Privacy Policy
Draft: pending legal review. This is a working draft. It is not legal advice and is not yet in force. Highlighted text in brackets is a placeholder to fill in ([like this]) or an open business decision ([Decision: like this]). Purple "Drafting note" boxes are for reviewers and must be removed before publishing.
This policy explains what personal data Bonus Round collects, why, who we share it with, how long we keep it, and the rights you have. It covers people with Bonus Round accounts, visitors to bonusround.io, and players of games that use our SDK.
The short version
- Players: our SDK does not ask for, or send us, a player's name, email, account, chat or location. In games for kids, and in any game where kids may be playing, it stores nothing in the browser and uses a random ID for that visit only. In other games it keeps one random, anonymous ID in the game site's browser storage so we can cap how often an ad is shown and count ad events. We match ads to games, not to people, and we never use behavioural targeting.
- Customers: we hold your account details (email, optional name, a hashed password), your games, brands, campaigns and billing records. Stripe handles card and bank details; we never see your full card number.
- AI: our agents visit the websites and games you give us, take screenshots and send them, with related text, to AI providers to do the work.
- We don't sell personal information, and we don't share it for cross-context behavioural advertising.
Who we are
Bonus Round is operated by Dream Park Immersive Inc. ("Dream Park", "we", "us"), 1525 Van Ness Ave, San Francisco, CA. For the personal data described in this policy we act as follows:
- Account holders, website visitors, people who contact us, and developers we contact about their games: we are the controller.
- Players of games that use our SDK: [Decision: Controller/processor role for player ad data. Proposed: Bonus Round is an independent controller for the limited ad-measurement data its SDK sends (anonymous player ID, ad events), and the game developer is the controller for its own site and responsible for player notice and any consent].
- Test logins and other material a customer gives us to operate the service for them: we act on the customer's behalf (as a processor or service provider), under our Terms of Service and any data processing addendum.
Privacy contact: Aidan Wolf, aidan@dreampark.app. Data Protection Officer: Aidan Wolf, aidan@dreampark.app. EU representative (GDPR Art. 27) and UK representative (UK GDPR Art. 27): not yet appointed. Until then, contact Aidan Wolf at aidan@dreampark.app for EU and UK privacy matters. [Decision: Appoint an EU and a UK representative established in the EU and the UK, if Art. 27 applies]
What we collect
If you have an account
- Account details: your email address, an optional name, and your password. We store the password only as a salted scrypt hash, never in readable form.
- Sign-in session: when you log in we set a
br_sessioncookie. We keep only a hash of its value, with its creation and expiry time (30 days). Expired sessions are deleted from our database every hour. - API keys: a name you choose, the first characters (prefix) of the key, a hash of the key, and when it was created, last used and revoked. We show the full key once, when you create it.
- Usage of the dashboard and API: the actions you take, such as creating games, brands, campaigns and creatives, approving or rejecting a creative (with any reason you give) and changing settings.
- Technical data: your IP address and browser user agent reach our server with every request. We use the IP address in memory for rate limiting (for example, to stop repeated sign-up or log-in attempts). [Decision: Server access-log policy: whether production hosting keeps request logs with IP addresses, and for how long]
If you are a game developer (publisher)
- Your game: its URL, name, domains, content rating, categories, audience, ad settings (formats, triggers, floors, blocked categories, frequency cap) and whether it is in test mode.
- Integration data: the page origins (sites) the SDK has run on, when we first and last saw it, how often, the SDK version and the three.js version.
- What our play agent records when it plays your game: screenshots, text visible on the page (such as the HUD and menus), technical data about the 3D scene (objects, materials, colours, lights, camera and positions), gameplay measurements (speeds, scale, controls), and sometimes an export of the player character's 3D model so we can preview ads with it. Before saving that model we strip name tags, text sprites, cameras and lights, so it doesn't carry another player's username or on-screen text. From this the agent writes a "world manifest": a summary of the game's genre, controls, art style, natural breaks, audience and brand-safety rating. If your game shows other people's usernames or chat, they may appear in screenshots and page text. [Decision: Whether to blur or drop third-party usernames and chat from play-agent captures]
- Test login (optional): if you give us a login URL, username, password and notes so our agent can play the full game, we encrypt them with AES-256-GCM before storing them. When the agent needs them, our software types them into the game; the AI model is never shown the username or password. Your notes are shown to the model. You can delete the login at any time.
