1. Scope
This Privacy Policy describes how HyperLeague (“we”, “the Operator”, “the Protocol” interfaces) handle information when you use tournament products and related marketing pages.
On-chain data is public by nature of the blockchain; this notice explains what we process off-chain around that public record.
This draft is provisional and will be reviewed by counsel. It is not legal advice.
2. Who processes data
For this provisional draft, the Operator of the HyperLeague interfaces is the party presenting this site. A formal legal entity, registered address, and data-protection officer contact will be added after counsel review.
Independent processors may include wallet auth (Privy), hosting (e.g. Vercel), database (e.g. Supabase), RPC providers, and analytics if enabled. Their own policies also apply.
3. Categories of information
We may process:
- Wallet addresses and public on-chain activity (joins, trades, claims, vault interactions) — public on HyperEVM / indexed mirrors.
- Authentication identifiers from Privy (e.g. session, linked email or social login if you choose those methods).
- Device and usage data (IP address, user agent, pages viewed, approximate location derived from IP) via hosting logs and any analytics you have not opted out of where offered.
- Local preferences stored in your browser (theme, layout panel sizes, trade tags/notes you save locally).
- Support messages you send in public Discord/Telegram or other channels you choose.
4. Purposes
We process information to operate the interface, index chain events for display, secure the service, debug outages, improve UX, prevent abuse, and communicate about the product when you contact us.
We do not sell personal information. We do not use tournament entry fees as a pretext to build off-chain credit profiles.
5. Blockchain publicity
Transactions you sign are broadcast to a public network. Wallet addresses and trade outcomes can be correlated by anyone. The Operator cannot “delete” confirmed chain history.
Off-chain caches may retain indexed copies of public events for product features (leaderboards, profiles, charts). Those mirrors can be corrected or re-indexed; they do not erase the chain.
8. Retention
Auth and hosting logs are retained under provider defaults and operational need. Indexed public chain data may be retained for as long as the product offers historical views.
Local-only notes and tags remain on your device until you clear them.
9. Your rights
Where applicable law provides, you may have rights to access, correct, delete, restrict, or port personal information we hold off-chain, and to object to certain processing.
We cannot fulfill deletion requests against immutable public chain data. For off-chain account/auth data, contact us via the footer social channels; a formal privacy email will be published after counsel review.
References to GDPR, CCPA, or similar regimes are descriptive only — rights apply where those laws actually cover you.
10. Security
We use industry-typical protections (TLS, access-controlled service roles for writes, RLS on public read caches). No method is perfect. You must protect your own keys.
11. Children
The product is not directed at children. Do not use it if you are below the age of digital consent in your jurisdiction.
12. Changes
We may update this notice. The “Last updated” date will change. Continued use after updates means you acknowledge the revised notice for future activity.
13. Contact
Use the public channels in the site footer (X, Discord, Telegram, GitHub). Entity identity and a dedicated privacy inbox are deferred to counsel review.