PRIVACY POLICY

We, at X-FLOW LTD (“X-FLOW” “we” or “us”), are committed to respecting your privacy and the integrity and security of your personal data.

X-FLOW is data controller with registered office at 8 Genethliou Mitella, 3036, Limassol, Cyprus.

This Privacy Policy applies to https://www.xflowgames.com/, all other sites or online services that are owned or operated by X-FLOW, all mobile games published by X-FLOW, X-FLOW games that can be played through third party platforms (collectively “Services”). This Privacy Policy explains how we collect, store, use and share your personal data and how you can exercise your privacy rights.

We may update our Privacy Policy from time to time. When we do, we will revise the date at the top of the policy. If we make changes that are material, we will use reasonable efforts to notify you (such as by placing an in-game notice or a push-notification). We encourage you to check this Privacy Policy regularly for updates, so that you know our current practices.

By downloading, accessing and/or using our Services, you acknowledge the collection and use of your information in accordance with this Privacy Policy, including X-FLOW’s and our partners’ use of your data for the purposes as described below.

You are not obliged to actively provide any of your personal data. However, some functionalities of our Services may not be accessible if you do not provide us with the respective personal data (such as contact information for customer support).

Please, read the following carefully and make sure you fully understand this Privacy Policy. If you have any concerns about providing information to us or it being used as described in this Privacy Policy, please, discontinue and avoid using our Services.

1. What Data We Collect

The personal data we collect will depend on the circumstances and the Services you are using. We collect data in three ways: (a) data you provide to us; (b) data we collect automatically; and (c) data we collect from our partners. We do not knowingly collect (d) special categories of information.

a. Data you provide to us

  • Contact information (such as name and email address)
  • Your messages to the Services (such as chat logs and player support tickets)
  • Other data you choose to provide us when you contact us (through the Services, social media, e-mail or any other channels).

b. Data we collect automatically

  • Data and analytics about your use of our Services (e.g. your game progress, the date and time you used a Service, session length, features you have used, your in-app purchase history, your interaction with advertisements)
  • Your IP address and mobile device identifiers (such as your device ID, advertising ID, MAC address, IMEI)
  • Non-identifying data about your device, such as device name and operating system, browser type, language and other technical data like screen size or processor, or combination of this data available for a developer for checking the device compatibility with a particular Service
  • General location data (e.g. country or city-level location) inferred from your IP address
  • Data about your use of the Services, such as gameplay data and your interactions with other players inside the Services

Note that we do not use such data to learn a person’s true identity or contact details, but mostly to understand how our users typically use and interact with our Services, so that we could maintain and improve them.

c. Data we collect from our partners

  • Third-party tools. Data we may receive if you choose to link a third-party tool with the Services (such as Facebook, Google or Apple). Exactly what information we receive from such third-party tool will depend on your privacy settings, but it would typically include your basic profile information such as your user id, username, gender, picture, e-mail, your friends playing the same game. We do not get access to or store your logins or passwords for any of these third-party tools.
  • Third-party platforms. In-app purchases are typically processed by the platforms (e.g. Apple App Store, Google Play, Amazon AppStore or Facebook). We do not collect or store your financial data, such as your credit card number or bank account. You are requested to provide payment details directly to the relevant platform. We may, however, receive limited non-financial data relating to the purchase (e.g. platforms may notify us if a purchase was successful). Any post-purchase processes are controlled by the platforms. We encourage you to review privacy policies and terms of service of the platforms for further information before making a purchase in the Services.
  • Advertising partners. From time to time, we may receive non-personal information from our advertising partners concerning the performance of our advertising campaigns (e.g. we may be provided with information from which ad network and advertising campaign the install of our Service originated from or data necessary to fight fraud (such as refund abuse in games or click fraud in advertising).
  • Third-party service providers. Our analytics providers may provide us with information regarding your use of our Services (such as in-game events, your interaction with the Services and in-game advertisements, software errors, etc.) so that we could improve our Services.

d. No special categories of information

We do not request or intend to collect any “special categories of information” such as data revealing racial or ethnic origin, political opinion, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. Please, be cautious when sharing this information about yourself (or others) in our Services.

