Privacy Policy
Last updated: August 14, 2026CardsClan ("we", "our", or "us") is operated by Sunrise Entertainment LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit cardsclan.com, use our mobile application (iOS and Android), or interact with our services. This policy complies with GDPR, CCPA, COPPA, and international privacy standards.
Please read this policy carefully. If you disagree with its terms, please discontinue use of the service.
1. Definitions
- Service – CardsClan mobile application and website operated by Sunrise Entertainment LLC for iOS and Android platforms.
- Personal Data – any information relating to an identified or identifiable natural person, directly or indirectly.
- Usage Data – data collected automatically from your use of the Service, such as gameplay statistics, session duration, device type, operating system, and diagnostic information.
- Device Identifier – unique identifiers assigned to your device (e.g., IDFA on iOS, Google Advertising ID on Android) used for analytics and fraud prevention.
- Processing – any operation performed on data, including collection, recording, storage, use, and transmission.
- Data Controller – Sunrise Entertainment LLC, which determines the purposes and means of processing.
2. Information We Collect
We collect the following categories of information:
2.1 Information You Provide
- Account information – email address (for registration, email verification, and account recovery).
- Communications – support inquiries, feedback, and user-generated content you send us.
2.2 Information Collected Automatically
- Device information – device type, operating system, OS version, unique device identifiers (IDFA/AAID), IP address, and mobile network information.
- Usage data – gameplay statistics, session duration, game events, features accessed, performance metrics, and crash reports.
- Location data – we do not collect precise geolocation; however, we may infer general location from IP address for compliance and fraud prevention.
- Cookies and tracking technologies – session identifiers and preference data stored locally on your device.
What We Do NOT Collect: We do not intentionally collect payment card data, Social Security numbers, government-issued IDs, biometric data, or other sensitive personal information. We do not track your location with GPS.
3. Legal Basis for Processing (GDPR Compliance)
We process your personal data based on:
- Consent – explicit consent for analytics and tracking technologies (iOS/Android app permissions).
- Contract Performance – to provide the Service and verify your account.
- Legal Obligation – to comply with applicable laws and regulations.
- Legitimate Interests – to improve the Service, prevent fraud, and ensure security.
4. How We Use Your Information
We use collected data for the following purposes:
- Provide, operate, maintain, and improve the Service.
- Verify your email address and authenticate your account.
- Send transactional emails (account verification, password reset, support responses).
- Monitor and analyse usage trends to enhance user experience.
- Detect, prevent, and address technical issues, fraud, cheating, and abuse.
- Respond to support requests and inquiries.
- Generate aggregated, anonymised analytics reports.
- Comply with legal obligations and protect our rights.
5. Service Providers and Third-Party Analytics
We do not sell or share your personal data for advertising purposes. We may share information with trusted service providers who assist us:
5.1 Hosting and Infrastructure
- Cloud service providers for game hosting and data storage.
5.2 Analytics
Google Analytics for Mobile Apps
- Google Analytics collects anonymous usage data (events, sessions, device type, OS).
- Data is shared with Google for analytics and service improvement purposes.
- Google may use aggregated data for contextualising advertising in their network.
- You can control data collection through device settings:
- iOS: Settings → Privacy → Tracking → disable app tracking
- Android: Settings → Google → Manage your Google Account → Data & Privacy → Ad Settings
- For more information, visit Google Privacy Policy and How Google Uses Information.
5.3 Other Service Providers
- Email delivery – services for transactional email delivery.
- Support systems – platforms for managing user inquiries and support tickets.
All service providers are contractually obligated to: (1) process data only as instructed, (2) maintain confidentiality, and (3) implement appropriate security measures. We ensure they comply with applicable data protection laws (GDPR, CCPA).
6. Cookies and Tracking Technologies
On the Website (cardsclan.com):
- Session Cookies – automatically deleted when you close your browser; used to maintain session state.
- Preference Cookies – store your settings and preferences (e.g., language, theme).
- Analytics Cookies – track page views and user interactions via Google Analytics.
You can control cookies through your browser settings or opt out of Google Analytics at Google Analytics Opt-out Browser Add-on.
On Mobile Apps (iOS/Android):
- We use app-level analytics (Google Analytics for Firebase) and identifier tracking (IDFA/AAID).
- Disable tracking via device advertising settings (see Analytics section above).
7. International Data Transfers
Your information may be transferred to, stored in, and processed in countries outside your country of residence, including the United States. These countries may have data protection laws that differ from your home country. By using the Service, you consent to such transfers, which are necessary to provide the Service. We implement appropriate safeguards, including:
- Standard Contractual Clauses (SCC) for GDPR-compliant transfers.
- Data Processing Agreements (DPA) with service providers.
- Encryption and technical security measures.
8. Data Retention
We retain your personal data only as long as necessary:
- Account data (email) – retained while your account is active and for 30 days after deletion, then anonymised.
- Usage and analytics data – typically retained for 13 months by Google Analytics, then automatically deleted.
- Support communications – retained for 2 years to handle disputes and improve support.
- Crash reports and diagnostic data – retained for 30 days for troubleshooting, then deleted.
You may request deletion of your account data at any time (see Your Rights, Section 10).
9. Security of Data
We implement industry-standard technical and organisational security measures to protect your information against unauthorised access, alteration, disclosure, or destruction:
- HTTPS encryption for all website communications.
