Last Updated: September 11, 2026
This Privacy Policy describes the collection and processing of information about you that can directly or indirectly identify you (the “Personal Data”) carried out by the mobile applications (the “App”) provided by Gora Games ME FZ LLC (“we”, “us”, “our”).
Contact details of data controller:
EU Representative:
Please read this Privacy Policy carefully as it contains important information about the following:
We may update this Privacy Policy from time-to-time to keep it in conformity with the relevant legislation, including the Regulation of the European Parliament and of the Council (EU) 2016/679 (the “GDPR”) and California Consumer Privacy Act 2018 (the “CCPA”). We will keep you informed about the changes to our Privacy Policy. If we make any major changes to our Privacy Policy and will need your explicit consent for further processing of your Personal Data, we will request your consent or your renewed consent (in case it was obtained previously).
We collect Personal Data if you provide it to us or automatically by electronic means.
We respect your privacy and aim to limit the Personal Data that we collect from you to the amount which is strictly necessary to fulfill the purposes of processing.
Categories of Personal Data that we process are specified below:
Purpose of the processing
Personal Data
Legal basis for the processing
to register your account in the App
Terms and Conditions
to fill out an account in the App
Terms and Conditions
Terms and Conditions
Our legitimate interest in receiving communication from you and reacting to it and your interest in getting our response
to manage and optimize users’ experience by improving our knowledge of our users
Our legitimate interest in evaluating and creating statistics on the use of the App and your interest in the App updates which will be tailored to your needs
to provide you with advertising, including that is relevant to your interests
Purpose of processing:
To prevent fraud, detect and block the creation of multiple accounts, and protect the integrity and security of the App ("Anti-Fraud Processing").
Personal Data:
Internet Protocol (IP) address (processed server-side); Android Advertising ID (GAID); App Set ID; hardware device fingerprint (comprising device model, OS version, screen resolution, installed font set, sensor configuration and other hardware-level attributes); and probabilistic device identifier generated by Fingerprint Pro (visitorId).
The above identifiers are collected and processed irrespective of whether you have provided consent to personalised advertising, as they serve a distinct and independent processing purpose.
We may also collect Apple ID for Advertisers (IDFA) if you consent to tracking via Apple's App Tracking Transparency (ATT) framework. If you do not provide consent, you will only see non-personalized ads that do not rely on tracking or personal data collection.
The above identifiers are collected and processed irrespective of whether you have provided consent to personalised advertising, as they serve a distinct and independent processing purpose.
In compliance with Apple’s ATT requirements, we seek explicit user consent before collecting any data for tracking or personalized advertising purposes. If you consent to tracking, we may use your device’s IDFA to provide personalized advertisements based on your interactions with the App and other apps or websites.
If you decline consent, no tracking will occur, and you will receive non-personalized advertisements that do not rely on tracking your behavior or data collected from other sources.
You can manage or revoke your consent at any time through your device settings.
The App enforces a one-account-per-user policy. The Company reserves the right to restrict, suspend, or refuse any new registration where it is reasonably determined, based on technical indicators and security measures, that such registration is intended to circumvent the App’s rules, including by creating multiple accounts or engaging in abusive behavior. Such measures are implemented solely for security and integrity purposes and in the legitimate interests of the Company and its users.
Where the Google Advertising ID (GAID) is collected in connection with Anti-Fraud Processing as described above, such processing constitutes a compatible further use of data originally collected in connection with the operation and improvement of the App. In assessing compatibility pursuant to Article 6(4) GDPR, the Company has had regard to: (a) the link between the original and the further purpose, namely the operation and security of the App; (b) the context in which the data were collected and users' reasonable expectations; (c) the nature of the personal data concerned; (d) the possible consequences of the further processing; and (e) the existence of appropriate safeguards, including the technical and organisational measures described herein. The Company has determined that Anti-Fraud Processing is compatible with the purposes for which GAID was originally collected.
Analytics and advertising measurement identifiers
When you use the App, we may collect and process a Firebase App Instance ID, which may also appear in Google Analytics reporting as a user_pseudo_id (the “App Instance ID”). The App Instance ID is a pseudonymous identifier automatically generated for a particular installation of the App on a device. It does not directly identify you by name, email address or other direct identifier. However, we treat it as Personal Data where applicable data protection law requires us to do so.
We rely on our legitimate interests in operating, securing, measuring and improving the App and our advertising services, and in preventing fraud and abuse, as the legal basis for this processing. We have assessed that these interests are not overridden by your rights and freedoms, taking into account the pseudonymous nature of the App Instance ID and the limited purposes described above.
We do not use the App Instance ID for interest-based or personalised advertising, and we do not use it to create advertising profiles about you based on your activity across different apps or websites
We can share your Personal Data with third parties only in the cases listed below.
When we are required by law: We may disclose your Personal Data to the extent that we are required to do so by law (which may include to government bodies and law enforcement agencies), in connection with any legal proceedings or prospective legal proceedings and in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention).
With our partners who help us support the App:
We may have partners that help us to make the App better, including analytics, advertising and payment services which may process your Personal Data for purposes specified in section “HOW DO WE PROCESS YOUR PERSONAL DATA?” above respectively.
A list of third-party services used by App is below.
