Entity Name Declaration
For the purposes of this document, “Lost Temple Games” and “MAXX Games” refer to the same legal entity. Any reference to either name shall be deemed a reference to that same entity, and the two names may be used interchangeably where the context requires.
The use of either name does not create a separate legal person or alter any rights, obligations, liabilities, or responsibilities under this document.
1. Introduction
Welcome to MAXX Games ("MAXX," "we," "us," or "our"). This Privacy Policy (the "Policy") describes our handling of personal data ("Personal Data") when you interact with our games, websites, mobile applications, client software, and related platforms (together, the "Services").
The Policy is intended to address applicable privacy rules around the world, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), Brazil's Lei Geral de Proteção de Dados (LGPD), and children's privacy requirements such as the U.S. Children's Online Privacy Protection Act (COPPA).
By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please discontinue use of the Services.
2. Scope
This Policy covers users who access the Services through websites, mobile apps, desktop clients, and other supported platforms. It also covers in-game participation, purchases of virtual goods, premium subscriptions, and the processing performed by partners that support our Services, including payment, advertising, cloud, analytics, support, and social-media providers.
3. Definitions
- Personal Data: Information connected to an identified or identifiable person. This may include names, email addresses, IP addresses, device identifiers, or attributes connected with a person's physical, physiological, genetic, mental, economic, cultural, or social identity.
- Processing: Any action performed on Personal Data, whether automated or manual, including collection, recording, organization, storage, alteration, retrieval, use, disclosure, combination, restriction, deletion, or destruction.
- Data Controller: The organization that decides why and how Personal Data is processed. For this Policy, the Data Controller is MAXX Games.
- Data Processor: A third party that processes Personal Data for the Data Controller under a written agreement.
4. Data Collection and Purposes
4.1 Types of Personal Data Collected
The information collected depends on how you use the Services and may include:
- Account Information: Name, email address, username, password, birth date, gender, and phone number, provided during registration or through sign-in services such as Google or Apple.
- Payment Information: Card information, payment-provider identifiers, and transaction history supplied during purchases or processed by providers such as Stripe or PayPal.
- Device and Technical Data: Device model, operating-system version, IP address, MAC address, unique device identifiers such as UDID, app version, crash information, playtime, achievements, and in-game interactions. These details may be collected automatically or through cookies and related technologies.
- Communication Data: Messages sent through in-game chat, email, customer-support requests, and other communications you submit to us.
- Marketing and Analytics Data: Advertising identifiers such as Google AdMob ID and Apple IDFA, browsing and clickstream activity, demographic information, analytics data, and interactions with advertisements.
4.2 Legal Bases for Processing
- Contractual Necessity: Processing needed to create or manage an account, deliver requested virtual items, process payments, or otherwise provide the Services.
- Legal Obligations: Processing required for tax, accounting, financial reporting, regulatory, or other legal responsibilities.
- Legitimate Interests: Processing used to keep the Services stable and secure, prevent fraud, improve experiences, and personalize content, after balancing those interests against user rights and freedoms.
- Consent: Processing based on your permission where the law requires it, including certain sensitive-data uses or direct marketing in applicable regions.
4.3 Purposes of Processing
- Service Operations: Administering accounts, delivering game content, processing transactions, and maintaining availability and security.
- User Experience: Providing recommendations and event notices, improving game design, and resolving technical problems.
- Marketing and Advertising: Showing targeted advertising where permitted, evaluating ad performance, and measuring campaigns.
- Security and Compliance: Detecting fraud, investigating violations, reviewing communications where necessary to enforce our terms, and responding to lawful regulatory requests.
- Analytics: Using aggregated or individual-level data, as legally permitted, to understand behavior, improve performance, and guide business decisions.
5. Data Sharing with Third Parties
5.1 Third-Party Service Providers
We may provide Personal Data to trusted vendors that perform functions for us. These can include payment processors such as Stripe and PayPal; hosting services such as AWS and Google Cloud; analytics services such as Google Analytics and Mixpanel; advertising networks such as Facebook Ads and Unity Ads; and support platforms such as Zendesk.
Our service providers are required by contract to follow our instructions and maintain suitable safeguards. They are not authorized to use Personal Data for unrelated purposes.
5.2 Business Transfers
If MAXX is involved in a merger, acquisition, financing, reorganization, or sale of all or a substantial part of its assets, Personal Data may transfer to the relevant successor. Where required, we will notify users and provide available choices.
5.3 Publicly Available Information
We may publish information that does not identify individuals, such as aggregated gameplay statistics. User-generated screenshots, videos, or similar content may also be shared publicly, subject to available opt-out rights.
