1. Who We Are and What This Policy Covers
This privacy policy ("Policy") explains how RANDM.GAMES LTD ("RANDM.GAMES", "we", "us", "our") handles personal data when you use our mobile games, apps and related services - together, our "Apps", and each an "App".
RANDM.GAMES LTD is the data controller for the processing described here, and is a company incorporated in the Republic of Cyprus, having its registered office at 11, Stratigou Papagou str., 3091 Limassol, Cyprus. For any privacy question, or to exercise your rights, write to us at info@randm.games.
This Policy covers our whole present and future catalogue. Our Apps differ from one another, so some sections describe features - purchases, subscriptions, advertising, accounts, leaderboards or social features - that a particular App may not have. A section applies to you only where the App you are using offers the feature it describes.
Your use of our Apps is also governed by our Terms of Service at randm.games/terms-of-service.
2. Information We Collect
Depending on the App and on your choices, we may process:
- device and technical data: device model and manufacturer, operating system and version, system language, region and time zone, app version, IP address, and crash and diagnostic data;
- usage data: the screens and features you use, session length and timing, and events describing how an App is used;
- gameplay data: progress, achievements, scores, settings and, where an App offers multiplayer or social features, your interactions with other users;
- purchase data: what you bought, subscription and entitlement status, receipts and transaction identifiers, and the virtual items you receive and use;
- identifiers: app-instance identifiers, platform identifiers, and - only where you have given the consent described under Advertising and Your Choices - advertising identifiers such as Apple's IDFA and the Google Advertising ID;
- support data: your email address and the content of your message if you contact us;
- account and platform data, only where an App offers it and you choose to use it: display name, avatar, platform account identifier and leaderboard information received from services such as Apple Game Center, Google Play Games or Sign in with Apple.
Most of this data is generated automatically as an App runs, and we need it to provide the App, process purchases, keep things secure and answer support requests. Optional features, where an App offers them - personalised advertising, marketing messages, or connecting a platform account - can be refused or switched off without losing access to the App.
3. How We Use Information and Our Legal Bases
Running the Apps, saving your progress and providing the features you ask for. Data: device and technical data, usage and gameplay data, app-instance identifiers, and account and platform data where an App offers those features. Legal basis: performance of our contract with you, Article 6(1)(b) GDPR.
Processing purchases, subscriptions and entitlements, and keeping the records tax and accounting law requires. Data: purchase data, platform purchase references. Legal basis: performance of our contract, Article 6(1)(b), and compliance with a legal obligation, Article 6(1)(c).
Keeping the Apps secure and stable, preventing fraud and abuse, and diagnosing and fixing crashes. Data: technical data, crash and diagnostic logs, IP address, device and app-instance identifiers, event logs. Legal basis: our legitimate interest in providing a working and secure service, Article 6(1)(f), and performance of our contract.
Answering support requests and handling privacy requests. Data: contact details, your message, identifiers needed to find the right records. Legal basis: performance of our contract, Article 6(1)(b), our legal obligations, Article 6(1)(c), and our legitimate interest in responding to you, Article 6(1)(f).
Understanding how our Apps are used, so we can improve and balance them. Data: usage and gameplay events, app-instance identifiers, device and technical data. Legal basis: your consent where the law requires consent for storing or reading information on your device, Article 6(1)(a); otherwise our legitimate interest in improving our Apps, Article 6(1)(f), which you can object to at any time.
Showing contextual advertising, which is chosen from the App and screen you are on and coarse signals such as country, and not from a profile of your behaviour. Data: the App and screen you are on, device type, country and non-behavioural advert delivery data. Legal basis: our legitimate interest in funding free Apps, Article 6(1)(f), and your consent where the law requires it for access to your device.
Showing personalised advertising, and measuring advertising and app installs across apps. Data: advertising identifiers, usage events, attribution data and consent records. Legal basis: your consent only, Article 6(1)(a). We do not rely on legitimate interest for personalised advertising.
Complying with the law and establishing or defending legal claims. Legal basis: our legal obligations, Article 6(1)(c), and our legitimate interests, Article 6(1)(f).
