Privacy Policy
This Privacy Policy explains how [LEGAL ENTITY NAME] (“Company”, “we”, “us”) collects, uses, and shares personal data when you use the Narde mobile application and related services (the “Service”). It is written to meet the EU/UK GDPR, the California CCPA/CPRA, and the requirements of the Apple App Store and Google Play. The English version prevails over translations.
1. Who We Are (Controller) & Contacts
The data controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
- Privacy contact / Data Protection Officer: [DPO or PRIVACY EMAIL]
- EU Representative (GDPR Art. 27): [EU REP NAME & ADDRESS]
- UK Representative (UK GDPR): [UK REP NAME & ADDRESS]
2. Data We Collect
- Account & identity: e-mail address, username, password (stored only as a salted hash), passkey credential identifiers, account ID and status.
- Profile & social: nickname, public ID, avatar (image and color), language preference, following/followers, mute list, online-presence status. We also keep previous avatar images and previous nicknames for a limited period — see §6.
- Gameplay: ELO rating and history, games played/won/lost and outcome types, match history, leaderboard standing.
- User content & communications: chat and private (whisper) messages, profile fields, reports you submit (which may include information about another user), and support correspondence.
- Settings: in-app preferences (sounds, hints, animations, board theme, matchmaking, messaging-privacy choices, etc.).
- Device & technical: IP address, device fingerprint, device model and operating system, app version, language, and diagnostic/crash logs (crash logs when added).
- Moderation: restriction and enforcement records, moderation events, and IP/device-fingerprint signals used to enforce safety rules and prevent ban evasion.
- Purchases (when subscriptions/IAP go live): subscription/plan status and transaction identifiers. Payment-card details are handled by Apple/Google, not by us.
- Push notifications (when added): device push token.
- Analytics & advertising identifiers (when added): usage events and, only with your consent, analytics/attribution and advertising identifiers (e.g., IDFA/GAID).
- Consent records: your privacy choices and timestamps.
We do not currently use third-party analytics, advertising, or crash-reporting SDKs, and we do not offer Sign in with Apple/Google; this policy will be updated before any such feature is enabled.
3. How and Why We Use Data (Legal Bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and operate your account; authenticate you | Contract |
| Run matches, calculate ELO, leaderboards, presence, following | Contract |
| Transactional/service notifications (your turn, invites) | Contract / legitimate interests |
| Subscriptions and in-app purchases | Contract |
| Safety, moderation, anti-cheat, fraud prevention, handling reports | Legitimate interests (and legal obligation where required) |
| Security, debugging, service improvement | Legitimate interests |
| Marketing notifications | Consent |
| Analytics and advertising SDK identifiers (when added) | Consent |
| Complying with legal obligations and responding to authorities | Legal obligation |
We use IP addresses and device fingerprints to detect and prevent abuse, cheating, and ban evasion, and to keep the Service secure. We have assessed that this is necessary for our legitimate interest in protecting users and the integrity of the Service.
4. How We Share Data
We share personal data only with categories of recipients that help us run the Service: cloud hosting and infrastructure providers; the app stores (Apple, Google) for purchases; authentication and push providers (when added); analytics/attribution providers (when added, and subject to your consent); customer-support and moderation tools; and professional advisers, authorities, or other parties where required by law or to protect rights and safety. We may also transfer data as part of a merger, acquisition, or sale of assets. We do not sell your personal data, and we do not “sell” or “share” it for cross-context behavioral advertising as those terms are defined under U.S. state laws.
5. International Transfers
We may process data in countries outside your own, including outside the EEA/UK. Where we transfer personal data of EEA/UK individuals to such countries, we rely on an adequacy decision (including the EU-US Data Privacy Framework where applicable) or on the European Commission’s Standard Contractual Clauses (and the UK IDTA/Addendum for UK data), together with appropriate supplementary measures. You may request a copy of the relevant safeguard at [PRIVACY EMAIL].
6. Retention
We keep personal data only as long as necessary for the purposes above:
- Account and profile data: while your account is active; deleted or anonymized after account deletion (without undue delay), subject to the exceptions below.
