Privacy Policy
Last updated: January 26, 2026
This Privacy Policy explains how Hopae Inc. (“PlayID,” “we,” or “us”) collects, uses, shares, and protects your personal information when you use the PlayID website and services (the “Service”). Hopae Inc. is the controller responsible for that information. This policy applies to everyone who uses the Service, wherever you are located.
1. Information we collect
We collect only what we need to run the Service, and what we collect depends on how you use it:
- Account information — your email and display name, plus your password (stored hashed) if you sign up with one. If you sign in with Google, we receive your email and name from Google instead.
- Identity & age attributes— confirmed through Hopae Connect, a digital identity-verification service, when you verify. You complete verification through Hopae Connect, and PlayID receives only the result: a verification reference, your verified status, your verified name (shown on your profile), and your date of birth, which we use to confirm your age (including for age-restricted events, for example over 18 or over 21). You review and approve the information that will be shared, and PlayID never receives the identity information Hopae Connect uses to verify you.
- Orders and tickets— the events, ticket types, and amounts you purchase, and when your ticket's QR code is scanned for entry. Payments are handled by Stripe; we never store your card details.
- Competition entries — some events and competitions require additional information, which varies by event. We collect only the items the organizer requires (for example, name, date of birth, nationality, contact details, or team), disclose them to you before you enter, use them only to run that event, and delete them once that purpose is fulfilled, unless the law requires us to keep them longer.
- Support — your email, name, and the contents of your inquiry when you contact us.
- Usage data — standard logs and device information, such as your IP address, device and browser type, pages viewed, and timestamps, needed to keep the Service secure and reliable. We use only essential cookies.
2. How we use your information
We use your information primarily to prevent scalping (the unauthorized resale of tickets): each ticket is bound to a verified person, and per-person limits help prevent bots and resellers from hoarding and flipping inventory. We also use it to operate your account, issue and validate tickets, confirm age for age-restricted events, run competitions you enter, respond to support requests, keep the Service secure, and meet our legal obligations. We do not sell your personal information, and we do not use it for cross-context behavioral advertising.
Where the EU or UK GDPR applies, our legal bases for this processing are: performance of our contract with you (creating your account, issuing and validating tickets, and verifying your identity and age); compliance with legal obligations (such as tax and accounting records); and our legitimate interests in preventing scalping, fraud, and abuse and in keeping the Service secure. Where we rely on your consent, you may withdraw it at any time.
3. Identity and age verification
Verification is carried out through Hopae Connect, a digital identity-verification service, which confirms that you are a real, unique person. Hopae Connect handles the underlying data used to verify you; PlayID receives only verified attributes in return — including your verified name and date of birth — which we use to confirm your identity and your eligibility for age-restricted events (for example, 18+ or 21+).
You review and approve the information that will be shared before it is shared. PlayID stores a verification reference, your verified status, your verified name, and your date of birth — not the underlying data Hopae Connect used to verify you. We hold only these verified attributes, and treat your identity and age data as sensitive (see Section 8).
4. When we share information
We disclose personal information only:
- To service providers that process data on our behalf — under our instructions and contractual safeguards, including Stripe (payment processing), Supabase (database and authentication, on AWS infrastructure), Vercel (application hosting), and providers that help us deliver email and keep the Service secure. They act as our processors, using your information only to provide these services to us — not as independent recipients for their own purposes. Identity verification is handled separately by Hopae Connect, described in Section 3.
- With event organizers— only for events or competitions you join, only the items the organizer requires (disclosed at registration, for example name, date of birth, or eligibility attributes), and only to run that event. Each organizer's retention period is stated at registration.
- When required by law, or to protect the rights, safety, and integrity of the Service and its users.
- In a business transfer (such as a merger or acquisition), in which case we will notify you as required by law and require the recipient to protect your information consistently with this policy unless and until an updated policy or your consent applies.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. International transfers
PlayID is a global service. When you create an account and use PlayID, your personal information is transferred to and stored in the United States, where our platform and our processors — Stripe (payments), Supabase (database and authentication), and Vercel (hosting) — operate. Identity and age verification is carried out by Hopae Connect in the European Union, and PlayID receives only the verification result — a reference, your verified status, name, and date of birth — into its U.S. systems. We transfer only the account, order, and verification-reference data needed to run the Service, and keep it only for the periods described in Section 6.
When personal information is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, and — where a processor is certified — on the EU-U.S. Data Privacy Framework. You can request a copy of these safeguards by emailing esports@hopae.com.
6. Retention
We keep your information for as long as your account is active. When you close your account, we delete or anonymize your personal information promptly, except where we must keep it longer: order and tax records retained as required by law, competition records retained for the period stated at registration, and records of accounts restricted for fraud or abuse, which we may retain as permitted by law to keep the Service fair.
7. Security
We protect personal information with administrative, technical, and physical measures — access controls and least-privilege permissions, encryption, security monitoring, and staff training. Hopae maintains ISO/IEC 27001 and ISO/IEC 27701 certifications and undergoes SOC 2 (Type II) examinations. If a personal-data breach affects your information, we will notify you and the relevant authorities without undue delay where the law requires.
8. Your rights
Depending on where you live, you may have rights under laws such as the California Consumer Privacy Act and other U.S. state privacy laws, the EU or UK GDPR, or Korea's Personal Information Protection Act. Wherever you are, we honor requests to:
- access the personal information we hold about you, and receive a copy;
- correct inaccurate information;
- delete your information (subject to the retention exceptions in Section 6);
- restrict or object to certain processing;
- receive the information you gave us in a portable, machine-readable format, and have it transferred to another service where technically feasible; and
- ask for human review of a decision made solely by automated means (for example, an automated account restriction).
Contact us at esports@hopae.com and we will respond promptly. An authorized agent — or the parent or legal guardian of a minor — may exercise these rights on your behalf. We will never discriminate against you for exercising them, and where the GDPR applies you may also lodge a complaint with your local supervisory authority. You are always free to decline to provide personal information, though some features — such as buying tickets, which requires verification — may then be unavailable. Because we treat your identity and age data as sensitive, we use it only for the purposes described in this policy.
9. Children and minors
The Service is not directed to children under 13, and we do not knowingly collect their personal information; if we learn that we have, we will delete it. Users under 18 may use PlayID only with the consent and supervision of a parent or legal guardian. Competitions involving minors aged 13–17 require separate parent-or-guardian consent for collecting and sharing the entrant's information as part of that competition's registration. Parents and guardians may review, correct, or delete their child's information at any time using the contact below.
10. Privacy contact
Privacy Officer: Kim Jun-min, Head of Trust — Hopae Inc.
Hopae Inc., 28 Geary St, STE 650 #355, San Francisco, CA 94108, USA
esports@hopae.com
EU representative (GDPR Art. 27): Kim Jun-min, c/o Hopae S.A., 20 Rue des Peupliers, L-2328 Luxembourg.
11. Changes to this policy
We may update this policy as the law and the Service evolve. We announce material changes on the Service at least 7 days before they take effect.