Privacy Policy
Language Priority Notice: This Privacy Policy is published in English and translations into other languages may be provided for users' convenience. Where applicable law requires that a notice be provided in a particular language, the version in that language will prevail for users in that jurisdiction. In all other cases, if there is any inconsistency between a translated version and the English version, the English version will prevail.
1. Introduction
This Privacy Policy (the "Policy") applies to all games published by Hyspire Pte. Ltd. ("Hyspire") on app stores such as the Apple App Store and Google Play (each, a "Game," and collectively, the "Service"). This Policy is provided by Bagelcode, Inc. ("Bagelcode," "we," "us," or "our") and explains how Bagelcode collects, uses, shares, retains, and protects users' personal information in connection with the Service, and what rights and choices users have with respect to their personal information.
Hyspire is an affiliate of Bagelcode located in Singapore and acts as the app store publisher. In this Policy, "we," "us," or "our" refers to Bagelcode unless otherwise stated.
Games distributed through Hyspire are generally developed by Bagelcode, and Hyspire acts as the app store publisher. However, Dream Recipe is an exception and is developed by Aloha Factory, a separate legal entity. See Section 4 (How We Share Your Information), Section 6 (International Data Transfers), and Section 13.1 (Korea Supplement) for the basis for personal information processing arising from the fact that Dream Recipe is developed by a different developer.
This Policy contains terms that commonly apply to users in regions where the Service is provided, including Korea, the European Economic Area (EEA) and the United Kingdom, and the United States. Additional or different terms that apply by region are set out separately in Section 13 (Regional Supplements). If there is a Regional Supplement for the region where a user resides, and the main body of this Policy conflicts with that Regional Supplement, the Regional Supplement will prevail.
2. Information We Collect
We collect the following categories of information from users directly, automatically, or through third parties. The specific items collected and whether they are collected may vary depending on the Game (see Section 1) and the login method that is automatically linked based on the user's device (Android/iOS).
2.1 Account and Login Information
- Account identifiers: Unique user identifiers issued and stored when a user accesses a Game (for example, identifiers based on Firebase authentication tokens, user IDs issued through Apple/Google account linking, etc.). These identifiers are persistent identifiers used to continuously recognize and distinguish a specific user without other identifying information such as real name, and are used for purposes such as saving game progress, preventing abuse, and verifying identity for customer inquiries and refunds. They constitute personal information.
- Login provider (IdP): Users do not separately select a login provider; it is automatically linked based on the user's device platform (Android devices: Google account; iOS devices: Apple account).
- Email: Collected only if email information is included in the authentication token provided by the login provider.
- In-game nickname and other display information directly entered or configured by the user.
- Sign-up date and time: The time when the account is first created.
Note: We do not separately store the display names from Google Play Games or Apple Game Center from login tokens. If a user requests account deletion, we may additionally collect the user's email address and authentication information for identity verification (see Section 5).
2.2 Device and Technical Information
- Country, device information (device type, device model, OS/client version, language, time zone, etc.), and device identifiers (DeviceID, app installation ID, etc.).
- Login session information, IP address, and User-Agent (which may be stored in connection with an account identifier).
- Information that may be collected through advertising SDKs: Advertising identifiers (IDFA/GAID, etc.), app/device identifiers, IP address, approximate location information (not precise GPS location information), User-Agent, device information such as OS/device model/language/country, app version, session/app launch information, ad impression/click/view information, purchase/conversion information, install/acquisition/campaign/attribution information, in-app events, diagnostics/performance information, user/account identifiers depending on the network, and consent/privacy signals. The actual scope of collection and sharing may vary depending on SDK settings by app and advertising platform dashboard settings.
- Error and crash information (see Section 4).
- Push notification-related information: Push tokens (identifiers used to send notifications to each device), notification consent status, and notification delivery/click records.
2.3 Gameplay Information
- Game progress information (level, stage, character, currency, inventory, growth, game settings, and other game data) and in-game event information.
2.4 Payment and Support Information
- In-app purchases are processed through Google Play for Android and Apple for iOS.
- Transaction information received from Google Play/Apple for receipt validation may include order/transaction identifiers (Order ID/Transaction ID), purchase tokens or receipt data, price and currency, purchase date and time, and region/country code. Product IDs are fixed values in each Game's product catalog and are not personal information, so they are not separately listed.
- If a user submits an inquiry to customer support, in addition to the inquiry content written by the user, account identifiers (UUID/UID, etc.), device identifiers (DeviceID, etc.), OS version, device type, platform, country, app version, game data, User-Agent, and similar information are automatically included in the email. Submitted inquiries are connected to and processed through the customer support system (Zendesk) via the customer support email account, and may be forwarded among internal responsible departments where necessary for handling.
