Privacy Policy
Last updated: August 4, 2026
1. Scope and Controller Information
This Privacy Policy explains how NitroPing collects, uses, discloses, and safeguards personal data when you use our websites, applications, and related services.
NitroPing is a product and brand of HighGround LLC, Sharjah Media City, Sharjah, UAE. In this Policy, "NitroPing", "we", "us", and "our" refer to HighGround LLC. For most processing described here, HighGround LLC is the data controller. In limited contexts, we may process data on behalf of a business customer under contract, in which case that customer is the controller and we act as processor. You can reach us about this Policy at [email protected].
2. Data We Collect
We collect personal data necessary to provide, secure, improve, and support the Services.
- Account data: email, authentication identifiers, profile preferences, language settings.
- Sign-in provider data: if you sign in with Google or Discord, we receive your name and profile picture from that provider to create and personalise your account. We never receive your password from them.
- Profile data you give us at sign-up: your name, your country, and your phone number. If you provide a phone number, we use it for account and support contact and, only if you separately opt in, for WhatsApp or SMS updates - we never send WhatsApp or SMS marketing messages unless you have opted in to that channel. If you choose to verify your number, we send it to our verification provider to deliver a one-time code, and we keep a short-lived verification record together with a one-way hash of the number to prevent abuse of the verification system. You can use NitroPing without providing these details.
- Marketing preferences: your opt-in choices for email, WhatsApp/SMS, and personalised marketing, together with a record of the consent you gave. If you opt in, marketing may cover HighGround LLC products and services, including NitroPing and future HighGround LLC products, as disclosed at opt-in; you can withdraw at any time, and marketing is never a condition of service.
- Subscription and transaction data: plan, billing status, renewal state, payment event metadata.
- Device and service telemetry: app version, device/OS details, diagnostics, service interaction events.
- Device identifier: a random value the app creates on your device the first time it runs. It is generated locally, is not derived from your hardware, your account, or any personal detail, and identifies a device rather than a person. We use it for one purpose only: to enforce the one-device-at-a-time limit described in the Terms, so that we can tell your own computers apart. It is stored on your device, and on our servers for as long as a connection slot is held, which expires automatically after 6 minutes (360 seconds) without activity. If a connection is refused because another device holds the slot, or an older session is replaced, the device identifiers involved are additionally kept in a security log for up to 30 days and then deleted automatically, so that we can explain and audit those decisions. The app's Clear All Data option deliberately keeps this one value, because discarding it would make your own computer look like a brand new device and could stop you connecting for several minutes.
- Consent and acceptance records: when you accept the Terms or this Policy, or change your marketing choices, we record which version you accepted, the time, your choice, and the IP address you acted from. We keep this as proof of the consent or acceptance you gave, and we use it for nothing else.
- Support data: messages, tickets, and attachments you provide to support.
- Security data: event logs used to detect abuse, fraud, service misuse, or security incidents. These logs record that a connection happened and how it went - which of our own servers you used, when, for how long, and whether it succeeded - not what you did through it. We do not build any record of the game servers or other destinations you connect to, or of the contents of your traffic, and where a diagnostic error message could contain such an address, the address is removed before the message is stored. Separately, if the app crashes, a crash report may be sent to our error-diagnostics provider so we can find and fix the fault. A crash report describes the state of the app at the moment it failed and can include a snapshot of the app's memory at that moment, which may incidentally contain whatever the app was handling when it crashed, such as the address of a server it was connected to. We use crash reports only to diagnose and fix faults, and we do not use them to build any record of where you connect or what you send.
3. How We Use Data and Legal Bases
Depending on your region, we rely on one or more legal bases, including contract performance, legitimate interests, consent, and legal obligations.
- Provide and operate the Services, including account access and subscription lifecycle.
- Maintain service integrity, reliability, anti-abuse controls, and security operations.
- Respond to support requests, troubleshoot incidents, and communicate service updates.
- Comply with legal obligations, enforce terms, and prevent fraud or misuse.
- Analyze and improve product quality and user experience in a privacy-conscious manner.
