Privacy Policy
This Privacy Policy describes how FlareRapids ("we", "us", "our") collects, uses, discloses, and safeguards personal data when you (i) visit our corporate website at flarerapids.com, (ii) download or use any FlareRapids mobile application published on Google Play or the Apple App Store, and (iii) use any custom mobile management application we deliver on behalf of an enterprise client.
§ 01 Scope & Who We Are
FlareRapids (the "Studio", "we", "us") is the data controller for personal data processed through (a) the website at flarerapids.com, and (b) the consumer mobile applications we publish under our own developer accounts on Google Play and the Apple App Store (collectively, the "Apps").
For bespoke mobile management applications delivered to enterprise clients, the client organization is the data controller of any end-user data processed inside that app, and FlareRapids acts as a data processor under a written Data Processing Agreement (DPA) compliant with Article 28 of the GDPR, the UK GDPR, and equivalent provisions in other jurisdictions. In that case, please direct your data rights requests to the relevant client organization.
Contact for privacy matters: buinhuy9082@icloud.com. We make every effort to respond within 30 days, and in any case within statutory deadlines.
§ 02 Data We Collect
We collect the minimum data necessary to provide and improve our Services. The categories below are grouped by source.
2.1 Data you provide directly
- Account & contact data — name, email address, business name, role, when you fill in a form on our website, sign up for a newsletter, or contact us.
- Correspondence — the contents of messages you send us, including attachments.
- Support data — anything you share when you request help inside one of our Apps or enterprise applications.
- Enterprise onboarding data — for mobile management applications, your employer provisions the account; the data we receive is limited to what the administrator enables (typically: name, work email, role, group memberships, and permissions).
2.2 Data collected automatically when you use our Apps
- Device & connection data — device model, OS version, app version, locale, time zone, mobile carrier, screen size, and IP address (truncated where required by law).
- Usage data — taps, screens viewed, session length, features used, level progression, crash logs, and in-app purchase receipts.
- Advertising identifiers — Apple's Identifier for Advertising (IDFA) on iOS, and Google's Advertising ID (GAID / Android ID) on Android, only after you grant consent through the App Tracking Transparency prompt (iOS) or our consent management platform (Android).
- Crash & performance data — stack traces, device state, and network conditions captured by Firebase Crashlytics, Sentry, or equivalent.
2.3 Data collected on our website
- Server logs — IP address, browser type, referring page, pages visited, time on page. Retained for up to 90 days for security and analytics.
- Cookies & local storage — see the Cookies & SDKs section.
- Form submissions — anything you type into a contact form, newsletter signup, or job application form.
§ 03 How We Use Data
We use the data we collect for the following purposes:
- To provide and operate the Apps — installing, authenticating you, syncing your progress across devices, processing subscriptions and in-app purchases.
- To improve the Apps — analyzing aggregated usage to fix bugs, optimize flows, and design new features.
- To show advertising — in free-to-play Apps, we display ads from third-party networks. See Advertising & Ad Networks.
- To respond to inquiries — answering your questions, sending the information you requested, and following up on leads.
- To prevent fraud and abuse — detecting bots, blocking cheating, and protecting users from malicious behavior.
- To comply with law — meeting tax, accounting, anti-money-laundering, sanctions, and law-enforcement obligations.
- To enforce our terms — investigating violations and protecting our rights and the rights of other users.
We do not sell personal data. We do not use the contents of your private messages for advertising training. We do not share precise location with advertisers.
§ 04 Legal Bases (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 of the GDPR (and the equivalent Article 6 of the UK GDPR):
| Purpose | Legal basis |
|---|---|
| Providing and operating the Apps | Contract (Art. 6(1)(b)) |
| Responding to your inquiries | Contract / Pre-contractual steps (Art. 6(1)(b)) |
| Showing contextual ads (no profiling) | Legitimate interest (Art. 6(1)(f)), balanced against your rights |
| Showing personalized ads (with consent) | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Analytics & product improvement | Consent (Art. 6(1)(a)) for non-essential; legitimate interest for strictly necessary |
| Fraud prevention & security | Legitimate interest (Art. 6(1)(f)) |
| Tax, accounting, legal compliance | Legal obligation (Art. 6(1)(c)) |
§ 06 Advertising & Ad Networks
Our free-to-play mobile Apps display advertising through a mediation stack that combines multiple third-party ad networks. Each network acts as an independent controller of the personal data it receives. Below we list every network we currently integrate, the data they process, and links to their privacy documentation.
