Privacy Policy – Hitster App

1. Introduction

We respect your privacy and are committed to ensuring that your personal information is handled safely and responsibly. This Privacy Policy explains what data the Hitster app collects, how we use it, and your rights.

The Hitster app is designed to be privacy-friendly. It does not collect or store any data that directly identifies you. All analytics are anonymous and used only to improve the app’s functionality and performance.

2. What the App Does

The Hitster app allows players to scan QR codes on game cards and enjoy an interactive music-based experience.
To maintain and improve the app, we collect limited technical information about how the app is used.
This includes event data such as:

  • the number of sessions started;
  • general app performance (crashes, loading times);
  • basic app installation statistics; and
  • debugging information to resolve technical issues.

No personal identifiers, account details, or contact information are collected.

3. Data Collected and Purpose of Use

  • Functional and usage data: To understand how features are used and maintain technical performance.
    • Example: Number of sessions started
    • Legal basis: Legitimate interest (Article 6(1)(f) GDPR)
  • Crash and debugging data: To detect and fix app errors.
    • Example: crash reports, error logs, etc.
    • Legal basis: Legitimate interest (Article 6(1)(f) GDPR)
  • Installation and usage metrics: To measure downloads and general app stability.
    • Example: app install events
    • Legal basis: Legitimate interest (Article 6(1)(f) GDPR)

We do not collect names, contact details, advertising identifiers, or precise location data.
We also do not use cookies, marketing pixels, or any technology that tracks you across apps or websites.

4. How Analytics Work

We use Google Firebase Analytics to gather aggregated, anonymous usage information.
Firebase generates a random App Instance ID when you first open the app.
This ID allows us to measure how often the app is used, but does not identify you personally.
The ID resets automatically when the app is uninstalled, and IP addresses are not logged or stored.
All advertising features (including Google Signals and Advertising IDs) are disabled.

Data processing occurs in Google’s European servers under Jumbo Group’s control and in accordance with Google’s Data Processing Terms.

5. Legal Basis for Processing

Because we collect only technical usage data, we rely on legitimate interest under Article 6(1)(f) GDPR for the purpose of:

  • maintaining app functionality;
  • ensuring security and debugging; and
  • understanding feature usage to improve the user experience.

No consent banner is required under the ePrivacy Directive, as no cookies or non-essential tracking identifiers are used.

6. Data Retention

We retain only aggregated and anonymized event data for as long as necessary to analyze app performance and maintain functionality.
Data linked to the App Instance ID automatically expires or becomes irretrievable once you uninstall the app

7. Data Recipients

Access to analytics data is limited to:

  • the Hitster development team;
  • the Jumbo Group app team (for compliance and oversight); and
  • The Data Story (technical analytics support provider).

All parties operate under confidentiality and data processing agreements in compliance with the GDPR.

8. International Data Transfers

Analytics data is stored within the European Union through Google Cloud’s EU data region.
Where data may be transferred outside the EEA (e.g. for Google’s technical support), this is governed by Standard Contractual Clauses (SCCs) approved by the European Commission.

9. Your Rights

Because the data processed through the Hitster app does not identify you, your GDPR rights (such as access, rectification, or erasure) generally do not apply.
However, if you contact us regarding privacy matters, we will respond to your request transparently and assist where possible.
You can reach us at gdpr@jumboplay.com.

If you believe we have not handled your data appropriately, you may contact your local Data Protection Authority.

10. Security and Anonymity

We take appropriate technical and organizational measures to ensure that all event data is anonymous, aggregated, and processed securely.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in technology or regulation.
The latest version will always be available within the app and on our website.

12. Contact Us

For any questions about this Privacy Policy or our data practices, please contact: gdpr@jumboplay.com.
Jumbo Group B.V., Westzijde 184, 1506 EK Zaandam, The Netherlands