Legal
Legal · Privacy

Privacy Policy

Last updated: Effective: Status: Draft

Draft: pending legal review. This is a working draft. It is not legal advice and is not yet in force. Highlighted text in brackets is a placeholder to fill in ([like this]) or an open business decision ([Decision: like this]). Purple "Drafting note" boxes are for reviewers and must be removed before publishing.

This policy explains what personal data Bonus Round collects, why, who we share it with, how long we keep it, and the rights you have. It covers people with Bonus Round accounts, visitors to bonusround.io, and players of games that use our SDK.

The short version

  • Players: our SDK does not ask for, or send us, a player's name, email, account, chat or location. In games for kids, and in any game where kids may be playing, it stores nothing in the browser and uses a random ID for that visit only. In other games it keeps one random, anonymous ID in the game site's browser storage so we can cap how often an ad is shown and count ad events. We match ads to games, not to people, and we never use behavioural targeting.
  • Customers: we hold your account details (email, optional name, a hashed password), your games, brands, campaigns and billing records. Stripe handles card and bank details; we never see your full card number.
  • AI: our agents visit the websites and games you give us, take screenshots and send them, with related text, to AI providers to do the work.
  • We don't sell personal information, and we don't share it for cross-context behavioural advertising.

Who we are

Bonus Round is operated by Dream Park Immersive Inc. ("Dream Park", "we", "us"), 1525 Van Ness Ave, San Francisco, CA. For the personal data described in this policy we act as follows:

Privacy contact: Aidan Wolf, aidan@dreampark.app. Data Protection Officer: Aidan Wolf, aidan@dreampark.app. EU representative (GDPR Art. 27) and UK representative (UK GDPR Art. 27): not yet appointed. Until then, contact Aidan Wolf at aidan@dreampark.app for EU and UK privacy matters. [Decision: Appoint an EU and a UK representative established in the EU and the UK, if Art. 27 applies]

What we collect

If you have an account

If you are a game developer (publisher)

If you are a brand (advertiser)

If you play a game that uses Bonus Round

Our SDK runs inside the game's web page. This is everything it sends to us:

WhenWhat the SDK sendsWhy
The page loadsThe game's public publisher ID, the page origin (for example https://example.com, without the path or query string), the SDK version and the three.js version.To check the SDK is running on the game's registered domains and to show the developer that the install works.
An ad is requestedPublisher ID, ad format and trigger (for example, an intermission or an opt-in rewarded round), the anonymous player ID, the page origin, the SDK version, and a test flag.To pick an ad for the game and apply frequency caps.
Something happens in the adA signed token for that ad, the event type (impression, viewable, start, engagement, complete, click or reward), a number such as visible milliseconds or a score, for a viewable event the viewability measurement (how much of the ad was on screen, its share of the screen and the viewing angle), and the anonymous player ID.To measure the ad, bill the advertiser, pay the developer and detect duplicate or invalid traffic.
Drafting note (remove before publishing)

Verify each of these against the shipped code before publishing; they were in progress when this draft was written: (1) the ad server never derives a player ID from the IP address or user agent (platform/ads/routes.js; the earlier code fell back to a hash of IP + user agent); (2) the load ping sends the origin only, not the full URL (sdk/br.js); (3) the SDK's no-storage/consent mode exists and the SDK honours GPC; (4) the "directed to children" game setting exists; (5) the broader restricted-category detection; (6) ambient props carry a "Sponsored" label.

If you visit bonusround.io

If you contact us

We keep your messages and contact details so we can reply and keep a record.

If we contact you about your game

Our founder invites some independent developers of three.js games to try Bonus Round. To do that:

What we don't do

How we use personal data, and our legal bases

If you are in the EU, the EEA, the UK or Switzerland, the law requires us to name a legal basis for each use.

PurposeDataLegal basis (GDPR / UK GDPR)
Create and secure your account, keep you signed inAccount details, session, API keys, technical dataContract; legitimate interests in security
Learn games and brands with our AI agents and generate creativesGame and brand data, screenshots, page text, uploads, test loginsContract
Serve ads, apply frequency caps, measure and report ad eventsPlayer ID, ad events, page origin[Decision: Legitimate interests vs consent for player measurement data; consent may be needed for local storage under ePrivacy rules, see the Cookie Notice]
Billing, payments, payouts and accountingLedger, payment and payout records, Stripe IDsContract; legal obligation (tax and accounting records)
Prevent fraud, invalid traffic and abuse; enforce our termsAd events, player ID, IP address (in memory), account activityLegitimate interests in protecting advertisers, publishers and the service
Public website preview and its free-use limitsSubmitted URL, salted IP hashLegitimate interests in offering a demo and preventing abuse
Referral programme: credit the referrer and apply the self-referral rulesbr_ref cookie, keyed hash of network address, account links[Decision: Legal basis for referral tracking]
Inviting developers to try Bonus Round, and honouring opt-outsPublic posts, names or usernames, public handles and email addresses, game addresses; do-not-contact list[Decision: Legal basis for founder outreach to developers, and for keeping the do-not-contact list]
Support and service messagesContact details, messagesContract; legitimate interests
Legal claims, compliance and requests from authoritiesAny relevant dataLegal obligation; legitimate interests
Marketing emails [Decision: Whether Bonus Round sends marketing email at all]Email addressConsent, or legitimate interests where the law allows for existing customers; you can opt out at any time

Where we rely on legitimate interests, you can ask us for details of the balancing test we carried out.

