Privacy Policy
Effective Date: September 29, 2026
This Data Lifecycle & Security Manifesto details the precise engineering and compliance protocols Yuan Lai Yuan ("we," "us," or "our") deploys to ingest, compute, and encrypt your personal telemetry when you run Path Finder: Arrow Puzzle from Google Play. Our ultimate objective in managing this telemetry lifecycle is to guarantee a fluid, high-performance gameplay loop while maintaining zero compromises on data privacy.
1. Telemetry Capture Mechanisms
We implement heavily monitored tracking vectors to pull and sanitize your data, bound by an unwavering commitment to cyber hygiene. The breakdown below details the exact payloads we capture and our handling logic.
1.1 Client-Side Data Extraction Once the Path Finder: Arrow Puzzle client boots up, our backend nodes automatically sync the following data classes:
Network Analytics: IP routing addresses, precise TCP/IP handshake timestamps, and primary hardware classifications.
Device Telemetry: OEM (Original Equipment Manufacturer) data, hardware model variations, operating system iterations (Android/Google OS), localized time strings, and UI language flags.
Persistent Hardware Tags: Network-level identification strings permanently or semi-permanently tied to your device, such as the Google Advertising ID (GAID), Android Device ID, Google Play Games ID, and the root Google Account token.
Gameplay Event Logs: Node progression, high-score variables, achievement unlocks, and payload data transmitted during multiplayer packet exchange.
Monetization Ledgers: Database entries reflecting virtual goods purchased, fiat transaction histories, customized client-side variables, and digital coin balances.
1.2 Federated Authentication Services If you trigger a login request via a federated service like Google Play Games Services, our servers will call their APIs to ingest permitted profile attributes (like your public alias). This data handoff is strictly governed by the federated service's API rules and your prior agreement to their sharing parameters. We strongly urge you to audit the data processing schemas of these federated networks:
Google Play Games / Google Services: https://policies.google.com/privacy
By authenticating via these external nodes, you cryptographically warrant that:
Your usage is perfectly aligned with the prevailing Terms of Service of that federated provider.
You meet the statutory minimum age parameters enforced by that provider in your global region.
2. Computational Motivations for Processing
We manipulate your data strictly to execute the operational goals mapped out below, ensuring all computing events are tied to a robust legal framework:
App Execution and Ticket Resolution: To validate digital receipts, route support tickets, and sustain backend connectivity; to render the core game loop, load local save states, and distribute binary updates, security hotfixes, and system broadcast messages.
Legal Framework: Authorized by GDPR Article 6(1)(b) (contractual necessity). Processing is technically indispensable to enforce our software license and keep the application online.
Algorithm Optimization and Engagement: To deploy targeted promotional packets regarding Yuan Lai Yuan or vetted associates; to cache user-specific variables; and to run heuristic analyses to blueprint new features and streamline both marketing operations and helpdesk efficiency.
Legal Framework: Grounded in GDPR Article 6(1)(f) (legitimate interests). This processing supports our valid corporate objective to iterate on our software architecture and improve the end-user experience.
Programmatic Ad Serving: To render targeted commercial payloads to users whose device parameters have been cleared for access by our ad-tech network partners.
Legal Framework: Also supported by GDPR Article 6(1)(f). This ensures our legitimate commercial viability through optimized programmatic ad monetization.
3. Data Sunset Policies and Archival
Your personal telemetry remains active in our hot storage databases exclusively for the lifecycle necessary to render our services, clear legal audits, and manage judicial disputes. In edge cases involving arbitration, infrastructural triage, contract disputes, or compliance audits, we retain the jurisdiction to freeze specific data blocks in cold storage for an extended, legally validated duration. Conversely, aggregated and hashed Usage Metrics used for internal dashboarding are routinely subjected to rapid garbage collection cycles, unless extended preservation is mandated by law or critical security incident responses.
4. Third-Party Data Bridging
Adhering to strict privacy boundaries and governed by GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may establish secure data pipelines to authorized external vendors under these conditions:
Service Integrators: To deploy joint operational features, satisfy compliance checks, facilitate corporate acquisitions, or any workflow requiring your explicit opt-in.
State and Legal Apparatuses: In the event of an anomaly breaching our Terms, or if a subpoena compels data release to shield the IP, network integrity, or safety of Yuan Lai Yuan and the public.
The Multiplayer Ecosystem: Consequent to your participation in server-side matchmaking, global chat channels, or high-score leaderboards.
