Privacy Policy

Effective Date: August 19, 2026

This Privacy & Data Governance Policy delineates the methodologies employed by Yuan Lai Yuan ("we," "us," or "our") to capture, process, and safeguard your personal information during your utilization of our mobile software application, Meow Plaza: Business Simulator, distributed via the Google Play platform. Our exclusive mandate in governing this data is to facilitate a premium interactive entertainment experience while strictly maintaining data integrity and security.

1. Personal Data Acquisition Protocols

We institute multifaceted protocols to collect and manage your personal data, maintaining an absolute commitment to data security. The subsequent subsections categorize the exact nature of the information captured and our processing mechanisms.

1.1 Classifications of Captured Data Upon your initialization of Meow Plaza: Business Simulator, our network infrastructure may record the following data taxonomies:

Server Telemetry: Internet Protocol (IP) addresses, precise connection timestamps, and base hardware classifications.

Device Nomenclature: Manufacturer details, hardware model specifications, operating system versions (Android/Google OS), localized time zones, and system-level language configurations.

Distinctive Identifiers: Network-level tags corresponding to your hardware, including your Google Advertising ID (GAID), Android Device ID, Google Play Games profile ID, and overarching Google Account ID.

Interaction Metrics: In-game progression trajectories, peak score achievements, unlocked milestones, and comprehensive logs of multiplayer networking sessions.

Fiscal Records: Ledgers of virtual commodity usage, historical financial transactions, configurations tailored to the user, and records of digital currency acquisition.

1.2 Ancillary Data Origins In the event you elect to authenticate your access via external ecosystems, such as Google Play Games Services, we shall retrieve pertinent profile attributes (e.g., public monikers and profile configurations) in absolute compliance with their established authorization mechanisms. Such retrieval is strictly conditioned upon your prior ratification of the third party's data syndication policies. Users are strongly advised to audit the data handling frameworks of these external entities:

Google Play Games / Google Services: https://policies.google.com/privacy

By authenticating via a third-party gateway, you formally warrant that:

Your utilization is in full compliance with the prevailing Terms of Service governed by said third party.

You satisfy all statutory minimum age thresholds mandated by the third-party entity within your applicable legal jurisdiction.

2. Rationale for Data Processing

We process your personal information to satisfy the predefined operational objectives listed herein, ensuring all data utilization is anchored to a codified legal foundation:

Operational Execution and User Assistance: To process commercial transactions, resolve user inquiries, and sustain communication architectures; to deploy foundational software mechanics, personalize user interfaces, and issue technical patches, security advisories, and administrative notices.

Legal Foundation: Predicated upon Article 6(1)(b) of the General Data Protection Regulation (GDPR) (contractual necessity). This processing is compulsory for the execution of our Terms of Service, the maintenance of our software infrastructure, and the continuous deployment of updates.

Strategic Enhancement and Promotional Activities: To transmit targeted marketing collateral regarding Yuan Lai Yuan or vetted third-party affiliates; to archive user-defined configurations; and to execute analytical assessments to drive feature development, software refinement, and optimization of marketing and support operations.

Legal Foundation: Authorized by GDPR Article 6(1)(f) (legitimate interests). We exercise this basis to fulfill our legitimate corporate interest in delivering optimized digital content and elevating our service standards.

Targeted Advertising Syndication: To project customized commercial advertisements and marketing materials to users who have provided requisite consent for our advertising network affiliates to access their device identifiers.

Legal Foundation: Concurrently supported by GDPR Article 6(1)(f), driven by our legitimate commercial interest in sustaining platform monetization through relevant advertising deployments.

3. Data Retention and Archival Protocols

Your personal data shall be retained exclusively for the duration necessary to provision our software services, comply with statutory mandates, and assert or defend legal claims. For contingencies encompassing dispute arbitration, contractual enforcement, infrastructural auditing, statutory compliance, or the mitigation of security vulnerabilities, we reserve the right to archive specific data segments for a legally justifiable epoch. Concurrently, aggregated Usage Data is retained for internal analytical auditing. Such data is typically subjected to rapid deletion cycles unless extended retention is dictated by regulatory compliance mandates or is indispensable for reinforcing infrastructural security.

4. Information Dissemination and Third-Party Access

In strict observance of user privacy rights and governed by GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may facilitate the disclosure of your data to authorized external entities under the following parameters:

Strategic Collaborators: For the execution of integrated operational services, statutory compliance, corporate asset restructuring, or any endeavor requiring your explicit authorization.

Regulatory and Law Enforcement Authorities: In the event of an identified breach of our governing policies, or if statutory edicts compel disclosure to protect the intellectual property, physical safety, or legal rights of Yuan Lai Yuan and the broader public domain.

Public Player Base: Resulting from your participation in networked multiplayer environments, public discussion forums, or placement on globally broadcasted performance leaderboards.

