Privacy Policy
Your privacy matters. This document explains clearly how Arrow Maze Escape collects and uses personal information while you navigate arrow mazes, clear paths, and engage with optional rewards — and what control you have over it. It is designed to align with GDPR, CCPA/CPRA, and VCDPA.
1 Definitions
- Application
- Arrow Maze Escape, the mobile arrow-maze puzzle we distribute.
- Personal information
- Any information relating to an identified or identifiable natural person.
- Usage Data
- Data collected automatically from your Device or our infrastructure (session length, maze progress signals, crash reports).
- Device
- A smartphone, tablet, or similar apparatus used to access the Application.
- Service Provider
- A party that processes data on our behalf to help operate the service.
2 Information Collection
When you open Arrow Maze Escape, certain information is gathered in the background — device type, how long you play, and basic network details.
Automatically recorded
- IP address and network connection metadata
- Device Info: model, OS, and WebView or browser details
- Identifiers such as GAID, ANDROID_ID, or platform equivalents
- Usage Data: maze interactions, session duration, and feature taps
- Crash logs, diagnostics, and performance metrics
With your permission or when you provide it
- Advertising identifiers (GAID on Android, IDFA on iOS)
- Engagement signals tied to levels and in-app events
- PayPal account email and associated name, solely for withdrawals
3 Use of Information
We use your personal information to keep Arrow Maze Escape working, handle accounts and transactions, send relevant updates, and improve the experience.
Operate
- Deliver maze gameplay and sync progress
- Manage accounts and settings
- Process PayPal withdrawals and verification
Improve & Communicate
- Analyze usage to refine levels and stability
- Support inquiries and service notices
- Measure offers and related product news
5 Analytics & Endpoints
Our analytics and game services are reachable at https://dah.arrowmaesc.com. Analytics payloads are anonymized and are not designed to include personally identifiable information. The same endpoint supports core maze delivery, progress sync, stability work, and support.
- TLS 1.2+ on all transmissions
- Role-based access controls
- Data minimization and periodic security reviews
- Data Processing Agreements with third-party handlers
6 Third-Party Services / Ad Partners
Ads may be served through AppLovin and mediated partners. Categories shared are limited; credentials, PayPal emails, and detailed maze progress are not shared for advertising.
May be shared
- Resettable advertising identifiers
- Device model, OS, screen size
- Session frequency and duration
- Ad impressions and clicks
- Non-precise demographics (country, language)
Not shared for ads
- Email or phone numbers
- Account credentials
- Detailed maze solutions or progress
- User-generated content
- Precise geolocation
Partner privacy policies
7 App Permissions
| Permission | Purpose | Data |
|---|---|---|
INTERNET | Ads, updates, gameplay | Network status |
ACCESS_NETWORK_STATE | Adapt to connection type | Network type |
ACCESS_WIFI_STATE | Stable Wi-Fi play | Wi-Fi status |
AD_ID | Ad personalization | Resettable ad ID |
VIBRATE | Haptic feedback on path clears | None |
ACCESS_ADSERVICES_TOPICS | Ad topic signals | Topic data |
ACCESS_ADSERVICES_ATTRIBUTION | Campaign attribution | Attribution data |
BIND_GET_INSTALL_REFERRER_SERVICE | Install source | Campaign parameters |
BIND_APPHUB_SERVICE | Ad delivery optimization | Impression data |
ACCESS_ADSERVICES_AD_ID | Modern ad API compliance | Ad service IDs |
FOREGROUND_SERVICE | Critical background tasks | None |
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Secure broadcasts | None |
8 Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or opt out of certain uses of your personal information.
GDPR (EEA)
- Access
- Rectification
- Erasure
- Restrict processing
- Object
CCPA / CPRA (California)
- Know
- Delete
- Opt-Out of sale
- Non-Discrimination
VCDPA (Virginia): Access, Correct, Delete, Portability, and Opt-Out of targeted advertising, sales, and profiling.
Email requests to frankcrawfordn824@gmail.com.
9 Opting Out
- Android: Settings → Google → Ads → “Opt out of Ads Personalization”
- iOS: Settings → Privacy → Advertising → “Limit Ad Tracking”
- Do Not Sell: email frankcrawfordn824@gmail.com with subject Do Not Sell
10 Data Retention
Not using Arrow Maze Escape? After 90 days of inactivity, we remove your personal information. Any retained Usage Data is fully anonymized when kept for internal analysis.
11 Data Security
We apply commercially reasonable safeguards, including TLS 1.2+, access controls, encryption where appropriate, and partner contractual requirements. No method of transmission or storage is perfectly secure.
12 International Transfers
Personal information may be processed on servers outside your country. Transfers use TLS 1.2+ and, where required, contractual safeguards such as Standard Contractual Clauses.
13 Children's Privacy
The Application is not directed to children under 13. We do not knowingly collect personal information from children under 13. Parents or guardians who believe a child has provided data should contact us; we will delete it after verification.
14 Disclosure Requirements
- Business transactions may involve transfer of personal information to a successor, with notice where practicable
- We may disclose information when compelled by law or governmental request
- We may disclose information in good faith to protect rights, property, or safety
15 Third-Party Links
Links in the Application may lead to sites we do not operate. Review their privacy policies; we are not responsible for their practices.
16 Cookie Policy
If the Application opens WebViews or related web surfaces, cookies and similar technologies may be used for session continuity, analytics, and advertising measurement. You can limit some tracking via device ad settings described in Opting Out.
17 Do Not Track Signals
There is no consistent industry standard for responding to browser Do Not Track (DNT) signals. The Application primarily operates as a native mobile experience; where WebViews are used, we do not currently alter practices solely based on DNT headers. Use the device-level and email opt-out options above instead.
18 Changes to Policy
We may update this Policy as features or laws change. The Effective Date at the top will be revised. Material changes may be announced in-app or by other reasonable means.
19 Get in Touch
Email: frankcrawfordn824@gmail.com
In-App: Settings → Help & Support
We endeavor to respond within 48 hours.