3. How We Use Your Information
We use the information we collect for the following purposes.
- Providing the Service, creating and managing accounts, saving game progress, and synchronizing across devices.
- Processing payments and confirming transactions.
- Responding to customer inquiries and providing technical support.
- Detecting and preventing abuse, fraud, and other improper use, and maintaining service security.
- Improving the Service, conducting statistical analysis, and developing new features.
- Providing marketing and personalized advertising within the scope permitted by user consent or applicable law.
- Complying with legal obligations and responding to legal claims.
The legal basis for using information may vary depending on the laws of the region where the user is located. The GDPR legal bases for processing for users in the EEA/UK are described separately in Section 13.2 (EU Regional Supplement).
4. How We Share Your Information
We may share personal information in the following cases and with the following recipients.
- Hyspire Pte. Ltd.: For app store publisher operations, store payment processing, and handling customer support contact points (common to all Games). Sharing of personal information between Bagelcode and Hyspire is based on a Data Processing Agreement (DPA) entered into between the parties.
- Aloha Factory (Dream Recipe only): For game development and service operation support, including backend infrastructure operation. Aloha Factory is a separate legal entity from Bagelcode and Hyspire, develops only Dream Recipe, and accesses and handles actual Dream Recipe operational data (Firebase authentication information, DR operational DB, etc.). This item does not apply to Games other than Dream Recipe, because all Games other than Dream Recipe are developed by Bagelcode. Sharing/processing of personal information between Bagelcode and Aloha Factory is based on a personal information processing outsourcing agreement (DPA) entered into between the parties.
- Infrastructure service providers: Companies that provide infrastructure necessary for service operations, such as server hosting and cloud storage. Dream Recipe uses the Google Cloud Platform (GCP) Seoul region (Korea), and all Games other than Dream Recipe use Amazon Web Services (AWS) us-west-2 (Oregon, United States) region as the same integrated platform. See Sections 6 and 13.2 for the specific basis for international transfers.
- In-app purchases: In-app purchases are processed through Google Play for Android and Apple for iOS.
- Advertising networks and analytics partners: We use Adjust and AppsFlyer for analytics and attribution, and AppLovin MAX for ad mediation. Due to the nature of mediation, AppLovin MAX may internally mediate various advertising networks, including Google AdMob, Meta Audience Network, Mintegral, Pangle, Unity Ads, Moloco, and InMobi (which may vary by Game). Through these SDKs, advertising identifiers (IDFA/GAID, etc.), device information, IP address, approximate location information, ad impression/click/view information, purchase/conversion information, diagnostics/performance information, and similar information may be transmitted to the relevant providers (see Section 2.2). If the user consents, personalized advertising will be enabled, and networks other than AppsFlyer use in-game data by combining it with data from third-party apps, websites, and services within each network's advertising ecosystem for personalization.
- Analytics and service operation partners: We use Google (game usage analytics through Firebase Analytics, push notification delivery through Firebase, app distribution and in-app purchases through Google Play) and Hackle (A/B test audience classification).
- Error and crash analytics tools: We collect and analyze error and crash information through Sentry.
- Customer support (CS) tool providers: We use Zendesk and Chloe (an internal tool) to receive and respond to customer inquiries.
- Disclosure in response to legal requirements: We may disclose information to the extent necessary under laws, court orders, or lawful requests from government authorities.
- Business transfers: Personal information may be transferred in connection with mergers, acquisitions, asset sales, or other changes in business structure, in which case users will be notified in advance.
Except where required by law, we do not sell or provide users' personal information to third parties for purposes other than those described above. Please refer to Section 13.3 (CCPA/CPRA Supplement) for whether our practices constitute "Sale" or "Share" for U.S. users.
5. Data Retention
We retain personal information for the period necessary to achieve the purposes of collection, or for the period required by applicable law. If a user deletes their account or terminates use of the Service, the relevant information will generally be deleted, but may be retained for a certain period in the following cases.
- Transaction and payment records, records related to fraud prevention, and other records required to be retained under applicable laws, including laws on consumer protection in electronic commerce and tax laws.
- Information necessary to resolve disputes or respond to legal claims.
Account deletion procedure: Users may request account deletion/withdrawal through the account deletion page. Users may request account deletion after 14 days have passed from the date of sign-up, and a 30-day grace period is provided after the request during which the request may be withdrawn. After the grace period ends, personal information is masked.
