Privacy Policy
This Privacy Policy outlines how Lemon Crate Studio LLC collects, uses, and protects your personal information when you visit our website and use our services.
Privacy Policy
Last Updated: February 13, 2026
This Privacy Policy describes how Lemon Crate Studio LLC (“we”, “us”, or “our”) collects, uses, and discloses information about you when you use our website (https://cardandpuzzle.com) and our mobile applications (collectively, the “Services”).
We are the Data Controller for your information.
1. Information We Collect
We collect information to provide a seamless gaming experience across web and mobile. We categorize data collection by the source:
A. Information You Provide to Us
- Contact Information: If you use our contact form or email us, we collect your name, email address, and message content.
- Voluntary Feedback: Any game reviews or bug reports you submit.
B. Information Automatically Collected (Web & Mobile)
| Data Category | Specific Data Points | Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Game State | Game progress, settings, and preferences. | Strictly Necessary: To save your progress locally on your device so you can resume playing. Game save data is stored locally on your device unless you explicitly use features that require server storage (such as accounts, leaderboards, or multiplayer features). | Performance of Contract |
| Web Analytics | Pages visited, time spent, clicks, referring URL. | To understand how users navigate our website. | Consent (or Legitimate Interest where allowed) |
| Mobile Device Data | Device Model, OS Version, Carrier, Language. | To ensure the game runs without crashing on your specific phone. | Legitimate Interest |
| Identifiers | IP Address, Advertising ID (IDFA/GAID), Cookies. | To deliver personalized ads and prevent fraud. | Consent |
2. Legal Bases for Processing (EEA/UK)
Where required by law, we rely on the following legal bases to process your personal data:
- Consent — for personalized advertising, analytics cookies, and advertising identifiers. You can withdraw consent at any time via the “Consent Preferences” link on our website or “Manage Consent” in our mobile apps.
- Legitimate Interest — for security (e.g., Cloudflare DDoS protection), crash reporting (e.g., Crashlytics), and basic device diagnostics needed to ensure game compatibility.
- Performance of Contract — to provide core game functionality such as saving your progress locally on your device.
3. Third-Party Data Processors
We do not sell your personal data. We share data with trusted third-party service providers to operate our business.
A. Website Services (Web Only)
These services operate when you visit cardandpuzzle.com.
- Google Funding Choices: Manages your consent preferences and cookie choices.
- Google AdSense: Displays advertisements on the website. Uses cookies to personalize ads.
- PostHog: Our primary analytics tool. Analyzes user behavior and improves website performance.
- Formspark: Processes our contact form submissions.
- Cloudflare: A Content Delivery Network (CDN) that secures our site and speeds up loading. (Processes IP addresses for security).
- Google Ads (gtag.js): Tracks ad conversions.
B. