Legal
Privacy Policy
01Scope
This policy explains what personal data the HYPURR.STKR app and the website at hypurrstkr.xyz collect, why, who else sees it, and what you can do about it. It applies to the Service described in our Terms of Service.
We are the controller of this data. We handle it under the Korean Personal Information Protection Act (PIPA) and, where they apply to you, under other applicable privacy laws.
02What we collect
| Category | Items | Source |
|---|---|---|
| Account | Email address; the social account identifier you sign in with (Apple or Google); your embedded wallet address | You, via our login provider |
| Wallets | Wallet addresses you bind, and the message signatures proving you control them; NFT holdings read at snapshot | You, and public blockchain data |
| Orders & delivery | Recipient name, shipping address, contact details, order contents, order status, carrier and tracking number | You |
| Payment | Paying wallet address, transaction hash, amount, asset, chain | You, and the blockchain |
| Consent records | NFT Holder License signature, licence version, timestamp | You |
| Support | Messages you send us and what we reply | You |
| Technical | IP address, device and OS type, app version, timestamps, error logs | Collected automatically |
| Notifications | Push token for this device (Firebase Cloud Messaging / Apple Push Notification service), device platform (iOS/Android), your device’s time zone (UTC offset and, on newer app versions, the IANA time-zone name — used only to word snapshot reminders in your local time), notification preferences (order updates on/off, drop alerts on/off, and which snapshot-reminder lead times you want — 1 day / 1 hour / 30 min / 5 min), an in-app inbox of the messages we sent you (title, short body, a reference such as an order number or series id, sent/read/hidden timestamps, plus internal delivery bookkeeping: how many push attempts were made and when the next retry is due), and an unread count that we send with each push as the app-icon badge number | Collected when you allow notifications and sign in; you can turn each type off in Notifications settings, and turning notifications off in iOS/Android settings stops delivery to that device |
We do not collect payment card numbers or bank details — we never see them, because payment is on-chain. We do not collect government ID, and we do not ask for your private keys or seed phrase. No one legitimate will ever ask you for those, including us.
The app does not request camera, microphone, location, contacts, or NFC permissions. Event pickup uses a QR code that the app displays; it is scanned by our staff’s device, not by yours. The pickup QR image itself contains only a short-lived random ticket id, its expiry, and a server signature — not your wallet address or name. (Our server keeps a matching ticket record that does link that random id to your wallet, the series and event it is for, and when it was issued, invalidated, and scanned — see §7.) If you enable Face ID / Touch ID for quick sign-in, the check is done by your device’s operating system; we never receive biometric data, only whether the check passed.
03Why we use it
- To run your account — sign-in, session, profile.
- To check eligibility — reading public holdings for the wallets you bind.
- To fulfil orders — production, payment verification, shipping, pickup, and returns.
- To keep legal records — consent signatures, transaction and contract records we must retain.
- To support you — answering enquiries and handling complaints.
- To keep the Service safe — preventing fraud, abuse, and sanctions breaches.
We rely on your consent, on performing our contract with you, on complying with legal obligations, and on our legitimate interest in operating and securing the Service. We do not sell personal data and we do not use it for advertising profiling.
04On-chain data
A wallet address is pseudonymous, not anonymous. If an address is linked to you elsewhere — on an exchange, a social profile, or a name service — its activity here can be linked to you too. Consider that before binding a wallet you use for other things.
When you delete your account we remove the link between your identity and your addresses in our records, as described in section 9. The on-chain record remains.
05Who we share with
We share only what each provider needs, under contracts requiring them to protect it. We do not share your data with anyone else except where the law requires it, or to establish or defend legal claims.