- Earnings and payouts: your earnings ledger and payout history. If you set up payouts, Stripe collects your identity, bank and tax details directly through Stripe Connect. We keep only your Stripe account ID and status flags (for example, whether payouts are enabled and whether Stripe needs more information).
If you are a brand (advertiser)
- Your brand: its website URL and any images you upload (PNG, JPEG or WebP, up to six files of 8 MB each).
- What our brand agent collects: screenshots of your website's public pages, page text, colours and fonts, and images it saves (such as your logo and product images). It may also use web search and other public sources [Decision: Confirm which public sources the brand agent uses in production: the current code uses Anthropic's web search tool; Wikipedia/Wikidata are planned]. From these it writes a "brand kit": your brand's name, tagline, products, palette, tone, mascot and things to avoid. A brand website can include personal data, for example a founder's name or photo; our agent is told to collect brand identity, not information about people.
- Campaigns and creatives: campaign settings, budgets, bids, targeting (game categories, ratings and specific games), call-to-action labels and URLs, generated creatives, and your review decisions.
- Billing: your ad-account ledger, payments, auto-recharge settings, and the Stripe customer, payment, invoice and subscription IDs and receipt links for each payment. Stripe collects and processes your card or other payment details; we never receive the full card number.
If you play a game that uses Bonus Round
Our SDK runs inside the game's web page. This is everything it sends to us:
| When | What the SDK sends | Why |
|---|---|---|
| The page loads | The game's public publisher ID, the page origin (for example https://example.com, without the path or query string), the SDK version and the three.js version. | To check the SDK is running on the game's registered domains and to show the developer that the install works. |
| An ad is requested | Publisher ID, ad format and trigger (for example, an intermission or an opt-in rewarded round), the anonymous player ID, the page origin, the SDK version, and a test flag. | To pick an ad for the game and apply frequency caps. |
| Something happens in the ad | A signed token for that ad, the event type (impression, viewable, start, engagement, complete, click or reward), a number such as visible milliseconds or a score, for a viewable event the viewability measurement (how much of the ad was on screen, its share of the screen and the viewing angle), and the anonymous player ID. | To measure the ad, bill the advertiser, pay the developer and detect duplicate or invalid traffic. |
- The anonymous player ID is a random value such as
p_k3x9…that the SDK creates and keeps in the game site's local storage (br_pid). Because local storage belongs to each website, a game on one site cannot read the ID from a game on another site. It is not linked to a name, email, game account or device fingerprint. The SDK also stores the times of sponsored rounds shown in the last hour (br_rounds) so it can apply the game's hourly cap without asking our server. - Contextual-only mode: in games made for kids, games with a mixed audience, games whose developer hasn't told us yet, games rated Everyone or not rated yet, when a game loads the SDK in no-storage mode (for example until the player has given consent), and when the browser sends Global Privacy Control (GPC), the SDK writes nothing to the browser and uses a random ID that lasts only for that page visit. Our server keeps only a hash of it that changes every day, never attaches it to ad events, and uses it only to cap how often an ad is shown during that visit. No player-level or behavioural data is used to choose the ad.
- Network data: like any website, our server receives the player's IP address and browser user agent with each request. Our ad server shortens the IP address (the last part of an IPv4 address, most of an IPv6 address) and uses it in memory for rate limiting only; it never stores it. We never derive a player ID from the IP address or user agent.
- What the SDK does not do: it sets no cookies, doesn't read the game's own cookies or player accounts, doesn't collect names, emails, chat, contacts, precise location or advertising IDs, and loads no third-party trackers. The sponsored round runs with our code and our ad files only.