6.1 Google ad stack
- Google AdMob (publisher monetization) — banner, interstitial, rewarded, native, app-open. Privacy · Partner Sites Policy
- Google Ad Manager (programmatic) — for premium direct & open auction placements. Privacy
- Google AdSense (web only, where applicable) — contextual & personalized ads. Privacy & Cookies
6.2 Meta ad stack
- Meta Audience Network (FAN) — banner, interstitial, rewarded, native. Privacy · Ad Preferences
6.3 AppLovin ecosystem
- AppLovin MAX (mediation) — orchestrates bidding across demand sources. Privacy
- AppLovin (direct demand) — banner, interstitial, rewarded, native. Privacy
6.4 Unity ecosystem
- Unity LevelPlay (formerly ironSource mediation) — mediation & bidding. Privacy
- Unity Ads (direct demand) — in-game video, rewarded, playable. Privacy
- ironSource (where still integrated) — rewarded & offerwall. Privacy
6.5 ByteDance / TikTok
- Pangle — global monetization platform with strong APAC reach. Privacy
6.6 Mobile-first SSPs & networks
- Mintegral — AI-driven bidding. Privacy
- InMobi — premium video & rich media. Privacy
- Vungle (Liftoff) — rewarded & playable specialists. Privacy
- Chartboost (now integrated into Liftoff) — direct & programmatic via Helium. Privacy
- AdColony (now part of Digital Turbine) — video & interactive end-cards. Privacy
- Digital Turbine — full-funnel monetization. Privacy
- Tapjoy — offerwall, rewarded, direct deals. Privacy
- Smaato — open RTB mobile SSP. Privacy
- Start.io (StartApp) — Android emerging-markets demand. Privacy
- Liftoff (Vungle + Chartboost + GameRefinery) — creative optimization & monetization. Privacy
6.7 Header bidding & programmatic
- Amazon Publisher Services (APS) — transparent ad marketplace. Privacy
- Prebid Mobile (open-source header bidding wrapper). Privacy
6.8 What each network receives
When you grant advertising consent, the active networks may receive some or all of the following:
- Advertising identifier (IDFA / GAID, hashed)
- IP address (often truncated or hashed for geo-targeting)
- Device & OS information
- App ID, ad unit ID, and placement ID
- Coarse location (derived from IP), if you have granted location permission
- Event-level data (impression, click, conversion)
You can opt out of personalized advertising at any time:
- iOS: Settings → Privacy & Security → Tracking → toggle off "Allow Apps to Request to Track" for FlareRapids apps.
- Android: Settings → Privacy → Ads → "Opt out of Ads Personalization".
- Or reset your in-app choice: Settings → Privacy → Ad & Tracking Preferences → Reset.
6.9 app-ads.txt & sellers.json
To combat ad fraud and improve transparency, we publish an app-ads.txt file at the root of this domain, listing all authorized advertising sellers for our Apps. We also participate in the IAB Tech Lab sellers.json standard where applicable.
§ 07 Ad Formats We Use
The following ad formats may appear in our free-to-play Apps. Each format is implemented with frequency capping, a user-friendly dismissal, and respect for in-session context (no interstitial at the wrong moment).
7.1 Banner ads
Standard, adaptive, or collapsible banner strips rendered at the top or bottom of a screen. Always dismissible, never blocking.
7.2 Interstitial ads
Full-screen static, video, or playable ads shown at natural transition points (between levels, after a game-over). Capped per session per the App Store and Play Store guidelines.
7.3 Rewarded video ads
Opt-in only. Users choose to watch a full-screen video in exchange for an in-app reward (extra life, in-game currency, hint). Always voluntary, never required.
7.4 App-open (splash) ads
Shown when the user opens or returns to the app, before the loading screen. Capped so users see at most one app-open per session, and never on the very first launch after install.
7.5 Native ads
Custom layouts matched to the surrounding content (e.g. in-feed). Clearly labeled "Sponsored" or "Ad".
