Introduction & Scope
This Privacy Policy ("Policy") describes how Mert Burak Dervisoglu ("we", "us", or "our") collects, uses, shares and protects information in connection with the mobile game Bounstrike and its related features (collectively, the "App") on Android & iOS.
We act as the data controller for personal data processed through the App. By downloading, accessing or using the App, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the App.
Information We Collect
Depending on the features you use, the App may involve the following categories of information:
- Account & identity data. When you sign in, we receive a user identifier (UID), display name, email (where provided) and an authentication token from your chosen provider (Anonymous, Google Play Games, Apple Sign-In).
- Game progress & saved data. Your saved progress, scores, settings and related game state, synchronized to the cloud and linked to your account.
- Usage & analytics data. Events and interactions such as sessions, screens viewed, levels started/completed, in-game actions, feature usage and engagement, together with an app-instance identifier — collected via Google Firebase Analytics.
- Advertising identifiers. Your device advertising ID (Google Advertising ID on Android, IDFA on iOS, where permitted), IP address, approximate (coarse) location derived from IP, and ad-interaction data — used to serve and measure ads via Google AdMob.
- Diagnostics & crash data. Crash stack traces, device model, operating-system version, app version, language, and a diagnostic installation identifier — collected via Google Firebase Crashlytics to keep the App stable.
- Push token. A device push-notification token (via Firebase Cloud Messaging) used to deliver notifications you have enabled.
- Purchase data. Confirmation and receipt of in-app purchases. Payments are processed by the app store (Google Play / Apple); we do not receive or store your full payment-card details.
We collect this information directly from you (e.g. when you sign in), automatically through the software development kits (SDKs) integrated into the App, and from third parties such as your sign-in provider or the app store.
How We Use Information
- To provide, operate, maintain and improve the App and its features;
- To diagnose problems, fix bugs and ensure stability and security;
- To create and authenticate your account and keep you signed in;
- To save and synchronize your progress across sessions and devices;
- To understand how the App is used through aggregated analytics and to improve the experience;
- To display and measure advertising, including frequency capping and fraud prevention;
- To send notifications you have enabled (you can disable these at any time);
- To process and confirm in-app purchases;
- To prevent fraud, abuse and cheating, and to enforce our terms;
- To comply with legal obligations and respond to lawful requests.
Legal Bases for Processing (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
| Account, sign-in and cloud save | Performance of a contract (Art. 6(1)(b)) |
| In-app purchases and receipts | Contract (Art. 6(1)(b)) and legal obligation for tax/accounting records (Art. 6(1)(c)) |
| Analytics and usage measurement | Your consent where required for on-device identifiers (Art. 6(1)(a)); otherwise our legitimate interest in improving the App (Art. 6(1)(f)) |
| Crash and diagnostics data | Legitimate interest in App stability and security (Art. 6(1)(f)) |
| Personalized advertising | Your consent (Art. 6(1)(a)), requested via the consent prompt |
| Non-personalized / contextual advertising | Consent for storing identifiers where required by ePrivacy rules; otherwise legitimate interest (Art. 6(1)(f)) |
| Push notifications | Your consent (Art. 6(1)(a)) |
| Security, fraud prevention and legal compliance | Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
Advertising & Your Choices
The App displays advertising through Google AdMob (banner, interstitial, rewarded ads). Ad providers may use device identifiers and related data to deliver and measure ads, including personalized (interest-based) ads where permitted. Even non-personalized ads use a device identifier for purposes such as frequency capping and fraud prevention.
For more information on how Google uses data when you use apps that use its services, see "How Google uses information from sites or apps that use our services", Google's Privacy Policy and its Advertising page.
EEA, UK & Switzerland. Before showing personalized ads, we request your consent through a Google-certified consent message (the User Messaging Platform, based on the IAB Transparency & Consent Framework). If you decline, you will see non-personalized ads. You can change or withdraw your choice at any time from the App's privacy/consent settings.
Apple devices. On iOS we ask for your permission through Apple's App Tracking Transparency framework before accessing your device's advertising identifier (IDFA) or tracking you across other companies' apps and websites. If you do not grant permission, we do not track you and show only non-personalized ads. This is a separate choice from the consent message described above.
You can also reset or limit your advertising identifier in your device settings (Android: Settings → Privacy/Ads; iOS: Settings → Privacy & Security → Tracking).
