This Privacy Policy ("Policy") sets forth the terms and conditions under which Fortune Tap Mahjong ("the Application," "we," "us," or "our") collects, processes, retains, and discloses personal data obtained from users of the Application. Your use of Fortune Tap Mahjong constitutes acknowledgment that you have read, understood, and consent to the data practices described herein. This Policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Virginia Consumer Data Protection Act (VCDPA), as well as other applicable international privacy frameworks.
Article I — Definitions
1.1 "Application" shall mean Fortune Tap Mahjong, the mobile mahjong game developed and distributed by the Company.
1.2 "Company" shall mean the operating entity of Fortune Tap Mahjong, referred to throughout as "we," "us," or "our."
1.3 "Personal Data" shall mean any information relating to an identified or identifiable natural person, including without limitation data that can identify a person directly or in combination with other information.
1.4 "Usage Data" shall mean data generated automatically through your interaction with the Application, including but not limited to session metrics, gameplay events, error logs, and performance telemetry.
1.5 "Device" shall mean any electronic apparatus — including smartphones, tablets, and personal computers — used to access or operate the Application.
1.6 "Service Provider" shall mean any natural or legal person engaged by the Company to process data on the Company's behalf pursuant to a binding Data Processing Agreement.
1.7 "Advertising Identifier" shall mean the resettable, non-persistent device identifier assigned by the operating system for advertising purposes, including the Google Advertising ID (GAID) on Android and the Identifier for Advertisers (IDFA) on iOS.
1.8 "You" / "User" shall mean the individual who downloads, installs, or otherwise accesses the Application.
Article II — Information We Collect
2.1 Automatically Collected Data. The following categories of technical data are recorded by the Company's systems upon each session, without requiring any affirmative action by the User:
(a) Internet Protocol (IP) address and network connection type (Wi-Fi, cellular);
(b) Device hardware model, operating system name and version, and screen resolution;
(c) Mobile device identifiers, including GAID, ANDROID_ID, and unique device ID;
(d) Session and gameplay data, including mahjong levels attempted, tiles sorted, session duration, and in-app navigation events;
(e) Diagnostic information including crash logs, error stack traces, and application performance benchmarks;
(f) Mobile network operator name and carrier-related connectivity data.
2.2 Data Provided with Explicit Consent. The Company collects the following additional data only upon the User's affirmative grant of permission:
(a) Advertising Identifiers (GAID on Android; IDFA on iOS), for the purpose of delivering and measuring personalized advertisements;
(b) Application engagement metrics and in-game behavioral signals;
(c) PayPal account email address and display name, collected solely to process prize withdrawal transactions and retained exclusively for the duration of the transaction window.
Data Minimization Notice: Fortune Tap Mahjong does not collect real names, postal addresses, telephone numbers, or precise geolocation data. Advertising Identifiers may be reset or disabled at any time through Device privacy settings without affecting access to core Application features.
Article III — Purposes of Data Processing
3.1 Personal Data and Usage Data are processed solely for the following documented and lawful purposes:
| Processing Purpose | Categories of Data Used | Legal Basis (GDPR) |
| Operation and maintenance of the Application and game servers | Usage Data, Device Identifiers | Legitimate interests / Contract performance |
| User account management, authentication, and preference storage | Identifiers, Usage Data | Contract performance |
| Processing PayPal prize withdrawals | PayPal email, display name | Contract performance / Consent |
| Customer support and help-ticket resolution | Diagnostics, Support communications | Legitimate interests |
| Product communications, push notifications, and update notices | Device token, Identifiers | Consent / Legitimate interests |
| Analytics, feature improvement, and bug remediation | Usage Data, Diagnostics | Legitimate interests |
| Delivery and measurement of in-app advertising | Advertising Identifiers, Device Info | Consent |
| Compliance with applicable legal obligations | As required by applicable law | Legal obligation |
| Facilitation of corporate restructuring or business transfers | Aggregate account data | Legitimate interests |
Article IV — Disclosure and Sharing of Data
4.1 The Company does not sell Personal Data. Disclosure to third parties occurs strictly under the following conditions:
(a) Service Providers. Third-party entities performing analytics, infrastructure hosting, payment processing, customer support, and fraud prevention functions on the Company's behalf, each bound by a Data Processing Agreement;
(b) Advertising Partners. Advertising Identifiers and device metadata are shared with ad network partners solely for ad delivery and attribution measurement, in strict accordance with Article XI of this Policy;
(c) Corporate Affiliates. Entities under common ownership or control with the Company, each subject to the same obligations as set forth herein;
(d) Business Transfers. In connection with a merger, acquisition, reorganization, or sale of assets; Users shall receive notice before their data becomes subject to a materially different privacy policy;
(e) Legal and Regulatory Obligations. When required by law, court order, subpoena, regulatory directive, or other valid governmental process;
(f) Protection of Rights and Safety. Where the Company reasonably believes disclosure is necessary to prevent fraud, protect its legal rights, or safeguard user or public safety;
(g) User Consent. For any purpose expressly authorized by the User at or after the time of collection.