7.6 Playable ads & interactive end-cards
Opt-in mini-games or interactive cards, primarily in rewarded placements.
7.7 Offerwall
Where available, a list of partner offers (surveys, app installs, video views) the user can complete in exchange for in-app rewards. Tapjoy is the primary offerwall provider in our Apps.
§ 08 App Store Specifics
8.1 Google Play (Google LLC)
Our Apps are published on Google Play under our developer account. We comply with the Google Play Developer Program Policies, including the User Data Policy, the Families Policy, the Ads Policy, and the Payments Policy.
- Data Safety form: Every App published on Google Play includes a completed Data Safety section disclosing the data types collected, the purposes, and whether data is shared with third parties.
- Families Policy: Apps designed for or marketed to children use only neutral age-gates, do not transmit Advertising IDs, and do not use personalized advertising. The Designed for Families program applies where applicable.
- Personalized ads: Only served to users who have granted consent through the Google UMP (User Messaging Platform) consent flow, or who are not in a jurisdiction requiring consent.
- Billing: In-app purchases are processed by Google Play Billing; FlareRapids does not directly receive payment card data.
8.2 Apple App Store (Apple Inc.)
Our Apps are published on the Apple App Store under our Apple Developer Program enrollment. We comply with the Apple App Review Guidelines (including Guidelines 1, 5, and 6), the Developer Program License Agreement, and the Apple Privacy Policy.
- App Privacy labels (Nutrition Labels): Every App published on the App Store includes a completed App Privacy section listing data types, purposes, and tracking practices.
- Privacy Manifest (PrivacyInfo.xcprivacy): Each App declares the required reason APIs it uses (e.g. UserDefaults, file timestamp, system boot time, disk space) per Apple's privacy manifest requirements.
- App Tracking Transparency (ATT): Where any third-party SDK performs tracking as defined by Apple, we surface the ATT prompt before any tracking begins. We do not pre-prompt or dark-pattern users into accepting.
- Sign in with Apple: Where an App offers any third-party or social login, "Sign in with Apple" is offered as an equivalent option per Guideline 5.1.1.
- Kids Category: Apps in the Kids Category comply with the full restrictions of that category, including the prohibition of behavioral advertising and external links.
- Billing: In-app purchases are processed by Apple's In-App Purchase system; FlareRapids does not directly receive payment card data.
§ 09 Children's Privacy
9.1 COPPA (United States — children under 13)
We comply with the U.S. Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 in a manner that requires verifiable parental consent, except where such consent has been obtained (for example, in school-district deployments of our mobile management applications, where the school acts as the parent's agent).
- Children's Apps in our portfolio: no behavioral or personalized advertising, no Advertising ID collection, no chat or open social features without moderation, no in-app purchases without parental gate.
- Where data is collected from a known child (with verifiable parental consent), it is used solely to provide the service, retained only as long as necessary, and never used for any other commercial purpose.
- Parents may review, delete, or refuse further collection of their child's information by contacting us at buinhuy9082@icloud.com.
9.2 GDPR & EU Member States (children under 16 by default, 13 in some states)
For Apps accessible to children in the EU, we treat the minimum age of digital consent as set by each member state (13, 14, 15, or 16). We never process children's data on the legal basis of "consent" where consent is given by the child alone; in such cases we require parental consent or a comparable age-appropriate safeguard.
9.3 UK Age-Appropriate Design Code (AADC)
For Apps likely to be accessed by children in the UK, we conduct a Data Protection Impact Assessment (DPIA) and apply the AADC's 15 standards: best interests of the child, age-appropriate application, transparency, detrimental use of data, policies and standards, default settings, data minimization, data sharing, geolocation, parental controls, profiling, nudge techniques, connected toys/devices, online tools, and DPIA publication.
9.4 China — Personal Information Protection Law (PIPL)
For users under 14 in mainland China, we treat their personal information as sensitive personal information, require verifiable parental consent before any processing, and apply strict data minimization. We do not profile minors for advertising.
9.5 Other jurisdictions
We apply the strictest applicable standard across our portfolio. If your jurisdiction sets a lower age of digital consent, we still treat all users under 16 as children for advertising and profiling purposes.
