GDPR Compliance Statement

Last updated: 2026-08-22 08:54 (UTC+00:00)

Effective Date: 13 June 2025
Last Updated: 22 August 2026

At Game Farm Studios Ltd (“Game Farm”), we are committed to protecting personal data and respecting the rights of individuals under the UK General Data Protection Regulation (UK GDPR) and the EU GDPR where applicable.


1. Our Role as Data Controller

Game Farm Studios Ltd acts as a data controller for the personal data of:

  • Players who create accounts to access and track game progress
  • Customers who license our games and use our management dashboards

We determine the purposes and means of processing this personal data.

For optional anonymous analytics (for example Ish guest stats/metrics with consent), we process pseudonymous gameplay data keyed by a hashed device identifier, not by name or email.


2. Our Lawful Basis for Processing

We process personal data based on the following lawful grounds under Article 6 of the GDPR:

  • Contractual necessity – to create and manage user accounts, store scores, and fulfill licensing agreements
  • Legitimate interests – to maintain platform security, operate leaderboards, and understand aggregate usage patterns (for example device type and OS family breakdowns)
  • Consent – for optional anonymous stats and metrics, and for any future cookie-based analytics

3. Types of Personal Data We Process

Account holders

  • Email address (from Google sign-in)
  • Display name and onboarding preferences
  • Gameplay activity data (time spent, scores, sessions, streaks)
  • Consent preferences (statsConsent, metricsConsent, terms version)
  • Coarse device context: mobile/desktop and OS family (iOS, Android, macOS, Windows, Linux, ChromeOS) — not version strings or fingerprinting data

Customers

  • Business contact information (email, company name, address)
  • Licensing and product usage data

Authentication

  • Authentication metadata via Firebase Auth (Google sign-in)

Pseudonymous / consent-gated data (guests)

  • Hashed device identifier (server stores a one-way hash only)
  • Lean session summaries, derived stats, and engagement events
  • Coarse device type and OS family as above

We minimise data collection: we do not collect OS or browser version numbers for analytics, and we do not use analytics data to identify individual users.


4. Consent model (stats vs metrics)

Where games offer optional cloud analytics, consent is split:

| Flag | Typical use | |------|-------------| | statsConsent | Session history, score aggregates, streaks | | metricsConsent | Engagement event streams (pack started, question answered, etc.) |

  • Guests: per-game consent in browser storage; can be changed in Settings.
  • Signed-in players: account-wide flags on players/{uid}.privacy (shared across games that honour them).

Withdrawing consent stops further optional uploads; it does not by itself delete data already stored — you may request erasure separately.


5. Data Security

We implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data. These include:

  • Secure login via Firebase Auth (Google sign-in)
  • Application-layer encryption of selected player fields in our database (AES-256-GCM) where configured
  • Access controls and server-only profile writes
  • Hashed anonymous device identifiers for guest contributions
  • Regular review of third-party processor compliance

6. International Data Transfers

Where personal data is transferred outside the UK or EU (for example via Firebase / Google Cloud), we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs)
  • Ensuring our vendors are GDPR-compliant

7. Data Retention

We retain personal data only as long as necessary to fulfill the purposes for which it was collected:

  • Active accounts: while in use
  • Inactive accounts: up to 12 months
  • Anonymous metrics: retained for aggregate reporting; not linked to identity unless you later sign in and link activity
  • Upon request: deleted promptly in line with our privacy policy

8. Data Subject Rights

All individuals whose data we process have the right to:

  • Access their personal data
  • Correct or update inaccurate information
  • Request deletion of their data
  • Restrict or object to processing
  • Data portability (where applicable)
  • Withdraw consent (for consent-based processing)
  • Lodge a complaint with the UK Information Commissioner’s Office (ICO)

9. Contact Information

To exercise your GDPR rights or for any data protection concerns, contact us at:
Email: farmers@gamefarm.ing