Last updated: 29 August 2026
HoppingBooks lets people give away books they have finished with. The person receiving a book pays the postage and a small fee; the book itself is free. To post a parcel we need somewhere to send it, so this service cannot work without handling some personal data. This page explains exactly what we hold, why, who else sees it, and what you can ask us to do.
The controller for the data described here, in the sense of the GDPR, is:
[FULL NAME OR COMPANY] [STREET ADDRESS] [POSTCODE, CITY] [COUNTRY] Email: [CONTACT EMAIL ADDRESS]
Write to that address for anything on this page, including any of the requests described under Your rights.
Your account. Your name, email address, and — if you sign in with a password — that password stored only as a bcrypt hash, never as text we can read. Optionally a profile photo and a short bio, if you add them. We need this to know who you are and to let you back in.
Your postal address. Street, city, postcode, any state or region, and country. We need it to work out what postage will cost and to get a parcel to you or from you.
Books you list. Title, author, condition, language, your note about the book, and any cover photo you take yourself. This is what other people browse.
Ratings and reader notes. The stars you give a book and anything you write about it. These are public and shown next to your name to anyone using the site.
Messages. Messages you send another member about a book, and who sent them.
Claims and parcels. Which books were claimed, what postage and fee were charged, the status of the parcel, and — once posted — the tracking number and carrier.
Payments. Payments are handled by Stripe. We never see or store your card number. What we keep is the identifiers Stripe gives us so we can match a payment to a claim.
Images you upload. Profile photos and cover photos are stored as files rather than in our database. For each upload we also record the time, the size and the storage key, so we can enforce a daily limit and remove images nothing refers to any more.
Technical data. Our host keeps server logs, which can include IP addresses, for security and troubleshooting. Before you commit to a book we also estimate postage using a country code our host derives from your IP address. We do not store that country code, and it tells us your country, not your location.
Running your account, taking your payment, and getting a parcel to you are all performance of a contract with you (Art. 6(1)(b) GDPR). Keeping the service secure and preventing abuse — for example the daily limit on uploads — rests on our legitimate interests (Art. 6(1)(f)). Anything you choose to publish, such as a bio or a public rating, rests on your consent (Art. 6(1)(a)), which you can withdraw by removing it. Records connected to payments may also be kept because the law requires it (Art. 6(1)(c)).
The person at the other end. This is the important one. To post you a book, the sender needs a label with your name and postal address on it, and they will see it. Equally, when you give a book away, the person receiving it sees the name on your profile. There is no way to post a parcel without this. Everything you publish — your name, photo, bio, books and ratings — is visible to anyone using the site, signed in or not.
Services that work on our behalf. Hosting, file storage and logs (Netlify); our database (Prisma Data Platform); payments (Stripe); postage labels and tracking (Sendcloud); the emails we send you (Resend). Each of these acts on our instructions under a data processing agreement, and each sees only what it needs.
Book catalogues. To fill in a book's details and show what other readers thought, we ask Google Books and Open Library about an ISBN. Those requests are made by our server and contain the book's number only — never anything about you.
Some of the services above are operated by companies based in the United States and may process data outside the European Economic Area. Where that happens it is covered by the European Commission's standard contractual clauses, or by an adequacy decision. [Confirm the regions your Netlify site, database and Stripe account are configured to use, and name them here.]
Your account and the things attached to it are kept for as long as you have an account. Records of a completed transfer — what was sent, what was paid — are kept longer, because tax and commercial law requires it. [Confirm the retention period that applies to you; in Germany this is commonly six to ten years for records connected to payments.] Server logs are kept for a short period and then discarded.
You can ask us, at any time and free of charge, to:
There is no button for this yet: write to the address above and we will do it by hand. Deleting an account that has taken part in a completed transfer is not always possible in full, because we have to keep the record of that transfer — in that case we remove or anonymise everything we are not required to keep, and tell you what remains and why.
If you think we have handled your data badly you can complain to a supervisory authority. In Germany that is the data protection authority for the state you live in.
We set two, and both are strictly necessary: one that keeps you signed in, and one that protects sign-in forms against cross-site request forgery. There are no analytics or advertising cookies, which is why this site does not ask you to accept any.
HoppingBooks is not intended for children. You need to be at least 16 to have an account, or the age of consent for data processing where you live if that is lower.
If what we do with data changes, this page changes with it, and the date at the top is updated. If the change is significant we will tell account holders directly.