2. Why We Collect and Use Your Data

To make our Services work

To perform the contract with you, which you enter into when you download or access our Services and accept our Terms of Use, we process data necessary to:

  • Allow you to use our Services
  • Facilitate, operate, provide and maintain our Services
  • Recognize you when you return to our Services
  • Verify and confirm payments in our Services
  • Provide and deliver in-app products and services you request
  • Send you Services-related communications
  • Respond to your comments and questions and provide player support

Our legal basis for such processing of personal data is Art. 6 para. 1 lit. b) GDPR

To make our Services more suitable for our players

To provide great Services to our players, we process personal data based on our legitimate interest to improve our Services in the following situations:

  • Develop and improve the Services and player experience
  • Manage our relationship with you
  • Provide social features as part of the Services
  • Customize your Services experience
  • Provide you our offers in the Services
  • Send you related information, such as updates, security alerts, and support messages
  • Enable you to communicate with other players
  • Show you contextual advertisements in our Services
  • Cross-promote our Services, meaning to promote one of our games while you are playing a different game of ours

Our legal basis for such processing of personal data is Art. 6 para. 1 lit. f) GDPR

To serve you advertising

Our games may include advertising for third party products and services. Advertising includes serving you generic non-personalized advertisements and providing you with personalized advertising experience.

Non-personalized advertisements

To serve you generic non-personalized advertisements in the Services using third party advertising networks, it is generally necessary to process some data that may be considered as personal, such as your IP address or certain device identifiers. To do this, we rely on our legitimate interest in monetizing our Services.

Our legal basis for such processing of personal data is Art. 6 para. 1 lit. f) GDPR

Personalized advertisements

To serve you personalized advertisements in the Services using third-party advertising networks we will rely on your consent to process necessary data to:

  • Track the content you access in connection with the Services and your online behavior
  • Deliver, target and improve advertising in our Services

You can opt out of personalized advertising by following the instructions in section 5 below.

You can withdraw your consent at any time by contacting us using the details given in section 10 below.

Our legal basis for such processing of personal data is Art. 6 para. 1 lit. a) GDPR

To keep our Services safe and fair

In order to keep the Services and its social features safe and fair, to fight fraud and ensure acceptable use otherwise, we have a legitimate interest to process necessary data to

  • Analyze, monitor and moderate use of the Services and its social features
  • Take action against fraudulent or misbehaving players
  • Track how our advertising campaigns perform and identify and prevent fraud for our advertising campaigns

Our legal basis for such processing of personal data is Art. 6 para. 1 lit. f) GDPR

To analyze, profile, and segment

In all of the above cases and purposes, we may analyze, profile and segment all collected data and create aggregated statistical data, inferred non-personal data or anonymized or pseudonymized data, which we and our partners may use to provide and improve our Services. If such analyses require the processing of personal data (such as pseudonymized data), we do so based on our legitimate interest to improve our Services based on Art. 6 para. 1 lit. f) GDPR.

To comply with our legal obligations

In limited cases we may process your data where we need to do so to comply with a legal obligation, or if we receive an order from a court or regulatory authority.

Our legal basis for such processing of personal data is Art. 6 para. 1 lit. c) GDPR

3. How We Share Your Data

Apart from X-FLOW, your data can be accessed by others in the following situations:

Other players and users

Social features are a core component of our Services. Other players and users may, for example, see your profile data, in-game activities and read the messages you have posted.

Other companies and public authorities

In order to combat fraud and illegal activity, we may exchange data with other companies and organizations and provide it to public authorities in response to lawful requests.

We may also disclose your data based on your consent, to comply with the law or to protect the rights, property or safety of ours, our players or others.

Our Service Providers and Partners

We use third parties to help us operate and improve our Services. These third parties assist us with various tasks, including hosting and maintenance, on-going development, analytics, customer care, marketing, advertising. We may also share information with advertising partners who distribute advertising in our Services.

We share your personal data with these third parties only where we have a legal basis as set out above or where such third parties process data on our behalf based on a data processing agreement, which may restrict further subcontracting by such third parties.

For further information, please, see our List of Partners Schedule and their privacy policies. We may update it from time to time, so you understand who we partner with to bring you our Services.

4. International Data Transfers

Our Services are global by nature and your data can therefore be transferred and processed in other countries other than the country in which you are resident. Because different countries may have different data protection laws than your own country, we take steps to ensure adequate safeguards are in place to protect your data as explained in this Policy. Adequate safeguards that our partners may use include transfer of data to the jurisdictions, which are considered by the European Commission to be offering an adequate level of protection for personal data of EU residents or standard contractual clauses approved by EU Commission.

If you are a user located in South Korea, please see more details about overseas transfers of personal information in our Overseas Transfer Schedule.

5. Your Rights and Options

Opt-out of personalized advertising

You can opt-out of personalized advertising on mobile applications by checking the privacy settings of your Android or iOS device.

