Privacy Policy
Last updated: July 24, 2026
1. Who operates hiphop.id
hiphop.id is operated by One vs Many LLC as part of the 1vsM network.
hiphop.id is the public passport surface — one URL,
hiphop.id/{username}, that shows a member's links, socials and tip handles.
hiphop.id is not the identity authority. It is a thin presentation layer over hiphop.world, which stores and owns every identity record described below. The two sites are operated by the same company and share one database; hiphop.id reads and writes identity only through hiphop.world's own code. hiphop.world's network policy is at hiphop.world/privacy and also applies to your account.
Privacy questions: contact@1vsm.com. Requests about your identity record itself (access, correction, deletion): contact@hiphop.world.
2. What we collect, and why
2.1 Your account and passport (you provide it)
- Username, display name, email address and password — created on hiphop.world, not here. The password is stored hashed; hiphop.id never sees or stores it after the sign-in request. Purpose: to authenticate you and to give your passport an address.
- Profile details — bio, avatar image URL, social handles. Purpose: they are the passport. You choose what to fill in.
- Links — the title and URL of every link you add. Purpose: they are the passport. A link added here also appears on your hiphop.world profile — it is one identity.
- Tip handles — a payment method (CashApp, Venmo, PayPal) or a crypto address (BTC, ETH, SOL), plus an optional label. Purpose: display only. No money moves through hiphop.id. Fiat handles become deep links to your own account on the provider's site; crypto addresses are shown as text to copy or scan. We hold no funds, take no custody, run no checkout, collect no amount, and perform no KYC.
- Verification tier — self-claimed, peer-verified or notarized. Purpose: to show visitors how strongly the identity is attested.
Your internal Hip Hop ID is owner-only. It is never rendered on a public passport, never returned by the public API, and is stripped from your own data export.
2.2 Cookies we set
hiphop_id_session— hiphop.id's own sign-in session. Set only once you sign in. HTTP-only,SameSite=Lax, marked Secure over HTTPS, 30-day lifetime by default. It also carries the CSRF token that protects every write.hhid_sso_seen— a 15-minute marker set when you first land on the homepage signed out. Its only job is to stop us asking the network hub "is this browser signed in?" on every single visit. It contains the value1and nothing else.
We set no advertising cookies, no third-party analytics scripts, and no cross-site trackers on hiphop.id.
2.3 What we do not collect here
hiphop.id's own database tables are analytics only and hold no identity: a badge-embed table (a username and the host a badge was embedded on — no path, no query string, no visitor identifier) and a QR-scan table (a username and a timestamp). Neither records who you are, your IP address, or what you looked at.
Ordinary web-server access logs and PHP error logs exist on the host, as on any website, and can contain an IP address. They are used for security and debugging only.
3. How signing in works
hiphop.id does not run its own account system and does not use federated tokens. When you sign in here, your username and password are checked by hiphop.world's own login code against the shared account table. Two-factor authentication is never bypassed — if 2FA is on, you are asked to finish signing in on hiphop.world.
Because the network shares one identity, two hops can happen automatically:
- Landing on hiphop.id signed out sends one silent round trip to hiphop.world to ask whether
that browser already has a network session. If it does not, you come straight back and see the
page. Passport links (
hiphop.id/{username}) are never probed — they load directly for guests. - Signing in on hiphop.id issues a single-use, short-lived token so hiphop.world recognizes you too.
Those tokens are single-use, expire quickly, and are bound to the site they were minted for.
4. What is public
A passport is a public page by design. When your passport is visible, anyone with the URL can see your display name, avatar, bio, verification tier, links and tip handles. Your email address, your password, and your Hip Hop ID are never shown. If your profile is set to private, the page says so and shows nothing else.
5. Who else sees your data
We do not sell your personal information. It is shared only:
- With hiphop.world — the identity authority, operated by the same company on the same database. This is not a transfer to a third party; it is where the record lives.
- With anyone who opens your passport — see section 4.
- With a tip provider, only when a visitor chooses to go there. Tapping a CashApp, Venmo or PayPal button leaves hiphop.id for that provider's own site, under that provider's own privacy policy. We send them nothing but the handle you published.
- With our hosting provider, which stores the database and serves the site.
- When the law requires it — a valid legal order, or to protect the safety and rights of members and the public.
6. Where it is stored, and for how long
Identity data is stored in hiphop.world's MySQL database on servers in the United States. If you use hiphop.id from outside the United States, your information is processed there.
Retention follows the network policy at hiphop.world/privacy: account data is kept while your account is active and removed within 30 days of deletion; server access logs containing IP addresses are kept for 90 days; error logs for 30 days. hiphop.id's own analytics counts (section 2.3) contain no personal data and are kept indefinitely as aggregate numbers.
7. Your rights, and how to use them
- Get a copy. Signed in, you can download your own identity as JSON at any time. The export is self-only by construction — there is no way to export anyone else — and your Hip Hop ID is stripped from it.
- Correct it. Edit your profile, links and tip handles from your passport editor. Changes write straight to the identity record.
- Delete it. Deleting your account is done on hiphop.world, because that is where the account exists — removing it there removes the passport here. You can also email contact@hiphop.world with the subject line "Deletion Request".
- Object or restrict. Email contact@1vsm.com and we will route it.
If you are in the EEA, the UK or Switzerland, or you are a California resident, the network policy at hiphop.world/privacy sets out your GDPR and CCPA rights and the response windows that apply to your account.
8. Children
hiphop.id is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has an account, email contact@hiphop.world and we will remove it.
9. Security
Passwords are stored hashed by hiphop.world and never in plain text. hiphop.id is served over HTTPS only, sets a hardened session cookie, requires a CSRF token on every write, validates tip handles server-side, and escapes every value it renders. No system is perfectly secure — if you find a vulnerability, please report it to contact@1vsm.com rather than disclosing it publicly.
10. Changes to this policy
If we change this policy in a way that matters, we will update the date at the top of this page and, where we reasonably can, notify account holders. Continuing to use hiphop.id after a change means you accept the updated policy.
11. Contact
One vs Many LLC — contact@1vsm.com
Identity and account requests — contact@hiphop.world