PayPal Data Protection Notice: The User's PayPal email address and display name shall not be sold, rented, or provided to advertising partners under any circumstances. Such information is shared solely with PayPal's payment processing infrastructure during the withdrawal transaction and only with the User's explicit consent or as mandated by applicable law.
Article V — Opt-Out Mechanisms
5.1 Advertising Personalization. Users may limit or disable personalized advertising through the following Device-level controls, which require no account login:
(a) Android 12 and later: Settings → Privacy → Ads → "Delete advertising ID;" alternatively, Settings → Google → Ads → "Delete advertising ID;"
(b) Android (prior to version 12): Settings → Google → Ads → "Opt out of Ads Personalization;"
(c) iOS: Settings → Privacy & Security → Tracking → disable "Allow Apps to Request to Track;" and Settings → Privacy & Security → Apple Advertising → disable "Personalized Ads."
5.2 Sale or Sharing of Personal Data (CCPA/CPRA). To opt out of the sale or sharing of Personal Data for cross-context behavioral advertising, Users shall submit a written request to
creativesoftbangladesh@gmail.com with the subject line
"Do Not Sell My Data." The Company shall process such requests within fifteen (15) business days.
5.3 Marketing Communications. Users may withdraw consent to receive promotional email communications by using the unsubscribe mechanism included in all such messages. Push notification preferences may be managed through Device system settings (Settings → Notifications → Fortune Tap Mahjong).
5.4 Automated Decision-Making and Profiling. The Company does not engage in automated profiling that produces legal or similarly significant effects upon Users. Users with questions regarding profiling practices may contact the Company at
creativesoftbangladesh@gmail.com.
Article VI — Analytics and Service Endpoints
6.1 Primary Infrastructure Endpoint. Fortune Tap Mahjong routes game server traffic and operational analytics through the following endpoint:
https://xdp.fortunemo.com/
6.2 Scope of Processing. The above endpoint handles: (i) mahjong game state synchronization and server-side tile validation; (ii) leaderboard updates and reward processing; (iii) anonymized usage analytics for performance monitoring; and (iv) user support request routing. No personally identifiable information is retained within the analytics processing layer.
6.3 Endpoint Security Protocols. All data transmissions to and from the endpoint are subject to the following mandatory security measures:
(a) Transport Layer Security (TLS) protocol version 1.2 or higher for all data in transit;
(b) Role-based access controls limiting raw data access to authorized engineering personnel on a strict need-to-know basis;
(c) Data minimization principles enforced at every stage of the processing pipeline;
(d) Scheduled penetration tests and vulnerability assessments conducted on all production endpoints;
(e) Executed Data Processing Agreements (DPAs) with every third-party entity receiving access to user data.
Article VII — Application Permission Disclosures
7.1 Fortune Tap Mahjong requests the following system permissions. Each permission is disclosed to the User prior to installation and is strictly limited to the stated purpose:
| Permission | Operational Purpose | Data Involved |
INTERNET | Network connectivity for game servers, ad networks, and update distribution | Network traffic data |
ACCESS_NETWORK_STATE | Detect connection type to optimize data loading and error handling | Connection type and status |
ACCESS_WIFI_STATE | Identify Wi-Fi availability for stable download and sync operations | Wi-Fi connectivity status |
AD_ID | Retrieve Advertising Identifier for personalized ad delivery | Resettable device ad identifier |
VIBRATE | Haptic feedback during mahjong tile matching and win events | None |
ACCESS_ADSERVICES_TOPICS | Provide interest-topic signals via Android Privacy Sandbox | Interest category signals (no PII) |
ACCESS_ADSERVICES_ATTRIBUTION | Measure ad campaign performance and install attribution | Attribution metrics (no PII) |
BIND_GET_INSTALL_REFERRER_SERVICE | Identify app installation source for campaign analysis | Install referrer, campaign identifiers |
BIND_APPHUB_SERVICE | Optimize ad delivery and reporting via AppHub SDK | Ad parameters, impression events |
ACCESS_ADSERVICES_AD_ID | Compliance with Android Privacy Sandbox ad identifier API | Ad service identifiers |
FOREGROUND_SERVICE | Maintain critical game-state processes when Application is backgrounded | None |
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Secure internal broadcast receiver communication within the Application | None |
7.2 All permissions listed herein comply with Google Play Developer Program Policies and applicable international regulatory requirements. Permissions will not be requested beyond what is strictly necessary for stated operational purposes.
