PRIVACY POLICY
INTRODUCTION
This Privacy Policy explains how BitMango, Inc. (“BitMango,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information in connection with our mobile games, PC games, websites, and related services (collectively, the “Services”).
We process personal information in accordance with applicable privacy and data protection laws, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), the General Data Protection Regulation (“GDPR”), the UK GDPR, and the U.S. Children’s Online Privacy Protection Act and its implementing rule (“COPPA”).
This Privacy Policy also explains the choices and rights available to you, including how to withdraw consent, object to or restrict certain processing, opt out of targeted advertising or the sale or sharing of personal information where applicable, and request access to, correction of, portability of, or deletion of personal information.
Where applicable law requires consent, we will request consent before carrying out the relevant processing. Your use of the Services does not replace any consent that is legally required.
If you do not agree with this Privacy Policy, please do not install, access, or use the Services. Questions or requests may be submitted using the methods described in the Contact Us section.
INFORMATION WE COLLECT
Before collecting personal information for purposes that depend on age, we may use an age-screening or age-assurance process. Our age gate is designed neutrally: it does not preselect an adult age, give greater visual prominence to adult-age options, encourage users to enter an older age, or otherwise steer users toward an adult result.
The information we collect depends on the Service, your device and settings, your location, your interactions with us, and the age category identified through our age-screening process.
General Users
For users who are not identified as children, we may collect information to operate and improve the Services, maintain security, prevent fraud, provide support, process transactions, measure performance, and, where permitted, provide or measure advertising and marketing.
Children
For users identified as children under 13 in the United States, or below another applicable age threshold, we limit collection and use in accordance with applicable law.
Without verifiable parental consent, we do not knowingly collect direct contact information, precise geolocation, photographs, voice recordings, or other personal information from children except as permitted by law. We may process persistent identifiers only where permitted to support the internal operations of the Service, such as security, authentication, technical maintenance, fraud prevention, and bug diagnosis.
We do not use information from users identified as children for behavioral advertising, cross-context behavioral advertising, marketing profiles, or promotional targeting.
Utah Minor Users
For Utah residents under 18, we apply age-related protections required by applicable Utah law. Age-category information received from an app store or collected through our own age-screening process is used only for age assurance, safety, legal compliance, and enforcement of age-appropriate service restrictions. We do not disclose age-category information for advertising or marketing purposes.
Categories of Information
Depending on how you use the Services, we may collect:
- device type, operating system, language, device settings, app version, IP address, country or approximate region, and network information;
- game or player identifiers and device identifiers, including advertising identifiers where permitted;
- gameplay information, including session duration, level progress, scores, achievements, virtual items, and in-game activity;
- transaction and purchase-status information received from platform or payment providers; we do not directly collect full payment-card details;
- cookie, SDK, pixel, local-storage, and similar technology information;
- communications with us through in-game support, email, social media, or other support channels;
- information received when you connect a supported social-network, platform, or game-services account;
- information received from group companies, platforms, analytics providers, advertising partners, publishing partners, or other third parties that are legally permitted to provide it;
- job-application information, such as name, contact details, résumé, employment and education history, qualifications, portfolio, and other information submitted in connection with recruitment;
- publishing-submission information, such as name, email address, company, country, game title, app link, and portfolio; and
- other information you voluntarily provide or that we describe at the time of collection.
Advertising identifiers, inferred interests, social-network information, and similar information used for advertising or marketing are not collected or used for those purposes from users identified as children.
If you do not connect a social-network account, we may still collect device-level and gameplay information as described above. Device-level data may still constitute personal information under applicable law even when it does not directly identify you by name.
When we request additional information, we will describe what we are collecting, why we need it, and how it will be used.
HOW WE USE INFORMATION
We may use information for the following purposes.
Providing and Optimizing the Services
We use information to provide gameplay and account functionality, maintain sessions, save progress, process transactions, troubleshoot problems, verify compatibility, prevent abuse, create updates, measure performance, and develop or improve our products.
Customer Support
We use information you provide through customer-support channels to answer questions, investigate technical or account issues, manage our relationship with you, and improve the Services.
Our support page is available at:
Analytics and Research
We may use analytics tools and similar technologies to understand use of the Services, diagnose errors, measure performance, conduct research, generate reports, and improve our products.
For users identified as children, analytics collection is limited to information and purposes permitted under applicable law, including support for internal operations. Child information is not used to build advertising or marketing profiles.