Apple devices:

For iOS 14 and newer:

  1. Open Settings
  2. Select Privacy
  3. Select Tracking and disable “Allow Apps to Request to Track”

For iOS 13 and older:

  1. Open Settings
  2. Select Privacy
  3. Select Advertising and enable "Limit Ad Tracking"

Android devices:

Delete your device’s advertising ID

To delete your device’s advertising ID:

  1. Open Settings
  2. Tap Privacy > Ads
  3. Tap Delete advertising ID and confirm your changes

On some older versions of Android

If your Android device’s version is 4.4 or older:

  1. Open Settings
  2. Tap Privacy > Advanced > Ads
  3. Select Ads and enable "Opt out of Ads Personalization"

If you are interested in more information about personalized advertising and your choices in this regard, you may visit the following websites:

All of the opt-out tools described in this subsection are provided by third parties, not by us. We do not control or operate these tools or the choices that advertisers and others provide through these tools.

Please note that opting out does not mean that you will stop seeing advertisements in our Services, rather third-party advertising networks will show you contextual advertisements not tailored to your interests. Please, be aware that such actions may result in decrease of advertising quality and less enjoyable user experience.

Data subject rights

In case we process personal data about you and if you are an EU resident or the resident of another jurisdiction that affords you the below rights you:

  • have the right to access data we hold on you;
  • may request us to make any changes and corrections to your personal data or restrict the processing if it is inaccurate or incomplete;
  • may request that your personal data is erased where we do not have a compelling reason to continue to process such personal data in certain circumstances;
  • may ask to transfer your personal data in accordance with your right to data portability;
  • may withdraw your consent where you have previously given your consent to the processing of your personal data. Note that withdrawal of your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal data conducted pursuant to lawful processing grounds other than consent.
  • have the right not to be subject to a decision based solely on automated processing, (including profiling), which produces legal effects or could significantly affect you;
  • have the right to object to or restrict how we use or process your data in certain circumstances. Please, note in case of such a request we may not be able to provide you with all of our Services or the quality of our Services may be decreased;
  • right to lodge a complaint with a data protection supervisory body.

To submit a request, please, use the contact details in section 10 below.

Please, note that your request must:

  • provide sufficient information necessary to verify you as our user about whom we collected and processed personal data or to verify you as an authorized representative of such a user;
  • contain sufficient details describing your request to allow us to properly understand, review and respond to it;

We reserve the right not to respond to your request or provide you with personal data, in case we were unable to verify your identity or authority to make such a request.

6. Cookies and Similar Technologies

Like most online services, we and our partners use cookies and similar technologies to provide and personalize the Services, analyze use, target advertisements and prevent fraud. You can disable cookies in your browser settings, but some parts of the Services may then not function properly.

For further information, please, read our Cookie Policy.

7. How We Protect Your Data

Security Safeguards

In order to help ensure a secure and safe player experience, we are continuously developing and implementing administrative, technical and physical security measures, such as limitation of access to personal information by personnel, utilizing Firewalls encryption, backup systems, bastion host to access cluster, RBAC to manage cluster resources, to protect your data from unauthorized access or against loss, misuse or alteration.

Although we use commercially reasonable efforts to assure that your data remains secure when maintained by us, please, be aware that no security measures are perfect or impenetrable.

Data retention

We keep your information only so long as we need it to provide our Services to you and fulfill the purposes described in this Privacy Policy. When we no longer need to use your information and there is no need for us to keep it to comply with our legal or regulatory obligations, we will either destroy it or depersonalize it so that we cannot identify you.

The procedure and method of destroying the information is as follows:

Destroying Procedure: Your personal information will be destroyed without delay after the end of retention period or after its purpose has been achieved.

Destroying Method: Printed personal information will be shredded through a paper shredder. If the information is stored as a data file, it will be deleted safely in an irreversible way.

8. Age Limits

We appreciate the need to provide extra privacy protections to users who are children. Our Services are intended for use only by those aged 16 and over. We do not knowingly collect personal information from children under 16 years of age. In order to request the deletion of personal data, for any reason, please use the in-app support feature in our Services or contact us at the address provided in section 10 below and we will take reasonable measures to promptly delete such personal data from our records.

9. US Privacy Rights

This section provides additional information for residents of California, Virginia, Colorado, Utah, and Connecticut.

If you are a resident of California, Virginia, Colorado, Utah or Connecticut, you have certain privacy rights as specified under your state law: California Consumer Privacy Act of 2018 (“CCPA”), the Virginia Consumer Data Protection Act (“CDPA”), the Colorado Privacy Act (“CPA”), the Utah Consumer Privacy Act (“UCPA”), the Connecticut Data Privacy Act (“CTDPA”) (together “US Privacy laws”).

This section describes how to exercise those rights and our process of handling those requests. We reserve the right to ask for reasonable information to verify your identity before we process your request.