Article VIII — Data Security Measures
8.1 The Company implements the following commercially reasonable technical, administrative, and organizational safeguards to protect Personal Data against unauthorized access, alteration, disclosure, or destruction:
Technical Controls
- TLS 1.2+ encryption for all data in transit
- Encryption at rest for stored Personal Data
- Automated anomaly and intrusion detection systems
- Regular penetration tests and security audits
Organizational Controls
- Role-based access controls (least-privilege principle)
- Mandatory privacy and security training for all personnel
- Contractual security obligations imposed on all vendors
- Documented incident response and escalation procedures
8.2 Notwithstanding the foregoing safeguards, no method of transmission over the Internet or electronic storage medium is completely secure. The Company cannot guarantee the absolute security of Personal Data and encourages Users to contact
creativesoftbangladesh@gmail.com immediately upon suspecting any unauthorized access to their account.
Article IX — Retention and Deletion of Data
9.1 The Company shall retain Personal Data only for so long as is necessary to fulfill the specific processing purposes documented in Article III of this Policy, and in accordance with applicable statutory retention requirements.
9.2 In the event that a User does not access the Application for a period of ninety (90) consecutive calendar days, the Company shall permanently and irreversibly delete all Personal Data associated with that User's account from its active systems.
9.3 Usage Data shall be retained exclusively in fully anonymized and aggregated form beyond the period required for operational purposes. Such anonymized data shall not be capable of being used to re-identify any individual User.
9.4 Upon receipt of a verified data deletion request under the rights enumerated in Article X, the Company shall purge the relevant Personal Data within the timeframe mandated by applicable law. Residual copies held in backup systems shall be deleted on their normal rotation schedule, ordinarily within thirty (30) days.
Article X — Third-Party Advertising Services
10.1 The Application delivers in-app advertising through the AppLovin mediation platform and its partner network. The categories of data disclosed to advertising partners are strictly circumscribed as follows:
Data Disclosed to Ad Partners
- Advertising Identifiers (resettable via Device settings)
- Device model, OS version, and screen dimensions
- Session frequency and cumulative engagement duration
- Ad impression and click interaction events
- Country code and language preference
Data Never Disclosed
- Email address or telephone number
- PayPal credentials or payment information
- Mahjong gameplay history or tile records
- User-generated content or support communications
- Precise GPS or geolocation data
10.2 Advertising Partner Privacy Policies. The privacy practices of each advertising partner are governed by their respective policies, enumerated in Schedule A below:
Schedule A — Advertising Partner Directory
Article XI — Data Subject Rights
11.1 Depending on the User's jurisdiction of residence, one or more of the following data protection frameworks confers specific legally enforceable rights. The Company shall honor all valid and verified requests within the timeframe required by applicable law.
| Right |
GDPR (EEA / UK) |
CCPA / CPRA (California) |
VCDPA (Virginia) |
| Access / Know what data is held | ✓ | ✓ | ✓ |
| Correct / Rectify inaccurate data | ✓ | ✓ | ✓ |
| Delete / Erasure | ✓ | ✓ | ✓ |
| Data portability | ✓ | — | ✓ |
| Restrict processing | ✓ | — | — |
| Object to processing | ✓ | — | — |
| Opt-out of sale / sharing / targeted advertising | ✓ (consent withdrawal) | ✓ | ✓ |
| Limit use of sensitive personal information | — | ✓ | — |
| Non-discrimination for exercising rights | — | ✓ | — |
| Appeal the Company's decision on a request | Lodge complaint with supervisory authority | — | ✓ |
11.2 To exercise any right enumerated in this Article, the User shall submit a written request to
creativesoftbangladesh@gmail.com with the subject line
"Privacy Rights Request." The Company will verify the User's identity prior to processing the request and will respond within the period prescribed by applicable law (generally 30–45 days, with a possible 30-day extension where permitted).
Article XII — International Data Transfers
12.1 Personal Data may be transferred to and processed on servers located outside the User's country of residence, including jurisdictions that may have differing data protection standards from those in the User's home country.