Destruction procedure and method: When the retention period expires or personal information becomes unnecessary because the processing purpose has been achieved, information in electronic file form is permanently deleted in a way that prevents recovery and reproduction, and other records are destroyed by shredding or incineration.
6. International Data Transfers
Our Service is operated across multiple countries, and in that process users' personal information may be transferred to and processed in countries other than the country where the user resides. These transfers may include the following.
- Bagelcode (Korea) <-> Hyspire (Singapore): Transfers for store publisher operations, payment processing, and customer support contact point handling (common to all Games). Transfers are made based on the DPA entered into between Bagelcode and Hyspire.
- Transfers to server/infrastructure locations: Bagelcode's infrastructure (DB) and the servers for all Games other than Dream Recipe use the same integrated platform, AWS us-west-2 (Oregon, United States) region. AWS is certified under the EU-U.S. Data Privacy Framework (DPF), UK Extension, and Swiss-U.S. DPF (AWS is included as an applicable entity under Amazon.com, Inc.'s certification), so DPF may also be relied on, in addition to SCCs, as a legal basis for transfers to the United States. Dream Recipe's GCP servers are located in the Seoul region (Korea) and therefore do not constitute an international transfer.
Note: Aloha Factory (the developer of Dream Recipe) is a domestic company located in Korea, and data processing between Bagelcode and Aloha Factory does not constitute an international transfer. However, from the perspective of Korean users, it constitutes domestic personal information processing outsourcing (see Section 13.1), and from the perspective of EEA/UK users, it is still a transfer to a country outside the EEA/UK (Korea), and therefore is included in the international transfer analysis under Section 13.2 (EU Supplement).
Where personal information is transferred internationally, we provide notices required by applicable law, including the transfer purpose, recipient, destination country, and retention period, and endeavor to implement appropriate safeguards required by the laws of the relevant region (for example, SCCs for the EEA/UK). Please refer to Section 13 (Regional Supplements) for details.
7. Your Rights and Choices
Depending on the laws of the region where the user resides, users may have the following rights with respect to their personal information.
- The right to request access to and confirmation of the status of processing of their personal information.
- The right to request correction of inaccurate or incomplete personal information.
- The right to request deletion of personal information.
- The right to request suspension or restriction of personal information processing.
- The right to receive the personal information they provided (data portability).
- The right to object to personal information processing for marketing purposes and certain processing.
- Where processing is based on consent, the right to withdraw consent at any time.
- The right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning the user or similarly significantly affects the user (including the right to request human intervention or object, where applicable). See Section 13.2 (EU Supplement) for details.
How to exercise rights and additional rights by region (for example, rights under the GDPR for EEA/UK users, rights under the CCPA/CPRA for California users in the United States, and rights under the Personal Information Protection Act for Korean users) are described in detail in Section 13 (Regional Supplements). Users who wish to exercise their rights may contact us using the contact information in Section 12 (Contact Us).
8. Children's Privacy
We do not have a separate procedure to verify users' ages.
Our Service is not directed to children under the age of 16 (or any other age required by local law), and we do not knowingly collect children's personal information.
For games that are not directed to children but may appeal to children, we include measures to protect children's personal information in this Policy.
If a guardian becomes aware that a child has provided personal information to us, the guardian may contact us using the contact information in Section 12 to request deletion of that information.
Items collected from children and purposes of use: We do not separately distinguish child users or process their information differently. We collect the same items from children for the same purposes as described in Section 2. There are no additional items collected only from children.
Rights of parents or legal guardians and how to exercise them: A child's parent or legal guardian has the following rights and may exercise them through the contact information in Section 12.
- The right to request access to personal information provided by the child.
- The right to refuse additional collection/use of the child's personal information and request deletion.
- The right to withdraw consent to the collection/use of the child's personal information.
9. Cookies and Similar Technologies
We and our partners use technologies such as mobile advertising identifiers (IDFA/GAID) and SDKs (Adjust, AppsFlyer, AppLovin MAX, etc.; see Section 4) for service usage analytics, advertising performance measurement, and similar purposes.
Users may reset advertising identifiers or limit tracking through device settings (such as App Tracking Transparency or limiting ad personalization). However, because some functions depend on the use of these technologies, restricting them may limit use of the Service.
Profiling and behavioral advertising: We or our advertising partners may conduct profiling to analyze users' Service usage behavior and provide interest-based (behavioral) advertising. Users may object to or opt out of such processing in accordance with Section 7 and the applicable Regional Supplement in Section 13.