Social and Community Channels
We receive information when you choose to communicate with us through social or community channels. We may respond through those channels and, where appropriate and permitted, reshare content you have intentionally made public.
We do not use personal information from users identified as children for marketing, advertising personalization, or public promotional features.
Social Sharing Features
Some Services may contain social-sharing or platform-integration features provided by third parties. These features may be subject to the third party’s own age requirements, account settings, and privacy controls.
Where age-appropriate controls are technically available, we apply them to limit access by users identified as children. We do not use information from users identified as children to personalize advertising or for marketing purposes.
Relevant provider policies include:
Job Applicants
We process job-applicant information to administer recruitment, communicate with applicants, assess qualifications, and determine suitability for employment.
We do not intentionally request special-category personal data under Article 9 GDPR unless it is legally required or voluntarily provided in circumstances where processing is permitted.
Developers Submitting Games for Publishing
We process developer-submission information to evaluate publishing proposals and communicate with the submitting developer or company. We disclose this information only as necessary to evaluate or administer the submission, operate our business, comply with law, or with the submitter’s direction.
Legal, Safety, and Security Purposes
We may use information to protect users, investigate fraud or security incidents, enforce applicable terms, comply with legal obligations, establish or defend legal claims, and respond to lawful requests from authorities.
LEGAL BASES FOR PROCESSING
Where the GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases:
- performance of a contract, including providing requested game or account functionality;
- compliance with a legal obligation;
- our legitimate interests, such as maintaining security, preventing fraud, supporting users, and improving the Services, where those interests are not overridden by your rights;
- your consent, including where required for personalized advertising, certain analytics technologies, cookies, or access to information on your device; and
- protection of vital interests or establishment, exercise, or defense of legal claims where applicable.
You may withdraw consent at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.
MARKETING
For users who are not identified as children, and where legally permitted, we may use information to promote our games and measure marketing effectiveness. This information may include:
- advertising identifiers and device information;
- interactions with our games and Services;
- age category, country or region, and gender where lawfully collected;
- campaign interactions and attribution information; and
- information received from third parties that have a lawful basis to provide it.
You may still receive non-personalized or contextual advertisements after opting out of personalized advertising.
No Behavioral Marketing to Children
Users identified as children are not subject to behavioral marketing, cross-context behavioral advertising, or advertising profiling. We do not use child information for promotional targeting or disclose child identifiers to third parties for promotional purposes.
Marketing Partners
We may work with marketing, attribution, and measurement partners. Their processing is governed by their own privacy notices and applicable agreements. We require partners to process information only where they have an appropriate legal basis and to comply with applicable data-protection requirements.
A current list of relevant partners and links to their privacy notices should be made available through the Service or on a dedicated partner-list webpage.
ADVERTISING
The following advertising practices apply only to users who are not identified as children through our age-screening process, unless this Privacy Policy expressly states otherwise.
Our Services may display advertisements for third-party products and services. Subject to your location, consent choices, device settings, and applicable law, we and our advertising partners may process information to select, deliver, limit frequency, secure, measure, or personalize advertisements.
This information may include:
- advertising identifiers and device information;
- IP address and approximate location;
- interactions with advertisements and the Services;
- gameplay or app-usage events;
- age category, country or region, and gender where lawfully collected; and
- information lawfully received from third parties.
If you opt out of personalized or targeted advertising, you may continue to see contextual, non-personalized, or limited advertisements.
Advertising for Children
For users identified as children, we disable targeted, interest-based, and cross-context behavioral advertising. Any advertising shown to child users is limited to contextual or otherwise legally permitted advertising.
We do not disclose child information to third parties for advertising purposes unless the disclosure is strictly necessary to support internal operations as permitted by law or is covered by verifiable parental consent that specifically authorizes the disclosure.
EEA, UK, and Switzerland Users
For users located in the European Economic Area, the United Kingdom, or Switzerland, advertising partners, including Google, may use information such as IP address, device identifiers, and device information for advertising personalization and measurement.
Where consent is required, this processing occurs only after consent is obtained through our in-app Consent Management Platform (“CMP”). You may withdraw or change your consent at any time through the privacy settings made available in the Service.
For information about Google’s processing, see How Google uses information from sites or apps that use its services.
When we use Google publisher advertising products to serve personalized ads in these regions, we use a Google-certified CMP integrated with the applicable IAB Transparency and Consent Framework requirements.