4.1 Bridging to Ad Exchanges Subject to your explicit consent gate as defined by GDPR Article 6(1), we will bridge your device tags to advertising exchanges to render hyper-relevant ad units. Our matrix of integrated ad exchanges includes:
Applovin Corporation: https://www.applovin.com/privacy/
AdColony: https://yandex.com/legal/international_ads_privacy_policy
Amazon Publisher Services: https://www.amazon.com/privacyprefs
Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/
Google LLC: https://policies.google.com/privacy
Google Admob: https://support.google.com/admob/
Unity Technologies: https://unity3d.com/legal/privacy-policy
IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf
Vungle, Inc.: https://vungle.com/privacy/
Fyber: https://www.fyber.com/privacy-policy/
InMobi: https://www.inmobi.com/privacy-policy/
Disclaimer: This Manifesto does not control the server-side logic of these external entities. Users must audit the distinct privacy documentation of these third parties to evaluate their data routing.
4.2 Infrastructure Sub-Contractors To maintain server uptime, we rely on third-party backend-as-a-service (BaaS) and analytics sub-processors:
Firebase (Google LLC): https://firebase.google.com/support/privacy
Adjust: https://www.adjust.com/terms/privacy-policy/
5. Age-Restricted Compilation
The Path Finder: Arrow Puzzle application binaries are strictly not compiled for, nor distributed to, individuals under the age of 13. We implement hard blocks against the intentional ingestion of Personally Identifiable Information (PII) from this demographic. Upon detecting that such telemetry has bypassed our filters, a permanent database wipe will be initiated. Legal custodians identifying unauthorized telemetry leaks from minors must ping our support desk for immediate intervention.
6. Cryptographic Baselines
We deploy enterprise-grade cryptographic standards and perimeter defenses to secure your telemetry. However, end-users must acknowledge the axiom that no cloud infrastructure or TCP/IP transmission is 100% impenetrable. We cannot cryptographically guarantee absolute immunity against zero-day exploits or unauthorized data exfiltration.
7. OS-Level Payloads
Contingent on a positive opt-in flag, we may trigger OS-level push payloads for game status updates, marketing, and patch notes. Users command total authority to kill this permission and block these payloads via the native notification manager on their Android/Google device.
8. Statutory Regulatory Directives
8.1 European Economic Area (EEA) Directives We SLA our privacy queue to a one-month resolution time. For heavily fragmented or complex queries, GDPR Article 12 permits us to delay resolution by an extra two months. We will broadcast a status update explaining any SLA breaches.
(1) Data Access Query: Under GDPR Article 15, you may query our databases for your specific records, the processing logic, third-party handoffs, and TTL (time-to-live) settings. A digital payload of this data can be generated, barring intellectual property conflicts.
(2) Processing Objection: Per GDPR Article 21, you can throw an exception against processing tied to "legitimate interests" (Article 6(1)(f)). We will kill the processing threads unless we log a critical legal override. Objecting to direct marketing data streams is an un-overridable right.
(3) Data Rectification: Under GDPR Article 16, you can issue a command to overwrite corrupted or incomplete database entries regarding your profile.
(4) Processing Restriction: Governed by GDPR Article 18, you can mandate a system-level freeze on the active processing of your data under specific edge cases.
(5) Consent Revocation: Dictated by GDPR Article 7, if a workflow relies on a consent flag, you can flip that flag to 'false' at any time. This will not trigger a rollback of previously executed processes.
(6) Data Portability Extraction: Under GDPR Article 20, you possess the clearance to dump your personal records into a machine-readable format (e.g., JSON/XML) and migrate it to external controllers.
8.2 California Consumer Directives (CCPA)
(1) Resolution Window: We target a 45-day SLA for verified queries. If system complexity demands a spike to 90 days, a written status log will be sent.
(2) Lookback Window: Evidentiary data dumps are hard-limited to the 12-month window preceding the timestamp of your request.
(3) Opt-Out Directive: The CCPA grants you the explicit right to set a "Do Not Sell" flag on your telemetry data.
(4) Transparency Right: You are granted full visibility into the schemas we use and our processing motives, which are hardcoded into this document annually.
(5) Audit Access: You may execute a request for a complete ledger of PII ingested over the past 12 months (executable twice per 365-day cycle at zero cost).
(6) Deletion Command: You can issue a delete command for PII captured over the trailing 12 months, barring hardcoded statutory exceptions (e.g., critical debugging, security logging).
9. Executing Data Destruction
Once your telemetry outlives its operational utility, you may issue a command for its secure destruction. To trigger this database wipe, transmit a formal request to the compliance inbox detailed below.
10. Compliance Communications
For protocol clarifications, security concerns, or to execute formal privacy directives, route all traffic to: Contact Email: [email protected]