Information collected through SDKs is not separately deleted and is retained until account deletion/withdrawal (see the account deletion procedure in Section 5).
10. Security
We take administrative, technical, and physical safeguards to prevent loss, theft, misuse, unauthorized access, alteration, and leakage of personal information. However, transmission over the Internet and electronic storage methods cannot be guaranteed to be 100% secure, and we endeavor to maintain a reasonably expected level of security.
11. Changes to This Policy
We may revise this Policy due to changes in the Service, changes in laws, or other reasons. If there are material changes, we will provide prior notice through appropriate methods such as in-service notices or email, and the revised Policy will take effect from the separately specified effective date.
12. Contact Us
If you have any questions about this Policy or the processing of personal information, you may contact us as follows.
- Personal information department - Bagelcode, Inc. Platform Division
- Personal information contact - platform.security@bagelcode.com
- EEA GDPR representative (Article 27): Bagelcode, Inc. has appointed the European Data Protection Office (EDPO) as its GDPR Article 27 representative in the EU. You may contact EDPO through its online request form (https://edpo.com/gdpr-data-request/) or in writing (Avenue Huart Hamoir 71, 1030 Brussels, Belgium).
- UK GDPR representative (Article 27): Bagelcode, Inc. has appointed EDPO UK Ltd as its UK GDPR Article 27 representative in the United Kingdom. You may contact EDPO through its online request form (https://edpo.com/uk-gdpr-data-request/) or in writing (Unit 33, Waterside, Schooner Court, 44-48 Wharf Road, London, N1 7UX, United Kingdom).
13. Regional Supplements
This section sets out additional or different terms that apply depending on the laws of the region where the user resides. If the main body of this Policy conflicts with the regional terms below, the terms for the region where the user resides will prevail.
13.1 Korea
- The personal information controller for the Service is Bagelcode, Inc.
- Users have the right to request access to, correction/deletion of, and suspension of processing of their personal information, and may exercise these rights through the contact information in Section 12. We process requests within the period prescribed by applicable law (for example, within 10 days from receipt in the case of access requests).
- Payment/refund-related records may be retained separately for the period prescribed by applicable law, including laws on consumer protection in electronic commerce.
- Pursuant to Article 30(1)(5) of the Personal Information Protection Act, the responsible department and its contact information are provided in lieu of the name of the Chief Privacy Officer: Department - Bagelcode, Inc. Platform Division / Contact - platform.security@bagelcode.com (same as Section 12).
- Outsourcing of personal information processing: We outsource personal information processing as follows: (1) to Aloha Factory (located in Korea) for the development and operation support of Dream Recipe, including backend infrastructure operation; and (2) to Hyspire Pte. Ltd. (located in Singapore) for app store publisher operations, store payment processing, and customer support contact point handling (common to all Games). We disclose the outsourced tasks and processors in accordance with the Personal Information Protection Act, and the details are governed by the outsourcing agreements entered into between Bagelcode and Aloha Factory and between Bagelcode and Hyspire, respectively.
- International transfer of personal information: We transfer personal information internationally as follows.
- Recipients and destination countries: Hyspire Pte. Ltd. (Singapore), Amazon Web Services, Inc. (United States, server infrastructure provider; see Section 4).
- Items of personal information transferred: All categories of collected information described in Section 2.
- Timing and method of transfer: Transferred from time to time over the network in the course of using the Service.
- Purposes of use and retention/use period by recipients: The purposes of use by each recipient follow Section 4, and the retention/use period follows Section 5.
- How to refuse transfer and consequences of refusal: Users may express their intent to refuse international transfers through the contact information in Section 12. However, international transfers are essential processing for providing the Service, including store payment processing, customer inquiry handling, and server infrastructure operation, so if users refuse such transfers, use of the Service may be limited or unavailable.
- Children's personal information: We do not have a procedure to verify users' ages (see Section 8), but we understand that users may include children under the age of 14. Under Article 22(6) of the Personal Information Protection Act, processing personal information of children under the age of 14 requires consent from a legal guardian.
- Rights of data subjects regarding automated decisions: Under Article 37-2 of the Personal Information Protection Act, users have the right to refuse or request an explanation of a decision made by a fully automated system if the decision significantly affects their rights or obligations. We do not make such automated decisions (see Section 7).
13.2 European Economic Area (EEA) and United Kingdom (UK) - GDPR
- The controller is Bagelcode, Inc., and the legal bases by processing purpose are as follows: performance of a contract (providing the Service and processing payments), legitimate interests (preventing abuse and improving the Service), compliance with legal obligations, and user consent for certain processing such as marketing.