| Provider | Purpose | Data they receive |
|---|---|---|
| Privy | Login and embedded wallet | Email, social account identifier, wallet address |
| Supabase | Database, file storage, backend functions | All account, order, shipping, and consent data |
| Vercel | Website hosting | IP address and request logs for the website |
| Shipping carriers | Delivery | Recipient name, address, contact details |
| Blockchain RPC providers | Reading holdings and transactions | Wallet addresses you query, and your IP address |
| Name resolution service | Resolving .hl names |
Wallet address or name queried |
| Apple / Google | App distribution and sign-in | Handled under their own privacy policies |
| Google Firebase Cloud Messaging / Apple Push Notification service | Delivering push notifications you opted into | Device push token, a message id and category, your current unread count (badge number), and the notification text: the message title (for order-related messages this names the series, the item and the new status, e.g. “2026-09 · V1 has shipped”) plus a short status sentence — lock-screen texts never include order numbers, tracking numbers, addresses or amounts; those are only in the authenticated in-app inbox |
Provider entities and processing locations (as published by each provider; we accept
each provider’s standard data processing terms as part of its service agreement):
Privy — Horkos, Inc. (United States); Supabase — Supabase, Inc. (United
States), with our database and storage hosted in the AWS Seoul region (Republic of
Korea); Vercel — Vercel Inc. (United States); push delivery — Google LLC
(Firebase Cloud Messaging, United States) and Apple Inc. (Apple Push Notification
service, United States); shipping — Korea Post (우정사업본부, Republic of Korea)
for domestic and outbound international parcels, handed to the destination postal
operator abroad; blockchain reads — public HyperEVM RPC endpoints operated by the
Hyper Foundation and, where configured, our own read-only RPC; .hl name
resolution — the operator of the Hyperliquid Names registry. The app and site
currently use no analytics, crash-reporting, or attribution SDK; if one is added, it
will be listed here.
06Transfers outside Korea
Our providers are located outside Korea, so your personal data is transferred abroad. PIPA requires us to tell you the following.
| Item | Detail |
|---|---|
| Recipients | Privy, Supabase, Vercel, shipping carriers, RPC and name-resolution providers, Google Firebase / Apple push services (section 5) |
| Countries | United States (Privy, Vercel, Google, Apple); Republic of Korea (Supabase database region — AWS Seoul; Korea Post); the destination country of an international parcel; and each provider’s published sub-processor locations |
| When and how | Transmitted over encrypted connections at the time you use the relevant feature |
| Data transferred | As listed for each provider in section 5 |
| Purpose | Providing the Service as described in section 3 |
| Retention by recipient | For the period in section 7, or until our contract with them ends |
| How to refuse | You may refuse. Because these providers are essential to sign-in, ordering, and delivery, refusing means you cannot use those parts of the Service. |
Separately, blockchain transactions are broadcast to a public global network with no fixed location, and cannot be restricted to any country.
07How long we keep it
We keep personal data only as long as needed, then delete, anonymise or pseudonymise it. Korean e-commerce law requires certain records to be kept for fixed periods, and those override a deletion request for those records only.
| Record | Period | Basis |
|---|---|---|
| Contracts and withdrawal of subscription | 5 years | E-Commerce Act |
| Payment and supply of goods | 5 years | E-Commerce Act |
| Consumer complaints and dispute handling | 3 years | E-Commerce Act |
| Display and advertising records | 6 months | E-Commerce Act |
| Access logs | 3 months | Communications Secrets Protection Act |
| Account profile and bound wallets | Until account deletion | Consent / contract |
| Licence signature records | For as long as your account exists — each record evidences your acceptance of the licence version you signed, and signing a newer version adds a new record rather than replacing the old one. The IP address and device string stored with a signature are erased when you delete your account, and the record itself is erased at the 7-day purge described in section 9. | Legal claims |
| Deletion register and revocation records | After you delete your account we keep your wallet address, the time you requested deletion and the time the 7-day purge ran (the deletion register), plus two technical fence records that are kept permanently: a session-revocation record (wallet address and a token version number) and device-token fence records (the push token identifier and a timestamp, with no readable content). These are what keep revoked sign-ins and push registrations revoked and let us evidence that the deletion happened. | Legal obligation / legal claims |
| Basic edition purchase-cap counter | We keep one purchase-cap counter per wallet for every series in which you buy Basic packs (series id, wallet address, number of packs bought), including series that have no per-wallet limit; it is what enforces the per-wallet Basic limit where a series has one. It is derived from your retained order records (section 7, pseudonymised ledger) and is kept after the 7-day purge so that the per-wallet limit cannot be reset by deleting and re-creating an account. It contains no contact or delivery details. | Contract / sales-policy enforcement (legitimate interest) |
