Privacy Policy
Effective Date: September 29, 2026
This Operational Privacy and Compliance Standard constitutes the formal operating procedures utilized by Yimu Health Care ("we," "us," or "our") to log, process, and secure user data during the operation of Wharf Match Wonders via the Google Play platform. Our primary operational mandate is to ensure an optimal gaming product while strictly adhering to global data compliance standards.
1. Standard of Data Collection
We implement structured mechanisms to aggregate and administer your data, with a strict adherence to operational security. The following sections detail the exact data elements we capture and our processing procedures.
1.1 Automated Data Capture Upon the initialization of Wharf Match Wonders, our servers are programmed to log the following user data categories:
Infrastructure Telemetry: IP addresses, precise server connection timestamps, and foundational hardware types.
Hardware Specifications: Device manufacturer, hardware model, operating system version (Android/Google OS), localized time configurations, and system language properties.
Device Identification Tags: Network identifiers permanently associated with your hardware, including the Google Advertising ID (GAID), Android Device ID, Google Play Games ID, and your primary Google Account ID.
Operational Gaming Metrics: Player progression logs, peak score records, achievement unlocks, and transactional data from multiplayer servers.
Economic Activity Logs: Histories of virtual purchases, consumption of in-game resources, tailored account settings, and records of digital currency acquisition.
1.2 Third-Party Integrations If you choose to authenticate your session via external gateways such as Google Play Games Services, we will import approved profile data (e.g., public display names) in strict accordance with their API authorization protocols. This action is entirely dependent on your prior acceptance of the third party's privacy parameters. Users are instructed to review the compliance frameworks of these external organizations:
Google Play Games / Google Services: https://policies.google.com/privacy
By utilizing a third-party authentication gateway, you formally acknowledge that:
Your usage remains in full compliance with the prevailing Terms of Service of that external platform.
You meet the legal age of consent required by the third party within your specific legal jurisdiction.
2. Operational Directives for Processing
We process your personal data exclusively to execute the operational tasks listed below, ensuring every process is validated by a statutory legal basis:
Service Delivery & Support: To clear commercial transactions, resolve customer support tickets, and maintain communication lines; to execute core game logic, apply custom user configurations, and distribute software updates, security warnings, and administrative alerts.
Statutory Basis: Anchored in GDPR Article 6(1)(b) (contractual necessity). This processing is structurally mandatory to uphold our Terms of Service and maintain application functionality.
Product Enhancement & Promotions: To dispatch curated marketing materials concerning Yimu Health Care or authorized affiliates; to archive user preferences; and to conduct analytical research to drive feature development, software optimization, and marketing efficiency.
Statutory Basis: Authorized by GDPR Article 6(1)(f) (legitimate interests). We utilize this provision to fulfill our legitimate corporate interest in refining our product and increasing consumer satisfaction.
Targeted Commercial Advertising: To present customized marketing content to users who have explicitly permitted our advertising partners to access their device identification tags.
Statutory Basis: Equally supported by GDPR Article 6(1)(f). This serves our legitimate operational necessity to monetize the application effectively through relevant ad placements.
3. Statutory Retention Standard
Your personal information is retained strictly for the duration necessary to provision our software, comply with legislative mandates, and manage legal liabilities. For scenarios involving arbitration, contract enforcement, infrastructural auditing, or regulatory compliance, we retain the right to archive specific data segments for the legally mandated period. Additionally, anonymized Usage Data is retained for internal auditing. Such aggregated data is typically purged rapidly unless an extended retention period is compelled by law or is necessary to secure our network infrastructure.
4. Network Sharing Protocols
In strict observance of user privacy entitlements and governed by GDPR Articles 6(1)(b), 6(1)(c), and 6(1)(f), we may facilitate the transfer of your data to authorized external parties under the following conditions:
Strategic Partners: For the delivery of integrated services, legal compliance, corporate restructurings, or any initiative demanding your explicit consent.
Law Enforcement & Regulatory Bodies: In the event of a verified breach of our policies, or if statutory obligations necessitate disclosure to protect the physical safety, legal rights, or intellectual property of Yimu Health Care and the general public.
Public Player Communities: As a result of your engagement in networked multiplayer environments, message boards, or global leaderboards.