Separately from the legal bases above, where the law requires consent before information is stored on or read from your device, we ask for it before any non-essential analytics, attribution or advertising technology starts. Storage and access that is strictly necessary to run an App, deliver a purchase you have made or keep the App secure may take place without consent.
We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you, within the meaning of Article 22 GDPR.
4. Advertising and Your Choices
Some of our Apps contain no advertising at all. Where an App does show advertising, it is either contextual - selected from the App you are using, the screen you are on and coarse signals such as country, without building a profile of your behaviour - or personalised, which uses your advertising identifier and your activity across apps to select adverts likely to interest you. For personalised advertising our only legal basis is your consent, and we do not treat the absence of an objection as consent.
Accepting our Terms of Service when you first open an App is not that consent, and we do not treat it as such. We ask separately and later - on iOS through Apple's App Tracking Transparency prompt, before any advertising identifier is accessed or shared. Where an App shows advertising, we also present a consent flow in the European Economic Area, the United Kingdom and Switzerland before any non-essential advertising or measurement technology starts, and it lets you refuse without losing access to the App. If you refuse, or do not answer, you can still use the App and will simply see contextual advertising, or none.
You can withdraw consent at any time, as easily as you gave it. Where an App shows personalised advertising it provides privacy or consent settings in the App's settings screen that reopen the same choices. On iOS you can also turn off tracking permission in Settings > Privacy & Security > Tracking. You can reset or delete your advertising identifier in your device settings at any time - "Limit Ad Tracking" or App Tracking Transparency on iOS, "Delete advertising ID" or "Opt out of Ads Personalisation" on Android. Withdrawing consent does not affect processing carried out before you withdrew.
5. Children
Our Apps are for a general audience and are not directed to children. We do not declare a target audience that includes children in the app stores we publish through, and we do not offer our Apps in the Apple Kids Category. An age rating in an app store describes what an App contains rather than who it is made for, so a low content rating does not mean an App is directed at children.
Our Apps are not intended for anyone under 16, unless the law of the country where you live sets a lower age for consenting to online services, in which case they are not intended for anyone under that lower age, which is never below 13. We do not ask you for a date of birth, because collecting one would mean collecting more personal data about you than we need.
Where an app store provides us with an age-assurance signal about an account, we act on it. Those signals come from the store rather than from us, and they do not include a specific birthdate. Where a signal indicates that a user is below the applicable age, we do not ask that user for advertising consent, we do not use an advertising identifier for personalised advertising, and we limit processing to what is strictly necessary to run the App and keep it secure.
Apart from that, we do not knowingly collect personal data from anyone below the applicable age. If we learn that we have, we delete it without undue delay.
A parent or guardian who believes that someone below the applicable age has given us personal data can write to info@randm.games with the name of the App and, where the App shows one, the identifier shown in the App's settings screen, and we will take reasonable steps to delete any personal data we can identify.
6. Partners We Use
The partners embedded in an App vary from App to App and change between releases. Each company named here processes data under its own privacy policy.
We currently use:
- RevenueCat, for subscription and in-app purchase infrastructure - www.revenuecat.com/privacy/;
- AppsFlyer, for install attribution and marketing measurement - www.appsflyer.com/legal/privacy-policy/;
- Apple, for App Store services, billing, Game Center and Sign in with Apple where an App uses them - www.apple.com/legal/privacy/;
- Google, for Google Play services, billing and Play Games where an App uses them - policies.google.com/privacy;
- Web3Forms, which delivers the contact form on our website. When you send that form, the name, email address and message you type are transmitted through Web3Forms to reach us by email - web3forms.com/privacy.
