You may revoke or modify your consent going forward, at any time.
6. Your Privacy Rights
Rights Under State Privacy Laws (U.S. Residents)
Depending on the state in which you reside, you may have some or all of the following rights under that state’s privacy law. For example, residents of California are protected by the California Consumer Privacy Act, as amended (CCPA) which grant rights such as those listed below:
- Right to Know/Access: You can request information about the personal information we collect, use, and share about you. California residents may exercise this right twice within a 12 month period without any cost.
- Right to Delete: You can request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You can request that we correct inaccurate personal information about you.
- Right to Data Portability: You can request a copy of your personal information in a portable, readily usable format.
- Right to Non-Discrimination (Non-Retaliation in California): We will not discriminate against you for exercising any of your privacy rights.
- Right to Limit Use of Sensitive Personal Information (California Only): California residents have a right to limit the use of their sensitive personal information when such use goes beyond what is necessary for providing the Services or other permissible purposes like fraud detection and prevention, customer service, or quality control. Hotshot does not collect or process sensitive personal information in a way that gives rise to this right.
Rights Under GDPR (EU/EEA/UK Residents)
If you are a resident of the European Union, a country in the European Economic Area, or the United Kingdom, you have the following rights under the GDPR:
- Right of Access (Art. 15): You can request confirmation of whether we process your personal data and obtain a copy of that data.
- Right to Rectification (Art. 16): You can request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You can request deletion of your personal data in certain circumstances (for example, if the data is no longer necessary for its original purpose; if you withdraw consent where consent was the basis of processing; if you object to processing based on legitimate interests; or if the data was unlawfully processed).
- Right to Restrict Processing (Art. 18): You can request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): You can request your personal data in a structured, commonly used format and have it transmitted to another controller, where technically feasible.
- Right to Object (Art. 21): You can object to processing of your personal data when the processing is based on our legitimate interests, or you can object to processing for direct marketing purposes.
- Rights Related to Automated Decision-Making (Art. 22): You have rights related to automated decision-making and profiling (note: Hotshot does not engage in any processing that produces legal effects based solely on automated decisions).
- Right to Withdraw Consent: If we are relying on your consent to process your personal data, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@hotshotlegal.com, or by writing to us at the mailing address provided in the “Contact Us” section below. After you submit your rights request, we will:
- Verify your identity before fulfilling your request. To confirm you identity, we may ask you to confirm information already associated with your account, such as your email address or name. If you do not have an account with us, we may request sufficient information to reasonably verify you are the person about whom we collected personal data.
- Respond within the timeframe required by applicable law (for example, within one month for GDPR requests).
- Provide our response or the requested information free of charge, unless a request is manifestly unfounded or excessive.
Authorized Agents: If you are a U.S. resident, you may designate an authorized agent to submit a request on your behalf. We will require the agent to provide proof that you gave them permission to act for you, and we may still ask you to verify your identity directly.
Right to Lodge a Complaint/Appeal
You have the right to appeal our refusal to act on your request to exercise your other rights. To request an appeal to our refusal please email us at privacy@hotshotlegal.com, with the subject line: “Appeal My Consumer Request.” We will review the appeal and notify you of our response. If we still refuse to act on your request, we will provide you with a written explanation for the reasons for the denial and notify you of the right to file a complaint with the applicable state regulator.
- If you are in the EU/EEA or UK, you have the right to lodge a complaint with your local Data Protection Authority if you believe our processing of your personal data violates the GDPR.
- California residents: If applicable, you can contact the California Attorney General or the California Privacy Protection Agency for concerns regarding the CCPA/CPRA.
7. International Data Transfers
When we receive personal data from the EU/EEA or UK, we ensure that appropriate safeguards are in place as required by the GDPR and other applicable laws.
8. Data Retention
Unless a longer retention period is required or permitted by law (for example, for legal compliance, accounting, or record-keeping purposes), we retain personal data: (1) only for as long as necessary to fulfill the purposes for which it was collected, (2) until we receive a valid request to delete the information, or (3) the information is no longer needed for a service provider or contractor’s operational purpose(s). Once personal data is no longer needed, we will delete or anonymize it in accordance with our data retention policies.
Unless you request earlier deletion or a longer period is required or permitted by law, we apply the following maximum retention periods to the personal data we hold about you:
Account information (name, email, login credentials, account settings): for the duration of your account, then deleted within 30 days after account closure or after two years of continuous inactivity.
Course usage data (learning progress, course completion records, quiz results, and related analytics tied to your account): up to 8 years from collection. After this period, we delete the data or retain it in aggregated, anonymized form that does not identify you.
Support communications (emails, chat transcripts, and support tickets): 2 years from resolution of the support issue.
Business contact data (contact details of client administrators and billing contacts): for the duration of the contract and 2 years after termination.
Contracts and related correspondence: 7 years after termination or expiry.
Financial and tax records (invoices, payment records, tax filings): 7 years from the end of the relevant fiscal year, or longer where required by tax or accounting laws.
Where personal data is subject to a legal hold or otherwise required to be preserved we will retain it until the hold is released or the obligation is satisfied.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data and ensure a level of security appropriate to the risk. These measures include, for example:
- Encryption of personal data in transit (using TLS/SSL) and at rest where applicable.
- Regular security assessments, vulnerability scans, and penetration testing of our systems.
- Access controls and authentication measures to restrict access to personal data on a need-to-know basis.
- Training our staff on data protection best practices and confidentiality.
- Maintaining incident response and breach notification procedures.
Despite our efforts, no security measures are 100% perfect, and we cannot guarantee absolute security of data. However, we continually evaluate and enhance our security practices to protect your information.
10. Children’s Privacy
Our services are not directed to children under 16, and we do not knowingly collect, sell, or share personal information from anyone under the age of 16. If we become aware that a child under 16 (or the minimum age required by applicable law) has provided us with personal information without parental consent, we will take steps to delete such information. If you believe that a child has provided us with personal data, please contact us using the information below so we can investigate and address the issue.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make material changes to this Policy (such as changes to the categories of personal data we process, our processing purposes, or our legal basis), we will notify affected individuals by posting a prominent notice on our website or emailing account holders, and provide you with a reasonable period of time to withdraw consent to any materially different collection, processing, or sharing of your personal data. For significant changes that require your consent, we will obtain consent as needed. The “Last Updated” at the top of this Privacy Policy will indicate when the latest changes were made.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below:
Hotshot – Privacy Team
Address: 79 Madison Avenue, 2nd Floor, NY, NY 10016
Email: privacy@hotshotlegal.com