§ 10 Country-by-Country
We apply a layered approach: the strictest applicable standard applies, and the rights below are granted to all users regardless of jurisdiction (some jurisdictions grant more).
10.1 European Economic Area (EEA) & United Kingdom
- GDPR (Regulation (EU) 2016/679) & UK GDPR — full scope; rights of access, rectification, erasure, restriction, portability, objection, and not to be subject to a decision based solely on automated processing.
- ePrivacy Directive 2002/58/EC — cookie consent on the website; software-based consent (CMP) for non-essential cookies & SDKs.
- Digital Services Act (DSA) & Digital Markets Act (DMA) — applicable where FlareRapids operates as a hosting service or designated gatekeeper-adjacent service; we do not currently operate in either role.
- EU AI Act (Regulation (EU) 2024/1689) — any AI features in our Apps are categorized and disclosed under the Act's risk taxonomy.
10.2 United States
- California — CCPA / CPRA: rights to know, delete, correct, and opt out of sale/sharing; right to limit use of sensitive personal information; non-discrimination. FlareRapids does not "sell" or "share" personal information as defined by the CCPA/CPRA.
- California — CalOPPA: Do Not Track signals are honored where technically feasible.
- Virginia — VCDPA, Colorado — CPA, Connecticut — CTDPA, Utah — UCPA, Texas — TDPSA, and other state laws — equivalent rights granted.
- COPPA (federal): see § 9.1.
- CAN-SPAM, TCPA — marketing email and SMS comply with opt-out and consent requirements.
10.3 United Kingdom
- UK GDPR & Data Protection Act 2018 — same rights as the GDPR, with the ICO as supervisory authority.
- Age-Appropriate Design Code (AADC) — see § 9.3.
- Privacy and Electronic Communications Regulations (PECR) — cookie consent on the website.
10.4 Brazil — LGPD (Lei Geral de Proteção de Dados)
Rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing. Legal bases aligned to the GDPR. ANPD is the supervisory authority.
10.5 Canada — PIPEDA & Quebec Law 25
Consent-based processing, access and correction rights, breach notification to the OPC and to affected individuals, and (for Quebec) privacy officer appointment, DPIA, and confidentiality incident registry.
10.6 Australia — Privacy Act 1988 & APPs
Compliance with the Australian Privacy Principles, Notifiable Data Breaches scheme, and (from late 2024) the enhanced transparency obligations.
10.7 Japan — APPI
Compliance with the Act on the Protection of Personal Information, including the 2022 amendments on cross-border transfers and breach notification.
10.8 South Korea — PIPA
Compliance with the Personal Information Protection Act, including the 2023 amendments on cross-border transfers (consent or specific contractual basis) and data subject rights.
10.9 China — PIPL, DSL, CSL
Compliance with the Personal Information Protection Law, Data Security Law, and Cybersecurity Law. Cross-border transfers of PI out of mainland China require a CAC security assessment, standard contract, or certification, as applicable to the volume and sensitivity of the data.
10.10 Singapore — PDPA
Compliance with the Personal Data Protection Act, including the 2020 amendments on financial penalties and the mandatory breach notification.
10.11 India — DPDP Act 2023
Compliance with the Digital Personal Data Protection Act, 2023, including consent, purpose limitation, and the rights of data principals.
10.12 Other jurisdictions
We extend GDPR-equivalent rights globally. If you are in a jurisdiction not listed above, you may still exercise the rights set out in § 14, and we will respond within statutory timeframes applicable to you.
§ 12 International Data Transfers
Personal data may be transferred to, and processed in, countries other than the one in which you reside. These countries may have different data protection standards than your country of residence.
When we transfer personal data out of the EEA, UK, or Switzerland, we rely on one or more of the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Module 1, 2, or 3 as applicable) and the UK International Data Transfer Addendum where relevant.
- Adequacy decisions where the European Commission (or the UK government) has determined that a country provides an adequate level of protection.
- Derogations under Article 49 GDPR in limited, specific circumstances (e.g. explicit consent, contract performance).
For transfers out of mainland China, we rely on the CAC Standard Contract, the CAC Security Assessment, or CAC Certification as applicable to the volume and sensitivity of the data, and we conduct the required PIPIA (Personal Information Protection Impact Assessment).
