1. Scope and controller
This Privacy Policy applies to websites, mobile games, applications, and related online services operated under the developer name Oviss (collectively, the “Services”). The data controller is Shaanxi Oviss Biotechnology Co., Ltd. (“Oviss,” “we,” “us,” or “our”), located at Room AZC 1-108, Zhongchuang Tianyuan, Middle Section of Xinqiao Road, Yangling Demonstration Zone, Shaanxi Province, Xianyang 712199, China.
Because our products are still in development, a particular Service may not use every practice described below. The in-app notices and the Google Play Data safety disclosure for each released product will identify the practices that actually apply to that product.
2. Information we collect
Depending on the Service, its features, your device settings, and your choices, we may collect the following categories:
| Category | Examples | Typical source |
|---|---|---|
| Identifiers and account data | Name or nickname, email address, player or account ID, Google or Facebook sign-in identifier, profile image, advertising ID, installation ID, device identifiers, and IP address. | You, your device, or a sign-in provider. |
| Gameplay and activity | Game progress, scores, achievements, virtual items, session activity, interactions, preferences, crash logs, diagnostics, and performance data. | Your use of the Services and integrated analytics SDKs. |
| Device and network data | Device model, operating system, language, app version, browser, mobile carrier, connection type, timestamps, and approximate device state. | Your device and software. |
| Purchases | Purchase history, product purchased, price, currency, and transaction status. Payment card details are normally processed by the app store or payment provider and are not received by us. | Google Play, another app store, or payment provider. |
| Communications | Support messages, survey responses, reports, and information you submit when contacting us. | You. |
| Location information | Approximate location inferred from IP address, device language, regional settings, or advertising technologies; and, only if a feature requires it and you grant device permission, precise location. | Your device, network, or permission-enabled location services. |
| Advertising data | Ad impressions and clicks, advertising identifiers, consent signals, inferred interests, and attribution or conversion information. | Advertising and attribution partners. |
We may also use cookies, local storage, pixels, SDKs, and similar technologies to operate the Services, remember preferences, maintain security, understand usage, and deliver or measure advertising. Where law requires, non-essential technologies will be used only after consent.
3. How we use information
- Provide, personalize, maintain, and improve the Services and save gameplay progress.
- Authenticate users, enable Google or Facebook login, and maintain accounts.
- Process purchases, provide rewards, and manage virtual items.
- Diagnose crashes, analyze performance, develop new features, and conduct aggregated analytics.
- Deliver, personalize, frequency-cap, measure, and prevent fraud in advertising, subject to consent and applicable law.
- Respond to support requests and send service-related communications.
- Protect players, enforce terms, prevent cheating, abuse, fraud, and security incidents.
- Comply with legal obligations and establish, exercise, or defend legal claims.
Where applicable law requires a legal basis, we process information to perform a contract with you, pursue our legitimate interests (such as security and service improvement), comply with law, or based on your consent. You may withdraw consent at any time, without affecting earlier lawful processing.
4. How we share information
We may disclose information to the following recipients, only as needed for the purposes described in this policy:
- Service providers: hosting, cloud storage, customer support, analytics, crash reporting, security, attribution, and technical operations vendors.
- Platform and identity providers: Google Play, Google Sign-In, Apple, Facebook Login/Meta, and other platforms you choose to connect.
- Advertising partners: Google AdMob/Google advertising services, Meta Audience Network or other disclosed ad networks, mediation partners, measurement providers, and their demand partners.
- Other players: information you choose to make public, such as nickname, avatar, scores, leaderboard position, or user-generated content.
- Legal and safety recipients: authorities or others where reasonably necessary to comply with law, protect rights and safety, investigate fraud, or enforce agreements.
- Corporate transaction parties: advisers and counterparties in a merger, financing, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.
We do not disclose personal information to third parties for money. Certain personalized advertising or cross-context behavioral advertising activities may, however, be considered a “sale,” “sharing,” or targeted advertising under some U.S. state laws. See the California notice below for opt-out rights.
5. Advertising, analytics, and third-party SDKs
Future Services may integrate third-party SDKs, including Google Play Services, Firebase Analytics and Crashlytics, Google AdMob, Google Sign-In, Facebook Login, Meta SDKs, Meta Audience Network, and other partners identified in the relevant app. These providers may independently collect identifiers, device and network information, approximate location, usage data, diagnostics, ad interactions, and consent signals under their own privacy policies.
Advertising may be contextual or personalized. Personalized ads can use activity over time and across apps or services. Where required, we will request consent through an in-app consent platform before using personal data for personalized advertising. Users may receive non-personalized or restricted ads based on consent, age, region, or settings; these ads can still use contextual information and approximate location and may still process limited data for delivery, reporting, security, and fraud prevention.
