This Privacy Policy ("Policy") explains how Trio Tangle: Triple Match ("the Application," "we," "us," or "our") gathers, processes, stores, and discloses personal data when you untangle tiles, clear boards, and engage with optional rewards. By installing or using the Application, you confirm that you have read and understood this Policy. It is intended to align with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the Virginia Consumer Data Protection Act (VCDPA).
Article I — Key Definitions
- "Application"
- Trio Tangle: Triple Match, the mobile triple-match puzzle software we distribute.
- "Company"
- The operating entity behind the Application, referred to as "we," "us," or "our."
- "Personal Data"
- Any information relating to an identified or identifiable natural person.
- "Usage Data"
- Information collected automatically from your Device or from Application infrastructure (for example, match clears, session length, and crash diagnostics).
- "Device"
- Any smartphone, tablet, or similar apparatus used to access the Application.
- "Service Provider"
- A natural or legal person who processes data on our behalf.
- "Account"
- Any profile or session identifier used to access features, progress, or withdrawals.
Article II — What We Collect
2.1 Automatically gathered categories. When you open the Application, the following may be recorded without further action:
- Internet Protocol (IP) address and network connection metadata
- Device type, operating system, and browser or WebView details
- Advertising and device identifiers (for example GAID, ANDROID_ID, or equivalents)
- Session metrics such as board interactions, time spent, and session duration
- Crash logs, diagnostic reports, and performance signals
- Mobile-specific identifiers needed to deliver gameplay and ads reliably
2.2 Data collected with your permission. Where you consent or platform rules require it, we may also process:
(a) Advertising identifiers, including GAID (Android) and IDFA (iOS);
(b) Engagement signals tied to matches, levels, and in-app events;
(c) PayPal account email address and associated name, solely to process withdrawal transactions.
Article III — How We Use Your Data
3.1 Personal Data and Usage Data are processed to:
Core Operations
- Operate, maintain, and monitor triple-match gameplay
- Manage Accounts, authentication, and settings
- Process PayPal withdrawals and related verification
- Respond to support and service notices
Improvement & Growth
- Analyze patterns to refine levels and stability
- Measure marketing and offer effectiveness
- Share news or related product information
- Support mergers, acquisitions, or restructuring
Article IV — When We Share Data
4.1 Disclosure may occur in these circumstances:
(a) Service Providers — analytics, hosting, customer support, and payment processors working under our instructions;
(b) Business Transfers — merger, acquisition, financing, or sale of assets;
(c) Affiliates — entities under common ownership or control, bound by this Policy;
(d) Business Partners — parties with whom we jointly offer products or promotions;
(e) Public Interactions — content you voluntarily post in public areas of the Application;
(f) Legal Obligations — where required by law, regulation, or valid legal process;
(g) Consent — for purposes disclosed at collection or with your later approval.
PayPal Data Protection Notice: We do not sell or rent PayPal account email addresses. Such information is disclosed only with your explicit consent or as required by applicable law.
Article V — Children's Privacy
5.1 The Application is not directed to individuals under thirteen (13). We do not knowingly collect Personal Data from children under 13.
5.2 If a parent or guardian believes a child has provided Personal Data, contact
arthouseclemnt.deal@gmail.com. After verification, we will delete the data promptly.
Article VI — Data Security
6.1 We apply commercially reasonable physical, administrative, and technical safeguards, including:
- Encryption of sensitive data in transit and, where appropriate, at rest
- Access controls limited to authorized personnel on a need-to-know basis
- Regular security reviews and vulnerability assessments
- Contractual security obligations for third-party partners
6.2 No Internet transmission or electronic storage method is perfectly secure. Absolute security of Personal Data cannot be guaranteed.
Article VII — Your Data Rights
7.1 CCPA / CPRA (California). You may request to Know, Delete, Opt-Out of the sale of Personal Data, and exercise these rights without Non-Discrimination.
7.2 GDPR (EEA). You may exercise Access, Rectification, Erasure, Restrict processing, and Object to certain processing (including direct marketing).
7.3 VCDPA (Virginia). You may Access, Correct, Delete, obtain Portability, and Opt-Out of targeted advertising, sales, and profiling.
Article VIII — Data Retention
8.1 Personal Data is kept only as long as needed for the purposes in this Policy.
8.2 If you do not access the Application for ninety (90) consecutive days, we permanently delete your Personal Data from our systems.