- Secure authentication (password hashing with salting).
- Regular security assessments and vulnerability testing.
- Access controls restricting data to authorised personnel.
- Secure deletion practices for archived data.
Important: No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You use the Service at your own risk.
10. Your Rights and Data Subject Requests
Depending on your jurisdiction, you may have the following rights:
10.1 GDPR Rights (EU/EEA Residents)
- Right of Access – request a copy of your personal data.
- Right to Rectification – request correction of inaccurate data.
- Right to Erasure ("Right to be Forgotten") – request deletion of your data (subject to exceptions).
- Right to Restrict Processing – request limitation of how we use your data.
- Right to Data Portability – receive your data in a structured, portable format.
- Right to Object – object to processing for specific purposes, including automated decision-making.
- Right to Withdraw Consent – withdraw consent for analytics and tracking at any time.
- Right to Lodge a Complaint – file a complaint with your local data protection authority.
10.2 CCPA Rights (California Residents)
- Right to Know – request what personal information we collect, use, and share.
- Right to Delete – request deletion of your personal information (with exceptions).
- Right to Opt-Out – opt out of the sale or sharing of personal information. (Note: We do not sell your personal information.)
- Right to Correct – request correction of inaccurate information.
- Right to Non-Discrimination – no discrimination for exercising your CCPA rights.
10.3 COPPA Compliance (Children's Accounts – Ages 13–17)
For users under 18, we offer parental controls and limited data collection. Parents/guardians may:
- Request access to their child's personal information.
- Request deletion of the child's account and data.
- Opt the child out of analytics tracking.
10.4 How to Submit Requests
To exercise any of these rights, contact us with:
- Your name and account email address.
- A clear description of your request.
- Verification of identity (last 4 digits of IDFA/AAID, or other identifier for security).
We will respond within 30 days (GDPR/CCPA timeframes) or as otherwise required by law. We may request additional information to verify your identity.
11. Children's Privacy (COPPA Compliance)
CardsClan complies with the Children's Online Privacy Protection Act (COPPA) and other applicable children's privacy laws.
- Age Requirement – the Service is intended for ages 13+. Users under 13 should not create accounts without parental consent.
- Limited Data Collection – we collect minimal personal information from younger users (email only with parental verification).
- No Third-Party Advertising – we do not use behavioural advertising targeted at children.
- Parental Access – parents/guardians can request access, correction, or deletion of their child's data.
- No Undisclosed Collection – analytics is disclosed in this policy; users/parents can opt out.
12. Disclosure of Data
We may disclose your personal information if required or permitted by law:
- Legal Obligations – to comply with court orders, subpoenas, or government investigations.
- Rights and Safety – to protect and defend our rights, property, and the personal safety of users and the public.
- Fraud and Abuse Prevention – to detect, prevent, and investigate wrongdoing, cheating, or violations of our terms.
- Legal Liability – to protect against legal liability and enforce our agreements.
- Business Transfers – in connection with a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred. We will notify you of any such change and any choices you may have.
13. Third-Party Links
Our Service may contain links to third-party websites and services (e.g., Sun-Ent.com, Instagram, social media platforms). We are not responsible for the privacy practices, content, or security of these external sites. We encourage you to review their privacy policies before providing any information. Your use of third-party sites is governed by their terms and policies, not ours.
14. California Privacy Rights (CCPA/CPRA Summary)
If you are a California resident, you have the right to:
- Know what personal information is collected, used, and shared.
- Delete personal information collected from you.
- Opt-out of the sale or sharing of personal information (we do not sell your data).
- Correct inaccurate information.
- Receive equal service and pricing for exercising your rights.
To submit a CCPA request, email us at info@sun-ent.com with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days.
15. EU Data Subject Rights (GDPR Summary)
If you are located in the EU/EEA, you have the right to access, rectify, erase, restrict, or port your personal data. You can also object to processing and withdraw consent. To exercise these rights or file a complaint with a supervisory authority, contact us or your local data protection authority.
16. iOS and Android Privacy Practices
iOS App (iOS Privacy Manifest):
- The app requests permission for access to your device's Advertising ID (IDFA) for analytics.
- You can revoke this permission in Settings → Privacy → Tracking.
Android App (Google Play Privacy Policy):
- The app uses Google Advertising ID (AAID) for anonymous analytics.
- You can reset or disable tracking via Settings → Google → Manage your Google Account → Data & Privacy.
17. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you by:
- Updating the "Last updated" date at the top of this page.
- Posting the updated policy on this page.
- Sending an email notification for significant changes (e.g., new processing, new third parties).
Your continued use of the Service after changes become effective constitutes your acceptance of the updated Privacy Policy. We recommend reviewing this policy periodically for any changes.
18. Contact Us
If you have questions, concerns, or wish to exercise your data rights, please contact us:
- Email: info@sun-ent.com
- Website: sun-ent.com
- Social Media: Instagram (@CardsClan)
Data Protection Officer / Privacy Inquiries: For GDPR, CCPA, or privacy-related requests, please email info@sun-ent.com with the subject line "Privacy Request" or "GDPR Request".
19. Policy Versions
Originally effective: November 25, 2018
Last updated: August 14, 2026
Applies to: CardsClan website (cardsclan.com) and mobile applications (iOS & Android)