The easiest way to submit a request is to use the in-app support feature (“Contact Us”) in our games. You may also submit your request via e-mail at privacy@xflowgames.com

Please, note that your request must:

  • provide sufficient information necessary to verify you as our user about whom we collected and processed personal data or to verify you as an authorized representative of such a user;
  • contain sufficient details describing your request to allow us to properly understand, review and respond to it;

We will respond to your request within 45 days, and in more difficult cases we may extend our response time by another 45 days. We reserve the right not to respond to your request or provide you with personal data, in case we were unable to verify your identity or authority to make such a request.

Right to know

You may submit up to two times in a 12-month period, free of charge, a verifiable request to disclose what personal information we collected, used or disclosed about you in the preceding twelve (12) months.

Right to delete

You have the right to request that we delete any of your personal information we collected and retained, subject to certain exceptions. Once we receive and verify your consumer request, we will delete your personal information from our records. However, we may deny your deletion request if retaining the information is necessary for us or our service providers under certain circumstances, which will be explained to you at the time of the denial, if any.

Right to data portability

You have the right to obtain your personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit your personal data to another controller without hindrance.

Right to opt-out

If you are a California resident, you have the right to opt-out of “sale” of your personal information, as defined by the CCPA.

If you are a Virginia, Colorado, Utah or Connecticut resident, you have the right to opt-out of the processing of the personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling (or solely automated decisions (Connecticut) that produce legal or similarly significant effects concerning you).

If you would prefer that your personal information is not shared with third parties in this way, please, visit List of Partners Schedule.

However, in certain circumstances we may share your information with our partners, who help us deliver advertisements in our games tailored to your interests. To learn what information we collect and how we share it with third parties for advertising purposes, please, see our "Do Not Sell My Personal Information".

Right to be free from discrimination

We may not discriminate against you for exercising any of your rights under US laws, including but not limited to (i) denying you our Services; (ii) charging you different prices or rates for our Services; (iii) providing you a different level or quality of Services; (iv) suggesting that you may receive a different price or rate for Services or a different level or quality of Services.

Authorized agents

In certain circumstances, you may exercise your rights by designating an authorized agent. If you would like to designate an authorized agent to make a request on your behalf, please, be sure that the agent can (i) demonstrate you have provided written permission for the agent to submit a request on your behalf and (ii) provide proof of his or her own identity. We reserve the right to require further reasonable information to verify the request. If the agent does not satisfy these requirements, we may deny the request.

Right to action

If you are a Virginia, Colorado, or Connecticut resident, you have the right to appeal our decision to deny your rights request. You can exercise this right by contacting us using the details given in section 10 below.

Selling of data

We do not “sell” data of our users as most people would typically understand this term. The definition of “selling” shall be interpreted in accordance with the meaning attributed to this term under US Privacy laws. We do, however, share certain data with third-party advertising partners for the purposes of serving advertisements in our Services, fraud detection and prevention and advertising campaign management. Generally, the data collected is limited the user’s advertising ID, device identifiers and other technical information. Such data collection practices may fall under the definition of “selling” under US Privacy laws.

Categories of personal information we collected, disclosed or "sold"

Personal information is information that directly or indirectly identifies a particular consumer, household or device. We have collected, disclosed or “sold” the following categories of personal information from California, Virginia, Colorado, Utah and Connecticut consumers within the last twelve (12) months.

CategoryPersonal informationCategories of service providers to whom personal information was disclosed or “sold”Business purpose for collection
A. IdentifiersName, username, email address, IP address, advertising ID, device identifiers and other device information
  • Advertising networks
  • Data analytics providers
  • Cloud storage providers
  • Social media services
  • Quality assurance vendors
  • App distribution platforms
  • Service providers
  • Provide services and operate business
  • Maintain, enhancing service, debugging
  • Customer support
  • Product development/improvement
  • Detection and prevention of fraud and security events
  • Analytics, research and reporting
  • Facilitate player’s social interaction
  • Serving advertisements
  • User acquisition
  • Compliance purposes and meeting legal/regulatory requirements
D. Commercial informationPurchase history, transaction information. This does not include any payment or financial information, which is collected directly by app distribution platforms
F. Internet or other similar network activityInteraction with our web-site and applications
G. Geolocation dataCountry, State, City

We obtain personal information from various sources, including but not limited to:

  • Directly from you.
  • Indirectly from our users and their agents.
  • Directly and indirectly from activity on our web-site or in our apps.
  • From third parties that interact with us in connection with the services or products we provide.

10. Contact us

If you have questions about data protection, or if you have any requests for resolving issues with your personal data, you can contact us through the in-app support feature “Contact Us” or via e-mail at privacy@xflowgames.com. However, we may still redirect you to make the same request through the in-app support feature to verify you as our user and/or request additional information necessary for us to respond.

You can also contact our DPO at dpo@xflowgames.com.