1. Data controller
The controller of personal data for Crystal Caverns is Ai-Studio Development OÜ, registry code 17404322, Estonia. The current email and postal address are available on the Contact page. The same channel can be used for data protection questions and to exercise your rights.
This Notice describes processing related to the website, game, account, cloud saves, leaderboards and purchases. Google, Stripe and other service providers may also act as independent controllers for their own purposes.
2. Data we process, purposes and legal bases
| Personal data processed | Purpose of processing | Legal basis for processing |
|---|---|---|
| Account ID, email, name and profile image received from Google, and login and session data | Creating and authenticating the account, displaying the account and providing user support | Entering into and performing a contract; legitimate interests in account security |
| Chosen public alias and leaderboard participation preference | Publishing results at the user's request without displaying the user's full Google name or profile image | Consent, which can be withdrawn in account settings |
| Game state, completed levels, settings, statistics, score, seed, difficulty, game mode and submission time | Operating the game, local and cloud storage, synchronising progress and providing the optional leaderboard | Performance of a contract; consent for leaderboard publication; legitimate interests in preventing fraud |
| Movement points, time and result for the daily-game replay | Personal records, the ghost feature, result verification and fair play | Performance of a contract; consent for public use; legitimate interests in preventing misuse |
| Purchase reference, Stripe session or payment ID, product, amount, currency, status, timestamps and evidence of acceptance of the terms | Accepting payment, activating Premium, refunds, disputes and accounting | Performance of a contract, compliance with a legal obligation and establishment, exercise or defence of legal claims |
| IP address, browser and device information, request time, URL, error message and security logs | Delivering the Service, troubleshooting, security and prevention of misuse | Legitimate interests in keeping the Service reliable and secure |
| Pseudonymous first-party analytics identifiers, page views, coarse country/region/city derived at the hosting edge, external referrer host and path without query strings, campaign tags, device/browser category and visible-tab engagement, when optional analytics is allowed | Understanding how the website and game are used so we can improve reliability, content and features | Consent, which can be withdrawn via the analytics cookie banner preference stored on the device |
| Correspondence and information voluntarily provided by the user | Responding to a question, complaint or data protection request | Performance of a contract, compliance with a legal obligation or legitimate interests |
Complete card details, including the card number and CVC, are entered in Stripe's environment and are not sent to us. If required data is not provided, the account, cloud saves or purchase may not function.
3. Cookies, local storage and PWA
The current version uses only technologies necessary to provide the Service:
- Authentication cookies maintain the Supabase sign-in session and protect the account.
- The localStorage entry identified by
crystal-caverns-save-v1stores game state, progress, records, the daily-game replay, and sound, speed and other game settings on the device. - A first-party preference cookie and the localStorage entry identified by
crystal-caverns-localeremember the language you selected. They are not used for advertising or cross-site tracking. - The localStorage entry identified by
crystal-caverns-analytics-consentstores whether you allowed or rejected optional measurement. First-party measurement starts, and the Google Analytics script loads where configured, only after you allow it. - After permission,
crystal-caverns-analytics-visitor-v1andcrystal-caverns-analytics-session-v1store random first-party visitor and session identifiers. They are unrelated to an account ID and are never used for advertising or cross-site tracking. - The PWA service worker and cache allow application files to load faster and provide limited offline use.
The local game state remains on the device until the user deletes it in the game or browser settings. When you sign in to an account, the local state may be combined with the cloud save. All analytics is optional: until you choose Allow analytics, neither first-party measurement nor the Google Analytics tag is activated. First-party statistics do not store raw IP addresses, full referrer query strings or raw user-agent strings. We do not use advertising pixels or cross-site marketing tracking.
Stripe Checkout opens as a separate payment environment. Stripe may use technologies needed for payments, fraud prevention and operation of its own service as described in its Privacy Notice.
4. Recipients of data
- Supabase provides authentication, the database, cloud storage and server-side functions.
- Google provides the sign-in method selected by the user.
- Supabase stores the optional first-party analytics records for us with browser access denied; only authorised administrators can retrieve aggregated statistics.
