Arrow Shift: Tap Out Puzzle (also "we", "us" or "our") is a mobile and browser gaming platform attached to Bagus dedicated to bringing games that inspire players' dreams around the world. This Privacy Policy explains what personal data we will collect from you, how we process, use, store and protect such personal data, and whether we will disclose your personal data to anyone else. We will also inform herein you of your rights to update, manage, export and delete your personal data.
This Privacy Policy shall apply to games and services (hereinafter collectively referred to as the "Services") provided by Bagus, including but not limited to Bagus (SINGAPORE) PTE LTD, Bagus GAMES HONGKONG LIMITED, Yousu HongKong Limited and their affiliates.
When you click to agree to this Privacy Policy, you accept our rules and policies regarding your personal data and you expressly grant us the rights to collect, process, use, share and store your personal data, as described in this Privacy Policy.
You acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, you must not use the Services. If you change your mind in the future, you may withdraw your grant to us regarding your personal data in accordance with this Privacy Policy.
This Privacy Policy forms a part of our User Agreement, which is linked below:hustranthaonhung@gmail.com. By reading the full version our User Agreement, you may learn more about the processing of your personal data.
If you have any comments, questions or complaints regarding the processing of your personal data, please contact us. Our contact information is as follows:
E-mail: hustranthaonhung@gmail.com
Address: 29 Media Circle, #09-01, North Tower ALICE @ Mediapolis, Singapore 138565
DPO’s Email: mailto:hustranthaonhung@gmail.com
What Data We Collect
1.1 Data you provide to us
1.1.1 Data you provide when sign up
You don’t have to create an account to use some of our service features, such as searching and viewing Carrot Rampage website. To sign up for a Carrot Rampage account, you are required to provide us with account information and contact information, as follows:
Account information, including your account name and account password (which will be encrypted); and
Contact information, namely your email address, which will be used to reset the password.
All your data is protected by Carrot Rampage account authorization. Therefore, you must keep your password safe and do not disclose it to anyone else in any way.
In addition, when you set up your profile, you may voluntarily elect to provide us your personal data, including head portrait, name, gender, date of birth, living location, national code and extra contact information.
If you are located in certain areas, as required by applicable laws and regulations, you may need to complete the identification verification before using and enjoying the Services. Upon your consent or by your voluntary provision, we will collect your real ID information (including name, ID number, photo, etc.).
1.1.2 Data you provide during using services
During using our services, you may be required to provide certain personal data as needed. To be specific, the scenarios include:
Social functions: To accommodate you with voice chatting, interaction during live broadcasting and other functions, we will access your microphone and camera upon your authorization.
Game Adaptation and Update: To make the best adaptation of our Game to your mobile device, we need to know the network environment and the storage of your device. And to provide an updated version of our Game to you, we need to have access to the storage of your device, which is inevitable.
Survey: To understand the performance of our Services and therefore make improvement, we may conduct surveys about our Services. During such survey, we may ask for your basic information (including age, role name and game zone) and your preference information (such as your preferences, interests, hobbies, your favorite games, and general demographic information or other related information). For the supplementary account information and information we collect during survey, since they are not essential or mandatory, it’s your right to refuse to provide such information.
1.2 Data we automatically collect
When you use the Services, we may automatically collect certain data about your devices, including your device information (such as the operating system and its version, hardware and software versions, processing capabilities, manufacturer and model, language and other regional settings, unique device IDs and similar unique identifiers, screen resolution, other device attributes or similar settings), network type, and application version number.
In addition, we may automatically collect certain data about your in‑game behavior. We will collect your game information, including role name, role level and scores. Meanwhile, we will collect the information you provide or generate when you communicate with others in the Services(“communication information”), including your chat log, your comments in the game, and the content you post on the forum. You acknowledge and agree that information generated within our Services should not be considered private and communications within our Services may be viewed/heard by other users. Please avoid revealing any personally identifiable or sensitive information during such communications. Other related information collected by us includes the monitoring data of availability and quality of the Services, loading errors and bugs. We also collect data by cookies and similar technologies, the detailed information please refer to our COOKIES POLICY.
1.3 Data from third parties
We only collect limited data from third parties when you use the services through their products or platforms. Such third parties include but are not limited to Apple, Facebook, Google, Twitter, Yahoo and Windows. To be specific:We only collect limited data from third parties (including Facebook and Google) when you use the Services through their products or platforms. We may collect third parties account open‑ID and authentication status when you login via third parties account provided that you have expressly agreed to the use of third parties account within the Services. In addition, we may collect
.