4.1 Disclosures to Advertising Coalitions Subject to the receipt of your explicit consent as dictated by GDPR Article 6(1), we shall transfer your device identifiers to advertising coalitions to power targeted ad campaigns. Our authorized roster of advertising affiliates encompasses:
Applovin Corporation: https://www.applovin.com/privacy/
AdColony: https://yandex.com/legal/international_ads_privacy_policy
Amazon Publisher Services: https://www.amazon.com/privacyprefs
Meta (Facebook, Inc.): https://www.facebook.com/about/privacy/
Google LLC: https://policies.google.com/privacy
Google Admob: https://support.google.com/admob/
Unity Technologies: https://unity3d.com/legal/privacy-policy
IronSource: http://www.ironsrc.com/wp-content/uploads/2019/03/ironSource-Privacy-Policy.pdf
Vungle, Inc.: https://vungle.com/privacy/
Fyber: https://www.fyber.com/privacy-policy/
InMobi: https://www.inmobi.com/privacy-policy/
Disclaimer: This Standard does not govern the independent data processing policies of these external corporations. Users must consult the respective privacy notices of these organizations to understand their data stewardship.
4.2 Infrastructure Sub-processors To maintain backend operations, we engage specialized data sub-processors, including hosting facilities and analytical engines:
Firebase (Google LLC): https://firebase.google.com/support/privacy
Adjust: https://www.adjust.com/terms/privacy-policy/
5. Child Privacy Mandates
The Wharf Match Wonders application is strictly not designed for, nor commercially marketed to, individuals under the age of 13. We maintain a strict prohibition against the intentional collection of personally identifiable information from this age bracket. Upon confirmation that such data has been inadvertently collected, permanent erasure protocols will be executed immediately. Legal guardians identifying unauthorized data submissions by minors are instructed to contact us forthwith to initiate remediation.
6. Cybersecurity Obligations
We acknowledge the sensitivity of your data and deploy commercially robust cryptographic and operational safeguards to defend your personal information. Notwithstanding these protocols, users must concede that no digital transmission or data storage network can ensure absolute invulnerability. We therefore cannot offer an absolute legal warranty against unauthorized data breaches.
7. Mobile Alert Authorizations
Conditioned upon your explicit opt-in, we may transmit system alerts, promotional notifications, and critical update logs directly to your Android/Google operating system. Users possess the absolute right to rescind this authorization and disable such push communications globally via their device’s native notification settings.
8. Jurisdictional Privacy Privileges
8.1 European Economic Area (EEA) Stipulations We are bound to process valid privacy inquiries within a standard operational window of one month. For submissions of significant complexity, GDPR Article 12 permits an extension of an additional two months. We shall proactively issue written notification detailing the rationale for any such extension.
(1) Right of Access: Under GDPR Article 15, you may formally request granular disclosures concerning your retained data, including processing motives, data classifications, recipients, and retention limits. A digital copy may be requested, provided it does not infringe upon trade secrets.
(2) Right to Object: Pursuant to GDPR Article 21, you may formally contest data processing activities justified by "legitimate interests" (Article 6(1)(f)). We shall suspend operations unless we demonstrate overriding legal justifications. The right to object to direct marketing is absolute.
(3) Right to Rectification: Mandated by GDPR Article 16, you hold the legal right to compel the correction of inaccurate or incomplete profile records.
(4) Right to Restriction: Under GDPR Article 18, you may compel our organization to restrict the active processing of your data under stringently defined legal conditions.
(5) Right to Withdraw Consent: Dictated by GDPR Article 7, if processing hinges upon your consent, you may nullify said consent at any time. This revocation is prospective and does not invalidate prior processing.
(6) Right to Data Portability: Authorized by GDPR Article 20, you possess the entitlement to extract your personal data in a standardized, machine-readable format and transfer it to an alternate data controller without systemic interference.
8.2 California Resident Stipulations (CCPA)
(1) Execution Timeline: We adhere to a 45-day statutory turnaround for verifiable consumer inquiries. Should constraints necessitate a prolongation (up to a 90-day maximum), formal written notification shall be dispatched.
(2) Disclosure Scope: Evidentiary data disclosures are strictly limited to information aggregated within the 12-month trailing window preceding your formal request.
(3) Right to Opt-Out: The CCPA guarantees your right to explicitly instruct our organization to cease the commercial sale of your personal information.
(4) Right to Know: You are empowered to comprehend the exact data categories we harvest and our operational motives, as codified in this annually reviewed Standard.
(5) Access Petitions: You may demand a comprehensive audit of the personal information logged over the trailing 12 months (executable twice per calendar year without penalty).
(6) Right to Erasure: You may instigate the permanent deletion of personal data gathered over the preceding 12 months, subject strictly to statutory exemptions (e.g., legal compliance, security auditing).
9. Execution of Data Erasure
Upon the cessation of the operational necessity for your personal data, you are authorized to mandate its secure destruction. To formally trigger these erasure protocols, submit your explicit directive to the compliance contact email designated below.
10. Corporate Communication Hub
For regulatory inquiries, compliance clarifications, or the execution of formal privacy rights, direct all communications to: Contact Email: sisknxbxxt78902@gmail.com