- Leaving the game: if a player clicks an ad's call to action, the advertiser's website opens in a new tab. That website's own privacy policy applies from then on. We don't add tracking parameters to the link.
Verify each of these against the shipped code before publishing; they were in progress when this draft was written: (1) the ad server never derives a player ID from the IP address or user agent (platform/ads/routes.js; the earlier code fell back to a hash of IP + user agent); (2) the load ping sends the origin only, not the full URL (sdk/br.js); (3) the SDK's no-storage/consent mode exists and the SDK honours GPC; (4) the "directed to children" game setting exists; (5) the broader restricted-category detection; (6) ambient props carry a "Sponsored" label.
If you visit bonusround.io
- Public preview: our home page lets anyone enter a website or game URL and watch our agents learn it. We store the URL, the results (including a screenshot) and a salted hash of your IP address, never the raw IP, so we can limit free previews per network per day. Results are cached and shared with other visitors who preview the same site within 24 hours.
- Referral links: if you open someone's referral link (
/r/…), we set a first-party cookie,br_ref, that holds the referral code and the time you arrived, so the person who invited you gets credit if you sign up. It lasts 30 days and is deleted when you create an account. To apply our self-referral rules, we also keep a keyed hash (not the address itself) of the network address used for referral-link clicks, sign-ups, sign-ins and visits to your Refer & earn page, for 30 days. See the Referral Programme Terms. - Fonts: our pages load fonts from Google Fonts, so your browser sends your IP address and user agent to Google. See the Cookie & Local Storage Notice.
- We use no analytics, advertising pixels or third-party trackers on bonusround.io. [Decision: Confirm before launch that no analytics will be added; if it will, update this section and the Cookie Notice]
If you contact us
We keep your messages and contact details so we can reply and keep a record.
If we contact you about your game
Our founder invites some independent developers of three.js games to try Bonus Round. To do that:
- What we collect: from public posts announcing three.js games (for example on the three.js forum, Reddit, Hacker News, itch.io, GitHub and X), we record the post's address, title, text and engagement counts, the author's name or username, the public handles and email address shown with the post or on the author's public profile, and the game's address. We only read public pages and official public feeds, and we don't log in to these sites.
- What we do with it: our play agent may play the game (as described for publishers above), and we may record a short private video of a Bonus Round inside it. An AI model (Anthropic's Claude) drafts a first message from the post and what our agent learned about the game. The founder reads, edits and sends every message himself, by X direct message or email. Nothing is sent automatically. If there's no reply, we send at most one follow-up, then stop. Emails include our postal address and a way to opt out.
- The private video: it can only be reached through an unguessable link in the message. We only show it publicly if you tick the consent box when you claim your game.
- Do-not-contact list: if you tell us you're not interested, by replying to the message, using "Not interested?" on the invitation page, or emailing aidan@dreampark.app, we add your handles, email address, game address and game domain to a permanent do-not-contact list and close your record, so we don't contact you again. We keep that list so we can keep honouring your opt-out.
What we don't do
- We don't build profiles of players, and we don't target ads to people based on their behaviour, interests, demographics or location. Ads are matched to games by the game's content, category, rating and style.
- We don't knowingly collect personal information from children (see Children and young players).
- We don't sell personal information, and we don't "share" it for cross-context behavioural advertising as California law defines those terms.
- We don't let advertisers upload customer lists or retarget players.