2. How We Use Your Personal Data
We will use your personal data in the following ways and in accordance with the following legal bases:
To create your personal account, to allow you to log‑in to the Services, and to provide the Services to you, we will use the account information and the contact information you provide when you sign up, as well as your data from third parties. We use this information with your consent to the Privacy Policy.
To provide customized services to you, we may use the information you provide when you set up your profile. We use this information with your consent to this Privacy Policy.
To conduct surveys within the Services, we may process your account information and device information. If you have agreed and confirmed to receive push notifications, we may occasionally to send you e‑mails about our promotions, sales or any other information you may be interested in. You can opt out of such email according to the instructions in such email. We use this information with your consent to this Privacy Policy.
To support the transaction process, and to accommodate you with voice chatting, we may process your account information, device information, network environment information, and application version number. We use this information with your consent to this Privacy Policy.
To provide you with payment‑related customer services, especially refunding service, we may need to share your transaction order information to the third‑party payment agencies that help you with the gam‑related payment.
We use device information to provide and improve the Services, so as to allow you to download and install the software on your devices; to record and keep track of requests from you; to detect the user network and device status when you are using the Services; and to correct bugs or errors that occur when you are using the Services. Use of device Information is necessary to perform our contract with you to provide the Services.
To fulfill our legal obligations under the applicable laws, we may process necessary information for the following purposes:
To monitor and protect services against fraud behavior, such as robot access, illegal add‑ons, we may process your account information, device information, network environment information, and game information;
To keep heathy in‑game communication and limit communication against illegal topics and content, we may adopt automatic technologies and process your account information and communication information to detect, filter and block forbidden content in black list;
To protect your account from unauthorized access and protect your transaction from fraud, we may process your account information; and
If you are located in certain areas, according to applicable laws and regulations, in order to protect children personal data, we will collect your real ID information. Your refusal to provide your real‑name ID information may result in a failure to log into the Services.
3. Cookies
We use Cookies to enhance your experience using the Services. Cookies are small files which, when placed on your device, enable us to provide certain features and functionality.
You can control cookies or similar technologies through your browse settings. Please see our COOKIES POLICY for more information regarding the use of cookies and other technologies described in this section, and how to manage or disable them.
How We Protect Your Personal data
4.1 Data security management system
We have implemented data security management system that meets industry‑standard, including organizational processes and technical solutions, to protect your personal data against unauthorized access, modification, copy, or deletion. For example, our network communication is encrypted and protected by HTTPS protocol. We have set up firewalls, WAF (web application firewall) and anti‑DDOS flow cleaning devices at network boundary to detect and defend against web attacks. We have encryption mechanism and strict access control to protect data in database. Besides, we have implemented collaborative security defense system at both network and terminal level to protect the information system and the computing environment.
In addition to the technical solutions, we also implemented information security management system, which is based on ISO27001, to set up policy, process and procedures which regulate employees’ daily information processing activities, such as access, modify, editing, storage, share, transfer and deletion. This system ensures that only authorized personnel can access the protected data, and can be used only in the authorized way. And we also provide training and arrange awareness raising activities about data security and privacy protection, so as to enhance employees' awareness regarding the importance of personal data protection.
4.2 Data security capabilities
For the security of your personal data, we adopt leading security technologies and continuously update our data security capabilities. To be specific, our data security capabilities include but are not limited to application layer encryption, network layer encryption, database encryption, network access monitoring, database access monitoring, host behavior monitoring, terminal behavior monitoring and tracking, and other technologies.
4.3 Personal data protection suggestions
Even with our data security capabilities, the internet is still not an absolutely secure environment. We strongly recommend that you shall at least take the following steps to enhance the security of your account:
Avoiding sending personal data in an unencrypted way; and
Using complex passwords, which should include numbers, alphabet letters, special symbols, and avoid names, birthdays and similar information.
4.4 Response to data security incidents
We have implemented reasonable technical and organizational measures to safeguard your personal data. If unfortunately, any personal data breach or similar security incident happens, we will promptly take responses to control and mitigate the influence of the incident. According to mandatory requirements in applicable laws and regulations, we will timely inform you as needed and share with you the following information:
The nature and possible impact of the incident;
The name and contact details of the data protection officer or other contact point where more information can be obtained;
The measures taken or proposed to be taken by us to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects;
The suggested actions you can take to eliminate or reduce risks; and
The remedial measures for you, where appropriate.
We will promptly inform you of the incident by mail, telephone, push notification, etc. When it is difficult to inform the affected data subjects one by one, we will take a reasonable and effective way to publish the announcement.