Privacy Policy
XV - Rugby Manager
Who and what
Controller: AJ Development, contact email, app name "Rugby Manager", bundle id, effective date.
No accounts, no name or email collected. Install-scoped random ID (
profile.uuid) is the only identifier you set, sent to Firebase Analytics and Crashlytics as user ID.
Data collected and by whom
Firebase Analytics (Google): screen views, gameplay events, device/OS, app version, Firebase app-instance ID. Ad storage, personalisation and user-data sharing disabled. Link Google's privacy policy.
Crashlytics (Google): crash logs, stack traces, device state, screen name, match mode/fixture id/seed as context.
Google AdMob: ad impressions, device identifiers (IDFA/GAID only if consented), approximate location by IP, ad interaction. Rewarded and interstitial placements. Link Google's ads policy and partner list.
In-app purchases via Apple App Store / Google Play: transaction id recorded locally to prevent double crediting. You never see payment card details. Purchases: XP packs (consumable), Remove Ads (non-consumable).
Local storage: save games, XP, unlocks, entitlements in on-device SQLite. Not transmitted.
Consent and choice
UMP consent form shown before ads in GDPR/UK regions; iOS App Tracking Transparency prompt after it. Users can decline; ads then non-personalised.
How to withdraw: reinstall, iOS Settings → Privacy → Tracking, Google ad settings. If you add a "privacy options" button (UMP requires one for EEA users to re-open consent), name it here.
Telemetry is on only in production builds; no opt-out toggle exists in-app today. Say so, or add one.
Standard sections
Purposes and legal bases (GDPR: legitimate interest for crash/analytics, consent for personalised ads).
Retention: Firebase Analytics default 2 months for user-level data, 14 months for aggregated; Crashlytics 90 days. Local data until uninstall.
Data sharing: only Google as processor/partner; no selling.
International transfers to Google servers (US).
Children: not directed at under-13s; if you set AdMob child-directed flags, say so. Real player names appear from public sports data, not user data.
User rights (access, deletion: uninstall clears everything local; email to request Firebase deletion), CCPA "do not sell" statement.
Security, changes to the policy, contact.
Store form alignment
Apple App Privacy: Identifiers (device ID), Usage Data, Diagnostics, Purchase history; tracking = yes if you use IDFA for ads.
Google Play Data Safety: same categories, mark encrypted in transit, no deletion request mechanism unless you add one.