- Specific details of legitimate interests: The items we process based on legitimate interests include prevention of abuse and fraud, service quality improvement, and statistical analysis. We have determined that these interests are not overridden by the impact on users' rights and freedoms. We maintain and prepare the results of the balancing test for each processing purpose so that they can be provided upon user request.
- Users have the rights under the GDPR to access, rectification, erasure (right to be forgotten), restriction of processing, data portability, objection, and the right to lodge a complaint with a supervisory authority. Because we do not have a main establishment in the EEA/UK/Switzerland, the one-stop-shop mechanism under GDPR Article 56 does not apply. Users may lodge a complaint with the supervisory authority in the place where they reside, work, or where the infringement occurred. However, we recommend contacting us first using the contact information in Section 12 before lodging a complaint. Supervisory authority contact information: EEA (https://edpb.europa.eu/about-edpb/board/members_en), UK (https://ico.org.uk/global/contact-us/), Switzerland (https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html).
- Automated decision-making: Under GDPR Article 22, users have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them. We do not carry out such automated decision-making (for example, automatic account suspension/blocking based on AI judgment or automatic determination of fraudulent transactions).
- International transfers: Korea has been subject to an EU adequacy decision since December 2021. This decision applies on a country-wide basis to businesses in Korea subject to the Personal Information Protection Act (PIPA), and no separate certification or application procedure is required. Bagelcode and Aloha Factory are both general private companies subject to PIPA and do not fall within excluded categories under the adequacy decision (such as national security-related processing by public authorities or credit information companies under the Credit Information Act). Therefore, transfers to Korean entities themselves are based on this adequacy decision. Dream Recipe's GCP servers are also located in the Seoul region (Korea), and are within the scope of the adequacy decision in the same way. However, Bagelcode's actual DB infrastructure uses AWS us-west-2 (Oregon, United States), so the physical location where data is stored is the United States, not Korea, and appropriate safeguards for transfers to the United States are required separately from Korea's EU adequacy decision. AWS is certified under the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF, and transfers are made based on this certification or Standard Contractual Clauses (SCCs).
- EU/UK representatives: Bagelcode has appointed EDPO (European Data Protection Office) as its EU representative and EDPO UK Ltd as its UK representative under GDPR Article 27. Please refer to Section 12 for specific contact information.
- Nature of providing information: If users do not provide personal information that is necessary to use the Service (for example, account identifiers; see Section 2), use of the Service may be limited or impossible. Other items (for example, marketing-related consent) are optional, and failure to provide them does not affect basic use of the Service.
13.3 United States - CCPA/CPRA and COPPA
- Users residing in U.S. states with privacy laws, including California, Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia, have, under the laws of each state (with applicability requirements and exceptions varying by state), the right to know the categories and sources of personal information collected about them, the right to request deletion, the right to request correction, the right to opt out of the "Sale" or "Share" of personal information and Targeted Advertising, and the right not to be discriminated against for exercising these rights.
- Non-discrimination: We do not discriminate against users for exercising the above rights, such as by refusing to provide the Service, charging different prices or rates, or providing a different level or quality of service. However, if the information necessary to provide the Service becomes unavailable due to the exercise of a right (for example, a deletion request), providing the Service may become impossible to that extent.
- Right to limit use of Sensitive Personal Information: We have confirmed that we do not collect items that constitute Sensitive Personal Information under the CPRA (such as precise location information or login credentials), and therefore do not provide a separate procedure for requests to limit the use of Sensitive Personal Information.
- Whether we provide users' personal information in a manner that constitutes "Sale" or "Share" under the CCPA/CPRA: Through advertising networks (AppLovin MAX, AdMob, Mintegral, InMobi, Meta, Pangle, Unity, and Moloco), we combine in-game data with data from third-party apps, websites, and services within each network's advertising ecosystem and use it for personalized advertising. This constitutes "Share" under the CPRA (provision for cross-context behavioral advertising). Users may opt out of the sale/share of personal information through the in-app privacy settings screen.
- Universal Opt-Out / Global Privacy Control: We recognize universal opt-out signals recognized by the CCPA/CPRA, such as Global Privacy Control (GPC), and process them as requests to opt out of the sale/share of personal information.
- COPPA: The Service is classified as a "mixed audience" service and is not considered child-directed. However, if we have actual knowledge that we collect personal information from children under the age of 13, we will obtain verifiable parental consent before collection in accordance with the federal Children's Online Privacy Protection Act (COPPA).