Privacy Policy
Effective Date: August 25, 2026
This Data Processing and Telemetry Agreement defines the exact parameters under which PT POLA PAPERINDO JAYATAMA ("we," "us," or "our") extracts, routes, and secures your personal telemetry when you operate our mobile software, Pocket Mine: Idle Tycoon, sourced from Google Play. Our prime directive for handling this telemetry is to guarantee optimal software performance and a superior interactive experience.
1. Telemetry and Data Ingestion Mechanisms
We leverage a matrix of tracking methodologies to securely ingest and govern your data. The subsequent clauses categorize the exact telemetry vectors we monitor and our internal handling protocols.
1.1 Data Taxonomies Extracted Upon the initialization of the Pocket Mine: Idle Tycoon client, our server endpoints automatically log the following parameters:
Endpoint Telemetry: IP routing addresses, precise timestamp logs for network handshakes, and baseline hardware classifications.
Device Profiles: Original equipment manufacturer (OEM) data, exact hardware models, OS variants (Android/Google OS), localized time parameters, and system UI languages.
Persistent Device Tags: Network-level tracking strings bound to your hardware, incorporating your Google Advertising ID (GAID), Android Device ID, Google Play Games ID, and core Google Account ID.
Behavioral Gameplay Metrics: Milestone progression, maximum scores achieved, achievement unlocks, and payload data from multiplayer network interactions.
Ledger Data: Logs reflecting the expenditure of virtual assets, historical fiat transactions, modifications to the client UI, and digital currency balances.
1.2 Third-Party Authentication Endpoints If you trigger a login via an external gateway, such as Google Play Games Services, our backend will interface with their APIs to ingest permitted payload data (e.g., standard usernames). This action is strictly governed by the external gateway’s authorization flow and your prior acceptance of their data-sharing manifests. We advise reviewing the data architectures of these external identity providers:
Google Play Games / Google Services: https://policies.google.com/privacy
By utilizing an external identity provider, you cryptographically and legally assert that:
Your usage remains in total compliance with the external provider's governing Terms of Service.
You clear the legal age requirements enforced by that third-party provider in your specific global region.
2. Operational Imperatives for Processing
We manipulate your data strictly to execute the operational goals mapped out below, ensuring all processing events are tied to a robust legal anchor:
Client Execution and User Support: To validate digital receipts, route support tickets, and sustain backend connectivity; to render the core game loop, load local save states, and distribute binary updates, security hotfixes, and system broadcast messages.
Legal Anchor: Authorized by GDPR Article 6(1)(b) (contractual necessity). Processing is technically indispensable to enforce our software license and keep the application online.
Software Optimization and Audience Engagement: To deploy targeted promotional packets regarding PT POLA PAPERINDO JAYATAMA or vetted associates; to cache user-specific variables; and to run heuristic analyses to blueprint new features and streamline both marketing operations and helpdesk efficiency.
Legal Anchor: Grounded in GDPR Article 6(1)(f) (legitimate interests). This processing supports our valid corporate objective to iterate on our software and improve the end-user experience.
Ad Serving Infrastructure: To render targeted commercial payloads to users whose device parameters have been cleared for access by our ad-tech network partners.
Legal Anchor: Also supported by GDPR Article 6(1)(f). This ensures our legitimate commercial viability through optimized ad monetization strategies.
3. Data Lifecycle Management
Your personal telemetry remains active in our databases exclusively for the lifecycle necessary to render our services, clear legal audits, and manage judicial disputes. In edge cases involving arbitration, infrastructural triage, contract disputes, or compliance audits, we retain the jurisdiction to freeze specific data blocks for an extended, legally validated duration. Conversely, aggregated and hashed Usage Metrics used for internal dashboarding are routinely subjected to rapid garbage collection cycles, unless extended preservation is mandated by law or critical security incident responses.
4. Third-Party Data Syndication
Adhering to strict privacy boundaries and governed by GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may establish data pipelines to authorized external vendors under these conditions:
Service Integrators: To deploy joint operational features, satisfy compliance checks, facilitate corporate acquisitions, or any workflow requiring your explicit opt-in.
State and Legal Apparatuses: In the event of an anomaly breaching our Terms, or if a subpoena compels data release to shield the IP, network integrity, or safety of PT POLA PAPERINDO JAYATAMA and the public.
The Multiplayer Ecosystem: Consequent to your participation in server-side matchmaking, global chat channels, or high-score leaderboards.
