Privacy Policy

Last updated: [PLACEHOLDER: date]. This is a draft for legal review and is not yet in force.

This Privacy Policy explains what personal data HeroBrowser (the "Service") collects, why, and what rights you have over it under the EU General Data Protection Regulation (GDPR).

1. Who Controls Your Data

The data controller for the Service is:

Trading nameHeroBrowser
Legal entity name[PLACEHOLDER: registered company name]
Legal form[PLACEHOLDER: e.g. B.V., eenmanszaak]
Chamber of Commerce (KvK) number[PLACEHOLDER: KvK number]
VAT / BTW number[PLACEHOLDER: VAT number]
Registered address[PLACEHOLDER: registered address]
Support / contact email[PLACEHOLDER: support email]
CountryNetherlands

2. What We Collect

  • Guest play: nothing. Your progress is stored only in your own browser's local storage and never reaches our servers.
  • Google sign-in: the Google account identifier, email address, display name, and profile picture URL that Google gives us when you sign in.
  • Email/password accounts: your email address and a securely hashed password. We never see or store your password in plain text.
  • Game save data: your character progress, floor reached, equipped gear, and in-game currency balances, tied to your account.
  • Purchase records: when you buy Gold Diamonds, we keep a record of the pack purchased, the price paid, the date, and its status (paid, refunded, or disputed), together with a Stripe reference used to reconcile refunds. We do not receive or store your card number — Stripe processes your payment directly.
  • Technical data: your IP address may be processed briefly by our infrastructure to prevent abuse (rate limiting) and is not stored against your account afterward.

We do not use tracking cookies, run ad networks, or sell your data to third parties.

3. Why We Process It

  • Performance of our contract with you: creating and running your account, saving your progress, and fulfilling purchases.
  • Legal obligation: keeping purchase and transaction records for accounting and tax law.
  • Legitimate interests: preventing cheating, fraud, and abuse, and keeping the Service secure and running.
  • Consent: for anything we ask separately. [PLACEHOLDER: the Service does not currently send marketing email; update this section if that changes.]

4. Who We Share It With

We use the following processors, each only for the purpose described:

  • Google LLC — verifying Google sign-in.
  • Stripe, Inc. — processing real-money purchases; Stripe receives your payment details directly and we never see your full card number.
  • Resend — sending transactional email (sign-up verification, password reset) if you use an email/password account.
  • [PLACEHOLDER: hosting provider entity name] — hosting infrastructure that stores your save file (currently deployed on Microsoft Azure).
  • Cloudflare — content delivery and a cookie-free page-view analytics beacon on our public site pages; this does not touch your account data.

Some of these processors may handle data outside the country you live in. [PLACEHOLDER: confirm the specific international-transfer safeguard for each processor with counsel.]

5. How Long We Keep It

We keep your account and game save data for as long as your account is active. Purchase records are kept for as long as required by applicable financial record-keeping law [PLACEHOLDER: confirm the exact retention period, e.g. under Dutch tax law, with counsel or an accountant]. We delete or anonymize data once it is no longer needed, unless law requires us to keep it longer.

6. Your Rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased ("right to be forgotten");
  • restrict or object to certain processing;
  • receive your data in a portable format; and
  • lodge a complaint with your national data protection authority [PLACEHOLDER: e.g. the Dutch Autoriteit Persoonsgegevens, or your own country's equivalent].

7. How to Exercise Your Rights

Email [PLACEHOLDER: support/privacy email] with your request. We will respond within the time required by law (normally one month).

8. Children

The Service is not directed at children under [PLACEHOLDER: age — the GDPR's digital-consent age varies between 13 and 16 depending on EU member state]. We do not currently verify age at sign-up. If you believe a child has given us personal data, contact us so we can delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy here with a new "Last updated" date.

10. Contact

Questions about this policy: [PLACEHOLDER: support/privacy email].