Privacy Policy — Mima Party
Effective date: 18 May 2026 Last updated: 19 June 2026
---
1. Who We Are
Mima Party is a party game application available on the web, Apple App Store, and Google Play Store.
Data Controller: Milosevic Zlatan Romania Email: mimaparty.app@gmail.com
As the data controller, we determine how and why your personal data is processed when you use the App. This Privacy Policy applies to all users worldwide, with particular attention to users in the European Union (EU) and European Economic Area (EEA), where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies directly and is binding on us as a Romanian operator.
---
2. What This Policy Covers
This policy describes:
- What personal data we collect and how we collect it
- The specific legal basis for each category of processing under the GDPR
- How we use, store, and share your data
- How long we keep your data
- Your rights as a data subject and how to exercise them
- How to contact us or the data protection supervisory authority if you have concerns
This policy does not govern data processed independently by third-party services you access through the App. Their own privacy policies govern their data practices.
---
3. Data We Collect and Legal Basis
3.1 Account and Identity Data
When you create an account or sign in via email, Google Sign-In, or Apple Sign-In, we collect and store:
- Email address
- Display name (from your profile or auth provider)
- Internal user identifier (a random UUID generated by our system)
- Authentication provider type (email, Google, or Apple)
- Avatar URL, if provided by the sign-in provider
We do not receive your Apple ID or Google account password. Sign-in providers authenticate you independently and pass only a verified identity token to us.
Legal basis: Article 6(1)(b) GDPR — processing is necessary to perform the contract for providing the App and your account. Without this data, account creation and authentication are not possible.
3.2 Profile and Preference Data
Once your account exists, we store:
- Language preference (locale, e.g. "ro" or "en")
- Country code and market code (used to serve localised content and region-appropriate pricing)
- Content language preference (the language in which game cards are displayed)
- Premium or subscription status and expiry date
- Identifiers of purchased deck packs, to grant and restore access to paid content
- Aggregate gameplay statistics: total games played, games won, and cumulative score
- Onboarding completion timestamp, to skip the first-run wizard on subsequent launches
Legal basis: Article 6(1)(b) GDPR — necessary to fulfil the service contract by delivering localised content, maintaining your purchased entitlements, and personalising gameplay experience.
3.3 Game Data
Mima Party is designed as a local, same-room party game. Active gameplay state and gameplay history are stored primarily on your device, not continuously synced to our servers.
The App may process locally on your device:
- Game mode, round count, turn duration, selected deck packs, and difficulty
- Player display labels entered for the game session
- Team assignment, per-game score, turn results, and local gameplay history
- The card prompts shown during play
- Unlocked premium deck prompt content cached on the device after purchase validation, so purchased packs can continue to work when the device is temporarily offline
This local information is used to run the game, show history on that device, and make already-unlocked packs available offline. It is removed from that device when you use the in-app account deletion flow on the same device or sign out, and it can also be removed by deleting the App or clearing local app data through your operating system. Premium content is initially delivered only after server-side entitlement validation; the local cache is a convenience copy and is refreshed when the App detects a newer catalog version from Supabase.
We may store limited pseudonymous analytics events on our servers, such as game_created, game_started, or game_completed, together with high-level properties such as game mode and locale. These analytics events do not include card text, player labels, team names, or free-text gameplay content.
Legacy server-side gameplay tables may exist for earlier versions and administrative cleanup, but the current App does not rely on them for active gameplay history.
Legal basis: Article 6(1)(b) GDPR for local processing necessary to provide gameplay. For pseudonymous analytics events, Article 6(1)(f) GDPR — legitimate interest in understanding and improving App usage, with limited and proportionate data.
3.4 Purchase and Transaction Data
Digital purchases are processed by Apple App Store, Google Play, or Stripe Checkout on the web. We do not receive or store your payment card number, billing address, or financial account details.
From Apple, Google, Stripe, and RevenueCat (our purchase validation and entitlement provider), we receive and store while your account is active:
- Transaction identifier and original transaction identifier
- Product identifier purchased (e.g. a specific deck pack SKU)
- Purchase date and, where applicable, expiry date
- Platform (iOS, Android, or web)
- Purchase and entitlement status (active, expired, refunded)
- RevenueCat app user identifier and entitlement status
- Receipt validation and entitlement metadata returned by RevenueCat, Apple, Google, or Stripe where necessary to validate purchases, prevent fraud, restore access, handle refunds, and resolve disputes
Legal basis: Article 6(1)(b) GDPR — necessary to validate purchases, grant access to paid content, and restore or sync purchases across devices. To the extent we must keep separate accounting, fraud-prevention, dispute, or tax records outside the active entitlement database, the legal basis is Article 6(1)(c) GDPR and the retention periods required by applicable Romanian and EU law. Store operators, Stripe/payment processors, and RevenueCat may retain their own transaction records under their own legal obligations and policies.