How we use personal data, and our legal bases
If you are in the EU, the EEA, the UK or Switzerland, the law requires us to name a legal basis for each use.
| Purpose | Data | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Create and secure your account, keep you signed in | Account details, session, API keys, technical data | Contract; legitimate interests in security |
| Learn games and brands with our AI agents and generate creatives | Game and brand data, screenshots, page text, uploads, test logins | Contract |
| Serve ads, apply frequency caps, measure and report ad events | Player ID, ad events, page origin | [Decision: Legitimate interests vs consent for player measurement data; consent may be needed for local storage under ePrivacy rules, see the Cookie Notice] |
| Billing, payments, payouts and accounting | Ledger, payment and payout records, Stripe IDs | Contract; legal obligation (tax and accounting records) |
| Prevent fraud, invalid traffic and abuse; enforce our terms | Ad events, player ID, IP address (in memory), account activity | Legitimate interests in protecting advertisers, publishers and the service |
| Public website preview and its free-use limits | Submitted URL, salted IP hash | Legitimate interests in offering a demo and preventing abuse |
| Referral programme: credit the referrer and apply the self-referral rules | br_ref cookie, keyed hash of network address, account links | [Decision: Legal basis for referral tracking] |
| Inviting developers to try Bonus Round, and honouring opt-outs | Public posts, names or usernames, public handles and email addresses, game addresses; do-not-contact list | [Decision: Legal basis for founder outreach to developers, and for keeping the do-not-contact list] |
| Support and service messages | Contact details, messages | Contract; legitimate interests |
| Legal claims, compliance and requests from authorities | Any relevant data | Legal obligation; legitimate interests |
| Marketing emails [Decision: Whether Bonus Round sends marketing email at all] | Email address | Consent, or legitimate interests where the law allows for existing customers; you can opt out at any time |
Where we rely on legitimate interests, you can ask us for details of the balancing test we carried out.
AI processing and automated decisions
- Our agents send screenshots, page text, uploaded images, brand kits, world manifests and prompts to AI providers (Anthropic for reasoning and planning, Google for image generation, Meshy for 3D models, ElevenLabs for music, sound effects and voice-over) to do the work you asked for. ElevenLabs voice-overs are synthetic: ElevenLabs reads out the round's script in a generated voice. We don't send recordings of anyone's voice. [Decision: Confirm the voices used are from ElevenLabs' licensed library, not cloned from a real person] The full list is on our Sub-processors page. [Decision: Confirm each AI provider's data-use terms for our account: no training on our inputs and outputs, and their retention periods]
- The test login for a game is never sent to an AI model.
- The auction, matching, frequency caps and brand-safety checks are automated. They make decisions about which ad goes in which game, not decisions about people that have legal or similarly significant effects. If we suspend an account or withhold earnings for suspected fraud, a person reviews the decision, and you can ask us to explain it and contest it. [Decision: Confirm a human-review process for enforcement decisions]
Who we share it with
- Sub-processors who host, process or generate on our behalf, under contracts that limit their use of the data. See the list.
- Stripe for payments, subscriptions and payouts. For identity checks and fraud prevention, Stripe may act as an independent controller under its own privacy policy.
- The other side of an ad, in aggregate: publishers see totals per brand, campaign and format for their games; advertisers see totals per game. Neither sees individual player IDs. Advertisers see the names, URLs, ratings and categories of the games they match.
- People with a test link: an advertiser can share a preview link to a creative. Anyone with the link can play the preview for 30 days, and it can show a screenshot of the game.
- Authorities and others when the law requires it, or to protect the rights, safety or property of players, customers, us or others.
- A buyer or successor if we are involved in a merger, acquisition or sale of assets, subject to this policy.
Children and young players
Many browser games are played by children and teenagers. Bonus Round is designed so that games for young audiences can show ads without anyone collecting personal information from players:
- No personal information from players. The SDK doesn't ask for or collect names, emails, contact details, photos, voice, chat, precise location or advertising IDs.
- Contextual ads only. Ads are chosen by matching a brand to a game, never by tracking a player. There is no behavioural advertising or profiling on Bonus Round, for any age group.
- Limited internal use of the anonymous ID. The random player ID in local storage is used only for frequency capping, counting and de-duplicating ad events, and detecting invalid traffic. It is not used to build a profile, to target ads, or to contact anyone.
