bg.where2go.wildhopWildHop is a mobile game. This document describes exactly what data is stored, why, and for how long. It lists only what the app actually does — nothing more.
Data is processed by УеърТуГоу ЕООД (WhereToGo), a company registered in Bulgaria. For questions and for account deletion: info@where2go.bg.
| Data | When it appears | Why |
|---|---|---|
| Nickname | Guest and registered players | So others can see you in the lobby, chat and leaderboards |
| Username and password | Only if you register | Sign-in. The password is stored as a bcrypt hash, never as text |
| Only if you register or sign in with Facebook | Account recovery and contacting you | |
| Facebook ID and profile picture | Only with Facebook sign-in | Recognising your account and showing your avatar |
| Chosen character, country (optional) | When you set them | Shown in your profile, the lobby and leaderboards |
| Game progress | While you play | Levels, stars, coins, items — so they survive a change of phone |
| Level times | On finishing a level | Weekly leaderboards |
| Friends and inbox messages | When you use them | Invitations and rewards |
| Room chat messages | While playing duo | Relayed live to the other player — not stored |
| Google Play purchase token | Only if you buy coins | To credit the coins once, and for support in case of a dispute |
| IP address in server logs | On every connection | Security and abuse detection. Kept for 30 days |
The app requests internet access only
(INTERNET, ACCESS_NETWORK_STATE) — for the account,
cloud save and two-player game.
If you choose “Continue with Facebook”, we receive your public profile and e-mail from Facebook. They are used to create the account and show your avatar. Nothing is posted on your behalf and nothing else is read.
In-game coins can be bought with real money. Payment is handled entirely by Google Play. The app and our server never see your card details — those are processed by Google.
From Google we receive only a purchase token and which product was bought. The server asks Google whether the payment is confirmed and only then credits the coins. That token is kept so coins are never credited twice and so we can help you if something goes wrong with a payment.
For payments, Google acts as an independent data controller. See the Google Privacy Policy.
The game is suitable for all ages and does not target children under 13 with advertising or tracking. If we learn that an account was created by a child under 13 without parental consent, the account is deleted.
For as long as the account exists. Sign-in tokens are kept until you log out. On a deletion request, the account and its related records are removed within 30 days.
Write to info@where2go.bg from the account e-mail or with your nickname. Deleted are: the profile, progress, times, friendships and inbox.
The connection between the game and the server uses HTTPS. Passwords are stored as bcrypt hashes.
On any change the date above is updated. Material changes are announced in the in-game inbox.