You can request a copy of the transfer safeguards we rely on by emailing buinhuy9082@icloud.com.
§ 13 Retention
We retain personal data only for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:
| Data category | Retention period |
|---|---|
| Account & contact form submissions | Up to 24 months from last interaction |
| Server logs (website) | Up to 90 days |
| Aggregated analytics | Up to 26 months (then anonymized) |
| App usage & crash logs | Up to 18 months |
| Ad data held by ad networks | Per each network's own retention policy (see § 6) |
| Billing & tax records | 7 years (US/EU), 10 years (China), or longer per local law |
| Enterprise mobile management data | Per the client's DPA (typically contract term + 30 days) |
After the retention period expires, we delete or irreversibly anonymize the data so that it can no longer be associated with you.
§ 14 Your Rights
Regardless of where you live, you have the following rights in respect of your personal data:
- Right to know / access — request a copy of the personal data we hold about you.
- Right to correct / rectify — request correction of inaccurate or incomplete data.
- Right to delete / erase — request deletion of your data ("right to be forgotten").
- Right to restrict processing — ask us to pause processing while a complaint is investigated.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interest, including profiling.
- Right to opt out of sale or sharing (CCPA/CPRA) — we do not sell data, but you can still opt out of any sharing.
- Right to opt out of targeted advertising — at any time via in-app settings, device settings, or our cookie banner.
- Right to withdraw consent — where we rely on consent, you can withdraw it at any time without affecting prior processing.
- Right to lodge a complaint — with your local data protection authority. A list is available at EDPB, the ICO (UK), the California AG, and equivalent authorities worldwide.
- Right to non-discrimination — we will not deny service, charge different prices, or provide a different level of quality because you exercised any of these rights.
To exercise any of these rights, email buinhuy9082@icloud.com with the subject "Data Subject Request". We will respond within statutory deadlines (typically 30 days under the GDPR; 45 days under the CCPA, extendable once).
§ 15 Security
We take the security of your personal data seriously. Our technical and organizational measures include:
- Encryption in transit — TLS 1.2+ (TLS 1.3 where supported) for all website, API, and app-backend traffic.
- Encryption at rest — AES-256 on cloud storage, encrypted local storage on devices (Keychain on iOS, EncryptedSharedPreferences on Android).
- Access control — least-privilege RBAC, MFA on all production systems, hardware keys for high-privilege accounts.
- Network security — VPC isolation, WAF, DDoS mitigation, regular penetration tests by independent third parties.
- Code security — SAST, DAST, dependency scanning, signed builds, app attestation.
- Operational security — background checks, security training, incident response plan, 24/7 on-call.
- Vendor security — every data processor is vetted against a security questionnaire and bound by a DPA with security obligations at least equivalent to ours.
Despite our efforts, no system is 100% secure. If we become aware of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority within statutory deadlines (72 hours under the GDPR, "without unreasonable delay" under the CCPA, 72 hours under PIPL).
§ 16 Contact & Data Protection Officer
For any privacy question, complaint, or data-subject request, contact us at:
FlareRapids — Privacy Office
Email: buinhuy9082@icloud.com
Subject line for fastest routing: "Privacy Request"
EU representative (Article 27 GDPR) and UK representative (Article 27 UK GDPR) can be reached at the same email address, marked clearly for the EU or UK representative.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. The list of EU supervisory authorities is available at the European Data Protection Board. The UK Information Commissioner's Office is at ico.org.uk.
§ 17 Changes to this Policy
We may update this Privacy Policy from time to time. The "Effective" date at the top of this page reflects when the policy was last revised. Material changes (changes that meaningfully expand the data we collect, the purposes for which we use it, or the third parties with whom we share it) will be communicated in advance via:
- An in-app banner or modal in each of our Apps, displayed for at least 30 days before the change takes effect.
- An email to registered users (where we have a working email on file).
- A notice on the home page of flarerapids.com.
Non-material changes (typographical corrections, clarifications, or updates to legal references) will be posted with an updated "Effective" date and version number. We encourage you to review this policy periodically.
This policy is provided in English. Translations may be provided for convenience; in case of conflict, the English version prevails.