- "Made for kids?" declaration. Every game developer must tell us whether their game is made for kids (Yes, Mixed audience or No) before real ads run. Games for kids and mixed audiences, games not declared yet, and games rated Everyone or not rated yet get contextual-only ads (see contextual-only mode): no player IDs, cookies or local storage, no behavioural targeting, and frequency caps for the current visit only. Games for kids and mixed audiences also get the strictest category rules.
- Category exclusions. Alcohol and gambling brands only run in games rated mature with no child or teen audience, energy drinks never run in games with a child audience, and other adult and prohibited categories are detected and kept out automatically. Publishers can block more categories, and our Ad Policy sets stricter rules for kids' games.
- No data collection inside ads. A sponsored round may not ask players for personal information.
- Accounts are for adults. Bonus Round accounts are for businesses and developers aged 18 or over.
Laws we design for: the US Children's Online Privacy Protection Act (COPPA), Article 8 of the GDPR and UK GDPR, the UK Age Appropriate Design Code, and the EU Digital Services Act's ban on profiling-based ads to minors. [Decision: Legal review: confirm the COPPA position that contextual-only mode (a per-visit ID, hashed on our server, used only for frequency capping and de-duplicating ad events) stays within "support for internal operations", and that the anonymous ID in standard mode (games declared not for kids and rated Teen or above) is used only for the same purposes]
Operator contact (COPPA): Dream Park Immersive Inc., 1525 Van Ness Ave, San Francisco, CA. Contact: Aidan Wolf, aidan@dreampark.app. Phone: [PHONE NUMBER].
Requests from parents and guardians
If you are a parent or guardian and you want to know what we hold about your child, or want it deleted, email aidan@dreampark.app. Because we don't know who players are, the quickest way is:
- In games made for kids, mixed-audience games and the other contextual-only games, there is nothing to find: the SDK stores nothing in the browser and we keep no player ID.
- To stop the ID being reused in other games: clear the game site's data in the browser (site settings → clear data). The SDK will create a new, unrelated ID next time.
- To delete what we hold: send us the value stored under
br_pidfor that game site (in the browser's developer tools under Application → Local storage), or the game's address and the approximate date and time your child played. We will delete the ad events linked to that ID and confirm when it's done. We won't ask you for your child's name or other information we don't already have.
If we learn that we have collected personal information from a child in a way the law doesn't allow, we will delete it promptly.
How long we keep data
| Data | How long |
|---|---|
| Account details | Until you delete your account; deletion removes them straight away [Decision: Retention in backups after deletion]. Financial records are kept as below, detached from you. |
| Sign-in sessions | 30 days, or until you log out; expired sessions are deleted within an hour |
| API keys (hash and prefix) | Until you delete your account [Decision: Retention of revoked key records while the account is open] |
| Test logins | Until you delete the login or your account |
| Agent captures (screenshots, page text, world manifests, brand kits) | [Decision: Retention for agent run folders (currently kept indefinitely)] |
| Raw ad request logs | 90 days in our live database. Then every identifier is removed and the anonymised records are moved to our archive (see Data retention policy) |
| Ad events (impressions, viewable, engagement, clicks) | The player ID is removed after 90 days; the anonymised events stay in our live database for 13 months and are then moved to the archive |
| Anonymised archive | Kept, with no player IDs, session IDs or IP addresses in it [Decision: whether the anonymised archive is ever deleted, and after how long] |
| Aggregated reports (daily counts per game, campaign and format) | Kept permanently; they contain no player IDs |
| ads.txt check results and sellers.json listings | While the game exists on Bonus Round |
| Ledger, payments, payouts and invoices | Kept permanently (this covers tax and accounting record-keeping); no player IDs |
| Public preview results and IP hashes | [Decision: Retention for public preview records (results are reused for 24 hours)] |
Referral cookie (br_ref) | 30 days, or until you create an account |
| Referral network-address hashes (link clicks, sign-ups, sign-ins) | 30 days; older entries are deleted automatically |
| Records about developers we contacted about their games | [Decision: Retention for prospect records (currently kept with no automatic deletion)] |
| Do-not-contact list | Kept permanently, so we can keep honouring the opt-out |
Player storage in the browser (br_pid, br_rounds) | Never written in contextual-only mode (and deleted if it was there before). Otherwise it stays in the browser until the player clears the site's data or the game withdraws consent; br_rounds only keeps the last hour |
Data retention policy
We keep personal information only as long as we need it for the purpose we collected it for. After that we remove every identifier, so what's left identifies no one, and move it to an archive. For players (including children, under COPPA's requirement for a written retention policy), that means:
- Purpose. Player ad data is kept only to serve and cap ads, measure and bill them, pay developers, detect invalid traffic and handle disputes.
