🥊 CRYPTO SUMO ARENA

Privacy Policy

Last updated: January 2025

This Privacy Policy describes how Crypto Sumo Arena ("we", "us", "the Platform") collects, uses, and protects information about you when you use our service.

1. Information We Collect

Account information: When you create an account, we collect your username, email address, and a hashed version of your password. If you sign in via Privy (Google, Twitter, Discord, email), we receive a Privy user ID and the minimal profile data you authorize.

Wallet information: We derive a Solana deposit address for your account and store your optional withdrawal address. We record your on-platform USDC balance.

Gameplay data: We record match results, win/loss records, kills, and aggregate performance statistics under your username.

Technical data: Standard web server logs (IP address, browser type, referring URL) retained for up to 30 days for security purposes.

2. How We Use Your Information

  • To provide and operate the Platform (account management, matchmaking, game sessions).
  • To process deposits, track balances, and send withdrawals.
  • To maintain leaderboards and display publicly visible gameplay statistics.
  • To detect and prevent fraud, cheating, or abuse.
  • To comply with legal obligations, including anti-money-laundering regulations where applicable.
  • To communicate with you about your account or changes to the Platform.

3. Information We Share

We do not sell your personal information. We may share information with:

  • Privy: For OAuth authentication flows. Privy's privacy policy applies to data they handle.
  • Helius: Our Solana RPC provider. Transaction data flows through their infrastructure.
  • Railway: Our hosting provider. Server-level data is processed on their infrastructure.
  • Law enforcement / regulators: If required by valid legal process or to protect safety.

4. Blockchain Transparency

Solana is a public blockchain. All on-chain transactions — including deposits and withdrawals — are publicly visible and permanently recorded. We cannot delete or modify blockchain records.

5. Data Retention

We retain account data for as long as your account is active. If you request account deletion, we will remove your personal information within 30 days, subject to any legal retention requirements. Gameplay statistics may be retained in anonymized form.

6. Security

Passwords are hashed with bcrypt and never stored in plaintext. Deposit wallet private keys are derived from a master mnemonic stored securely in environment variables and never exposed to clients. We use HTTPS for all data in transit.

7. Cookies & Local Storage

We use a session cookie (HTTP-only) to maintain your login state. We use browser localStorage to save cosmetic preferences (trail color, hat selection) locally on your device. No third-party advertising or tracking cookies are used.

8. Children's Privacy

The Platform is not directed at persons under 18. We do not knowingly collect information from minors. If we become aware that a minor has created an account, we will delete it promptly.

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. To exercise these rights, contact us at support@cryptosumo.gg. We will respond within 30 days.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by posting a notice on the Platform or via email. Continued use after changes constitutes acceptance.

11. Contact

Questions about this policy: support@cryptosumo.gg

← Back to Arena    Terms of Service