1. Introduction
Welcome to Pinquisite ("we," "our," or "us"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information. This Privacy Policy explains our practices regarding your data when you use our world knowledge quiz game.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Username
- Email address
- Password (encrypted)
- Profile picture (optional)
2.2 Game Data
During gameplay, we collect:
- Game scores and statistics
- ELO rating and tier progression
- Badges and achievements earned
- Daily challenge participation
- Duel match history
- Gameplay timestamps
2.3 Technical Data
We automatically collect:
- Device information (browser type, operating system)
- IP address
- Session data via JWT tokens stored in local storage
- Usage patterns and feature interactions
2.4 Waitlist Data
If you join our waitlist before creating an account, we collect:
- Email address
- Signup timestamp and source
- Position in queue
This data is used to notify you when access becomes available and may be used to create your account upon invitation.
2.5 Payment Information
For Premium subscriptions, payment processing is handled by Stripe. We collect:
- Billing name and address
- Subscription status and history
- Transaction dates and amounts
Important: We do not store or have access to your full payment card details. Your card information is provided directly to Stripe, which handles it under PCI-DSS security standards. See Stripe's Privacy Policy for more information.
3. How We Use Your Information
We use your information to:
- Provide and maintain the game service
- Calculate and display your ELO rating and tier
- Track and award badges and achievements
- Display global and friend leaderboards
- Match you with opponents in duel mode
- Send game-related notifications (with your consent)
- Improve game features and fix bugs
- Prevent cheating and ensure fair play
4. Cookies and Local Storage
We use local storage to store your authentication token (JWT) to keep you logged in between sessions. We may also use cookies for:
- Remembering your preferences
- Analytics to understand how you use the game
- Session management
You can control cookies through your browser settings, though this may affect some game functionality.
5. Data Sharing
We do not sell your personal data. We may share limited information with:
- Service providers: Hosting, analytics, and infrastructure services
- Other players: Your username, ELO rating, and badges are visible on leaderboards and in multiplayer matches
- Legal requirements: When required by law or to protect our rights
6. Data Retention
We retain your account and game data for as long as your account is active. If you delete your account, we will remove your personal information within 30 days, though some anonymized data may be retained for analytics purposes.
7. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and data
- Portability: Request your data in a portable format
- Objection: Object to certain processing of your data
To exercise these rights, please visit our support page and select "Privacy Request" as the category. We will respond to your request within 30 days (or sooner if required by applicable law).
8. Information for EEA and UK Users (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) provides you with additional rights regarding your personal data.
8.1 Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract performance: Processing necessary to provide the game service, including account creation, gameplay, and subscription management
- Legitimate interests: Processing for fraud prevention, security, service improvement, and analytics (where not overridden by your rights)
- Consent: Processing for marketing communications and optional features (which you can withdraw at any time)
- Legal obligations: Processing required to comply with applicable laws
8.2 Your GDPR Rights
In addition to the general rights above, you have the right to:
- Withdraw consent: Where processing is based on consent, withdraw it at any time
- Restriction: Request restriction of processing in certain circumstances
- Lodge a complaint: File a complaint with your local data protection authority
8.3 International Data Transfers
Your data may be transferred to and processed in the United States and other countries outside the EEA/UK. When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission or reliance on adequacy decisions where applicable.
9. Information for California Users (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights regarding your personal information.
9.1 Categories of Information We Collect
In the past 12 months, we have collected the following categories of personal information:
- Identifiers: Username, email address, IP address
- Commercial information: Subscription and transaction records
- Internet activity: Gameplay data, browsing history within our service
- Geolocation data: General location derived from IP address
- Inferences: Skill level, gameplay preferences based on activity
9.2 Your California Privacy Rights
As a California resident, you have the right to:
- Know: Request disclosure of what personal information we collect, use, and share
- Delete: Request deletion of your personal information (subject to certain exceptions)
- Correct: Request correction of inaccurate personal information
- Opt-out: Opt out of the "sale" or "sharing" of personal information
- Non-discrimination: Not be discriminated against for exercising your privacy rights
9.3 Sale and Sharing of Personal Information
We do not sell your personal information for monetary consideration. We do not share your personal information for cross-context behavioral advertising purposes. If our practices change, we will update this policy and provide an opt-out mechanism.
9.4 Exercising Your Rights
To exercise your California privacy rights, visit our support page and select "Privacy Request" as the category. We will verify your identity before processing your request. You may designate an authorized agent to make requests on your behalf.
10. Children's Privacy (COPPA)
Pinquisite is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us immediately through our support page.
Users between 13 and 16 years of age (or the applicable age in their jurisdiction) should have parental or guardian consent before creating an account. We comply with the Children's Online Privacy Protection Act (COPPA) and similar laws globally.
11. Security
We implement industry-standard security measures to protect your data, including:
- Encrypted password storage using industry-standard hashing algorithms
- Secure HTTPS/TLS connections for all data transmission
- JWT-based authentication with secure token handling
- Regular security audits and vulnerability assessments
- Access controls limiting employee access to personal data
- Secure cloud infrastructure with encryption at rest
However, no system is completely secure, and we cannot guarantee absolute security. We encourage you to use a strong, unique password and keep your login credentials safe.
12. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users as soon as reasonably possible
- Notify relevant data protection authorities as required by law (within 72 hours for GDPR)
- Provide information about the nature of the breach and steps you can take
- Take immediate steps to mitigate the impact and prevent future incidents
13. Third-Party Links and Services
Our Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through our Service, including:
- Map service providers
- Social media platforms (if you share content)
- Payment processors (Stripe)
- Authentication providers (Google, Apple)
14. Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) feature. There is currently no universally accepted standard for how to respond to DNT signals. We currently do not respond to DNT signals, but you can control tracking through your browser settings and our cookie preferences where available.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice on the game or website
- Send an email to registered users for significant changes
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. We recommend reviewing this policy periodically.
16. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us through our support page.
- Privacy Requests: Select "Privacy Request" as the category for data access, deletion, or correction requests
- General Support: Select "General Question" or "Account Issues" for other inquiries
We aim to respond to all inquiries within 30 days. For EEA/UK users, you also have the right to lodge a complaint with your local data protection supervisory authority.