- Raw request logs (one row per ad request, with the anonymous or hashed player ID) stay in our live database for 90 days. Then an automatic daily job removes every identifier from them (player and session IDs and their hashes, room IDs, and any network address; we never store IP addresses in the first place), adds them to daily counts per game, campaign, format and trigger, and writes the anonymised records to our archive. Only once the archive copy has been written and checked are they removed from the live database.
- Event-level data (one row per impression, viewable, engagement, completion, click or reward) loses its player ID after 90 days. The anonymised events stay in the live database for 13 months, so 12-month reports and year-on-year comparisons keep working, and are then moved to the archive the same way.
- The archive holds compressed files, one per day, with no player IDs, session IDs or IP addresses. It is stored [Decision: archive location: our own servers, or an S3-compatible store such as Amazon S3 Glacier or Cloudflare R2, and its region], is readable only by Bonus Round staff who need it (for audits, billing disputes and invalid-traffic reviews), and is kept [Decision: archive lifetime].
- Aggregated reports (daily counts and spend, with no player ID) are kept permanently.
- Financial records (the earnings and spend ledger, payments, payouts and invoices) are kept permanently, which covers what tax and accounting law require. They contain no player IDs.
- Contextual-only games never give us a reusable player ID in the first place: the per-visit ID is stored only as a hash that changes daily, and never on events.
- IP addresses of players are never stored by the ad server.
- How it's enforced. The job runs every day and can be re-run safely. It never deletes a record from the live database before its archive copy is confirmed, and the identifiers are removed first, so a failed archive write never leaves an ID behind. The periods are settings (
BR_RETENTION_RAW_DAYS,BR_RETENTION_AGG_MONTHS), so a shorter period can be applied without a code change. [Decision: who owns this policy and reviews it, and how often (proposed: the founder, every 12 months and whenever a new kind of player data is added)] - Backups that contain these tables are kept for [Decision: backup retention, e.g. 30 days] and then overwritten; deleted data isn't restored from them except to recover from an incident.
Account deletion, the hourly session sweep and the ad-data retention job (platform/compliance/retention.js: identifiers removed at 90 days, anonymised raw logs archived at 90 days and events at 13 months, aggregates and ledger kept) exist. There are no cleanup jobs yet for agent run folders or public preview records; those periods need one before this table is accurate. Account deletion doesn't remove agent run folders.
Security
We protect data with measures that suit its sensitivity, including salted scrypt password hashing, hashed session tokens and API keys, AES-256-GCM encryption for test logins, HttpOnly session cookies (sent only over HTTPS on the live site), signed ad-event tokens, rate limiting, and keeping service API keys only on our servers. No system is perfectly secure. If a breach affects your personal data, we will tell you and the authorities as the law requires.
Security contact: Aidan Wolf, aidan@dreampark.app.
Agent captures and logs (screenshots, page text, uploaded images and step logs) are private. Only the finished ad package, which games must be able to load, and a small set of preview files for test links are reachable by URL.