8.3 Anonymized or aggregated Usage Data may be retained for internal analysis when it can no longer identify you.
Article IX — Opting Out
9.1 Advertising personalization.
(a) Android: Settings → Google → Ads → "Opt out of Ads Personalization";
(b) iOS: Settings → Privacy → Advertising → "Limit Ad Tracking".
9.3 We do not use automated profiling that produces legal or similarly significant effects. Concerns may be sent to the same email address.
Article X — International Transfers
10.1 Personal Data may be processed on servers outside your country of residence.
10.2 Transfers are protected with Transport Layer Security (TLS) version 1.2 or higher.
10.3 Where required, we use appropriate contractual safeguards such as Standard Contractual Clauses.
Article XI — Analytics & Endpoints
11.1 Analytics and related services are reachable at https://aqna.triotangle.com. Processed analytics payloads are anonymized and are not designed to contain personally identifiable information.
11.2 The game server at the same endpoint supports core puzzle delivery, progress sync, stability work, and user support.
11.3 Endpoint protections include TLS 1.2+, role-based access controls, data minimization, periodic security reviews, and Data Processing Agreements with third-party handlers.
Article XII — Third-Party Services / Ad Partners
12.1 Ads may be served through AppLovin and its mediated network. Categories shared with advertising partners are limited as follows:
May Be Shared
- Resettable advertising identifiers
- Device model, OS, and screen size
- Session frequency and engagement duration
- Ad impressions and clicks
- Non-precise demographics (country, language)
Never Shared
- Email addresses or phone numbers
- Account credentials
- Detailed gameplay progress or tangle boards
- User-generated content
- Precise geolocation
12.2 Each partner's practices are governed by its own policy:
Schedule A — Advertising Partner Directory
Article XIII — App Permissions
13.1 Permissions are disclosed before install and limited to the stated purpose:
| Permission | Purpose | Data Collected |
INTERNET | Network access for ads, updates, and gameplay | Network status, transfer statistics |
ACCESS_NETWORK_STATE | Optimize behavior by connection type | Network type and status |
ACCESS_WIFI_STATE | Support stable Wi-Fi play | Wi-Fi status, signal strength |
AD_ID | Advertising identifier for personalization | Resettable device ad ID |
VIBRATE | Haptic feedback on matches and clears | None |
ACCESS_ADSERVICES_TOPICS | Ad interest topic signals | Advertising topic data |
ACCESS_ADSERVICES_ATTRIBUTION | Campaign attribution measurement | Attribution data |
BIND_GET_INSTALL_REFERRER_SERVICE | Track install source | Install source, campaign parameters |
BIND_APPHUB_SERVICE | Optimize ad delivery via AppHub | Ad parameters, impression data |
ACCESS_ADSERVICES_AD_ID | Modern ad API compliance | Ad service identifiers |
FOREGROUND_SERVICE | Maintain critical functions when backgrounded | None |
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Secure internal broadcasts | None |
13.2 Permissions are intended to comply with Google Play Developer Program Policies and applicable rules.
Article XIV — Disclosure Requirements
14.1 Business transactions. In a merger, acquisition, or asset sale, Personal Data may transfer to the successor. Affected users will be notified beforehand where practicable.
14.2 Law enforcement. We may disclose Personal Data when compelled by law, subpoena, court order, or governmental request.
14.3 Safety. Disclosure may occur where we believe in good faith it is needed to protect rights, property, or personal safety of the Company, users, or the public.
Article XV — Third-Party Links
15.1 Links inside the Application may lead to sites we do not operate. We are not responsible for their content, privacy practices, or security.
15.2 Review the privacy policies of any third-party site you visit.
Article XVI — Data Breach Notification
16.1 In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware of the incident, where required by applicable law, and will describe the nature of the breach, likely consequences, and measures taken or proposed to address it.
Article XVII — California Shine the Light
17.1 California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, email
arthouseclemnt.deal@gmail.com with the subject line
"Shine the Light".
Article XVIII — Changes to Policy
18.1 We may revise this Policy at any time. Amendments take effect when the revised Policy is posted on this page.
18.2 The Effective Date above will be updated to reflect the latest revision.
18.3 Material changes that substantially affect processing may be announced by email or a prominent in-app notice.
Article XIX — Contact Us
19.1 Privacy questions and requests may be sent to:
(b) In-Application: Settings → Help & Support
19.2 We endeavor to respond to privacy-related inquiries within forty-eight (48) hours of receipt.