3.5 Usage and Analytics Data
We record pseudonymised usage events in our own Supabase database to understand how the App is used and to improve it. Events recorded in Supabase include:
- App open
- Account sign-in and sign-up
- Game created, game started, game completed, rematch initiated
- Purchase flow completed
- Push notification permission granted or denied
- Advertising events (ad impression, rewarded ad completed) — only in ad-enabled builds
Each Supabase event record contains the event name, contextual properties (for example game mode, locale, or error code — never free-text gameplay content you enter), a pseudonymous user identifier (UUID), and a timestamp. Analytics data is not shared with advertising networks or data brokers.
In the web app (PWA), Vercel Web Analytics is loaded only after you accept optional analytics in the cookie consent banner. When enabled, it runs in a cookieless configuration and may receive page view and request metadata such as URL, referrer, user-agent/browser information, timestamp, and coarse request information. We do not use Vercel Web Analytics for advertising profiling. Static marketing and legal HTML pages do not load client-side analytics scripts in the current build.
Legal basis: Article 6(1)(a) GDPR for optional Vercel Web Analytics on web (consent). Article 6(1)(f) GDPR for pseudonymised Supabase product analytics after sign-in — legitimate interest in understanding product usage, with limited and proportionate data; you can object (see Section 8).
3.6 Crash and Diagnostic Data
When the App encounters an error, or when you submit an in-app bug report, we may collect:
- Error type and code-level stack trace (limited to App code paths)
- Device category (e.g. smartphone, tablet) and operating system version
- App version number
- Approximate screen name or action sequence at the time of the error
- The bug report message you choose to submit
- Recent technical logs attached automatically to help diagnose the issue
Automatic crash records are intended to contain technical information only. If you submit a bug report, the message you type and recent technical logs may contain information you choose to include or information useful for diagnosing the issue. Please do not include passwords, payment details, health information, or other sensitive personal data in bug reports. Diagnostic records are linked to your user identifier only to help reproduce account-specific issues.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in diagnosing and fixing software defects. Processing is limited to technical data strictly necessary for this purpose.
3.7 Push Notification Token
If you grant push notification permission, your device generates an Expo Push Token. We store this token, linked to your account, solely to deliver notifications you have opted into. Push tokens are not passed to any advertising or analytics third parties.
Legal basis: Article 6(1)(a) GDPR — consent. You can withdraw consent at any time by disabling notifications in your device settings (iOS: Settings → Notifications → Mima Party; Android: Settings → Apps → Mima Party → Notifications). Withdrawal does not affect the lawfulness of processing before withdrawal.
3.8 Advertising Identifiers (Conditional — Ad-Enabled Builds Only)
This section applies only when you use a version of the App with advertising enabled. In the standard release, advertising and associated tracking are disabled. Check the App Settings screen to see which version you have installed.
When advertising is active, Google AdMob may process on our behalf:
- Device advertising identifier (IDFA on iOS; Google Advertising ID on Android)
- Coarse location derived from your IP address (country or region level only; precise location is never accessed)
- Ad interaction data: impressions, clicks, rewarded video completions
On iOS 14.5 and later, accessing the advertising identifier requires your explicit consent via Apple's App Tracking Transparency (ATT) system prompt before any identifier is read. If you decline, only non-personalised ads are served. On Android, you may opt out via device settings: Settings → Google → Ads.
Legal basis: Article 6(1)(a) GDPR — consent, given via the ATT prompt on iOS or available to withdraw in Android device settings. Withdrawal does not affect prior lawful processing.
3.9 Web Cookies and Local Storage
The native iOS and Android apps do not use browser cookies. The web version may use browser storage mechanisms such as localStorage, IndexedDB or Cache Storage, and service worker cache for strictly necessary functions: authentication, language/theme preferences, catalog cache, premium offline cache for already-unlocked content, and PWA loading.
Mima Party does not set advertising cookies, social media tracking cookies, cross-site marketing cookies, or third-party advertising pixels. The web app shows a consent banner before enabling optional Vercel Web Analytics; strictly necessary storage (authentication, preferences, catalog cache, PWA) is always active. Static marketing and legal pages do not load client-side analytics in the current build.
