privacy policy
Privacy Policy
Game name: EXPRESS PRO HEXA PUZZLE
Developer / data controller: rewernator
Contact: marcin.rewertyn@gmail.com
Effective date: June 12, 2026
Last updated: June 12, 2026
1. Introduction and developer identity
rewernator provides the mobile game EXPRESS PRO HEXA PUZZLE. This Privacy Policy explains what data may be accessed, collected, used, stored, or shared when you use the game, why the data is processed, what external service providers may be involved, and what privacy rights you may have.
The developer / data controller for this game is rewernator. For privacy matters, data access requests, data deletion requests, or questions about this policy, contact us at marcin.rewertyn@gmail.com.
This policy is written for Google Play publication and for in-app privacy disclosure. It should be read together with any privacy notice or consent screen shown inside the game.
2. Scope of this policy
This Privacy Policy applies to the Android version of EXPRESS PRO HEXA PUZZLE distributed through Google Play or compatible Android app stores. It covers the current audited implementation described by the developer: local game progress, optional Firebase Analytics, optional Firebase Crashlytics, Google Play Billing / Google Payments, Unity / Unity In-App Purchasing, and Google Play Services.
The game does not operate its own account system or backend user profile database. If this changes in the future, this policy and the Google Play Data Safety declaration must be updated before the new version is published.
3. No account registration and no direct personal profile collection
The game does not require account registration. The game does not ask the user to provide a first name, last name, email address, phone number, postal address, contacts, photos, videos, microphone recordings, camera images, precise location, or calendar data.
If the user voluntarily contacts support by email, the email address and any information included in the message will be processed only to respond to the request, handle support, maintain records of the communication, and comply with legal obligations.
4. Local data stored on the device
The game may store the following data locally on the user's device:
- privacy consent status, such as accepted, rejected, or not selected;
- game progress, completed levels, unlocked levels, stars, hint status, reward status, and virtual currency balance;
- sound settings, music settings, interface preferences, and gameplay preferences;
- local purchase entitlement information, such as product alias, transaction status, and local transaction hash, to avoid granting purchased items more than once;
- technical local flags needed for app stability, onboarding, restore purchase logic, and user preferences.
Local data is stored using the local preferences mechanism used in the project, including the hashing and encryption layer described by the developer. Local data generally remains on the user's device and is not sent to the developer's own server, because the game does not use a developer-operated backend.
5. Optional analytics and crash reports after consent
The game includes a consent mechanism for anonymous analytics and crash reports. According to the current implementation described by the developer, Firebase Analytics and Firebase Crashlytics are initialized only after the user accepts consent. The user may refuse consent and continue using the game.
If the user accepts analytics and crash reports, the game may send the following types of diagnostic and gameplay data to Firebase Analytics and Firebase Crashlytics:
- app interactions, such as app start, game start, level progress, store opening, purchase click, reward use, hint use, settings use, and consent status events;
- anonymous game economy parameters, such as virtual currency balance category, source, spending target, and reward category;
- in-app purchase events, such as purchase start, purchase success, cancellation, validation error, restore attempt, restore result, and product identifier;
- technical app parameters, such as app version, platform, Unity version, device class, network type, language/region settings, and anonymized session hash;
- crash reports, stack traces, non-fatal errors, diagnostic logs, and safely sanitized error messages.
The game code should remove or limit sensitive information in telemetry, including tokens, purchase receipts, signatures, payloads, email addresses, and other direct identifiers if such information appears in diagnostic messages.
6. In-app purchases
The game uses Unity In-App Purchasing and Google Play Billing to process in-app purchases. Payments are handled by Google Play / Google Payments. The developer does not receive or store the user's full payment card number, bank account number, or complete payment credentials.
For purchase functionality, the game and its purchase providers may process purchase-related information, including product identifier, product alias, transaction status, purchase confirmation, local transaction hash, purchase restoration status, currency, price category, and fraud-prevention or entitlement-delivery signals.
This data is used to deliver purchased content, restore purchases where supported, prevent duplicate grants or abuse, maintain purchase security, handle refund-related effects where technically possible, and comply with Google Play and legal requirements.
Google Payments privacy information is available here: Google Payments Privacy Notice.
