Legal
Privacy Policy
Effective Date: April 6, 2026 · Operated by HEAPO Solutions, LLC
HEAPO Solutions, LLC ("we," "our," or "us") operates the 16-Bit Hockey mobile game and the website located at 16bithockey.com (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using the Service you agree to the collection and use of information as described in this Policy.
1. Information We Collect
Information you provide
- Account information — When you register, we collect your username, email address, and password. Passwords are stored only as a one-way cryptographic hash; we never store your plaintext password. You may also provide an optional display name.
- User-generated content — Team names, league names, and other in-game text you create.
Information collected automatically
- Push notification token — If you enable push notifications, we store a Firebase Cloud Messaging (FCM) device token to deliver in-game alerts (game start, goal scored, lineup reminders). This token identifies your device, not your identity, and is removed when you disable notifications or delete your account.
- Log data — Our servers automatically record IP address, device type, operating system, and the date and time of requests for security and diagnostic purposes.
Information from third-party sign-in
- Google Sign-In — If you choose to sign in with Google, we receive your email address and Google account identifier. We do not receive your Google password.
- Sign in with Apple — If you choose to sign in with Apple, we receive an email address (which may be an Apple-anonymized relay address) and an Apple user identifier. We do not receive your Apple ID password.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Operate the game — matchmaking, leagues, trades, standings, and all core gameplay features
- Send push notifications you have requested
- Send transactional emails — email verification, password reset
- Investigate and prevent abuse, cheating, and violations of our Terms of Service
- Maintain, improve, and troubleshoot the Service
We do not use your information for advertising and we do not sell it to third parties.
3. Third-Party Services
We share your information with the following service providers that help us operate the Service. Each acts as a data processor bound to use your data only as directed by us.
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Amazon Web Services | Hosting, database, and email delivery (SES) | aws.amazon.com/privacy |
| Firebase (Google) | Push notification delivery (FCM) | firebase.google.com/support/privacy |
| Google Sign-In | Optional social authentication | policies.google.com/privacy |
| Apple (Sign in with Apple) | Optional social authentication | apple.com/legal/privacy |
4. Data Sharing
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may disclose your information only:
- To the service providers described in Section 3
- If required by law, court order, or a valid government authority request
- To protect the rights, property, or safety of HEAPO Solutions, LLC, our users, or the public
- In connection with a merger, acquisition, or sale of substantially all of our assets — you will be notified before your information is transferred and becomes subject to a different privacy policy
5. Data Retention
We retain your personal information for as long as your account is active. When you delete your account:
- Your personal data (username, email address, display name) is deleted within 30 days
- Automated backup systems may retain copies for up to 90 days before purging
- Anonymized, aggregated gameplay data (win/loss records, league history) may be retained indefinitely for historical record purposes and cannot be linked back to you
You can delete your account at any time from Settings → Delete Account within the app, or by contacting us at the address in Section 10.
6. Security
We use industry-standard measures to protect your information:
- Passwords are stored as cryptographic hashes — we never store plaintext passwords
- All data is transmitted over HTTPS/TLS
- Our database is hosted on a private network with no direct internet access
- Authenticated sessions use short-lived JWT tokens (24-hour expiration)
No method of electronic transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately.
7. Children's Privacy
The Service is intended for users who are at least 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at the address in Section 10 and we will delete that information promptly.
8. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access — Request a copy of the personal information we hold about you
- Correction — Request that we correct inaccurate or incomplete information
- Deletion — Request that we delete your personal information (you can also do this directly in the app via Settings → Delete Account)
- Portability — Request your data in a structured, machine-readable format
To exercise any of these rights, contact us at the address in Section 10. We will respond within 30 days. Some information may be retained as required by law or for legitimate business purposes even after a deletion request.
California Residents (CCPA)
California residents may have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect and the right to opt out of the sale of personal information. We do not sell personal information.
European Users (GDPR)
If you are located in the European Economic Area, our legal basis for processing your personal information is (i) contract performance — operating your account and the game, (ii) legitimate interests — security and fraud prevention, and (iii) your consent — push notifications. You have the right to lodge a complaint with your local supervisory authority.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the Effective Date at the top of this page. For material changes we will provide notice via email or a prominent in-app notification. Your continued use of the Service after changes take effect constitutes your acceptance of the updated Policy.
10. Contact Us
If you have questions or requests regarding this Privacy Policy, please contact:
HEAPO Solutions, LLC
Email: legal [at] 16bithockey [dot] com