More detail is available at https://mimaparty.vercel.app/cookies.
Legal basis: Article 6(1)(b) GDPR for storage needed to provide authentication, preferences, catalog access, and PWA functionality. Where any future non-essential storage depends on consent, the legal basis will be Article 6(1)(a) GDPR.
---
4. How We Use Your Data
We use the data described in Section 3 to:
- Provide the service: authenticate you, manage your account, run local gameplay, maintain your profile and statistics, grant access to purchased content, and restore purchases on new devices
- Improve the App: analyse pseudonymous usage patterns to prioritise features, fix defects, and improve game balance
- Communicate with you: deliver push notifications you have opted into; respond to support and privacy requests
- Ensure security and prevent abuse: detect fraudulent transactions, prevent cheating, and protect account security
- Comply with legal obligations: retain transaction records as required by Romanian fiscal and accounting law; respond to lawful requests from competent authorities
We do not:
- Sell your personal data to any third party
- Share your data with third parties for their own direct marketing or advertising
- Carry out automated profiling that produces legal or similarly significant effects on you
- Serve behavioural advertising without your prior explicit consent
---
5. Who We Share Your Data With
We share personal data only with the following service providers, under data processing agreements, for the limited purposes described. We do not sell data.
Supabase Inc. (United States) — cloud database, authentication, and storage. Receives account, profile, game, analytics, purchase, and crash data. supabase.com/privacy
RevenueCat Inc. (United States) — purchase validation and entitlement management. Receives user identifier, product identifiers, transaction data, and purchase status. revenuecat.com/privacy
Stripe Payments Europe / Stripe, Inc. — web checkout and payment processing. Receives web checkout, payment, billing, transaction, fraud-prevention, and dispute data for purchases made on the web. stripe.com/privacy
Apple Inc. (United States) — iOS Sign in with Apple authentication and App Store payment processing. Receives an authentication token and optionally a private relay email address. apple.com/legal/privacy
Google LLC (United States) — Google Sign-In authentication, Google Play payment processing, and Google AdMob advertising (ad-enabled builds only). Receives authentication token, transaction data, and advertising identifiers for ad-enabled builds. policies.google.com/privacy
Expo Technologies Inc. (United States) — push notification delivery infrastructure. Receives push tokens and notification payload content. expo.dev/privacy
Vercel Inc. (United States / global infrastructure) — web hosting, CDN delivery, security logs, static file delivery, and Web Analytics for the web version. Receives technical request metadata and page view analytics such as URL, referrer, user-agent/browser information, timestamp, and coarse request information. vercel.com/legal/privacy-policy
We do not use advertising data brokers, third-party marketing analytics platforms, or social media tracking pixels.
---
6. International Data Transfers
Some providers we use, including Supabase, RevenueCat, Stripe, Expo, Vercel, Apple, and Google, may process data outside the EU/EEA, including in the United States. The United States does not benefit from a blanket EU adequacy decision for all organisations and all processing.
Where a provider participates in the EU-US Data Privacy Framework and the relevant processing is covered by that certification, we may rely on the European Commission adequacy decision for that certified provider. Where that does not apply, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021) and supplementary safeguards where required, as the lawful transfer mechanism under Article 46 GDPR.
You may request a copy of the applicable standard contractual clauses or further information about our transfer safeguards by contacting mimaparty.app@gmail.com.
---
7. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.
- Account and profile data: retained while your account is active; deleted within 30 days of a valid deletion request
- Local game session history: retained on your device until you delete it, delete the App, clear local app data, or use the in-app account deletion flow on that device
- Legacy server-side game records, if any: deleted within 30 days of account deletion
- Server-side purchase entitlement records: retained while your account is active and deleted from the Mima Party entitlement database within 30 days of account deletion, unless a longer retention period is legally required for a specific dispute, fraud-prevention, accounting, or tax reason
- Store and payment transaction records: retained by Apple App Store, Google Play, Stripe, RevenueCat, and payment processors according to their own legal obligations and retention policies; Mima Party cannot delete those third-party records on your behalf
- Usage analytics events: retained for up to 90 days, after which they are deleted or aggregated
- Crash, diagnostic, and in-app bug report data: retained for up to 60 days, or shorter where reports are resolved and no longer needed, unless a longer period is required for support, security, fraud prevention, legal claims, or legal obligations
- Push notification tokens: retained while your account is active and notifications are enabled; deleted on account deletion or device-side token revocation
- Advertising identifiers: not retained by us; processed transiently by Google AdMob only at the moment of ad serving
- Web cookies/local storage: strictly necessary browser storage is retained until you clear site data, sign out, delete your account on that device, or the browser evicts cache; service worker and static asset cache may persist until browser cleanup or a new deployment invalidates it
---
8. Your Rights Under the GDPR
You may exercise any of the following rights using the in-app features described, or by contacting mimaparty.app@gmail.com. We will respond within one calendar month, extendable by two months where requests are complex (with prior notification).