12.2 All international transfers of Personal Data shall be protected by Transport Layer Security (TLS) version 1.2 or higher at the network transmission layer.
12.3 For transfers from the European Economic Area, the United Kingdom, or Switzerland, the Company shall implement appropriate safeguards including Standard Contractual Clauses (SCCs) or equivalent contractual mechanisms recognized under applicable law.
12.4 All hosting, processing, and infrastructure partners receiving Personal Data from cross-border transfers are vetted to ensure they maintain security and privacy standards equivalent to or exceeding those required by this Policy.
Article XIII — Protection of Minors
13.1 Fortune Tap Mahjong is not directed to, nor intended for use by, individuals under the age of thirteen (13) years. The Company does not knowingly solicit or collect Personal Data from children under the age of 13, and does not knowingly allow such persons to register Accounts.
13.2 In the event that a parent or legal guardian becomes aware that a minor has provided Personal Data to the Company without appropriate consent, such parent or guardian shall immediately notify the Company at
creativesoftbangladesh@gmail.com. Upon receipt of such notification and verification, the Company shall promptly delete the relevant data from its systems.
13.3 Users located in the European Economic Area should be aware that the applicable age threshold for consent may be up to sixteen (16) years in certain Member States. The Company complies with all jurisdiction-specific age-of-consent requirements.
Article XIV — Third-Party Links and External Services
14.1 The Application may contain hyperlinks to websites, advertisements, or services operated by third parties not affiliated with the Company. The Company exercises no control over, and accepts no responsibility for, the content, privacy practices, or security measures of such external services.
14.2 Users are strongly encouraged to review the privacy policies of any third-party website or service they access through or in connection with the Application before submitting any Personal Data.
Article XV — Data Breach Notification
15.1 In the event of a security breach that results in the unauthorized access, disclosure, or destruction of Personal Data and that is likely to result in a risk to the rights and freedoms of affected Users, the Company shall provide notification in accordance with the following protocol:
(a) Supervisory Authority Notification: Where required under GDPR or equivalent regulation, the Company shall notify the relevant data protection supervisory authority within seventy-two (72) hours of becoming aware of the breach;
(b) User Notification: Where the breach is likely to result in a high risk to the User's rights or freedoms, the Company shall communicate the breach to affected Users without undue delay, and no later than the timeframe required by applicable law;
(c) Content of Notification: All notifications shall include the nature of the breach, categories and approximate number of individuals affected, likely consequences of the breach, and measures taken or proposed to address the breach;
(d) Method of Notification: User notifications shall be delivered via the registered account email address and/or a prominent in-app notification.
Article XVI — Automated Decision-Making and Profiling
16.1 The Company does not engage in any automated decision-making processes, including profiling as defined under Article 22 of the GDPR, that produce legal effects concerning a User or that similarly significantly affect a User.
16.2 Notwithstanding the foregoing, certain automated processing activities are performed for the purpose of optimizing in-app advertising content. Such processing does not constitute profiling with legal or significant effect within the meaning of applicable data protection law, and Users retain the right to opt out of advertising personalization as set forth in Article V of this Policy.
16.3 Should the Company's automated processing practices change materially, this Article shall be updated and Users shall be notified in accordance with the amendment procedures set forth in Article XVII.
Article XVII — Amendments to This Policy
17.1 The Company reserves the right to amend this Policy from time to time to reflect changes in applicable law, regulatory guidance, technology, or the Company's data processing practices.
17.2 Any amendments shall take effect upon the posting of the revised Policy at the original publication URL. The "Effective Date" at the head of this document shall be updated to reflect the date of the most recent revision.
17.3 For amendments that materially alter the nature or scope of Personal Data processing, the Company shall provide Users with advance notice of no fewer than seven (7) calendar days prior to the effective date of such changes, by means of either email notification to the registered account address or a prominent in-app notice.
17.4 A User's continued use of the Application following the effective date of an amended Policy shall constitute acceptance of the revised terms. Users who object to any amendment may cease use of the Application and request deletion of their Personal Data prior to the amendment's effective date.
Article XVIII — Contact Information and Inquiries
18.1 All questions, concerns, rights requests, and privacy-related inquiries should be directed to the Company through the following designated channels:
(b) In-Application Support: Settings → Help & Support
18.2 The Company shall endeavor to acknowledge all privacy-related inquiries within forty-eight (48) hours of receipt and to provide a substantive response within the timeframe required by the User's applicable local law.