Depending on the App, and as our catalogue grows, we may also use partners in the following categories. The providers named are examples of who we expect to work with, and the list is not exhaustive:
- advertising mediation and advertising networks, for delivering, capping and measuring adverts, and - with your consent only - personalised adverts. We expect to use AppLovin MAX, and may use providers such as Google AdMob and Google Ad Manager, Unity Ads and Unity LevelPlay;
- attribution and marketing measurement, for install attribution, campaign performance and advertising fraud prevention. We expect to use Meta, and may use providers such as Adjust alongside AppsFlyer;
- product analytics, for gameplay events, retention and game balancing. We may use providers such as Google Analytics for Firebase and Amplitude;
- crash reporting and diagnostics, for stability and bug fixing. We may use providers such as Firebase Crashlytics and Sentry;
- push messaging, for service and - with your consent where required - promotional notifications. We may use providers such as Firebase Cloud Messaging and the Apple Push Notification service.
Some advertising and measurement partners, including Meta, do not act as our processors when they use data for their own advertising purposes. For those activities they act as an independent controller or as a joint controller with us, under their own privacy policies. Where we are joint controllers we agree who is responsible for what, and you may exercise your rights against either party.
7. How We Share Information
We share personal data with:
- the app stores and payment platforms that process purchases and subscriptions;
- service providers acting as our processors - subscription infrastructure, hosting, analytics, crash reporting, attribution, support and security - who act only on our instructions, are bound by data protection agreements, and cannot use the data for their own purposes;
- advertising, attribution and analytics partners, where an App uses them and your consent and settings permit;
- platform and social services, where an App offers them and you choose to connect;
- other users, where an App offers multiplayer, leaderboards or similar features and you take part;
- authorities, courts and our professional advisers, where the law requires it or where it is necessary to establish, exercise or defend legal claims, to investigate misuse, or in connection with a merger, acquisition, financing or transfer of assets.
8. International Data Transfers
We may transfer personal data outside the European Economic Area, the United Kingdom or Switzerland, including to the United States. Where we do, we rely on lawful safeguards: an adequacy decision of the European Commission; certification of the recipient under the EU-US Data Privacy Framework, together with the UK Extension and the Swiss-US Data Privacy Framework where relevant; the Standard Contractual Clauses approved by the European Commission, with the UK International Data Transfer Agreement or Addendum where required; or another lawful transfer mechanism. You may ask us for information about the safeguards we use for a particular transfer.
9. How Long We Keep Information
We keep personal data only as long as we need it, and then delete it or irreversibly anonymise it. Our standard periods are:
- gameplay and progress data: while an App is installed and in use, and up to 24 months after your last activity;
- usage and analytics events: up to 14 months;
- crash and diagnostic logs: up to 90 days;
- advertising identifiers and advertising events: up to 13 months, or until you withdraw consent or opt out, whichever comes first;
- attribution data: up to 24 months;
- purchase, subscription and entitlement records: up to 7 years, as accounting and tax law requires;
- support correspondence and privacy requests: up to 3 years after the matter is closed;
- records of the consent you gave or refused: while the consent is current and up to 5 years afterwards, so that we can show we complied.
Where the law requires a longer period, or where data is needed for a legal claim, we keep it for that period instead.
10. Security and Data Breaches
We use administrative, technical and organisational measures appropriate to the data and the risks involved to protect personal data against unauthorised access, loss, misuse, alteration and destruction. No system can be completely secure.
If a personal data breach occurs we assess it without undue delay. Where it is likely to result in a risk to your rights and freedoms we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, under Article 33 GDPR. Where it is likely to result in a high risk to you, we also notify you directly, under Article 34 GDPR. Where US state breach-notification laws apply, we notify affected residents and authorities as those laws require.
11. Push Notifications
Where an App uses notifications, service messages such as reminders you have set, maintenance notices, security alerts and replies to support requests are sent on the basis of our contract with you or our legitimate interest in operating the App. Promotional notifications about new Apps, offers or events are sent only where you have given marketing consent. Allowing notifications in the operating system prompt is a technical permission and we do not treat it as marketing consent. Where an App sends promotional notifications, it also lets you turn them off inside the App.
