Privacy Policy
Effective date: 24 April 2026
This Privacy Policy ("Policy") applies to all mobile games, websites (eggtart.io and its subdomains), and related services (collectively, the "Services") published by Game37s and operated under the eggtart brand. Unless otherwise stated, the terms "Game37s", "eggtart", "we", "us", and "our" in this Policy refer to the same entity.
By downloading, installing, or using the Services you agree to the practices described in this Policy. This Policy is designed to comply with the Apple App Store Review Guidelines, the Google Play Developer Program Policy, the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), as applicable.
1. Who we are
Operator: Game37s (Hong Kong), publishing, distributing, and operating the Services under the eggtart brand. The data controller under this Policy is Game37s. Contact: [email protected].
2. Information we collect
To provide, maintain, and improve the Services, we may collect the following categories of data:
- Account identifiers: your in-game nickname, avatar, and the basic identifier returned when you sign in with Apple ID (via Apple's private email relay) or Google Account. We do not collect your password.
- Device information: device model, OS version, language / locale, unique device identifiers (such as IDFV or Android ID), crash logs, performance metrics.
- Gameplay data: progress, rankings, match history, virtual items, in-game chat messages (where chat is available), and reports you submit.
- Transaction data: purchase receipts relayed to us by Apple App Store or Google Play Billing (credit-card numbers are not shared with us). All payments are processed by the platforms.
- Support communications: your name, email, and message content voluntarily submitted when you contact us.
- Technical logs: IP address, access time, request path, and error codes, used to prevent abuse and troubleshoot issues.
3. How we use your information
We only process your data for the following purposes:
- Provide, maintain and improve the Services, including matchmaking, leaderboards, and anti-cheat.
- Authenticate you and manage your game account.
- Process in-app purchases, refunds, and receipt validation.
- Respond to customer support requests and handle reports.
- Detect, prevent, and investigate suspicious, abusive, or unlawful activity.
- Comply with legal obligations, court orders, or requests from competent authorities.
- Serve and measure in-game advertising (only in games that contain ads).
4. Sharing of information
We do not sell your personal data. We share necessary data with third parties only in the following cases:
- App stores: Apple App Store and Google Play — for distribution, IAP, receipt validation, and App Privacy Label / Data Safety disclosures.
- Cloud and infrastructure providers: Cloudflare (CDN / WAF) and self-hosted servers located in Hong Kong.
- Crash and performance analytics: standard SDKs used on a per-game basis to diagnose errors and improve stability.
- Advertising partners (ad-supported games only): Google AdMob or equivalent networks. These SDKs may collect IDFA / GAID to serve relevant ads. You can disable ad tracking from your device (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads → Reset / Delete).
- Legal requests: in response to lawful subpoenas, court orders, or requests from competent authorities.
- Business transfers: in the event of a merger, acquisition, or asset sale, under equivalent confidentiality obligations.
5. Data retention
Unless otherwise required by law or this Policy, we retain your data according to the following periods:
- Game account and progress: while your account is active; if an account is inactive for 24 consecutive months, we reserve the right to delete, suspend, or anonymise the associated data without further notice.
- Transaction and receipt records: retained for at least 7 years, or longer as required by applicable law, for tax, accounting, audit, and refund-dispute purposes.
- Support communications: at least 24 months after the end of correspondence, or until any related dispute is resolved, whichever is later.
- Server technical logs: up to 90 days; logs relevant to a security incident, fraud, or policy investigation may be retained until the investigation is complete.
- Anonymised or de-identified statistical data: may be retained indefinitely for product analytics, business intelligence, and research.
- We reserve the right to continue retaining certain data where reasonably necessary to comply with legal obligations, enforce our terms, protect security, or prevent fraud.
6. Account and data deletion
If you wish to delete your eggtart game account and related personal data, email [email protected] with the subject line "Account Deletion" and provide:
- The game name;
- Your in-game nickname (In-game ID);
- Platform (iOS / Android);
- Information that helps verify your identity — for example a purchase receipt number, App Store / Google Play order ID, or the login email associated with the account.
6.1 Processing time and right to refuse
We will process the request within 30 days of receiving valid verification. To protect account security, we may require additional proof of identity. Where we reasonably believe the request is incomplete, unverifiable, fraudulent, or associated with a breach of this Policy or our terms of service, we reserve the right to refuse, suspend, or delay the request without further explanation.
