Privacy Notice

Version 2026-09-01

The game currently has no account system and payments are disabled. This notice separates present processing from the planned payment service.

Data used now

The game stores the best score in the player's browser. It is not sent to the game database. GitHub Pages, DNS and network providers may process ordinary technical logs such as IP address, time, requested page and browser details for delivery and security.

Data used if payments launch

The service would process an anonymous run identifier, pass type, order and payment references, price, currency, adult confirmation, accepted terms version, entitlement expiry, limited fraud-prevention data and support/refund records. Razorpay would process payment details under its own notice. The game must not store card or UPI credentials.

Purpose

Data is used to deliver the game, verify payments, grant and recover passes, prevent fraud, handle refunds and disputes, keep required records, secure the service and meet legal duties. It will not be sold.

Children

India treats a person under 18 as a child for the Digital Personal Data Protection framework. Children may play the free game with parent or guardian permission. They must not purchase directly. We will not knowingly use child data for targeted advertising or behavioural monitoring. If child personal data becomes necessary, verifiable parental consent will be obtained before processing where law requires it.

Storage and security

An opaque pass token may be stored in the browser so a valid pass survives refresh. The backend stores only its cryptographic hash. Database tables use row-level security and deny public access. Payment secrets remain in server-managed secrets.

Retention and rights

Records will be kept only for the period needed for access, security, disputes, tax, accounting and other law. Detailed retention periods, the operator identity, privacy contact and request process must be published before payments launch. Until then, use the current contact route and do not post personal or payment data publicly.

Providers

Current hosting uses GitHub Pages. The planned payment design uses Supabase for backend/database services and Razorpay for checkout and payment aggregation. No analytics or advertising library was found in the reviewed version.