Analytics & Crash Reporting
Google Firebase Analytics. Collects an app-instance identifier, device and usage information, and automatically-collected and custom events (such as sessions and screens) to help us understand and improve how the App is used. Data is used in aggregate.
Google Firebase Crashlytics. Collects crash reports and related device state solely to diagnose and fix stability problems.
These are Google/Firebase services. Google processes the data as described at Privacy and Security in Firebase and in the Google Privacy Policy.
Push Notifications
If you enable notifications, we use Firebase Cloud Messaging to deliver them to your device via a push token. You can disable notifications at any time from your device settings, which stops further notifications.
International Data Transfers
The providers above (including Google LLC and, where relevant, Apple) may process data on servers located outside your country, including in the United States. Where we or our providers transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework (for certified recipients such as Google LLC), and the UK International Data Transfer Addendum.
If you are in Türkiye, cross-border transfers are carried out in accordance with Article 9 of the KVKK; see our KVKK notice for details.
Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, including providing the App, maintaining your account and saved data, complying with legal, tax and accounting obligations, resolving disputes and enforcing our agreements. When data is no longer needed, we delete it or irreversibly anonymize it.
- Account and saved data is kept while your account is active and for a limited period afterward; you may request deletion at any time.
- Analytics event data is retained for a limited period (for example, up to 14 months) and then aggregated or deleted.
- Crash and diagnostics data is retained only as long as needed to investigate stability issues.
- Purchase records are kept for the period required by tax and accounting law.
Data Security
We use reasonable administrative, technical and organizational measures to protect information, such as encryption of data in transit (HTTPS/TLS), access controls, and reputable infrastructure providers (e.g. Google Cloud / Firebase). However, no method of transmission or electronic storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a personal-data breach that affects you, we will notify you and the competent authorities where required by applicable law.
Your Privacy Rights
Subject to applicable law, you may have the right to access your personal data, correct inaccurate data, request erasure, restrict or object to processing (including direct marketing), request data portability, and withdraw consent at any time. Residents of Türkiye have rights under the KVKK — see our KVKK notice; residents of the EEA/UK have rights under the GDPR / UK GDPR.
To exercise any of these rights, contact us at mertburakdervisoglu@gmail.com. We will respond within the time required by law (generally one month under the GDPR; 30 days under the KVKK). You also have the right to lodge a complaint with your local data-protection supervisory authority.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of its "sale" or "sharing", as well as the right not to be discriminated against for exercising these rights.
We do not sell your personal information for money. However, our use of advertising identifiers for personalized advertising may be considered "sharing" (cross-context behavioral advertising) under California law. California residents may opt out by declining the advertising consent prompt or by disabling/limiting ad tracking in their device settings; we also honor recognized Global Privacy Control signals where applicable. The categories we may collect include identifiers, internet/network activity and inferences.
To exercise your California rights, contact mertburakdervisoglu@gmail.com.
Other U.S. State Privacy Rights
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas and others) may have rights to access, correct, delete and obtain a copy of their personal data, and to opt out of targeted advertising, the sale of personal data and certain profiling. Where required, we honor recognized universal opt-out signals. To exercise these rights, or to appeal a decision, contact mertburakdervisoglu@gmail.com.
Children's Privacy
The App is intended for a general audience and is not directed to children under the age of 13 (or the minimum age required in your country, which may be higher — for example up to 16 in parts of the EEA under Article 8 GDPR). We do not knowingly collect personal information from children below that age.
If you believe a child has provided us with personal information, please contact mertburakdervisoglu@gmail.com and we will delete it promptly. We comply with the U.S. Children's Online Privacy Protection Act (COPPA), and we do not enroll the App in child-directed store programs (such as the Apple Kids Category) or use child-directed advertising settings.
Third-Party Links & Content
The App may display, link to, or open third-party websites, apps or content that we do not control. We are not responsible for the privacy practices, content, accuracy or safety of those third parties, and this Policy does not apply to them. we encourage you to review the privacy policies of any third party before providing information to them.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes are effective when posted on this page with a revised effective date shown above. For material changes we will provide reasonable notice where required. Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.
Contact Us
If you have any questions, requests or complaints about this Policy or your personal data, contact us:
| Data controller | Mert Burak Dervisoglu |
| mertburakdervisoglu@gmail.com | |
| App | Bounstrike (com.mertburakdervisoglu.bounstrike) |