6.2 Scope of deletion
On successful processing, the following will be deleted or anonymised:
- In-game nickname, avatar, and account identifiers
- Game progress, match history, virtual items, and leaderboard data
- Chat messages and report records
- Support correspondence associated with you
6.3 What we may retain
Within reasonable and legally permitted limits, we may continue to retain:
- Transaction and receipt records for tax, accounting, audit, and refund-dispute purposes (at least 7 years or longer);
- Risk-control records necessary to prevent cheating, multi-accounting abuse, and fraud (may be retained with correlation markers to prevent re-registration);
- Data we are required by law, court order, or competent authority to preserve;
- Data that has been anonymised and can no longer identify you, which may be retained indefinitely.
6.4 Other important terms
Virtual items, points, membership benefits, and paid content are non-refundable upon account deletion, except as required by applicable law. Once deletion is complete, the account and associated data cannot be restored. If you only wish to suspend your account temporarily, please write "Suspend" instead of "Delete" in your request.
7. Children's privacy
The Services are not directed to children under 13 (or equivalent minimum age in your jurisdiction), and we do not market to children. We do not knowingly collect personal data from children under 13.
If we learn that we have collected personal data from a child without verifiable parental consent, we will delete it promptly. If you are a parent or guardian and believe your child has provided personal data to us, please contact [email protected] and we will remove it as soon as possible.
We comply with the US Children's Online Privacy Protection Act (COPPA), the Google Play Families Policy, and Apple's Kids Category requirements. In child-directed apps, we do not use third-party advertising SDKs, third-party analytics SDKs, or collect precise location.
8. Your rights
Subject to the laws of your jurisdiction (including GDPR, CCPA, and PDPO), you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion (see Section 6).
- Restrict or object to specific processing activities.
- Data portability — receive your data in a structured, commonly used electronic format.
- Withdraw consent — without affecting processing carried out before withdrawal.
- Lodge a complaint with a supervisory authority (Hong Kong: Privacy Commissioner for Personal Data, PCPD; EU: your local data protection authority).
9. International data transfers
Our servers are located in Hong Kong. Certain third-party processors (such as Apple, Google, Cloudflare) may process data across their global networks. Where transfers occur, we rely on contractual arrangements (such as Standard Contractual Clauses) to ensure an adequate level of protection.
10. Data security
We implement reasonable administrative, technical, and physical safeguards, including encryption in transit (HTTPS / TLS), access controls, and regular vulnerability reviews. However, no method of internet transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
11. Disclaimers, limitation of liability, and governing law
To the maximum extent permitted by applicable law, the Services are provided on an "as-is" and "as-available" basis. We make no express or implied warranty as to reliability, stability, fitness for a particular purpose, or freedom from error.
Except in the case of our wilful misconduct or gross negligence, we shall not be liable for any direct, indirect, incidental, punitive, or consequential loss arising out of your use of the Services, account suspension, data loss, server outage, or the acts of any third-party SDK or platform. Our total aggregate liability under any circumstance shall not exceed the amount you have actually paid to us in the 12 months preceding the event giving rise to the claim.
Third-party services: Apple, Google, Cloudflare, advertising partners, and other third-party services are governed by their own terms and privacy policies. We are not responsible for their acts or omissions.
Force majeure: we are not liable for any interruption or delay caused by acts of God, war, strikes, cyber-attacks, power or telecom failures, governmental action, or any other event beyond our reasonable control.
Governing law and jurisdiction: this Policy is governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region. Any dispute arising out of or in connection with this Policy or the Services shall be submitted to the exclusive jurisdiction of the Hong Kong courts.
Language versions: this Policy is published in Chinese and English. In case of any discrepancy, ambiguity, or conflict between the versions, the Chinese version shall prevail.
12. Changes to this Policy
We may update this Policy from time to time in response to legal, regulatory, or operational changes. Updates will be posted on this page and the "Effective date" will be revised; material changes will be announced prominently on our website or in the apps. Your continued use of the Services after the update takes effect constitutes acceptance of the revised Policy.
13. Contact us
For questions about this Policy, to exercise your rights, or to raise a complaint, please contact us at:
Email: [email protected] (use subject line "Privacy" or "Account Deletion")
Operator: Game37s (operating the eggtart brand) · Hong Kong