Learn more from Google’s Privacy Policy, Google advertising technologies, and Meta’s Privacy Policy. The inclusion of a provider here does not mean it is active in every Service.
6. Your choices and controls
- Device permissions: control location, notifications, camera, microphone, and other permissions through your device settings.
- Advertising: use the privacy or consent settings presented in the Service, device-level advertising controls, and Google or Meta ad settings. Where required, you may opt out of targeted advertising, sale, or sharing.
- Cookies: adjust browser settings or any consent banner provided on our website.
- Communications: opt out of marketing messages through the unsubscribe method provided. Service and security messages may still be sent.
- Access, correction, deletion, and portability: submit a request using the contact details below. We may verify your identity before fulfilling it.
7. Data retention and deletion
We retain personal information only as long as reasonably necessary to provide the Services, fulfill the purposes described in this policy, maintain security, resolve disputes, enforce agreements, and comply with legal, tax, accounting, or reporting obligations. Retention periods depend on the data type, sensitivity, purpose, and legal requirements. For example, account data is generally kept while an account is active; support records may be kept for up to three years after resolution; and transaction records may be retained for the period required by applicable law.
When data is no longer needed, we delete or anonymize it. Information may persist temporarily in encrypted backups until those backups rotate, and we may retain limited records where legally required or necessary to prevent fraud. Aggregated or de-identified information that cannot reasonably identify you may be retained.
If a Service offers user accounts, you may initiate deletion inside the app where available or use our web-based data deletion request page. Deleting an app does not by itself delete your account or all associated data.
8. Data security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information, which may include encryption in transit, access controls, least-privilege practices, vendor review, monitoring, and secure development practices. No system or transmission is completely secure, and we cannot guarantee absolute security.
9. International data transfers
Oviss is based in China, and our providers may process information in China, the United States, Singapore, the European Economic Area, or other countries where they operate. These locations may have different data protection laws. Where required, we use recognized transfer mechanisms and safeguards, such as contractual protections, and take steps intended to protect information consistently with this policy.
10. Children’s privacy
Unless a particular Service is expressly identified as child-directed, our Services are not directed to children under 13 (or the minimum digital consent age in their country), and we do not knowingly collect personal information from such children without legally valid parental consent. If we learn that a child provided personal information without required consent, we will take reasonable steps to delete it. Parents or guardians may contact us.
If we release a Service intended for children or mixed audiences, we will apply age-appropriate design, use only permitted SDKs, limit personalized advertising as required, and provide any additional notices and parental controls required by law and platform policy.
11. Additional notice for California consumers
This section supplements the rest of this policy for California residents and uses terms defined by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”).
Categories and purposes
In the preceding 12 months, depending on the Services used, we may have collected the categories described in Section 2, corresponding to CCPA categories including identifiers; customer records information; commercial information; internet or other electronic network activity; geolocation data (including approximate location used for advertising); audio, electronic, or visual information you choose to provide; and inferences. We collect these categories from the sources and for the purposes described above and disclose them to the recipient categories in Section 4.
We do not knowingly sell or share the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA/CPRA. If our practices change, we will provide the required notice and controls.
Your California rights
- Right to know/access: request the categories, sources, purposes, recipients, and specific pieces of personal information we have collected about you.
- Right to delete: request deletion of personal information, subject to legal exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out: opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising.
- Right to limit: limit certain uses or disclosures of sensitive personal information where the law grants that right.
- Right to non-discrimination: exercise your rights without unlawful discrimination or retaliation.
To exercise these rights, email [email protected] with the subject “California Privacy Request,” or use our request page. To opt out of sale or sharing, use any “Privacy Choices” or consent control in the applicable Service, enable a legally recognized Global Privacy Control where supported, or email us with the subject “Do Not Sell or Share My Personal Information.” We will honor legally valid browser-based opt-out preference signals where required.
We may ask for information reasonably necessary to verify your identity and match your request to our records. An authorized agent may submit a request, but we may require proof of authorization and identity verification. We aim to respond within 45 days, subject to any lawful extension.
12. Rights in other regions
Depending on your location, including the EEA, United Kingdom, Switzerland, Brazil, or other U.S. states, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, and appeal a decision. You may also complain to your local data protection authority. To make a request or appeal, contact us below. Rights are subject to applicable exceptions.
13. Changes to this policy
We may update this policy as our Services, partners, or legal obligations change. We will post the revised policy here and update the “Last updated” date. If changes materially affect your rights, we will provide additional notice or obtain consent where required.
14. Contact us
Developer name: Oviss
Room AZC 1-108, Zhongchuang Tianyuan
Middle Section of Xinqiao Road, Yangling Demonstration Zone
Shaanxi Province, Xianyang 712199, China (CN)
Privacy email: [email protected]
Website: ovars.top
Please include the relevant game or app name, your player/account ID if available, your country or region, and the nature of your request. Do not send passwords or payment card details.