Hustlr.io
Play High Scores Account

Privacy Policy

Last updated: July 2, 2026

This Privacy Policy describes how BLOCKXS ("Hustlr.io", "we", "us", or "our"), Südstr. 58, 58509 Lüdenscheid, Germany, collects, uses, shares and protects personal information when you visit our websites, create an account, or play Hustlr.io (collectively, the "Services"). By using the Services you agree to the collection and use of information in accordance with this policy.

1. Data Controller

The controller responsible for data processing under the EU General Data Protection Regulation (GDPR) is:

BLOCKXS
Südstr. 58
58509 Lüdenscheid
Germany

See our Imprint for full legal details and contact information.

2. Information We Collect

2.1 Information you provide

  • Account information: username and password (stored hashed) when you register. An email address is optional unless you use a third-party sign-in.
  • Google Sign-In: if you sign in with Google, we receive your Google account identifier, email address, name and profile picture as provided by Google. We do not receive your Google password. Google's processing is governed by the Google Privacy Policy.
  • Purchase information: if you buy virtual items or currency, payments are processed by third-party payment providers. We receive transaction confirmations but never store full payment card details.
  • Communications: in-game chat messages and any messages you send to us (e.g. support requests).

2.2 Information collected automatically

  • Gameplay data: character progress, inventory, in-game currency, playtime, positions and actions in the game world, required to operate a persistent online world.
  • Technical data: IP address, device and browser type, operating system, screen resolution, language settings, connection timestamps and crash/error logs.
  • Local storage: we use browser local storage to keep you logged in, remember settings (e.g. music mute, controls) and cache game assets for performance. See Section 7.

3. How We Use Information

  • To create and manage your account and authenticate you (Art. 6(1)(b) GDPR — contract performance);
  • To operate the persistent game world, save your progress and synchronize gameplay between players (Art. 6(1)(b));
  • To process purchases and prevent payment fraud (Art. 6(1)(b), (f));
  • To enforce our Terms of Service, detect cheating, abuse, and to keep the Services safe and fair (Art. 6(1)(f) — legitimate interest);
  • To maintain, debug and improve performance and stability of the Services (Art. 6(1)(f));
  • To comply with legal obligations (Art. 6(1)(c)).

We do not sell your personal information, and we do not use it for third-party advertising.

4. Sharing of Information

  • Other players: your username, character appearance, in-game actions and chat messages are visible to other players as part of normal multiplayer gameplay.
  • Service providers: hosting, infrastructure and payment providers who process data on our behalf under data processing agreements.
  • Sign-in providers: if you use Google Sign-In, Google processes data as an independent controller.
  • Legal reasons: where required by law, court order, or to protect our rights, our players or the public.

We do not transfer personal data outside the EU/EEA unless adequate safeguards (e.g. EU Standard Contractual Clauses) are in place.

5. Data Retention

We keep account and gameplay data for as long as your account exists. If you delete your account, we delete or anonymize your personal data within 30 days, except where we must retain it to comply with legal obligations (e.g. tax records for purchases) or to resolve disputes. Server logs are retained for a maximum of 14 days.

6. Your Rights (GDPR)

You have the right to access, rectify, erase, and receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. To exercise these rights, contact us using the details in the Imprint. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).

7. Cookies & Local Storage

The Services use only technically necessary browser storage: session/login tokens, gameplay settings, and asset caching (service worker) to reduce load times and bandwidth. We do not use tracking or advertising cookies. If you use Google Sign-In, Google may set cookies necessary to provide the sign-in function.

8. Security

We use appropriate technical and organizational measures to protect your data, including TLS encryption in transit, password hashing, and access controls. No method of transmission or storage is 100% secure, but we work to protect your personal information in line with industry standards.

9. Children

The Services are not directed to children under 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent. If you believe a child has provided us personal data, please contact us and we will delete it.

10. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last updated" date, and for material changes we will provide additional notice in the Services.

11. Contact

BLOCKXS
Tobias Plomann
Südstr. 58
58509 Lüdenscheid
Germany
Email: blockxs@proton.me

Terms of Service Privacy Policy Imprint