12. Your Rights in the EEA and the UK
If you are in the European Economic Area or the United Kingdom you have the following rights, which you can exercise by writing to info@randm.games:
- Right of access, Article 15 GDPR: to confirm whether we process your personal data, receive a copy, and be told the purposes, categories, recipients and retention periods;
- Right to rectification, Article 16: to have inaccurate or incomplete data corrected;
- Right to erasure, Article 17: to have your data deleted where it is no longer needed or where you withdraw the consent it was based on;
- Right to restriction, Article 18: to have processing limited while a dispute about accuracy or a legal claim is resolved;
- Right to object, Article 21: to object to processing based on our legitimate interests, and to direct marketing at any time, which we stop immediately;
- Right to data portability, Article 20: to receive data you provided in a machine-readable format, or have it sent to another controller;
- Right to withdraw consent, Article 7: at any time, without affecting the lawfulness of earlier processing;
- Right to lodge a complaint, Article 77: with a data protection supervisory authority.
We respond within one month. If a request is complex we may extend this by up to two further months, as Article 12 GDPR permits, and we will tell you if we do. Requests are free unless they are manifestly unfounded or excessive.
Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, Iasonos 1, 1082 Nicosia, Cyprus (www.dataprotection.gov.cy, commissioner@dataprotection.gov.cy). You may also complain to the supervisory authority of the EEA country where you live or work, or where you think the infringement took place. In the United Kingdom you may complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, www.ico.org.uk.
Because most of our Apps have no user accounts and collect data automatically, we may need a device or advertising identifier to find your records. Where an App shows that identifier, you will find it in the App's settings screen. If we cannot identify your data with reasonable effort we may have to decline the request, as the law allows.
To ask us to delete your data, write to info@randm.games with the subject line "Delete My Data", telling us which App you used and including that identifier where you can. We confirm when deletion is complete, and explain if we must keep something for legal, accounting or fraud-prevention reasons. Where an App offers user accounts it also provides a "Delete account" option in the account or settings screen, and the same request can be made by email without reinstalling the App.
13. US State Privacy Rights
We do not exchange personal data for money. Where an App shows personalised advertising, providing advertising identifiers and usage data to advertising partners may count as a "sale" or as "sharing" for cross-context behavioural advertising under the California Consumer Privacy Act as amended by the CPRA, and as targeted advertising under other US state privacy laws.
The categories of personal information we collect are identifiers, internet and other electronic network activity, commercial information about purchases, and approximate location inferred from IP address or country. We collect them from your device and from our service providers and platform partners, and we use them to operate our Apps, process purchases, keep them secure, provide support, measure and show advertising, and comply with the law. Retention is described above.
If you are a resident of California, or of another US state with a comprehensive privacy law - including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana - you have the rights to know and access the personal information we hold, to correct it, to delete it, to obtain a portable copy, and to opt out of the sale or sharing of personal information, of targeted advertising, and of certain profiling. We do not discriminate against you for exercising these rights. You may use an authorised agent, and we will ask the agent for written permission signed by you or proof of power of attorney.
Where an App shares data for advertising, it provides a "Do Not Sell or Share My Personal Information" control in the App's settings screen. You can also email info@randm.games with the subject line "Do Not Sell or Share". You do not need an account to use either route. We honour opt-out preference signals, including the Global Privacy Control, where our website or an App can receive them; in an App, please use the in-app control or your device advertising settings.
We do not intentionally collect sensitive personal information such as precise geolocation, health data, biometric data, government identifiers, racial or ethnic origin, religious beliefs or sexual orientation, and we do not use personal information to infer characteristics about you. If that ever changes we will provide the notice and the "Limit the Use of My Sensitive Personal Information" control the law requires. We do not knowingly sell or share the personal information of anyone under 16.
We aim to respond to California requests within 45 days, and will tell you if we need up to 45 days more. If we refuse a request you may appeal by writing to info@randm.games with the subject line "Privacy Appeal"; we will respond within the period your state law allows and tell you how to contact your state Attorney General if you remain dissatisfied.
14. Changes to This Policy
We may update this Policy, and when we do we change the "Last updated" date and keep the current version at randm.games/privacy-policy. Where a change is material - a new category of data, a new purpose, a new category of recipient, or a change to the legal basis for advertising - we give reasonable advance notice in the App before it takes effect, and where the change needs your consent we ask for it before the new processing begins.