International transfers
We are based in the United States and our servers are hosted in [HOSTING REGION]. Several sub-processors, including Anthropic, Google and Stripe, process data in the United States and other countries. When personal data from the EU, the EEA, the UK or Switzerland goes to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a sub-processor's certification under the EU–US Data Privacy Framework (and its UK and Swiss extensions), plus extra safeguards where needed. You can ask us for a copy of the relevant safeguards. [Decision: Confirm the transfer mechanism for each sub-processor]
Your rights in the EU, EEA, UK and Switzerland
You have the right to:
- access the personal data we hold about you and get a copy;
- correct inaccurate data;
- erase your data, where we don't need to keep it;
- restrict how we use it in some circumstances;
- port data you gave us to another service in a machine-readable format;
- object to uses based on legitimate interests, and always to direct marketing;
- withdraw consent at any time, where we rely on consent; and
- complain to a data protection authority, such as the one where you live or work. Our lead authority is [LEAD SUPERVISORY AUTHORITY, if applicable]. In the UK, this is the Information Commissioner's Office (ico.org.uk).
We reply within one month, which the law lets us extend by two more months for complex requests.
Your rights in California and other US states
This section applies to residents of California (under the CCPA as amended by the CPRA) and of other US states with similar laws, such as Colorado, Connecticut, Virginia and Utah. [Decision: Confirm whether Bonus Round meets the CCPA thresholds and which state laws apply]
Categories we collected in the last 12 months
| Category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Email address, name, account ID, anonymous player ID, IP address | Hosting provider; Stripe (account holders only); SendGrid (account holders' email addresses); AI providers (names and public handles in posts about games we invite) |
| Commercial information | Ad-account top-ups, spend, earnings, payouts | Stripe; hosting provider |
| Internet or network activity | Ad events in games, dashboard activity, pages our agents visited for you | Hosting provider; AI providers (agent captures) |
| Audio, visual or similar information | Screenshots of your website or game; images you upload | AI providers; hosting provider |
| Professional information | Your company, brand or studio | Hosting provider |
| Sensitive personal information | Account log-in (email and password), test logins you give us | Hosting provider only (stored hashed or encrypted) |
| Inferences | None about people. We infer things about games and brands, not individuals. | None |
Sources: you; your browser; the SDK running in games; public websites and search results our agents read at your request; Stripe. Purposes: those listed in How we use personal data. Retention: see How long we keep data.
We use sensitive personal information only to provide the service and keep it secure, so the right to limit its use doesn't apply. We do not sell or share personal information, including that of consumers under 16. Our SDK treats a browser's Global Privacy Control signal as an opt-out and stores nothing in that browser.
Your rights
You can ask to know what we collected, disclosed and why; to get a copy; to delete it; to correct it; and to opt out of sale, sharing or targeted advertising (we don't do these). We won't discriminate against you for using your rights. You can use an authorised agent; we may ask them for proof of authority and ask you to confirm your identity. We verify requests by matching the email address on the account or, for players, the player ID. If we turn down a request, you can appeal by replying to our decision.
Contact for requests under the CCPA and other US state privacy laws: Aidan Wolf, aidan@dreampark.app.
How to use your rights
- Account holders: you can download a copy of your data (your account, games, brands, campaigns, API key details and payouts) with
GET /api/me/export, and delete your account withDELETE /api/me[Decision: Add export and delete buttons to the dashboard; today both are API-only]. Deletion removes your account, sessions, API keys and stored test logins, and stops ad delivery for your games and campaigns. Financial ledger records stay for the period the law requires, detached from you. You can update games, brands, campaigns and test logins in the dashboard, and revoke API keys on the Developers page. For anything else, email aidan@dreampark.app from the email address on your account. - Players: clear the game site's data in your browser to reset the ID. For access or deletion, send us the
br_pidvalue as described in Requests from parents and guardians. - Someone whose data appears on a website or in a game we analysed: email us the address of the page and we will remove the capture.
Changes to this policy
We will update this policy as the service changes. The "Last updated" date shows the latest version. If we make a material change, we will tell account holders by email or in the dashboard before it takes effect.
Contact
Dream Park Immersive Inc., 1525 Van Ness Ave, San Francisco, CA
Privacy contact and Data Protection Officer: Aidan Wolf, aidan@dreampark.app