WildHop — Privacy Policy

Effective 4 September 2026 · App bg.where2go.wildhop

WildHop is a mobile game. This document describes exactly what data is stored, why, and for how long. It lists only what the app actually does — nothing more.

In short: you can play entirely as a guest, with no e-mail and no name. There are no ads, no tracking and no sale of data to third parties.

1. Who processes the data

Data is processed by УеърТуГоу ЕООД (WhereToGo), a company registered in Bulgaria. For questions and for account deletion: info@where2go.bg.

2. What is stored

DataWhen it appearsWhy
NicknameGuest and registered players So others can see you in the lobby, chat and leaderboards
Username and passwordOnly if you register Sign-in. The password is stored as a bcrypt hash, never as text
E-mailOnly if you register or sign in with Facebook Account recovery and contacting you
Facebook ID and profile pictureOnly with Facebook sign-in Recognising your account and showing your avatar
Chosen character, country (optional)When you set them Shown in your profile, the lobby and leaderboards
Game progressWhile you play Levels, stars, coins, items — so they survive a change of phone
Level timesOn finishing a levelWeekly leaderboards
Friends and inbox messagesWhen you use them Invitations and rewards
Room chat messagesWhile playing duo Relayed live to the other player — not stored
Google Play purchase tokenOnly if you buy coins To credit the coins once, and for support in case of a dispute
IP address in server logsOn every connection Security and abuse detection. Kept for 30 days

3. What is NOT collected

4. App permissions

The app requests internet access only (INTERNET, ACCESS_NETWORK_STATE) — for the account, cloud save and two-player game.

5. Facebook sign-in

If you choose “Continue with Facebook”, we receive your public profile and e-mail from Facebook. They are used to create the account and show your avatar. Nothing is posted on your behalf and nothing else is read.

6. In-app purchases

In-game coins can be bought with real money. Payment is handled entirely by Google Play. The app and our server never see your card details — those are processed by Google.

From Google we receive only a purchase token and which product was bought. The server asks Google whether the payment is confirmed and only then credits the coins. That token is kept so coins are never credited twice and so we can help you if something goes wrong with a payment.

For payments, Google acts as an independent data controller. See the Google Privacy Policy.

7. Children

The game is suitable for all ages and does not target children under 13 with advertising or tracking. If we learn that an account was created by a child under 13 without parental consent, the account is deleted.

8. How long data is kept

For as long as the account exists. Sign-in tokens are kept until you log out. On a deletion request, the account and its related records are removed within 30 days.

9. Deleting your account

Write to info@where2go.bg from the account e-mail or with your nickname. Deleted are: the profile, progress, times, friendships and inbox.

10. Security

The connection between the game and the server uses HTTPS. Passwords are stored as bcrypt hashes.

11. Changes

On any change the date above is updated. Material changes are announced in the in-game inbox.