Advertising Partners
For users who are not identified as children, we may disclose advertising identifiers and other information to Google and other advertising, attribution, mediation, and measurement partners in order to deliver, secure, limit, measure, and, where permitted, personalize advertisements.
Such disclosure may constitute “sharing” under the California Consumer Privacy Act (CCPA), even where no monetary consideration is exchanged.
A current list of advertising and analytics partners, together with links to their respective privacy policies, is made available through our Partner List page.
Advertising Identifiers
Advertising identifiers are resettable device identifiers, such as the Android Advertising ID or Apple’s Identifier for Advertisers (“IDFA”). Subject to your choices and applicable law, we and our partners may use these identifiers and related technologies to recognize a device, measure advertisements, prevent fraud, control ad frequency, and provide personalized advertising.
THIRD-PARTY DATA MANAGEMENT FOR CHILD USERS
Before allowing a service provider or other third party to process information from users identified as children for support of internal operations, we take reasonable steps designed to protect the information.
Due Diligence
We assess the third party’s privacy, security, and data-handling practices in light of the information and services involved.
Written Commitments
We obtain contractual or other written commitments requiring the third party to maintain confidentiality, security, purpose limitations, retention controls, and protections consistent with applicable children’s privacy requirements.
Purpose Limitation
Third parties receiving child information for internal operations are prohibited from using it for behavioral advertising, cross-context tracking, independent profiling, or unrelated commercial purposes.
Technical Controls
We configure applicable systems so that child-mode sessions do not transmit information to advertising or analytics destinations that are not authorized for child users. Technical controls may include delayed SDK initialization, child-directed treatment flags, restricted-data-processing settings, event suppression, endpoint filtering, or server-side routing controls.
The precise control depends on the architecture of the relevant Service. We regularly review these controls and do not rely solely on contractual statements where a technical restriction is reasonably available.
DATA RETENTION
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining security, resolving disputes, conducting audits, complying with legal obligations, and establishing or defending legal claims.
Retention periods vary by data category, purpose, system, legal requirement, and whether the information is stored in active systems, security logs, or backups. Where feasible, we delete or de-identify information when it is no longer necessary.
Account-linked and directly identifiable player-support data is generally retained for up to six months after it is no longer needed for the applicable support or operational purpose, unless a longer period is required for fraud prevention, security, legal compliance, dispute resolution, or another documented purpose.
The six-month period above does not override the shorter retention rules applicable to children’s information described below.
Children’s Data
Persistent identifiers processed from children for support of internal operations are retained only for as long as necessary for the specific permitted purpose. After that purpose is fulfilled, we delete or de-identify the information within 30 days from active systems unless a shorter period is required by law.
Where immediate deletion from backup media is not technically feasible, the information is isolated from ordinary use and deleted or overwritten according to the applicable backup lifecycle.
De-identified and Aggregated Information
We may retain information that has been aggregated or de-identified so that it cannot reasonably be linked to an individual, subject to measures designed to prevent re-identification.
YOUR RIGHTS AND CHOICES
Your rights vary depending on your location and applicable law. Subject to verification and legal exceptions, you may have the following rights.
Access and Right to Know
You may request information about the personal information we collect, use, disclose, sell, or share and request access to specific pieces of personal information.
Correction
You may request correction of inaccurate personal information.
Deletion
You may request deletion of personal information. We may retain information where permitted or required by law, including for security, fraud prevention, transaction records, legal compliance, or legal claims.
Deleting an account or player identifier may result in loss of progress, purchases, or virtual items that cannot be restored.
Withdrawal of Consent
Where processing is based on consent, you may withdraw consent through the privacy or consent settings available in the Service or by contacting us.
Restriction of Processing
Where applicable, you may request restriction of certain processing.
Data Portability
Where applicable, you may request a portable copy of personal information you provided to us.
Objection
Where applicable, you may object to processing based on legitimate interests or to direct marketing.
Opt Out of Sale, Sharing, or Targeted Advertising
Depending on applicable law, you may opt out of the sale of personal information, sharing for cross-context behavioral advertising, or processing for targeted advertising.
You may exercise advertising choices through:
- the in-app privacy or consent settings;
- your iOS or Android privacy and advertising settings;
- platform-provided privacy controls; or
- the contact methods in the Contact Us section.
You may continue to receive contextual, non-personalized, or limited advertisements after opting out.
