Privacy Policy - Arrow Chain Blitz

Privacy Policy

How Arrow Chain Blitz handles your information and honors your rights

Last Updated — September 8th, 2026

Arrow Chain Blitz collects certain information in order to operate — to render chain reactions, remember where you left off, serve advertising, and pay out optional rewards. This policy sets out what is gathered, why it is needed, who receives it, and the control you keep over it. It has been written to align with the General Data Protection Regulation, the California Consumer Privacy Act and Privacy Rights Act, and the Virginia Consumer Data Protection Act.


Definitions

A handful of terms recur throughout this document, so they are defined once here.

Application
Arrow Chain Blitz, the mobile arrow-chain puzzle software distributed by the Company.
Company
The operating entity behind Arrow Chain Blitz, referred to as "we," "us," or "our."
Personal information
Any information relating to an identified or identifiable natural person.
Usage Data
Information recorded automatically from your Device or our infrastructure, including chain clears, session length, and diagnostics.
Device
Any smartphone, tablet, or comparable hardware used to reach the Application.
Service Provider
A party that processes personal information on the Company's instructions.

What Data Do We Gather?

Two streams of personal information exist: the technical data your Device produces the moment the Application opens, and the details you choose to hand over.

Recorded automatically

  • IP address and network connection data
  • Device Info — model, operating system, WebView
  • Identifiers such as GAID and ANDROID_ID
  • Usage Data — chains cleared, levels, session duration
  • Crash logs, diagnostics, performance metrics

Provided by you

  • Advertising identifiers (GAID on Android, IDFA on iOS)
  • Engagement and in-app event signals
  • PayPal account email and name, used only for withdrawals

Why Do We Need Your Data?

Nothing is gathered speculatively. Each category of personal information serves a stated operational purpose.


When Is Data Shared?

We are selective about disclosure. Personal information travels beyond the Company only in the circumstances below.

The Company neither sells nor rents user PayPal account email addresses. That information is disclosed only with your explicit consent, or where applicable law requires it.


Analytics & Server Endpoints

Analytics and game services are delivered through https://zmpb.arrowchainz.com. Payloads handled by the analytics layer are anonymized and are not designed to carry personally identifiable information. The same endpoint supports core puzzle delivery, progress synchronization, stability engineering, and support tooling.

Endpoint safeguards


Your Privacy Rights

Depending on where you live, data protection law grants you concrete, enforceable rights over your personal information.

GDPR — European Economic Area

CCPA / CPRA — California

VCDPA — Virginia

To exercise any right above, write to igtryeh202407@gmail.com and name the right concerned.


Opting Out


Data Retention

Retention follows the principle of necessity: personal information is kept only while it serves the purposes described here.

90
days of continuous inactivity, after which your personal information is permanently deleted from our systems. Anonymized or aggregated Usage Data may persist for internal analysis where it can no longer identify you.

Data Security

The Company maintains commercially reasonable physical, administrative, and technical safeguards: encryption of sensitive data in transit, TLS 1.2 or higher, need-to-know access controls, periodic security audits, and contractual security obligations imposed on partners. No method of internet transmission or electronic storage is entirely secure, however, so absolute security cannot be guaranteed.


International Transfers

Personal information may be transferred to, and processed on, servers located outside your country of residence. Such transfers are protected by TLS 1.2 or higher and, where required, by appropriate contractual safeguards including Standard Contractual Clauses.


Third-Party Services & Ad Partners

Advertising is served through AppLovin and its mediated partner network. Only a limited set of categories reaches those partners.

Shared with partners

  • Resettable advertising identifiers
  • Device model, OS, and screen size
  • Session frequency and engagement duration
  • Ad impressions and clicks
  • Non-precise demographics (country, language)

Never shared

  • Email addresses or phone numbers
  • Account credentials
  • Detailed chain progress or reward balances
  • User-generated content
  • Precise geolocation data

Advertising partner privacy policies

AppLovin Chartboost Google InMobi IronSource Kwai Fyber Mintegral Moloco Bytedance (Pangle) Vungle Unity Ads Yandex BidMachine Verve Bigo TaurusX

Application Permissions

Each permission is disclosed before installation, confined to the stated purpose, and aligned with Google Play Developer Program Policies.

PermissionPurposeData collected
INTERNETNetwork access for ads, updates, and gameplayNetwork status, transfer statistics
ACCESS_NETWORK_STATEAdapt behavior to connection typeNetwork type and status
ACCESS_WIFI_STATEKeep Wi-Fi sessions stableWi-Fi status, signal strength
AD_IDAdvertising identifier for personalizationResettable device ad ID
VIBRATEHaptic feedback on chain reactionsNone
ACCESS_ADSERVICES_TOPICSAd interest topic signalsAdvertising topic data
ACCESS_ADSERVICES_ATTRIBUTIONCampaign attribution measurementAttribution data
BIND_GET_INSTALL_REFERRER_SERVICEIdentify install sourceInstall source, campaign parameters
BIND_APPHUB_SERVICEOptimize ad delivery via AppHubAd parameters, impression data
ACCESS_ADSERVICES_AD_IDComply with modern ad API requirementsAd service identifiers
FOREGROUND_SERVICEMaintain critical functions when backgroundedNone
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONSecure internal broadcast communicationNone

Children's Privacy

Arrow Chain Blitz is not directed to, nor intended for use by, individuals under the age of thirteen (13), and the Company does not knowingly collect personal information from children under 13. A parent or guardian who believes a child has supplied personal information should contact igtryeh202407@gmail.com; the data will be deleted promptly once verified.


Disclosure Requirements


Third-Party Links

The Application may link to websites or services the Company does not operate. We are not responsible for their content, privacy practices, or security, and we recommend reading the privacy policy of any external destination before using it.


Data Breach Notification

Should a data breach affect your personal information, we will notify you within 72 hours of becoming aware of the incident where applicable law requires it, describing the nature of the breach, its likely consequences, and the measures taken or proposed in response.


California Shine the Light

California residents may request details of any disclosure of personal information to third parties for those parties' direct marketing purposes. Send such a request to igtryeh202407@gmail.com with the subject line Shine the Light.


Changes to This Policy

This policy may be revised at any time, with amendments taking effect once the updated text appears on this page and the "Last Updated" line is refreshed. Where a change materially affects how personal information is processed, notice may be given by email or through a prominent in-app message.


Get in Touch