AI processing and automated decisions

Who we share it with

Children and young players

Many browser games are played by children and teenagers. Bonus Round is designed so that games for young audiences can show ads without anyone collecting personal information from players:

Laws we design for: the US Children's Online Privacy Protection Act (COPPA), Article 8 of the GDPR and UK GDPR, the UK Age Appropriate Design Code, and the EU Digital Services Act's ban on profiling-based ads to minors. [Decision: Legal review: confirm the COPPA position that contextual-only mode (a per-visit ID, hashed on our server, used only for frequency capping and de-duplicating ad events) stays within "support for internal operations", and that the anonymous ID in standard mode (games declared not for kids and rated Teen or above) is used only for the same purposes]

Operator contact (COPPA): Dream Park Immersive Inc., 1525 Van Ness Ave, San Francisco, CA. Contact: Aidan Wolf, aidan@dreampark.app. Phone: [PHONE NUMBER].

Requests from parents and guardians

If you are a parent or guardian and you want to know what we hold about your child, or want it deleted, email aidan@dreampark.app. Because we don't know who players are, the quickest way is:

If we learn that we have collected personal information from a child in a way the law doesn't allow, we will delete it promptly.

How long we keep data

DataHow long
Account detailsUntil you delete your account; deletion removes them straight away [Decision: Retention in backups after deletion]. Financial records are kept as below, detached from you.
Sign-in sessions30 days, or until you log out; expired sessions are deleted within an hour
API keys (hash and prefix)Until you delete your account [Decision: Retention of revoked key records while the account is open]
Test loginsUntil you delete the login or your account
Agent captures (screenshots, page text, world manifests, brand kits)[Decision: Retention for agent run folders (currently kept indefinitely)]
Raw ad request logs90 days in our live database. Then every identifier is removed and the anonymised records are moved to our archive (see Data retention policy)
Ad events (impressions, viewable, engagement, clicks)The player ID is removed after 90 days; the anonymised events stay in our live database for 13 months and are then moved to the archive
Anonymised archiveKept, with no player IDs, session IDs or IP addresses in it [Decision: whether the anonymised archive is ever deleted, and after how long]
Aggregated reports (daily counts per game, campaign and format)Kept permanently; they contain no player IDs
ads.txt check results and sellers.json listingsWhile the game exists on Bonus Round
Ledger, payments, payouts and invoicesKept permanently (this covers tax and accounting record-keeping); no player IDs
Public preview results and IP hashes[Decision: Retention for public preview records (results are reused for 24 hours)]
Referral cookie (br_ref)30 days, or until you create an account
Referral network-address hashes (link clicks, sign-ups, sign-ins)30 days; older entries are deleted automatically
Records about developers we contacted about their games[Decision: Retention for prospect records (currently kept with no automatic deletion)]
Do-not-contact listKept permanently, so we can keep honouring the opt-out
Player storage in the browser (br_pid, br_rounds)Never written in contextual-only mode (and deleted if it was there before). Otherwise it stays in the browser until the player clears the site's data or the game withdraws consent; br_rounds only keeps the last hour

Data retention policy

We keep personal information only as long as we need it for the purpose we collected it for. After that we remove every identifier, so what's left identifies no one, and move it to an archive. For players (including children, under COPPA's requirement for a written retention policy), that means:

  1. Purpose. Player ad data is kept only to serve and cap ads, measure and bill them, pay developers, detect invalid traffic and handle disputes.
  2. Raw request logs (one row per ad request, with the anonymous or hashed player ID) stay in our live database for 90 days. Then an automatic daily job removes every identifier from them (player and session IDs and their hashes, room IDs, and any network address; we never store IP addresses in the first place), adds them to daily counts per game, campaign, format and trigger, and writes the anonymised records to our archive. Only once the archive copy has been written and checked are they removed from the live database.
  3. Event-level data (one row per impression, viewable, engagement, completion, click or reward) loses its player ID after 90 days. The anonymised events stay in the live database for 13 months, so 12-month reports and year-on-year comparisons keep working, and are then moved to the archive the same way.
  4. The archive holds compressed files, one per day, with no player IDs, session IDs or IP addresses. It is stored [Decision: archive location: our own servers, or an S3-compatible store such as Amazon S3 Glacier or Cloudflare R2, and its region], is readable only by Bonus Round staff who need it (for audits, billing disputes and invalid-traffic reviews), and is kept [Decision: archive lifetime].
  5. Aggregated reports (daily counts and spend, with no player ID) are kept permanently.
  6. Financial records (the earnings and spend ledger, payments, payouts and invoices) are kept permanently, which covers what tax and accounting law require. They contain no player IDs.
  7. Contextual-only games never give us a reusable player ID in the first place: the per-visit ID is stored only as a hash that changes daily, and never on events.
  8. IP addresses of players are never stored by the ad server.
  9. How it's enforced. The job runs every day and can be re-run safely. It never deletes a record from the live database before its archive copy is confirmed, and the identifiers are removed first, so a failed archive write never leaves an ID behind. The periods are settings (BR_RETENTION_RAW_DAYS, BR_RETENTION_AGG_MONTHS), so a shorter period can be applied without a code change. [Decision: who owns this policy and reviews it, and how often (proposed: the founder, every 12 months and whenever a new kind of player data is added)]
  10. Backups that contain these tables are kept for [Decision: backup retention, e.g. 30 days] and then overwritten; deleted data isn't restored from them except to recover from an incident.
Drafting note (remove before publishing)