4.1 Syndication to Ad Exchanges Subject to your explicit consent gate as defined by GDPR Article 6(1), we will bridge your device tags to advertising exchanges to render hyper-relevant ad units. Our matrix of integrated ad exchanges includes:
Applovin Corporation: https://www.applovin.com/privacy/
AdColony: https://yandex.com/legal/international_ads_privacy_policy
Amazon Publisher Services: https://www.amazon.com/privacyprefs
Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/
Google LLC: https://policies.google.com/privacy
Google Admob: https://support.google.com/admob/
Unity Technologies: https://unity3d.com/legal/privacy-policy
IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf
Vungle, Inc.: https://vungle.com/privacy/
Fyber: https://www.fyber.com/privacy-policy/
InMobi: https://www.inmobi.com/privacy-policy/
Disclaimer: This Agreement does not control the server-side logic of these external entities. Users must audit the distinct privacy documentation of these third parties to evaluate their data routing.
4.2 Infrastructure Sub-Contractors To maintain server uptime, we rely on third-party backend-as-a-service (BaaS) and analytics sub-processors:
Firebase (Google LLC): https://firebase.google.com/support/privacy
Adjust: https://www.adjust.com/terms/privacy-policy/
5. Age-Restricted Usage
The Pocket Mine: Idle Tycoon application binaries are strictly not compiled for, nor distributed to, individuals under the age of 13. We implement hard blocks against the intentional ingestion of PII from this demographic. Upon detecting that such telemetry has bypassed our filters, a permanent database wipe will be initiated. Legal custodians identifying unauthorized telemetry leaks from minors must ping our support desk for immediate intervention.
6. Cryptographic and Security Baselines
We deploy enterprise-grade cryptographic standards and perimeter defenses to secure your telemetry. However, end-users must acknowledge the axiom that no cloud infrastructure or TCP/IP transmission is 100% impenetrable. We cannot cryptographically guarantee absolute immunity against zero-day exploits or unauthorized data exfiltration.
7. OS-Level Broadcasting
Contingent on a positive opt-in flag, we may trigger OS-level push payloads for game status updates, marketing, and patch notes. Users command total authority to kill this permission and block these payloads via the native notification manager on their Android/Google device.
8. Statutory Regulatory Rights
8.1 European Economic Area (EEA) Directives We SLA our privacy queue to a one-month resolution time. For heavily fragmented or complex queries, GDPR Article 12 permits us to delay resolution by an extra two months. We will broadcast a status update explaining any SLA breaches.
(1) Data Access Query: Under GDPR Article 15, you may query our databases for your specific records, the processing logic, third-party handoffs, and TTL (time-to-live) settings. A digital payload of this data can be generated, barring intellectual property conflicts.
(2) Processing Objection: Per GDPR Article 21, you can throw an exception against processing tied to "legitimate interests" (Article 6(1)(f)). We will kill the processing threads unless we log a critical legal override. Objecting to direct marketing data streams is an un-overridable right.
(3) Data Rectification: Under GDPR Article 16, you can issue a command to overwrite corrupted or incomplete database entries regarding your profile.
(4) Processing Restriction: Governed by GDPR Article 18, you can mandate a system-level freeze on the active processing of your data under specific edge cases.
(5) Consent Revocation: Dictated by GDPR Article 7, if a workflow relies on a consent flag, you can flip that flag to 'false' at any time. This will not trigger a rollback of previously executed processes.
(6) Data Portability Extraction: Under GDPR Article 20, you possess the clearance to dump your personal records into a machine-readable format (e.g., JSON/XML) and migrate it to external controllers.
8.2 California Consumer Directives (CCPA)
(1) Resolution Window: We target a 45-day SLA for verified queries. If system complexity demands a spike to 90 days, a written status log will be sent.
(2) Lookback Window: Evidentiary data dumps are hard-limited to the 12-month window preceding the timestamp of your request.
(3) Opt-Out Directive: The CCPA grants you the explicit right to set a "Do Not Sell" flag on your telemetry data.
(4) Transparency Right: You are granted full visibility into the schemas we use and our processing motives, which are hardcoded into this document annually.
(5) Audit Access: You may execute a request for a complete ledger of PII ingested over the past 12 months (executable twice per 365-day cycle at zero cost).
(6) Deletion Command: You can issue a delete command for PII captured over the trailing 12 months, barring hardcoded statutory exceptions (e.g., critical debugging, security logging).
9. Executing Data Destruction
Once your telemetry outlives its operational utility, you may issue a command for its secure destruction. To trigger this database wipe, transmit a formal request to the compliance inbox detailed below.
10. Compliance Communications
For protocol clarifications, security concerns, or to execute formal privacy directives, route all traffic to: Contact Email: merasustico313@gmail.com