Right of access (Article 15): Request confirmation and a copy of personal data we hold. Use Settings → Account → Export data for immediate self-service access.
Right to rectification (Article 16): Request correction of inaccurate or incomplete data. Update your display name, language, and country directly in Settings.
Right to erasure — "right to be forgotten" (Article 17): Request deletion of your personal data. Delete your account directly at Settings → Account → Delete account. Account, profile, and game data is deleted within 30 days. Some transaction records are retained as required by law (see Section 7).
Right to restriction of processing (Article 18): Request that we restrict processing in specific circumstances, such as while accuracy of contested data is being verified or pending resolution of an objection.
Right to data portability (Article 20): Receive a copy of personal data you have provided in a structured, machine-readable format. Use the in-app export function (Settings → Account). The export includes your profile, purchases, analytics events linked to your account, and bug reports you submitted.
Right to object (Article 21): Object, on grounds relating to your particular situation, to processing based on legitimate interest (Sections 3.5 and 3.6). If you object, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for legal claims.
Right to withdraw consent (Article 7(3)): Where processing is based on consent (push notifications — Section 3.7; advertising identifiers — Section 3.8), withdraw consent at any time through your device settings. Withdrawal does not affect the lawfulness of prior processing.
Right not to be subject to automated decision-making (Article 22): We do not use automated processing, including profiling, to make decisions that produce legal or similarly significant effects on you.
Right to lodge a complaint: You may lodge a complaint with the competent data protection supervisory authority:
- Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
- Bulevardul General Gheorghe Magheru 28-30, Sector 1, Bucuresti 010336, Romania
- anspdcp.ro / anspdcp@dataprotection.ro
If you reside in another EU or EEA member state, you may also contact the supervisory authority of your country of residence or habitual workplace.
---
9. Children's Privacy
Store age ratings are content ratings and are separate from account eligibility. Account features are intended only for users who meet the minimum age required to consent to online services in their country. You must be at least 13 years old in all cases. If you are in the EU, EEA, or United Kingdom, you must be at least 16 years old to create an account unless your national law permits a lower age or a parent/legal guardian validly authorises your use.
When you create an account, the app asks you to confirm that you meet these age requirements and accept the Terms and Privacy Policy before continuing. We do not collect date of birth. We do not knowingly collect personal data from children under the age of 13. If we become aware that a child under 13 has provided personal data without appropriate consent, we will delete that data promptly. Contact us at mimaparty.app@gmail.com if you believe this has occurred.
---
10. Security
We implement the following technical and organisational measures:
- All data in transit is encrypted using TLS 1.2 or higher; HTTPS is enforced on all endpoints
- Supabase enforces Row-Level Security (RLS) policies on every database table, ensuring each user can only access their own data
- Authentication credentials are managed by Supabase Auth and by sign-in providers; we never store or handle raw passwords
- Access to the production database is restricted to authorised personnel only, with access logging enabled
- Purchase receipt validation is performed server-side via RevenueCat, Stripe webhooks, and Supabase Edge Functions; payment card data is never handled by us
No security measure provides absolute guarantees. In the event of a personal data breach that risks your rights and freedoms, we will notify the ANSPDCP within 72 hours and communicate with affected users where required by Article 34 GDPR.
---
11. Changes to This Policy
We will update this policy when our data practices change, when new features involving personal data are introduced, or when legal requirements change. The "Last updated" date at the top reflects the most recent revision.
For material changes — such as a new purpose for processing or a new category of data — we will provide in-app notification before the change takes effect. Continued use of the App after a revised policy's effective date constitutes your acknowledgement of the changes. If you do not accept updated terms, you may stop using the App and delete your account before the new policy takes effect.
---
12. Contact
For privacy questions, data subject rights requests, or complaints:
Email: mimaparty.app@gmail.com Response time: We aim to respond within 30 days.
You can also delete your account directly in the App: Settings → Account → Delete account.
Website: https://mimaparty.vercel.app