Account deletion, the hourly session sweep and the ad-data retention job (platform/compliance/retention.js: identifiers removed at 90 days, anonymised raw logs archived at 90 days and events at 13 months, aggregates and ledger kept) exist. There are no cleanup jobs yet for agent run folders or public preview records; those periods need one before this table is accurate. Account deletion doesn't remove agent run folders.

Security

We protect data with measures that suit its sensitivity, including salted scrypt password hashing, hashed session tokens and API keys, AES-256-GCM encryption for test logins, HttpOnly session cookies (sent only over HTTPS on the live site), signed ad-event tokens, rate limiting, and keeping service API keys only on our servers. No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.

Security contact: Aidan Wolf, aidan@dreampark.app.

Agent captures and logs (screenshots, page text, uploaded images and step logs) are private. Only the finished ad package, which games must be able to load, and a small set of preview files for test links are reachable by URL.

International transfers

We are based in the United States and our servers are hosted in [HOSTING REGION]. Several sub-processors, including Anthropic, Google and Stripe, process data in the United States and other countries. When personal data from the EU, the EEA, the UK or Switzerland goes to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a sub-processor's certification under the EU–US Data Privacy Framework (and its UK and Swiss extensions), plus extra safeguards where needed. You can ask us for a copy of the relevant safeguards. [Decision: Confirm the transfer mechanism for each sub-processor]

Your rights in the EU, EEA, UK and Switzerland

You have the right to:

We reply within one month, which the law lets us extend by two more months for complex requests.

Your rights in California and other US states

This section applies to residents of California (under the CCPA as amended by the CPRA) and of other US states with similar laws, such as Colorado, Connecticut, Virginia and Utah. [Decision: Confirm whether Bonus Round meets the CCPA thresholds and which state laws apply]

Categories we collected in the last 12 months

CategoryExamplesDisclosed for a business purpose to
IdentifiersEmail address, name, account ID, anonymous player ID, IP addressHosting provider; Stripe (account holders only); SendGrid (account holders' email addresses); AI providers (names and public handles in posts about games we invite)
Commercial informationAd-account top-ups, spend, earnings, payoutsStripe; hosting provider
Internet or network activityAd events in games, dashboard activity, pages our agents visited for youHosting provider; AI providers (agent captures)
Audio, visual or similar informationScreenshots of your website or game; images you uploadAI providers; hosting provider
Professional informationYour company, brand or studioHosting provider
Sensitive personal informationAccount log-in (email and password), test logins you give usHosting provider only (stored hashed or encrypted)
InferencesNone about people. We infer things about games and brands, not individuals.None

Sources: you; your browser; the SDK running in games; public websites and search results our agents read at your request; Stripe. Purposes: those listed in How we use personal data. Retention: see How long we keep data.

We use sensitive personal information only to provide the service and keep it secure, so the right to limit its use doesn't apply. We do not sell or share personal information, including that of consumers under 16. Our SDK treats a browser's Global Privacy Control signal as an opt-out and stores nothing in that browser.

Your rights

You can ask to know what we collected, disclosed and why; to get a copy; to delete it; to correct it; and to opt out of sale, sharing or targeted advertising (we don't do these). We won't discriminate against you for using your rights. You can use an authorised agent; we may ask them for proof of authority and ask you to confirm your identity. We verify requests by matching the email address on the account or, for players, the player ID. If we turn down a request, you can appeal by replying to our decision.

Contact for requests under the CCPA and other US state privacy laws: Aidan Wolf, aidan@dreampark.app.

How to use your rights

Changes to this policy

We will update this policy as the service changes. The "Last updated" date shows the latest version. If we make a material change, we will tell account holders by email or in the dashboard before it takes effect.

Contact

Dream Park Immersive Inc., 1525 Van Ness Ave, San Francisco, CA
Privacy contact and Data Protection Officer: Aidan Wolf, aidan@dreampark.app