HangOn

Privacy Policy

Version 1.0 · Effective April 13, 2026 · DPDP Act 2023 Compliant

We do not sell personal data. We do not show ads. Partners never see your PAN or UPI.
Data Protection Officer: dpo@hangon.live

1. Who We Are and Who This Covers

HangOn Interactive Private Limited is the Data Fiduciary under the DPDP Act 2023. This policy applies to all Users of any HangOn feature: tournaments, discovery, chat, feed, voice rooms, venue booking, and rewards.

2. What Data We Collect and Why

2.1 Account and Identity

DataWhy We Collect ItLegal Basis
Mobile phone numberAccount login, OTP verificationContract
Display nameProfile display across all featuresContract
Date of birthAge verification, minor account detectionLegal obligation
Profile photoDiscovery, social feed identityConsent
City / locationLocal tournament and venue discoveryConsent
Guardian phone + PAN + UPI (minor accounts)Financial compliance for minorsLegal obligation

2.2 Gaming Profile

DataWhyLegal Basis
In-game names (IGNs)Tournament registration, profile displayContract
Game player IDsTournament verificationContract
Game ranks and statsProfile display, matchmakingConsent
Gaming platform (Mobile/PC)Tournament filteringContract
Playstyle preferencesDiscovery matchingConsent

2.3 Tournament Financial Data

DataWhyShared WithLegal Basis
PAN numberTDS deduction + Form 16AIncome Tax Dept.Legal obligation
UPI IDPrize payout disbursementRazorpay onlyContract
Entry fee payment IDRefund processingRazorpay onlyContract
Net winnings per FYAnnual TDS reconciliationIncome Tax Dept.Legal obligation

2.4 Partner Financial Data (Partners Only)

DataWhyShared With
Business name + addressPartner profile, KYCNot shared
PAN / GST numberTax compliance, KYCTax authorities if required
Bank account + IFSCEarnings settlementRazorpay only
Tournament history and earningsSettlement, analyticsNot shared

2.5 Social and Communication Data

DataWhyWho Can See It
Social feed posts and mediaFeed displayBased on your privacy settings
Chat messagesMessaging serviceOnly the parties in the conversation
Voice room participationService deliveryOther room participants (live only)
Connections / matchesDiscovery featureOnly you and the connected user
Blocked users listSafety featureOnly you
Reports submittedSafety and moderationHangOn safety team only

2.6 Venue Booking Data

DataWhyShared With
Booking date/time/venueBooking confirmationThe booked venue (Partner)
Payment for bookingTransaction processingRazorpay only
Booking historyRefund processing, recordsNot shared

2.7 Automatically Collected Data

DataWhyLegal Basis
Device fingerprint (hashed)Multi-account fraud detectionLegitimate interest
IP addressGeographic restriction enforcementLegal obligation
City-level GPS (if permitted)Local discovery, venue proximityConsent
App version and OSBug fixes, compatibilityLegitimate interest
Session and usage dataFeature improvementLegitimate interest
Push notification tokenTransactional notificationsContract
Crash reportsStability improvementsLegitimate interest

3. What We Do NOT Collect

  • Full bank account credentials, card numbers, or net banking passwords
  • Your camera, microphone, or contacts without explicit in-app permission
  • Your location continuously — location is read only when you open the app
  • Data from minors under 13 under any circumstances

4. Data Sharing

4.1 Third-Party Service Providers

ProviderWhat They ReceivePurposeTheir Policy
RazorpayPayment IDs, UPI IDs, bank detailsPayment collection + payoutrazorpay.com/privacy
Cloudflare R2Screenshots, profile photos, KYC docsSecure file storagecloudflare.com/privacypolicy
Expo / FirebasePush notification tokens onlyNotificationsexpo.dev/privacy
MSG91 / TwilioPhone number + OTP messageOTP verificationProvider privacy policy

4.2 Legal Disclosures

We share data with government and law enforcement authorities when: required by a valid court order or warrant, required by law (e.g. quarterly TDS filings with Income Tax Department), or in cases involving imminent threat to life or CSAM. We will attempt to notify you of legal requests unless prohibited by law.

4.3 What We Never Share

  • Your PAN, UPI ID, or bank details with any Partner, other Gamer, or advertiser
  • Your private chat messages with any third party except pursuant to a valid legal order
  • Your personal data with advertisers — HangOn does not run ad-based monetisation
  • Your contact details (phone number, email) with other users through any Platform feature

5. Data Retention

Data CategoryRetention PeriodReason
Account and profile data5 years after account deletionLegal disputes, audit
Tournament and result records7 yearsFinancial record requirement
TDS ledger and PAN data8 yearsIncome Tax Act obligation
Payment transaction records7 yearsGST and financial audit
Chat messages12 months, then permanently deletedService delivery
Social feed postsUntil you delete them + 30 daysCached copies
Tournament screenshots90 days post-tournamentDispute resolution
Device fingerprints2 years from last active sessionFraud prevention
Fraud signals and logs3 yearsPattern detection
Venue booking records3 yearsDispute and audit
Push notification tokensUntil account deletionService delivery
Voice room dataNot recorded — no retentionN/A

6. Your Rights under DPDP Act 2023

Right to access
Request a summary of personal data we hold about you and how it is used
Right to correction
Request correction of inaccurate or incomplete data
Right to erasure
Request deletion of your data, subject to legal retention obligations
Right to withdraw consent
Withdraw consent where processing is consent-based (may affect feature access)
Right to nominate
Nominate a person to exercise your rights in case of death or incapacity
Right to grievance
Lodge a complaint with our DPO or the Data Protection Board of India

Exercise your rights by contacting dpo@hangon.live. We respond within 30 days. We may require identity verification before processing a request.

7. Permissions the App Requests

PermissionWhy NeededWhen RequestedCan You Decline?
CameraProfile photo, screenshot uploadWhen you choose to uploadYes — use gallery instead
Photo LibraryScreenshot upload for verificationWhen submitting match proofYes — disqualifies from payout
MicrophoneVoice roomsWhen you join a voice roomYes — listen-only mode
Location (approximate)Local tournament/venue discoveryWhen you open discoveryYes — city selection manually
NotificationsTournament updates, creds, payoutsAt onboardingYes — use app manually
ContactsNot requestedNeverN/A

8. Data Security

  • All data in transit: TLS 1.3 encryption
  • PAN, UPI IDs, bank details: AES-256 encryption at rest
  • Screenshots and KYC docs: stored in Cloudflare R2 with signed URL access — not publicly accessible
  • Access to financial data: restricted to named HangOn personnel on need-to-know basis
  • Admin accounts: 2FA mandatory
  • Data breach notification: within 72 hours of discovery to affected users and the Data Protection Board

9. Cookies and Tracking

The HangOn mobile app does not use browser cookies. The HangOn website uses essential session cookies only for authentication. No advertising, analytics, or third-party tracking cookies are used on any HangOn surface. HangOn does not use pixel tracking or fingerprinting technologies on the website beyond what is described in Section 2.7.

10. Children's Privacy

HangOn does not knowingly collect personal data from users under 13. For users aged 13–17, data processing is conducted under Guardian consent. Guardian data is processed only for the purpose of enabling the minor's account and financial transactions. For full minor data protection details see the Child Safety Policy.

11. Contact

Data Protection Officer (DPDP Act)
dpo@hangon.live
Grievance Officer
grievance@hangon.live
Privacy Queries
privacy@hangon.live
Data Protection Board of India
www.meity.gov.in

HangOn Interactive Private Limited, Delhi, India · hangon.live