Privacy policy
Last updated 13 August 2026
This covers heypass.io and the waitlist on it. HeyPass is not open to customers yet, so what follows describes only what happens when you join the waitlist or write to us. A separate policy covers the product itself and will be published before anybody forwards a mailbox.
Who we are
HeyPass is a product of Quokka For Good LLC, 30 N Gould Street, Sheridan, WY 82801, United States. Write to hello@heypass.io about anything in this policy.
What we collect
| Item | Purpose | Required |
|---|---|---|
| Email address | To tell you when HeyPass opens | Yes |
| Team size | To decide which features matter at launch | No |
| Services you share | To decide which integrations are built first | No |
| Mail provider | To decide the order of provider support | No |
| Referring page and campaign tags | To know which channel a signup came from | Collected automatically |
We do not ask for your name, your company name, a phone number or a payment method. We collect nothing about any mailbox, because the product is not running.
Why we are allowed to hold it
You gave it to us so that we could contact you about a product you asked to hear about. That is consent for the purpose described above and for nothing beyond it. You can withdraw it whenever you like and we will delete your record.
Who else sees it
A small number of service providers run the waitlist on our instructions and cannot use your data for their own purposes. One stores form submissions, one sends the emails you receive from us, one serves this website. We will name each of them here once the product is open, and we will tell you before adding a new one that handles your data.
We do not sell your data. We do not pass it to advertisers. We do not use it to build audiences on any advertising platform.
Where it is stored
Our providers may store data outside the United States. Where that happens, transfers are covered by the safeguards those providers offer, such as standard contractual clauses.
How long we keep it
Until you ask us to delete it, or until 24 months after HeyPass opens if you never took up an account, whichever comes first. If you unsubscribe we keep a record of your address for the sole purpose of not contacting you again.
Your rights
Depending on where you live, you can ask us to send you a copy of everything we hold about you, correct anything that is wrong, delete your record, stop emailing you, or object to how we are using it. Unsubscribing works from any email we send.
Write to hello@heypass.io and we will act within 30 days. No reason is needed. If our response does not satisfy you, you can complain to your local data protection authority.
Cookies and measurement
We use Google Tag Manager to load measurement tags, and Microsoft Clarity to understand how people use the site (page views, clicks, and anonymised session recordings). These tools may set cookies or use similar local storage. We do not use them for advertising. Campaign tags in the address bar, such as those on a link from a newsletter, may be recorded alongside your signup so that we know which channel it came from. See Google’s and Microsoft’s own privacy documentation for how each provider processes this data.
Security
Data travels over HTTPS and is held by providers who encrypt it at rest. No system is perfect, so if something goes wrong that affects you we will tell you promptly rather than quietly.
Children
HeyPass is a workplace tool and is not directed at anyone under 18. We do not knowingly collect data from children, and accounts belonging to or operated by minors are not permitted under the terms of service.
Data we will not accept
HeyPass is not built for regulated data and we do not want it on our systems. Do not route health records, banking or payment verification, cardholder data, or government identity credentials through the service. Section 4 of the terms of service has the full list. We are not HIPAA compliant, we are not PCI DSS assessed, and we do not sign business associate agreements.
When the product opens
HeyPass will process email belonging to customers who forward a mailbox. That is a materially different activity, and it will be covered by a fuller policy and a data processing agreement published before anyone connects a mailbox. Nothing in the current policy grants us access to any mailbox.
The retention rule we intend to operate, which the separate policy will set out formally:
- Verification codes and sign-in links are held only while they are valid, then the value is deleted permanently.
- Request records are kept for the customer. Who asked, when, which account, which sender answered, and the outcome. No message body is stored with a request record.
- Every other message is deleted automatically within 24 to 48 hours of arrival. No customer action is required and the deletion cannot be reversed by us.
Customers can read recent mail inside their own account while it is present, because it is their mail. No HeyPass employee reads customer mail during normal operation. Where an engineer needs access to diagnose a fault, that access is logged, time limited, and disclosed to the customer.
Changes
If we change this policy in a way that affects you, we will email everyone on the waitlist rather than quietly updating the date at the top.