6. Children's Privacy
6.1 Age Restrictions
Children under 13, or below the minimum digital-consent age in their country (for example, 16 in parts of the EU), may not use the Services. Users aged 13–17, or 16–17 where the higher EU threshold applies, may use the Services only with verifiable permission from a parent or legal guardian.
6.2 Parental Controls
Parents and guardians should supervise a minor's use of the Services, set healthy playtime limits, review privacy options such as chat and advertising controls, and accept responsibility for the minor's activity. We do not knowingly collect a child's Personal Data without the required parental consent. If we discover that such data was collected, we will delete it promptly.
7. User Rights
Your location may give you some or all of the rights below. Contact us using the details in Section 14 to submit a request. We aim to respond within the period required by law, such as 30 days under relevant California requirements or one month under GDPR.
- Access: Ask for a copy of the Personal Data we hold about you.
- Correction: Ask us to correct information that is inaccurate or incomplete.
- Deletion (Right to Be Forgotten): Ask us to erase eligible Personal Data, including data no longer needed for its original purpose.
- Restriction of Processing: Ask us to limit processing in situations allowed by law, such as while data accuracy is being checked.
- Data Portability: Ask for eligible information in a transferable format or request its transfer to another provider when technically possible.
- Withdraw Consent: Revoke permission for processing based on consent. Withdrawal does not affect processing already performed or processing supported by a different legal basis.
- Object to Processing: Object to direct marketing or certain processing based on legitimate interests.
8. Data Retention
We keep Personal Data only while it is reasonably needed for the purposes described in this Policy or for a period required by law. Typical examples include:
- Account information remains on record until the account is permanently deleted, subject to longer tax, dispute, security, or legal requirements.
- Payment records may be retained through the transaction period and then for record-keeping, commonly for 7 years.
- Chat logs may be kept for up to 6 months to investigate disputes, safety reports, or violations.
You may request earlier deletion when applicable law permits it.
9. Data Security
We use reasonable, industry-standard safeguards intended to prevent unauthorized access, disclosure, alteration, or destruction. Measures may include encryption for sensitive information such as payment data and passwords, access-control and authentication procedures, security testing and vulnerability reviews, and anonymization or pseudonymization where appropriate.
No internet transmission or storage system can be guaranteed to be completely secure, so we cannot promise absolute protection.
10. Cookies and Similar Technologies
10.1 Types of Cookies
- Essential Cookies: Support core features such as sessions, login, and security.
- Analytical Cookies: Measure usage patterns and help improve the Services, including through tools such as Google Analytics.
- Advertising Cookies: Support personalized advertising and campaign measurement through services such as Facebook Pixel or Google AdMob.
- Social Media Cookies: Enable sharing and related social functions for platforms such as Twitter/X and Instagram.
10.2 Control Over Cookies
Most browsers, including Chrome and Safari, let you block or delete cookies through their settings. Some functions may not work correctly if essential cookies are disabled. You may also use industry opt-out tools offered by organizations such as the Digital Advertising Alliance (DAA) or European Interactive Digital Advertising Alliance (EDAA) for certain analytics or advertising cookies.
11. Cross-Border Data Transfers
Your Personal Data may be transferred to or processed in a country whose privacy laws differ from those where you live. We use applicable legal mechanisms for these transfers, including:
- GDPR: Standard Contractual Clauses (SCCs) or an approved certification framework, such as the EU-US Data Privacy Framework where available.
- CCPA/CPRA: Required disclosures about third-party transfers and applicable rights to opt out of certain sharing or transfers.
- LGPD: Written arrangements requiring the recipient to provide equivalent protection.
12. Data Breaches
If a Personal Data incident is likely to create a risk to user rights or freedoms, we will take legally required steps, which may include:
- Notifying the appropriate data-protection authority within the required period, including within 72 hours where GDPR applies, or otherwise as local law requires.
- Promptly informing affected users when notification is required and providing practical guidance on protective actions.
13. Changes to This Policy
We may revise this Policy when our Services, business practices, or legal obligations change. Material revisions will be posted on our website or within the Services at least 14 days before they take effect and, where practical, communicated through in-game notices, email, or pop-ups. Continued use after the new effective date means the revised Policy applies to your subsequent use, subject to mandatory local law.
14. Contact Us
Contact the Privacy Affairs Department if you have questions about this Policy, want to exercise a privacy right, or need to report a suspected data breach. We will respond within 30 days or within the period required by applicable law.
Privacy Officer: MAXX Games
Address: UNIT 608-613 LEVEL 6 CORE C, CYBERPORT 3, 100 CYBERPORT ROAD, HONG KONG
Email: contact@losttemplegames.com