- Google Analytics (Google LLC / Google Ireland Limited) processes measurement data when it is configured and the user has allowed analytics.
- Stripe processes payments, authentication and fraud prevention.
- Netlify hosts the web application and processes network traffic and technical logs.
- An accountant, legal adviser or competent authority, only where necessary and supported by a legal basis.
Service providers process data under our instructions, their own legal obligations and applicable contracts. We do not sell personal data or disclose it to third parties for their independent direct marketing.
Service-provider information: Supabase Privacy, Google Privacy, Google Analytics, Stripe Privacy and Netlify Privacy.
5. Transfers outside the EEA
A service provider or its subprocessor may process data outside the European Economic Area. In that case, an applicable safeguard is used, such as a European Commission adequacy decision, EU Standard Contractual Clauses and supplementary security measures. The exact location and mechanism depend on the provider's configuration and are described in its privacy or data-processing terms.
6. Retention
- Account, profile and cloud saves: until the account is deleted or the relationship necessary to provide the Service ends; backups are deleted through the provider's normal rotation process.
- Leaderboard data and replays: until the user opts out of publication, deletes the account or asks for removal, unless a shorter period is sufficient to protect the integrity of the Service.
- Payment and accounting data: generally for seven years from the end of the relevant financial year where the law requires the data to be treated as an accounting record.
- Evidence of acceptance and disputes: for the duration of the contract and until possible claims expire, unless accounting or another legal requirement requires longer retention.
- Application security and error logs: for the shortest period that fulfils their purpose; infrastructure logs are retained according to the providers' published retention periods.
- Correspondence: until the matter is resolved and afterwards only for as long as necessary to defend a possible claim.
- localStorage: until the user deletes the game state or the browser's site data.
- Language preference: the cookie expires after one year and is renewed when the site is used; the localStorage preference remains until the user changes it or clears the browser's site data.
- Optional measurement preference and first-party visitor identifier: remain until the user changes the preference or clears the browser's site data. Rejecting optional measurement removes the first-party identifiers.
- Detailed first-party analytics sessions and page views: automatically deleted after 25 months.
- Google Analytics measurement data: retained according to the configured measurement-property retention setting (the provider's default retention applies unless shortened).
Where data must be kept longer because of fraud, a dispute or a legal obligation, we restrict its use to that purpose. When the purpose and legal basis end, the data is deleted or anonymised.
7. Your rights
Depending on the circumstances, you may exercise the following rights:
- You may obtain confirmation and a copy of your personal data.
- You may correct inaccurate personal data.
- You may request deletion of personal data or restriction of processing.
- Where the right applies, you may receive data you provided in a machine-readable format and have it transferred.
- You may object to processing based on legitimate interests.
- You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- You may lodge a complaint with the Estonian Data Protection Inspectorate or with the supervisory authority in your country of residence.
A request can be submitted using the email address on the Contact page. Before responding, we may ask for reasonable proof of identity. Deleting an account does not erase data that we must retain by law; that data is separated from the active account and its use is restricted.
8. Public leaderboard and automated decisions
Leaderboard participation must be voluntary and can be switched off in account settings. Publication uses the alias selected by the user, the score and game context, rather than the user's full Google name or profile image. We may assess technical patterns and replays to detect fraud, but the user can ask for human review of a result removal or account restriction.
We do not make decisions about a person based solely on automated processing that produce legal or similarly significant effects for that person. Stripe may use automated fraud prevention for payment security and authentication under its own terms.
9. Security and children
We apply access controls, encrypted connections, separation of privileges and other technical and organisational measures that are reasonable for the risk. No internet service is completely risk-free. Notify us immediately if you suspect misuse of your account or data.
The Service is not directed to children under 13, and we do not knowingly collect their account data. If you believe that a child created an account without the required permission, contact us so that we can investigate and delete the data.
10. Changes to this Notice
We update this Notice when the data, purposes, service providers or legal requirements change. We will publish the new version and date on this page. We will notify users of a material change through the account or Service where reasonably necessary.