7. Ads and advertising identifiers
Game does not include an active advertising SDK, and ads are disabled in the game code. Earlier legacy versions of the game may have included third-party advertising features. These versions could display ads and may have allowed advertising providers to process certain technical data, such as device information, advertising identifiers, app interaction data, and ad performance data, in accordance with their own privacy policies.
8. External services and service providers
The game may use the following external services:
- Google Play Services: Android and Google functions required by Firebase, Google Play Billing, install/referrer functionality, and Google services. Privacy Policy: https://policies.google.com/privacy
- Firebase Analytics: optional app analytics after user consent. Data disclosure guidance: https://firebase.google.com/docs/android/play-data-disclosure
- Firebase Crashlytics: optional crash reporting and diagnostics after user consent. Privacy information: https://firebase.google.com/support/privacy
- Google Play Billing / Google Payments: in-app purchase processing, payment handling, refunds, purchase security, and legal compliance. Payment privacy information: https://payments.google.com/legaldocument?family=0.privacynotice
- Unity / Unity In-App Purchasing: game engine and purchase modules. Game Player and App User Privacy Policy: https://unity.com/legal/game-player-and-app-user-privacy-policy
- Google Play Data Safety: app privacy and security disclosure guidelines. Help page: https://support.google.com/googleplay/android-developer/answer/10787469
9. Device permissions
| Permission | Purpose |
|---|---|
android.permission.INTERNET |
Connection to Google/Firebase services, Google Play Billing, purchase validation / entitlement workflows, diagnostics, and opening the privacy policy link. |
android.permission.ACCESS_NETWORK_STATE |
Checking network availability for purchases, diagnostics, Firebase/Google service stability, and graceful offline handling. |
com.android.vending.BILLING |
Handling in-app purchases through Google Play Billing. |
android.permission.WAKE_LOCK |
Maintaining short technical SDK operations, such as Google/Firebase background service tasks, without interruption by the system. |
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE |
Reading install source information through Google/Firebase services, such as install attribution, diagnostics, and service reliability. |
ACCESS_ADSERVICES_ATTRIBUTION and ACCESS_ADSERVICES_AD_ID |
Android Privacy Sandbox / Ad Services permissions that may be added by Google dependencies. If they are not required by the final release, the developer should consider removing them from the final manifest and matching the Google Play declaration accordingly. |
The game does not request permissions for precise location, approximate location, camera, microphone, contacts, photos, videos, user files, calendar, SMS, call logs, or push notifications.
10. Purposes of processing
Data may be processed for the following purposes:
- App functionality: saving progress, settings, local entitlements, purchase state, and restoring game state;
- Purchase fulfillment: delivering purchased products, preventing duplicate grants, restoring purchases, and handling purchase errors;
- Analytics: understanding optional anonymous gameplay patterns, feature use, retention, and economy balancing after consent;
- Diagnostics and stability: detecting crashes, non-fatal errors, startup issues, SDK failures, and compatibility problems after consent where required;
- Security and fraud prevention: preventing purchase abuse, debugging entitlement problems, detecting abnormal events, and protecting the integrity of the game;
- Developer communications: responding to user emails or privacy requests;
- Legal compliance: complying with Google Play requirements, refund handling, tax/accounting obligations, and lawful requests.
11. Legal bases for users in the EEA, UK, and similar regions
Where the General Data Protection Regulation, UK GDPR, or similar privacy laws apply, the legal bases may include:
- Consent: optional Firebase Analytics and Firebase Crashlytics reporting after the user accepts consent in the game;
- Performance of a contract: saving game progress, applying settings, delivering in-app purchases, and restoring entitlements;
- Legitimate interests: app security, fraud prevention, error debugging, service reliability, abuse prevention, and maintaining game stability, while respecting consent choices where consent is required;
- Legal obligation: accounting, tax, refunds, compliance with Google Play rules, and responding to lawful requests.
12. User rights under GDPR / UK GDPR
Depending on the user's country or region, the user may have the right to request access to personal data, correction, deletion, restriction of processing, data portability, objection to processing, withdrawal of consent, and to lodge a complaint with a competent data protection authority.