- Unverified, never-used accounts: if you register but never confirm your e-mail address and never start a game, we may delete the account and its associated data after a period of inactivity (data minimization, GDPR Art. 5(1)(e)). We post an in-app notice in advance; confirming your e-mail or playing a game cancels the deletion.
- Match history and ELO: while active; anonymized on deletion.
- Avatar images and nicknames: your current avatar and nickname for as long as your account is active. An avatar image you replace or delete, and a nickname you change, are kept for a limited period after they stop being current — long enough that a report about them can still be reviewed and a breach of our Terms evidenced, and no longer: a picture must not become unreviewable the moment it is reported. We keep only a limited number of the most recent versions. During that period they are not shown to other players: only our moderation and support staff can see them. They are deleted at the end of that period, or when your account is deleted, whichever comes first (subject to the exceptions in this section and §8). Legal basis: our legitimate interest in a safe service (GDPR Art. 6(1)(f)). You can ask us for the period currently in force at [PRIVACY EMAIL].
- Moderation, ban, and report records: kept as long as necessary to enforce safety measures, prevent ban evasion, and establish or defend legal claims. A report keeps its own snapshot of the reported nickname and avatar for the life of that record, so that a decision remains reviewable and appealable.
- Push tokens: until you unsubscribe, uninstall, or the token expires.
- Analytics/diagnostics (when added): a short, defined window, then aggregated or deleted.
- Purchase/financial records: as required by tax and accounting law.
- Consent records: for as long as needed to demonstrate consent plus the applicable limitation period.
7. Security
We implement appropriate technical and organizational measures, including encryption in transit (TLS) and at rest, hashing/salting of credentials, least-privilege and role-based access controls, network segmentation, pseudonymization/anonymization where feasible, secure development and dependency/SDK review, logging and monitoring, vendor due diligence and data-processing agreements, backups, and an incident-response and breach-notification process. No method of transmission or storage is completely secure.
8. Your Rights
EEA/UK (GDPR): access, rectification, erasure, restriction, data portability, objection, the right to withdraw consent at any time, and the right to lodge a complaint with your supervisory authority (e.g., the UK ICO or your local Data Protection Authority). We respond within one month (extendable by two months for complex requests).
California (CCPA/CPRA): the right to know/access, delete, and correct your personal information; to opt out of sale/sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising your rights. Because we do not sell or share personal information, no “Do Not Sell or Share” action is required, but you may still exercise your other rights. We honor recognized opt-out preference signals (such as Global Privacy Control).
Other regions: residents of other jurisdictions (e.g., Brazil, Canada, and various U.S. states) have comparable rights and may contact us to exercise them.
How to exercise: use the in-app Privacy & Data screen to export your data, edit your profile, manage consents, and delete your account, or contact [PRIVACY EMAIL]. We verify your identity before acting on a request. Erasure is not absolute: we may retain limited data where another legal basis requires it (e.g., enforcing bans, tax records, or defending legal claims).
9. Children
The Service is not directed to children below the minimum age in our Terms (at least 16 in the EEA, at least 13 elsewhere, or higher where required). We do not knowingly collect personal data from children below that age. If you believe a child has provided us data, contact [PRIVACY EMAIL] and we will delete it.
10. Cookies & SDK Identifiers
The Service does not use advertising cookies. When we add analytics, attribution, or advertising SDKs, those that are not strictly necessary will be enabled in the EEA/UK only after you give consent through our in-app consent prompt, and on iOS we will request permission through Apple’s App Tracking Transparency before any cross-app tracking or use of the advertising identifier. You can change your choices at any time in the in-app privacy settings.
11. Account & Data Deletion
You can delete your account and associated data from within the app (Settings → Account → Delete account) and, if you have uninstalled the app, you can request deletion via our Account Deletion page. We delete or anonymize your data as described in §6, subject to the legal exceptions noted in §8.
12. Push Notifications
If enabled, we send service and (with your consent) promotional notifications. You can disable them in your device settings or in the in-app notification settings.
13. Changes to This Policy
We may update this Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide notice in the app or by e-mail.
14. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS] Privacy: [PRIVACY EMAIL] · DPO: [DPO CONTACT, if appointed] EU Representative: [EU REP NAME & ADDRESS] · UK Representative: [UK REP NAME & ADDRESS]