- Send you marketing by email, WhatsApp, or SMS, and personalise it, only where you have separately opted in to that channel (consent). If you opt in, marketing may cover HighGround LLC products and services, including NitroPing and future HighGround LLC products, as disclosed at opt-in. You can withdraw at any time, and we never make marketing a condition of using NitroPing.
4. Sharing and Disclosure
We disclose personal data only as needed to provide and secure the Services, comply with law, and operate our business.
We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
- Service providers and processors acting under contract on our instructions: cloud hosting and infrastructure providers (European Union, United States, and global edge locations), a payment processor (United States and global), a content delivery and security network (global), error-diagnostics and product-analytics providers (United States and European Union; analytics discards IP addresses at collection and never records game-server destinations or packet contents), email and phone-verification delivery providers (United States and global), and our game relay network (global). We describe these providers by category and location rather than by name. Where applicable law gives you the right to be told the identities of the specific providers that hold your personal data, you may request them by contacting [email protected].
- Professional advisors and corporate counterparties where necessary for lawful business operations.
- Authorities or other parties where required by law, court order, or valid legal process.
- Successors in the context of merger, financing, acquisition, or reorganization, subject to lawful safeguards.
5. International Transfers
Because we operate globally, personal data may be processed in countries other than your own.
Where required, we use lawful cross-border transfer mechanisms and supplementary safeguards designed to protect personal data.
6. Data Retention
We keep your account and profile data for as long as your account is active. If your account is inactive for a long period, we may re-confirm your marketing preferences or remove you from marketing.
When you delete your account, we delete your account, profile, and marketing data without undue delay, with a small number of deliberate exceptions kept only where the law requires or allows: (1) a minimal fraud-prevention record (your normalised email address, a one-way fingerprint of your payment card, and your payment processor's customer and subscription identifiers), kept and access-restricted solely to prevent repeat abuse of free trials and other fraud; (2) billing and tax records (largely held by our payment processor), kept for the period tax and accounting law requires, which can be several years; (3) a suppression record (a one-way hash of your email and, if provided, phone), kept so we never contact you again after you opt out or delete your account; and (4) proof of the acceptances and consents you gave - each such record contains the document version, the time, your choice, and the IP address you acted from - kept for as long as it stays relevant to demonstrating that we obtained your consent.
Separately, where you have contacted our support team or applied to our creator program, we may retain that support and contact correspondence and those creator-program applications under our legitimate interest in support auditing and fraud prevention. We keep these records no longer than necessary for those purposes.
We tell you at the point of collection that these minimal records survive account deletion, and if you ask us to erase your data we will tell you what we kept and why.
7. Data Security
We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, secure transmission practices, and monitoring for misuse or unauthorized access.
No system can be guaranteed fully secure, but we continuously improve controls and incident response readiness.
8. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port certain personal data, and to withdraw consent where consent is the legal basis.
You may submit rights requests through [email protected]. We may need to verify identity before fulfilling requests.
Where legally required, you may also have rights to appeal a request decision or complain to a supervisory authority.
9. Cookies and Similar Technologies
Our website and related services may use cookies or similar technologies for essential functions, performance, analytics, fraud prevention, and user experience improvements.
Where required by law, we provide controls for cookie preferences and consent management.
10. Children's Privacy
The Services are not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them or use it for marketing.
If you believe a child provided personal data contrary to this Policy, contact us and we will delete it and take appropriate action.
11. Region-Specific Disclosures
We apply region-specific privacy rights and disclosures where required, including rights frameworks in the EEA/UK, certain U.S. states, and other jurisdictions with mandatory privacy laws.
Nothing in this Policy limits non-waivable statutory rights in your jurisdiction.
12. Changes to This Policy
We may update this Policy periodically. Material changes will be reflected by an updated effective date and notice where required by law.
13. Contact
For privacy questions or rights requests, contact [email protected] or [email protected].
Governing language
This document is provided in English. Where a translation is made available, the English version is the authoritative version and prevails in the event of any discrepancy, except where mandatory law in your country requires otherwise.