LAST UPDATED: JUNE 2026

HHM Core Privacy Policy

Our commitment to Structured Transparency ensures your data is handled with absolute clarity and care. Review the core tenets of how we protect and manage your information.

Geometric mono-line lock illustration signaling security
Data Collection
Usage & Processing
Your User Rights

HHM Core Privacy Policy

TL;DR & Table of Contents

  • TL;DR: HHM Core is a licensed contractor acting on behalf of HHM. We only collect what is necessary to provide and improve the app; you control sensitive permissions and can delete your account anytime.
  • Table of Contents:
    • 1. App Identity & Controller
    • 2. TL;DR & Table of Contents
    • 3. Data We Collect (categories)
    • 4. How We Collect Data
    • 5. Purposes & Legal Basis
    • 6. Third Parties & SDKs (categories & links)
    • 7. Data Sharing & Disclosures
    • 8. Data Retention & Deletion
    • 9. Security Measures
    • 10. User Rights & How to Exercise
    • 11. Children’s Privacy
    • 12. International Transfers
    • 13. In-app Purchases & Subscriptions
    • 14. Advertising, ATT & Opt-outs
    • 15. Play Store Data Safety Summary
    • 16. Contact, DPO & Complaints
    • 17. Effective Date & Changelog

App identification and controller: "HHM Core" (the “App”) is provided by HHM. HHM Core is a licensed contractor that performs data processing on behalf of HHM to deliver the App’s functionality, perform analytics, provide customer support, process payments, and carry out other services described below. In this policy, "we," "us," and "our" refer to HHM and to HHM Core when it acts as a processor on HHM’s behalf.

This Privacy Policy applies to individuals who use the App and describes what information we collect, why we collect it, how we use and share it, how long we retain it, the choices you have, and how to contact us. Where we act as a processor for HHM, HHM is the controller and HHM Core acts under documented instructions from HHM. Where HHM Core acts as a controller for specific services, this policy will identify that role explicitly. If you are a resident of a jurisdiction with specific privacy laws, additional rights may apply.

Data Collection — Types of Data We Collect

TL;DR - Data Types

  • Contact information: name, email address, postal address and phone number when you provide them (for account setup, support, or billing).
  • Account data: username, profile data, account preferences, settings, and support communications.
  • Usage analytics: app usage metrics, feature interaction, session duration, aggregated analytics (may be pseudonymized).
  • Diagnostics & crash data: logs, performance metrics, error reports, stack traces to diagnose and fix problems.
  • Device identifiers & advertising IDs: device model, operating system, device identifiers, Advertising ID (Android) and IDFA (iOS) when used for advertising or attribution.
  • Location data: precise or approximate location only if you grant the App permission; used for location-based features and services.
  • Payment & purchase information: in-app purchase receipts, transaction identifiers and the minimum billing information required to validate purchases (we do not store full credit card numbers — payment processing is handled by third-party processors).
  • Health or other sensitive data: only collected if you explicitly provide it to the App for a specific feature; we do not collect health data by default.
  • Photos, media & contacts: only collected if you explicitly grant access and only for the stated feature (for example, uploading a profile photo or sharing a contact).

How we collect data: We collect data in three main ways: (1) directly from you when you create an account, contact support, or use interactive features; (2) automatically from your device and usage of the App (for example, device information, analytics and crash data); and (3) from third parties, such as payment processors, advertising partners, or identity providers, when you use an integrated service.

Purposes of processing & legal basis: We process personal information for the following purposes and legal bases where applicable:

  • Providing app functionality (Performance of a contract): account management, delivering features you request, synchronizing settings, and completing in‑app purchases.
  • Analytics & product improvement (Legitimate interest or consent): understand how people use the App, fix issues, and improve the experience. You may opt out of analytics as described below.
  • Personalized services & advertising (Consent or legitimate interest where permitted): show relevant content or offers; when required by law (for example, iOS App Tracking Transparency), we will obtain your consent before using advertising identifiers for tracking.
  • Fraud prevention & security (Legitimate interest or legal obligation): detect and prevent fraud, abuse, and security incidents.
  • Customer support (Performance of a contract / legitimate interest): respond to requests and resolve issues.
  • Legal compliance (Legal obligation): comply with legal processes and governmental requests.

If we rely on your consent for a specific processing activity, you can withdraw consent at any time in the App settings or by following the opt-out instructions below; withdrawing consent will not affect processing based on another lawful basis.

Third Parties, Data Sharing, Retention & Security

TL;DR - Sharing, Retention & Security

  • Service providers: we share limited data with hosting providers, analytics vendors, payment processors, and customer support platforms to deliver the App.
  • SDKs & third-party partners: analytics, crash reporting, advertising networks, and attribution providers may receive identifiers and usage data (see list below).
  • Legal requests: we may disclose data to comply with laws, respond to lawful requests, or protect rights and safety.
  • Business transfers: in the event of a merger, acquisition, or sale, personal data may be transferred as part of that transaction.
  • Retention & deletion: we retain data only as long as needed for the purposes described, for legal compliance, or to resolve disputes; you can request deletion as described below.

