Privacy Policy
Last updated:
1. Data Controller
Party Madness is operated by Johannes Hurmerinta / Mitrox (“we”, “us”, “our”). For questions about this policy or your personal data, contact us at johannes.hurmerinta@mitrox.io.
2. Data We Collect
We collect only what is necessary to provide and improve Party Madness:
- Account data — email address and display name if you create an account. Guest play requires no account.
- Device & usage data — anonymised device identifiers, app version, and session events (screens visited, features used) collected via PostHog for analytics.
- Purchase data — if you buy gems or cosmetics in-app, transaction details are processed by RevenueCat and the relevant app store (Apple / Google). We do not store raw payment card data.
- Game session data — room codes, answers, and vote data needed to run live sessions. Room data is deleted shortly after the session ends.
3. Legal Basis for Processing (GDPR)
Where the General Data Protection Regulation (EU) 2016/679 (“GDPR”) applies, we rely on the following legal bases:
- Performance of a contract(Art. 6(1)(b)) — to create and manage your account and to run game sessions you participate in.
- Legitimate interests(Art. 6(1)(f)) — to analyse aggregated, anonymised usage to improve the app and prevent abuse.
- Consent(Art. 6(1)(a)) — for any optional communications (e.g. update newsletters) where we ask for explicit opt-in.
- Legal obligation(Art. 6(1)(c)) — where required by applicable law.
4. How We Use Your Data
- Operate and deliver Party Madness game sessions in real time.
- Manage your account, cosmetic inventory, and purchase history.
- Analyse aggregated usage patterns to improve game modes and performance.
- Respond to support enquiries you submit to us.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal data to third parties, and we do not use it for targeted advertising.
5. Third-Party Processors
We share data with the following sub-processors, each bound by appropriate Data Processing Agreements:
- Supabase — database and authentication. Data stored in the EU (Ireland region).
- RevenueCat — in-app purchase management and subscription tracking.
- PostHog — product analytics. Configured for anonymised, aggregate telemetry only.
- Apple App Store / Google Play — app distribution and payment processing, governed by their own privacy policies.
6. International Data Transfers
Some of our processors are based outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses (SCCs) approved by the European Commission — in accordance with GDPR Chapter V.
7. Data Retention
- Account data — retained for as long as your account is active. Deleted within 30 days of an account deletion request.
- Game session data — ephemeral; purged within 24 hours of session end.
- Anonymised analytics — retained indefinitely in aggregate form (no personal identifiers).
- Purchase records — retained for 7 years in accordance with financial record-keeping obligations.
8. Your Rights (GDPR)
If you are located in the EEA, UK, or Switzerland, you have the following rights under applicable data protection law:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure— request deletion of your data (“right to be forgotten”), subject to legal retention obligations.
- Restriction — ask us to restrict processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email johannes.hurmerinta@mitrox.io. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g. the Finnish Data Protection Ombudsman or the Irish Data Protection Commission).
9. Children
Party Madness is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.
10. Security
We implement industry-standard technical and organisational measures to protect your data — including encryption in transit (TLS), access controls, and routine security reviews. No method of transmission over the internet is 100% secure; we will notify you of any breach as required by applicable law.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via an in-app notice or email (if you have an account). The “Last updated” date at the top always reflects the most recent revision.
12. Contact
For any privacy-related enquiries: johannes.hurmerinta@mitrox.io