| Operational alert logs | Alerts our operator receives while processing a deletion (for example when the wallet provider’s deletion has to be retried) may reference your wallet address and provider user id. They are kept for operations for up to 12 months. | Legitimate interest (operations) |
| Gas-relay job records | Each gas-sponsored USDC payment leaves a relay job row (wallet address, amount, transaction hash, outcome) that we keep for payment reconciliation under the 5-year rule above. The signature components of the payment authorisation are scrubbed from the row at the 7-day purge after account deletion. While a relay is in flight we also hold the signed raw relay transaction (which embeds the payer wallet, the amount, the authorisation nonce and the EIP-3009 signature) so that it can be re-broadcast; it is deleted within 7 days after the relay reaches a terminal state, and at the 7-day purge after account deletion. The append-only record of which relay attempt owned each relayer nonce keeps only the transaction hash, purpose, status and generation number — never the raw transaction. | E-Commerce Act / reconciliation |
| Push token and device time zone | Kept in our delivery list while that device is registered for notifications. When you sign out or the app unregisters the device, the server row for that token is removed from delivery. Until our server acknowledges that removal, the app keeps a local record on the device (in the operating system’s secure storage) of what it still has to tell us — the sign-in credential it was registered under, the push token, and the operation (register/unregister); each such record is cleared as soon as the server acknowledges it and there is no fixed time limit on the retry. If Apple/Google report the token as no longer valid, we do not delete the row: it is marked inactive (an “unregistered” timestamp) and is never sent to again; at present there is no automatic purge of these inactive rows, so the token string and its last account/time-zone remain in our database until deleted on request. A device that signs in with a different account takes over that token — the previous account stops receiving pushes on it immediately. | Consent (notification permission) |
| Notification preferences | One record per account (order updates on/off, drop alerts on/off, chosen snapshot-reminder lead times), kept while your account exists; you can change it at any time in Notifications settings | Consent |
| In-app inbox messages | You can delete messages one by one (swipe or select) or all at once. A deleted message disappears from all your devices immediately and its record (including delivery-attempt counters) is permanently erased from our database 30 days later. Every message is erased 12 months after it was created even if you never delete it, and all of your messages are erased immediately when you delete your account. Order facts themselves live in the order record (retention above), not in the inbox. | Contract / E-Commerce Act |
| Unread badge count | Not stored — computed from your inbox at the moment a push is sent | — |
| Pickup QR tickets | Each ticket is valid for a few minutes and is invalidated when a new one is issued or when it is scanned. The QR image carries only the random id, expiry, and signature; the server-side ticket record links that random id to your wallet address, the series and event label it was issued for, and the issue, invalidation, and scan times. Ticket records are kept with the pickup/order record; there is no separate purge job for them at present. | Contract |
08Your rights
You may at any time ask us to:
- tell you what data we hold about you, and give you a copy;
- correct data that is wrong or incomplete;
- delete your data;
- stop or restrict processing;
- withdraw consent you previously gave.
Email support@hypurrstkr.xyz. We respond within 10 days as PIPA requires. We may need to confirm it is really you before acting. We may refuse in the narrow cases the law allows — for example where a record must be retained under section 7 — and if we do, we will tell you why and how to object.
Depending on where you live you may have further rights, such as data portability or the right to object, and the right to complain to your local data protection authority.
09Deleting your account
You can delete your account from within the app (Profile → Delete account) in three steps: a summary of what will be erased, a confirmation signed with your wallet, and a final slide-to-confirm. You can also ask us by email (section 14). The deletion is refused while a payment or a sticker mint for your wallet is still in progress — this can last up to two hours while a recent payment attempt is unresolved; try again once it has settled. Once accepted, we immediately revoke every sign-in session, remove your push devices, notification preferences, inbox messages and wallet links, replace the recipient details on your orders and strip the IP address and device string from your order and licence records, and we ask our login provider (Privy) to delete the user record it holds for you. During the following seven days the same wallet cannot sign in again. Seven days after the request a scheduled server job erases every remaining off-chain record tied to your wallet address (pickup and shipping requests, licence signatures, wallet links, sign-in nonces, payment reservations and relay intents). Two technical records are kept permanently so that the revocation cannot be undone: a session-revocation record (wallet address and token version) and device-token fence records (push token identifier and timestamp, no readable content). If the provider-side deletion fails we retry it automatically every hour and our operator is alerted; if it is still pending when the 7-day purge runs, sign-in with that wallet stays blocked until the provider-side deletion succeeds.
