Privacy Policy

Last updated: 17 August 2026

1. Data Controller

Cropsicles is operated by Tyga.Cloud Ltd, a company registered in England and Wales (Company No. 14643275). We are the data controller for your personal data under UK GDPR and EU GDPR. Contact: privacy@tyga.cloud

2. Data We Collect

Account data: If you create an account, a username or display name, email address, and password (stored as a bcrypt hash -- we never store or can access your plain-text password). You can play as a guest without an account.

Game data: Level progress, high scores, coins, gems, boosters owned, settings, and leaderboard entries.

Technical data: Device type, operating system, app version, a randomly generated device or session identifier, and crash/diagnostic reports.

Payment data: If you make an in-app purchase, payment is processed by the app store or our payment provider. We do not store credit card numbers, CVVs, or full payment details on our servers. We receive only a transaction confirmation and amount.

3. Legal Basis for Processing (GDPR)

Contract: Processing your account and game data is necessary to provide the Game and save your progress.

Legitimate interests: Preventing cheating, maintaining fair leaderboards, diagnosing crashes, improving the Game, and ensuring security.

Consent: Optional marketing communications and any non-essential analytics are only used with your explicit consent, which you may withdraw at any time.

Legal obligation: We may process data to comply with applicable laws (e.g. financial record-keeping for 6 years under UK tax law).

4. How We Use Your Data

We use your data to: run the Game and your account; save and restore your progress across devices; operate leaderboards and events; process in-app purchases and keep transaction records; diagnose crashes and improve gameplay; and detect and prevent cheating and abuse.

5. Data Sharing

We share data only with the following categories of processors, all of whom are bound by data processing agreements:

Hosting provider: Hetzner Online GmbH, Germany (EU/EEA -- adequate under GDPR).

App stores: Apple App Store and Google Play, for distribution and in-app purchase processing.

Payment processor: For purchases made outside an app store (PCI DSS compliant).

We do not sell your personal data to third parties. We do not use third-party advertising networks or cross-app tracking.

6. Data Storage & Security

Your data is stored on servers located in Europe (Hetzner, Germany). All data in transit is encrypted using TLS 1.2 or higher. Passwords are hashed using bcrypt. Database access is restricted by IP whitelist and authentication. We conduct regular security reviews.

7. Data Retention

Active accounts: Data retained for as long as your account exists.

Deleted accounts: Personal data deleted within 30 days of an account deletion request, except where retention is required by law.

Transaction records: Financial records retained for 6 years as required by UK tax law (HMRC).

Diagnostic logs: Crash and technical logs retained for up to 12 months, then automatically purged.

8. Your Rights (UK/EU GDPR)

You have the right to: access a copy of your data; rectify inaccurate data; request erasure ("right to be forgotten"); restrict processing; request data portability; object to processing based on legitimate interests; and withdraw consent where processing is based on consent.

To exercise any of these rights, email privacy@tyga.cloud. We will respond within 30 days (extendable to 90 days for complex requests). You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.

9. International Transfers

Your data is primarily processed within the EU/EEA (Germany). If data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Agreement (IDTA).

10. Children

Cropsicles is intended for players aged 13 and over. We do not knowingly collect personal data from children under 13. In-app purchases are intended to be authorized by a parent or the account holder responsible for the payment method. If you believe a child under 13 has provided us with personal data, contact privacy@tyga.cloud and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-game notification or an update notice. The "Last updated" date at the top reflects the most recent revision. Continued use of the Game after changes constitutes acceptance.

12. Contact

Data Protection Officer: privacy@tyga.cloud
Tyga.Cloud Ltd
United Kingdom
Company No. 14643275