This Privacy Policy describes how Hopping Heads ("we", "us", "our") collects, uses, and protects your personal data when you use our website, game, and related services (collectively, the "Service"). We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
Hopping Heads is an independent game project. The data controller responsible for your personal data is the operator of hoppingheads.fun. For privacy-related inquiries, contact us at [email protected].
When you connect your X account via OAuth, we collect your X user ID, username, display name, and profile image URL. We do not access your direct messages, followers list, or post on your behalf.
We collect data generated when you play, including scores, rounds played, fragments collected, mints attempted, win/loss records, and timestamps. This data is linked to your X username.
We automatically collect IP addresses, browser type, device type, screen resolution, and approximate location (country level) for security, analytics, and rate limiting purposes.
During the closed beta, we record which beta access code you redeemed and when you joined.
We use browser localStorage to store your session token, control preferences, and skin selection. We do not use third-party tracking cookies.
Under GDPR, we process your personal data on the following legal bases:
We share data with the following third parties solely as necessary to operate the Service:
We do not sell your data to advertisers, data brokers, or any third party.
We retain your account data for as long as your account is active. If you request deletion, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as fraud prevention. Aggregated, anonymized statistics may be retained indefinitely.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:
To exercise any of these rights, email [email protected] with your X username and the specific request. We will respond within 30 days.
Our hosting provider may store data in jurisdictions outside the EEA. When this occurs, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the European Commission.
We implement technical and organizational measures to protect your data, including HTTPS encryption, parameterized database queries, rate limiting, signed session tokens, and secured admin endpoints. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16 without verified parental consent, we will delete that data promptly.
When onchain features launch on Base, any blockchain transactions you initiate (such as minting NFTs) will be recorded on the public Base blockchain and cannot be deleted or modified. This is the nature of public blockchains. Your wallet address and transaction history will be publicly visible. Use a wallet you are comfortable being associated with the game.
We may update this Privacy Policy from time to time. Material changes will be announced on the website with a notice on the homepage. The effective date at the top of this policy will be updated.
For questions about this Privacy Policy or to exercise your rights, contact us at