To exercise privacy rights, contact marcin.rewertyn@gmail.com. The request should include the game name, platform, country/region, and a clear description of the request. Do not send passwords, payment card data, full purchase receipts, or unnecessary sensitive information.
13. California privacy rights / CCPA / CPRA
California residents may have the right to know, access, delete, correct, and opt out of the sale or sharing of personal information, subject to legal limitations.
The developer does not sell users' personal information. According to the current audit description, the game does not use an active advertising SDK for personalized ads or cross-context behavioral advertising. If this changes, this policy and the Google Play Data Safety declaration must be updated.
California privacy requests may be sent to marcin.rewertyn@gmail.com.
14. Children's privacy and COPPA
Our game is intended for a general audience and is not specifically directed to children under the age of 13, or the equivalent minimum age required by applicable law in the user’s jurisdiction.
We do not knowingly collect personal information directly from children. The game does not require account registration, does not ask users to provide their name, email address, phone number, photos, messages, or other personal contact information, and does not include social features, public profiles, or user-generated content sharing.
If the game uses analytics, crash reporting, advertising, in-app purchases, or other third-party services, such services may process limited technical, device, usage, or transaction-related information as described in this Privacy Policy and in the privacy policies of those third-party service providers.
If you are a parent or legal guardian and you believe that your child has provided personal information to us, or that personal information about your child has been collected in a way that is not described in this Privacy Policy, please contact us at: marcin.rewertyn@gmail.com. We will review the request and take reasonable steps to delete such information where required by applicable law.
We encourage parents and legal guardians to monitor their children’s use of apps, games, and online services.
Google Play Families policy information is available here: https://support.google.com/googleplay/android-developer/answer/9893335.
15. International data transfers
External service providers such as Google/Firebase, Google Play / Google Payments, and Unity may process data in countries other than the user's country of residence. These providers are responsible for their own transfer mechanisms, safeguards, privacy terms, and data processing terms where applicable.
16. Data retention and deletion
Local data, such as game progress, settings, local purchase entitlement flags, and consent status, is stored on the device until the user deletes the application, clears application data in Android settings, resets settings where available, or the data is overwritten by normal game use.
Firebase analytics and diagnostic data are retained according to the Firebase/Google retention settings and policies configured for the project. Data deletion requests may be sent to marcin.rewertyn@gmail.com, and the developer will take reasonable actions to the extent technically possible.
Google Play purchase and payment data may be retained by Google to the extent required for payment processing, refunds, fraud prevention, security, tax/accounting, and legal obligations. The developer does not have access to the user's full payment credentials.
Support emails may be retained as long as reasonably necessary to respond to the request, maintain support history, resolve disputes, and comply with legal obligations.
17. Data deletion options
The user may delete local game data by clearing the app data in Android settings or uninstalling the game. This may reset progress, settings, virtual currency balance stored locally, and local entitlement flags unless the purchase can be restored through Google Play.
The user may request deletion of data associated with Firebase diagnostics or support communications by emailing marcin.rewertyn@gmail.com. The request should include the game name, platform, and a description of the data covered by the request.
18. Opting out of analytics and crash reports
The user may refuse consent in the privacy consent window or change the preference in the game's privacy settings if such an option is available. After consent is refused, the game suppresses the sending of analytics events and Crashlytics reports from application code according to the current implementation described by the developer.
Changing consent may not delete data that was already processed by external providers before the preference changed. To request deletion of previously collected data, contact marcin.rewertyn@gmail.com.
19. Security
Data sent to Google/Firebase, Google Play, Google Payments, and Unity services is transmitted using standard encryption-in-transit mechanisms, such as HTTPS/TLS, where supported by the relevant SDK and service.
The game does not operate its own backend server for storing user profiles. Local game progress is stored on the device using the project's local preferences mechanism with hashing and encryption as described by the developer. No method of electronic storage or transmission is completely secure, but reasonable technical and organizational measures are used to reduce risk.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example after adding new features, SDKs, ads, purchases, backend services, account systems, analytics changes, or changes in legal or Google Play requirements. The current version will be available at the privacy policy link provided in Google Play and, where available, inside the game.
21. Contact
For privacy matters, data access, data deletion, consent questions, or questions regarding this Privacy Policy, please contact:
rewernator
Email: marcin.rewertyn@gmail.com