Account Deactivation
You may request account deactivation using the contact methods below. Unspent virtual items, game progress, or account-linked content may not be recoverable after deactivation.
REQUEST VERIFICATION
To protect users and prevent unauthorized access or deletion, we verify privacy requests using information reasonably related to the account and proportionate to the request.
For game-related requests, we may ask you to open the relevant game and send a message through the in-app support system so that we can verify the game or player identifier associated with the request. We may also ask for limited information about account activity, purchases, or progress where necessary.
We do not require more information than reasonably necessary to verify the request. Information collected for verification is used only for verification, security, fraud prevention, and fulfillment of the request.
Authorized Agents
An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and may ask the user to verify their identity or confirm the request directly.
Parents and legal guardians may submit requests concerning a child as described in the Children’s Privacy section.
CHILDREN’S PRIVACY
We comply with COPPA and other applicable children’s privacy laws. Our Services are generally intended for a mixed audience unless a particular Service is specifically designated otherwise.
1. Age Screening
We use a neutrally designed age-screening process where age-dependent processing or features are involved. We do not design the age gate to encourage users to identify themselves as adults.
2. Limited Collection
For users identified as children under 13 in the United States, or under another applicable threshold, we do not knowingly collect personal information without verifiable parental consent except as permitted for support of internal operations or another legal exception.
3. Internal Operations
Persistent identifiers may be processed only as reasonably necessary for functions such as maintaining the Service, authenticating users, protecting security and integrity, preventing fraud, complying with law, or diagnosing technical errors.
4. Advertising and Profiling
We do not use child information for targeted advertising, behavioral advertising, cross-context behavioral advertising, marketing profiles, or promotional targeting.
5. Parental Rights and Choices
A parent or legal guardian may request access to or deletion of a child’s personal information, refuse further collection, or withdraw previously provided consent.
Where applicable, a parent may consent to collection and use while declining disclosure to third parties, except where disclosure is integral to the Service or support for internal operations and is permitted by law.
Requests may be submitted to cpo@bitmango.com.
6. Child-Appropriate Verification
We do not ordinarily require a government-issued identification document to process a request concerning a child when a less intrusive method is reasonably available.
A parent or guardian may be asked to open the child’s game and contact us through the in-app support system using information associated with the relevant session, such as the player identifier, current level, game progress, virtual items or currency, or recent account activity.
We use this information only to verify authority, identify the relevant data, protect the account, and process the request. Depending on the circumstances, we may request additional proportionate evidence of parental authority.
7. Retention
Children’s persistent identifiers are retained only as long as necessary for a legally permitted purpose and are deleted or de-identified from active systems within 30 days after that purpose is fulfilled.
8. Accidental Collection
If we learn that we collected a child’s personal information in a manner inconsistent with applicable law, we will take reasonable steps to stop the processing and delete the information or obtain legally sufficient parental consent.
UTAH PRIVACY RIGHTS FOR MINORS
Where the Utah App Store Accountability Act or other applicable Utah law applies, BitMango provides the following protections to Utah residents under 18:
- we use app-store-provided or independently collected age-category information only for age assurance, safety, security, legal compliance, and age-appropriate service controls;
- we do not disclose a minor’s age-category information for advertising or marketing purposes;
- we honor legally valid parental-consent and age-assurance signals provided through applicable app-store mechanisms; and
- we apply parental-consent requirements to contracts or other actions where required by applicable law.
This section applies only to the extent the relevant legal requirements are effective, enforceable, and applicable to the Service and user.
CALIFORNIA PRIVACY NOTICE
This section supplements the Privacy Policy for California residents and serves as a notice at collection under the CCPA.
Categories of Personal Information Collected
During the preceding 12 months, depending on use of the Services, we may have collected:
- identifiers, such as player ID, device ID, advertising ID, IP address, email address, or account identifiers;
- customer-record information, such as contact or account information;
- commercial information, such as purchase records and transaction status;
- internet or electronic-network activity, such as gameplay, app interactions, browser information, diagnostics, and ad interactions;
- approximate geolocation derived from IP address or device settings;
- inferences used to select or measure advertising for eligible users;
- audio, electronic, or communication information submitted to customer support; and
- professional or employment-related information submitted by job applicants or publishing applicants.
We collect these categories from users, devices, app stores, linked platforms, service providers, analytics providers, advertising and attribution partners, social networks, and publishing partners.