The only records kept after the 7-day purge are: (i) order and payment ledger records that the Act on Consumer Protection in Electronic Commerce requires us to keep for 5 years (section 7), in pseudonymised form — recipient, address and contact details replaced, IP address and user-agent removed, while the wallet address itself stays as the transaction identifier required for on-chain reconciliation; (ii) public on-chain-derived data such as snapshot membership and the mint queue, which contains only your public wallet address; (iii) the deletion register and the permanent session-revocation and device-token fence records described in section 7, kept so that revoked credentials stay revoked and the deletion can be evidenced; (iv) gas-relay job rows kept for payment reconciliation, with their signature components scrubbed at the purge; (v) operational alert logs that may reference your wallet address and provider user id, kept for up to 12 months; and (vi) the Basic edition purchase-cap counter (series id, wallet address, number of packs bought) described in section 7, a sales-policy record derived from the retained order records and kept so that the per-wallet purchase limit cannot be reset by deleting and re-creating an account. These records are separated and restricted to legally-required or operational use only. HYPE payment attempt records (wallet address, order numbers, transaction hash, the quote signature and the request fingerprint — technical reconciliation data) are also kept for payment reconciliation, in the same way as gas-relay records. Until the payment is confirmed or abandoned, each attempt record additionally keeps the full signed quote (amounts, destination country, chain, treasury address and validity window) and the confirmation context needed to complete that request without asking you again (for shipping: the recipient name, phone number and address; for on-site pickup: the event and series); these two fields are cleared within 7 days after the payment is confirmed and within 30 days after the attempt is abandoned. Account-deletion intents (wallet address, the app-generated request reference and its state) are kept for 30 days so that the app can obtain a deletion receipt after the session is gone; the same request reference is also stamped on the deletion register entry and is removed from it after 30 days (the register itself is kept as described above). Rate-limit counters keyed by IP address or wallet address that protect our public endpoints are kept for about 24 hours (cleaned hourly; they may persist somewhat longer during outages).
10Cookies and analytics
The website uses only what is needed to serve the page. It does not set advertising or cross-site tracking cookies. Our host records standard server logs, including IP addresses, to deliver and secure the site.
The app currently includes no analytics, crash-reporting, or attribution SDK; the only third-party SDKs that talk to a server are our login/wallet provider, Firebase Cloud Messaging (push), and the blockchain/RPC libraries listed in section 5. If any such SDK is added later, we will disclose it here and in the App Store Connect App Privacy questionnaire, and add a consent mechanism where the law requires one.
11Children
The Service is not directed at children under 14, and we do not knowingly collect their personal data. If we learn we have, we delete it promptly. If you believe a child has given us data, contact us.
12Security
We use encrypted connections, access controls limiting who on our side can reach personal data, and separation of secrets from application code. We keep only the data we need.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
13Changes
We may update this policy. We post the new version here with a new effective date and, for changes that materially affect your rights, give notice in the app or by email at least 7 days before they take effect, or 30 days where the change concerns a matter that disadvantages you.
14Contact and complaints
| Data protection officer (개인정보 보호책임자) | Bae Young-jin (BAE YJ), Representative Director, SJ Partners Co., Ltd. |
|---|---|
| support@hypurrstkr.xyz | |
| Postal address | 53-6 Jukjeon-gil, Sangju-si, Gyeongsangbuk-do 37154, Republic of Korea (경상북도 상주시 죽전길 53-6) |
If you are not satisfied with our response, you may contact the Korea Personal Information Protection Commission (privacy.go.kr, 118), the Personal Information Infringement Report Centre, or the police cybercrime unit. If you are outside Korea, you may also contact your local data protection authority.