Payment services. We may provide paid features in our App. In that case, we may use third-party services for payment processing, as follows:
We do not process your payment data; such data is processed by the relevant payment provider.
Analytics services. We may use third-party service providers to monitor and analyze the use of our App, as follows:
Personalised advertising. Where you have provided any consent required under applicable law, including through Apple’s App Tracking Transparency framework where applicable, we may share advertising identifiers and related advertising data with advertising partners, including Google Ads, Facebook Ads, IronSource, AppLovin and Unity Ads, for personalised advertising.
Non-personalised advertising, measurement and fraud prevention. Independently of personalised advertising, we may process and share limited pseudonymous identifiers and advertising-impression information with relevant service providers, for non-personalised advertising delivery, aggregated or pseudonymous measurement, reporting, service integrity and fraud-prevention purposes, where permitted by applicable law.
We may use third-party service providers advertising purposes respectively, as follows:
Other partners. We also have partners to help us maintain the App:
PLEASE NOTE THAT SOME OF THESE COMPANIES MAY BE LOCATED OUTSIDE THE EU (INTERNATIONAL DATA TRANSFERS) INCLUDING IN THE COUNTRIES WHICH DO NOT ENSURE AN ADEQUATE LEVEL OF PROTECTION OF YOUR PERSONAL DATA. Where this is the case, we meet the strict conditions of Personal Data transfers from the member states of European Union to other countries by using the Standard Contractual Clauses (SCC) adopted by the European Commission to ensure that Personal Data are properly protected or relying on other derogations compliant with GDPR.
We retain your Personal Data for no longer than it is necessary to fulfill the purposes specified in the section “How do we process your Personal Data”. Except for any legal obligation that sets a longer data retention period, at the end of these periods, the Personal Data processed will be deleted or anonymized.
Notwithstanding the foregoing, the Company is legally required to retain certain financial and transactional data for compliance with applicable accounting, tax, anti-fraud, and payment regulations. Such data may include transaction identifiers, dates and times of payouts, payout amounts, currencies, payment methods, masked recipient details, transaction status, and the user identifier or e-mail address as recorded at the time of the transaction.
Such financial records are stored in a separate, restricted accounting ledger and are retained for up to ашму (5) years or such longer period as may be required under applicable law. This data is processed on the basis of the Company’s legal obligations and legitimate interests and shall not be used for marketing purposes.
Following the deletion of a user account, the Company may retain a strictly limited set of identifiers in irreversibly hashed form (including hashed information, hashed device identifiers, or similar technical markers) solely for the purposes of fraud prevention, abuse prevention, enforcement of the App’s rules, and prevention of multiple account registrations.
Such hashed data cannot be reversed to identify the user and is not used for analytics, advertising, profiling, or any marketing purposes. This processing is carried out on the basis of the Company’s legitimate interests in protecting the integrity and security of the App and is retained for no longer than five (5) years following account deletion, after which it is permanently deleted.
Device identifiers and network identifiers processed for Anti-Fraud Processing purposes (including IP address, GAID, App Set ID, hardware device fingerprint and Fingerprint Pro visitorId) are retained for the duration of the user's account and for a period of no longer than twelve (12) months following the last recorded instance of the relevant fraud signal or the last date on which the processing was necessary for the applicable anti-fraud purpose, whichever is earlier, unless a longer retention period is required in connection with the investigation or adjudication of a specific fraud or abuse incident, in which case the relevant data shall be retained for no longer than is necessary for that purpose.
Upon account deletion, the Company may retain irreversibly hashed derivatives of the above identifiers for fraud prevention and prevention of multiple account re-registration, subject to the terms set out in the following paragraph.
We neither use automated decision-making nor refer to the automated profiling.
Rights of EU residents:
This includes, in particular, the retention of: (a) financial and transactional records required for accounting, tax, and regulatory compliance; and (b) irreversibly hashed technical identifiers retained solely for fraud prevention, abuse prevention, and prevention of multiple account registrations.
We will address your request as early as possible and no longer that within 1 month. Please note that this period may be extended by 2 further months where necessary, taking into account the complexity and number of the requests. In this case, we will inform you of the extension within 1 month of receipt of your request and will explain you the reasons for the delay.
Where you object to Anti-Fraud Processing carried out on the basis of the Company's legitimate interests, please note that the Company may demonstrate compelling legitimate grounds for such processing which override your interests, rights and freedoms, having regard in particular to the security and integrity interests of the App and its user community, and the Company's obligations to prevent fraud and abuse. The Company will assess each objection on its individual merits.
Rights of California residents:
Mandatory Verification: As required by CCPA we will need to verify your identity before processing your request. In order to verify your identity, you will be asked to log in to your account or (if you do not have an account) we will try to match the information you provided with the information we handle about you. In certain circumstances, we may decline the request, mainly where we are unable to verify your identity, for example, if you have requested us to delete your Personal Data.
As required by CCPA we endeavor to respond to a verifiable request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by e-mail.
How to exercise any of your rights? You may exercise your rights by sending a relevant request to the e-mail indicated in the contact details.
If you have any comments about how we process your Personal Data, please let us know and we will consider your claim. If you are not satisfied with our response to the complaint, you have the right to file a complaint with the competent authority.