Third parties, SDKs and links

We use a limited set of third-party services to operate and improve the App. Categories include analytics providers (e.g., Google Analytics / Firebase), crash reporting (e.g., Firebase Crashlytics, Sentry), payment processors (e.g., Stripe, Apple App Store, Google Play billing), and advertising/attribution partners (e.g., Google AdMob, Meta Ads). These providers may receive device identifiers, advertising IDs, usage and diagnostic data, and purchase receipts as necessary to provide their services. Please review the privacy pages of those providers for details:

  • Google/Firebase: https://policies.google.com/privacy and https://firebase.google.com/support/privacy
  • Stripe (payments): https://stripe.com/privacy
  • Apple: https://www.apple.com/legal/privacy/
  • Sentry (crash reporting): https://sentry.io/privacy/
  • Ad networks & attribution services: links are provided during integration and in the App’s settings when relevant.

Data sharing and disclosures

We only share the minimum data necessary with service providers under written contracts that require them to protect the data and to process it only on our instructions. We may disclose data to comply with laws, respond to lawful requests, or protect our rights or to investigate fraud or illegal activity. In the event of a corporate transaction, personal data may be transferred as part of that transaction. We will notify users where required.

Data retention and deletion policy

We retain personal data for the period necessary to provide the App and for legitimate business purposes (for example, to prevent fraud, enforce agreements, or comply with legal obligations). When data is no longer required, we will delete or anonymize it. You may request deletion of your account and personal data via the App: go to Settings → Account → Delete Account, or contact us using the details below. After a deletion request, we will de‑identify or delete your personal data within 30 days unless retention is required by law.

Security measures

We implement industry-standard administrative, technical, and physical safeguards to protect data (for example, encryption in transit (TLS), access controls, data minimization, and regular security assessments). However, no system is perfect; if we become aware of a security breach affecting personal data, we will follow applicable breach-notification laws and inform affected users where required.

User rights & how to exercise them

Depending on your jurisdiction, you may have rights including access, correction, deletion, data portability, restriction of processing, objection to processing, and the right to withdraw consent. To exercise these rights:

  • Account actions: Use the App Settings to update profile information or to delete your account (Settings → Account → Delete Account).
  • Access, correction, portability or deletion requests: Contact us at [email protected] with a clear request and we will verify your identity before responding. Formal data requests will be processed within 30 days unless additional verification is required.
  • Marketing opt-outs: You can opt out of marketing communications via the unsubscribe link in emails or in the App settings.
  • Analytics & tracking opt-out: Disable analytics in the App settings; for platform-level ad tracking see Opt-outs below.

Children’s privacy

The App is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children below the minimum age. If we learn that we have collected personal data from a child without parental consent, we will take steps to delete that data.

International transfers

Data may be processed and stored in the United States or other countries where our service providers operate. When personal data is transferred outside your country, we apply appropriate safeguards such as standard contractual clauses, where required, to ensure an adequate level of protection.

In‑app purchases & subscriptions

Purchases are processed by the platform store (Apple or Google) or by our third-party payment processor. We receive transaction receipts and identifiers needed to provide purchased features; billing information (such as full credit card numbers) is handled only by the payment provider and is not stored on our servers.

Advertising, personalized ads & opt-outs (ATT and Advertising ID)

For personalized advertising or measurement, we may access advertising identifiers (IDFA on iOS; Advertising ID on Android). On iOS, we will request permission via App Tracking Transparency (ATT) before using the IDFA for tracking or sharing with other companies for advertising purposes; you can change this permission in iOS Settings → Privacy → Tracking. On Android you can opt out of ad personalization by resetting or disabling your Advertising ID under Settings → Google → Ads → Opt out of Ads Personalization.

Play Store Data Safety — Developer Summary

For Play Console Data Safety fields, the following developer-facing summary reflects what should be declared:

  • Data types collected: Identifiers (Device identifiers, Advertising ID), Contact info (name, email), Financial info (purchase receipts, transaction IDs), Location (precise/approximate only if granted), Usage & diagnostics (crash logs, analytics).
  • Purpose: App functionality, analytics, fraud prevention, advertising/marketing, and legal compliance.
  • Shared with third parties: Yes — analytics vendors, crash reporters, payment processors, ad networks (only the minimum necessary).
  • Encrypted in transit: Yes — all data is transmitted over HTTPS/TLS.
  • Link to Privacy Policy: Include the URL to this privacy policy page when completing the Play Console Data Safety form.

Contact, DPO & complaints

If you have questions, requests, or privacy concerns, contact our privacy team at [email protected] or by mail at: HHM, Attn: Privacy Team, [Company Address]. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority.

Effective date & changelog

This Privacy Policy is effective as of 2026-06-02. We may update this policy occasionally to reflect changes in our practices or legal requirements; material changes will be notified in the App or by email where required. A brief changelog will be provided at the top of this page for major updates.

DATA PROTECTION OFFICER / PRIVACY CONTACT

Privacy Questions?

HHM Core (licensed contractor) is the designated privacy contact for the HHM App.

Need to exercise your data rights or speak with our Data Protection Officer (DPO) or designated privacy contact? HHM Core, acting as a licensed contractor, is the designated privacy contact for the HHM App. Contact our privacy team at [email protected].

1251 Arrow Pine Drive - F103 - The Connect Charlotte, NC 28273

Designated Privacy Contact / DPO: [email protected]. We aim to respond to privacy inquiries within 30 days. If you are not satisfied with our response you may escalate to your local supervisory authority. For details on data collection, use, sharing, retention, security measures, and your rights, please see our full Privacy Policy.

HHM Core

Licensed contractor delivering high-performance custom homes with privacy by design.

Privacy Resources

  • Privacy Policy
  • Data Rights Request
  • Cookie Preferences
  • Security Practices

Stay Connected

© 2026 HHM Core. All rights reserved.