Privacy Policy

Last updated: [PLACEHOLDER: date]. This is a draft for legal review and is not yet in force.

This Privacy Policy explains what personal data HeroBrowser (the "Service") collects, why, and what rights you have over it under the EU General Data Protection Regulation (GDPR).

1. Who Controls Your Data

The data controller for the Service is:

Trading nameHeroBrowser
Legal entity name[PLACEHOLDER: registered company name]
Legal form[PLACEHOLDER: e.g. B.V., eenmanszaak]
Chamber of Commerce (KvK) number[PLACEHOLDER: KvK number]
VAT / BTW number[PLACEHOLDER: VAT number]
Registered address[PLACEHOLDER: registered address]
Support / contact email[PLACEHOLDER: support email]
CountryNetherlands

2. What We Collect

  • Guest play: nothing on our servers. Your progress is stored only in your own browser's local storage and never reaches our servers.
  • Google sign-in: the Google account identifier, email address, display name, and profile picture URL that Google gives us when you sign in.
  • Email/password accounts: your email address and a securely hashed password. We never see or store your password in plain text.
  • Game save data: your character progress, floor reached, equipped gear, and in-game currency balances, tied to your account.
  • Purchase records: when you buy Gold Diamonds, we keep a record of the pack purchased, the price paid, the date, and its status (paid, refunded, or disputed), together with a Stripe payment reference (a Checkout session or payment intent id) used to reconcile refunds and disputes. We do not receive or store your card number — Stripe processes your payment directly.
  • Crash reports: if the game hits an error or an unhandled rejection on your device, your browser automatically sends us a report so we can find and fix the bug. A report contains the error's kind, name, and message, a short portion of its stack trace, the page path you were on (never the full URL or any query string), a build identifier, the active game scene, whether you were signed in or a guest, your locale, and your browser viewport size. If you are signed in, the report is attached to your account; a guest's report is not identified to anyone.
  • Activity telemetry: for each day you play while signed in, we record your account id and that calendar day only — no gameplay details, no event payloads — so we can measure day-level player retention internally.
  • Referral program: if you use a referral link or code, we record which account referred which other account, so the referral reward can be paid to both. A referral code you have not yet redeemed is held temporarily in your browser's local storage until you sign in.
  • Public leaderboard: if you sign in, your chosen display name, hero class, and the floor and level you reached may appear on the public leaderboard, visible to anyone. We never show your email address there.
  • Live events schedule: the in-game "what's currently running" schedule is fetched without sending or requiring any personal data.
  • Technical data: your IP address may be processed briefly by our infrastructure to prevent abuse (rate limiting) and is not stored against your account afterward.

We do not run ad networks or sell your data to third parties. Our public site pages (not the game itself) load a cookie-free page-view analytics beacon from Cloudflare — see Who We Share It With below.

3. What We Store In Your Browser

Some data lives only in your browser's local storage and is never sent to, or held on, our servers as part of any account record:

  • Your sign-in session — a session token and your display name, so a returning player doesn't have to sign in again on the same device.
  • An operator console session — present only on staff devices that use the internal admin console; ordinary players never have this.
  • A pending referral code — the code from a share link you followed, held until you sign in so it can be redeemed automatically.
  • Your guest save, if you play as a guest — your entire character progress, stored only in your own browser and never uploaded to our servers (see "Guest play" above).

We do not use any other browser storage beyond what is listed here and the Cloudflare analytics beacon described below.

4. Why We Process It

  • Performance of our contract with you: creating and running your account, saving your progress, and fulfilling purchases.
  • Legal obligation: keeping purchase and transaction records for accounting and tax law.
  • Legitimate interests: preventing cheating, fraud, and abuse, keeping the Service secure and running, fixing crashes, and running our referral program.
  • Consent: for anything we ask separately. [PLACEHOLDER: the Service does not currently send marketing email; update this section if that changes.]

5. Who We Share It With

We use the following processors, each only for the purpose described:

  • Google LLC — verifying Google sign-in.
  • Stripe, Inc. — processing real-money purchases; Stripe receives your payment details directly and we never see your full card number.
  • Resend — sending transactional email (sign-up verification, password reset) if you use an email/password account.
  • Microsoft Ireland Operations Limited (Microsoft Azure) — hosting infrastructure that stores your save file, crash-report logs, and activity telemetry (currently deployed on Microsoft Azure, in United States regions).
  • Cloudflare — content delivery and a cookie-free page-view analytics beacon on our public site pages; this does not touch your account data.

Some of these processors may handle data outside the country you live in. [PLACEHOLDER: confirm the specific international-transfer safeguard for each processor with counsel.] [PLACEHOLDER: international transfer basis — lawyer to confirm; data is hosted in United States Azure regions]

6. How Long We Keep It

We keep your account and game save data for as long as your account is active. Purchase records are kept for as long as required by applicable financial record-keeping law [PLACEHOLDER: confirm the exact retention period, e.g. under Dutch tax law, with counsel or an accountant]. Crash reports and activity telemetry are kept in server logs for 30 days (the retention configured on our Azure Log Analytics workspace), and are not linked back to your account beyond that window. Referral program records (which account referred which) are kept for as long as your account is active, for reward bookkeeping. We delete or anonymize data once it is no longer needed, unless law requires us to keep it longer.

7. Your Rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten");
  • restrict or object to certain processing;
  • receive your data in a portable format; and
  • lodge a complaint with your national data protection authority the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

8. How to Exercise Your Rights

Email [PLACEHOLDER: support/privacy email] with your request. We will respond within the time required by law (normally one month).

9. Children

The Service is not directed at children under [PLACEHOLDER: age — the GDPR's digital-consent age varies between 13 and 16 depending on EU member state]. We do not currently verify age at sign-up. If you believe a child has given us personal data, contact us so we can delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy here with a new "Last updated" date.

11. Contact

Questions about this policy: [PLACEHOLDER: support/privacy email].