We use these categories for the purposes described in How We Use Information, including providing and improving the Services, customer support, security, fraud prevention, analytics, legal compliance, transactions, advertising, and marketing.
Disclosure for Business Purposes
During the preceding 12 months, we may have disclosed identifiers, commercial information, internet or electronic-network activity, approximate location, support communications, and related information to service providers, processors, platforms, analytics providers, security providers, payment and transaction providers, and other parties described in this Privacy Policy.
Sale and Sharing
We do not sell personal information for monetary consideration.
For users who are not identified as children, some disclosures to advertising partners for cross-context behavioral advertising may constitute “sharing” under the CCPA, even when no money is exchanged.
California residents may opt out of sale or sharing through the in-app privacy controls, applicable platform settings, or by contacting us. We do not knowingly sell or share the personal information of users under 16 without the affirmative authorization required by law.
California Rights
Subject to applicable conditions and exceptions, California residents may have the right to:
- know the categories and specific pieces of personal information collected;
- know the categories of sources, purposes, and recipients;
- request deletion;
- request correction;
- opt out of sale or sharing;
- limit certain uses or disclosures of sensitive personal information, where applicable; and
- receive equal service and pricing without unlawful discrimination for exercising privacy rights.
Requests may be submitted to cpo@bitmango.com.
We will acknowledge and respond to verified requests within the periods required by applicable law. We may request information reasonably necessary to verify identity, authority, and the scope of the request.
Marketing Communications
You may opt out of promotional emails by using the unsubscribe mechanism in the message or contacting us. Transactional or service-related communications may continue where necessary.
Third-Party Services
Third-party SDKs, platforms, social networks, analytics providers, and advertising providers may process information under their own privacy notices. A current partner list should be made available through the Service or a dedicated partner-list page.
Google’s data-use explanation is available at How Google uses information from sites or apps that use its services.
COOKIES AND SIMILAR TECHNOLOGIES
Cookies and similar technologies include cookies, SDKs, pixels, tags, local storage, and device identifiers.
We may use these technologies to:
- maintain sessions and preferences;
- provide security and prevent fraud;
- remember consent choices;
- understand use and performance;
- diagnose errors;
- measure advertising; and
- personalize advertising where permitted.
Where required, we obtain consent before using non-essential technologies. You may manage consent through our cookie notice, in-app CMP, Service settings, browser settings, or device controls.
Withdrawing consent does not affect processing carried out before withdrawal. Deleting stored consent identifiers may cause the consent request to appear again.
DATA SECURITY
We maintain a written information-security program designed to protect the confidentiality, integrity, and availability of personal information, with particular attention to children’s information.
Our program includes:
- designated responsibility for the security and privacy program;
- periodic risk assessments, including assessments conducted at least annually where appropriate;
- administrative, technical, and physical safeguards proportionate to identified risks;
- access controls, encryption where appropriate, logging, network protections, and secure development or change-management practices;
- periodic testing and monitoring of safeguards;
- incident-response and remediation procedures; and
- review and adjustment of the program based on testing, material operational changes, and evolving risks.
No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.
INTERNATIONAL DATA TRANSFERS
Personal information may be transferred to and processed in countries other than the country where you live. Those countries may have different data-protection laws.
Where required, we use appropriate safeguards for international transfers, which may include:
- an adequacy decision;
- the European Commission’s Standard Contractual Clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- another legally recognized transfer mechanism; or
- a valid derogation permitted by applicable law.
For transfers to a U.S. recipient, we may rely on that recipient’s active certification under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework, where applicable and valid. We do not rely on the former EU-U.S. Data Privacy Framework.
Where required, we also assess transfer-related risks and implement supplementary safeguards.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect changes in the Services, our practices, technology, legal requirements, or other factors.
When required, we will provide notice of material changes through the Services, our website, or another appropriate channel before the changes take effect. Where a new purpose requires consent, we will obtain consent rather than treating continued use alone as consent.
The “Last Updated” date at the top indicates when this Privacy Policy was most recently revised.
CONTACT US
For questions, concerns, or privacy requests, contact us:
- Customer Support: https://bitmangogames.helpshift.com/
- Email: cpo@bitmango.com
The data controller for information processed under this Privacy Policy is:
BitMango, Inc.
Data Protection Officer / Privacy Contact:
This Privacy Policy was last updated on:: July 28, 2026