4.1 Advertising Syndication Contingent upon the acquisition of your explicit consent as defined by GDPR Article 6(1), we shall syndicate your device-level identifiers to advertising conglomerates to facilitate personalized commercial campaigns. Our portfolio of current and prospective advertising affiliates includes:

Applovin Corporation: https://www.applovin.com/privacy/

AdColony: https://yandex.com/legal/international_ads_privacy_policy

Amazon Publisher Services: https://www.amazon.com/privacyprefs

Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/

Google LLC: https://policies.google.com/privacy

Google Admob: https://support.google.com/admob/

Unity Technologies: https://unity3d.com/legal/privacy-policy

IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf

Vungle, Inc.: https://vungle.com/privacy/

Fyber: https://www.fyber.com/privacy-policy/

InMobi: https://www.inmobi.com/privacy-policy/

Disclaimer: This Privacy & Data Governance Policy does not bind or regulate the independent data processing activities of these third-party organizations. Users are directed to consult the respective privacy documentation of these entities to ascertain their specific data stewardship protocols.

4.2 Infrastructure Sub-processors To sustain our backend computational operations, we contract with specialized third-party data sub-processors, encompassing cloud hosting environments, authentication gateways, and analytical processing engines:

Firebase (Google LLC): https://firebase.google.com/support/privacy

Adjust: https://www.adjust.com/terms/privacy-policy/

5. Protection of Minors' Privacy

The Meow Plaza: Business Simulator software application is expressly not engineered for, nor commercially directed toward, individuals under the age of 13. We enforce a zero-tolerance policy regarding the intentional collection of personally identifiable information from this demographic. Upon verification that such data has been inadvertently aggregated, immediate and irreversible erasure protocols will be executed. Legal guardians who identify unauthorized data submissions by minors are compelled to contact us expeditiously to initiate corrective remediation.

6. Security and Safeguard Measures

We acknowledge the critical nature of your data and deploy commercially rigorous cryptographic and operational security frameworks to defend your personal information. Notwithstanding these efforts, users must concede that no digital transmission protocol or data storage architecture can guarantee absolute invulnerability. Consequently, we cannot formally warrant the absolute immunity of your data against unauthorized intrusion.

7. Device-Level Communications

Subject to your explicit opt-in authorization, we may transmit system alerts, promotional notifications, and critical software updates directly to your Android/Google hardware environment. Users retain the absolute autonomy to rescind this authorization and disable such push communications globally via their device’s native operating system configurations.

8. Statutory User Rights

8.1 European Economic Area (EEA) Jurisdictions We are bound to process valid privacy inquiries within a standard operational window of one month. For submissions of significant complexity, GDPR Article 12 grants us the authority to extend this window by an additional two months (three months total). We shall proactively issue written notification detailing any such extension and the operative rationale.

(1) Right of Access: Governed by GDPR Article 15, you may petition for granular disclosures regarding your retained data, encompassing processing rationale, data classifications, recipient entities, and projected retention limits. A digital artifact of this data may be requested, provided its issuance does not infringe upon intellectual property protections.

(2) Right to Object: Pursuant to GDPR Article 21, you may formally contest data processing activities justified by "legitimate interests" (Article 6(1)(f)). We shall suspend processing operations unless we can demonstrate compelling, overriding legal justifications. The right to object to direct marketing processing is absolute and unconditional.

(3) Right to Rectification: Enforced by GDPR Article 16, you hold the legal right to mandate the rectification of anomalous or incomplete profile data.

(4) Right to Restriction: Under GDPR Article 18, you may compel our organization to isolate and restrict the active processing of your data under stringently defined regulatory conditions.

(5) Right to Withdraw Consent: Dictated by GDPR Article 7, if processing operations hinge upon your consent, you may nullify said consent at any time. This revocation is prospective and does not invalidate processing executed prior to the withdrawal.

(6) Right to Data Portability: Authorized by GDPR Article 20, you possess the entitlement to extract your personal data in a standardized, machine-readable syntax and seamlessly transfer it to alternate data controllers without systemic interference.

8.2 California Jurisdictions (CCPA)

(1) Fulfillment Timeline: We adhere to a 45-day statutory turnaround for verifiable consumer inquiries. Should technical constraints necessitate a prolongation (up to a 90-day maximum), formal written notification shall be dispatched detailing the delay justification.

(2) Disclosure Boundaries: Evidentiary data disclosures are strictly confined to information aggregated within the 12-month trailing window preceding your formal request, formatted for optimized accessibility.

(3) Right to Opt-Out: The California Consumer Privacy Act guarantees your right to explicitly instruct our organization to cease the commercial sale of your personal information to external entities.

(4) Right to Know: You are empowered to comprehend the exact data categories we harvest and our foundational operational motives, which are codified in this annually reviewed Policy.

(5) Access Petitions: You may demand a comprehensive audit of the personal information logged over the trailing 12 months (an entitlement executable twice per calendar year without financial penalty).

(6) Right to Erasure: You may instigate the permanent deletion of personal data gathered over the preceding 12 months, subject strictly to statutory exemptions (e.g., fulfillment of legal compliance, security auditing, and service continuity).

9. Right to Erasure Execution

Upon the cessation of the operational necessity for your personal data, you are authorized to command its secure and irreversible destruction. To formally trigger data erasure protocols, submit your explicit directive to the compliance contact email designated below.

10. Corporate Communication Channels

For regulatory clarifications, compliance inquiries, or the execution of formal privacy rights connected to this Policy, direct all communications to: Contact Email: [email protected]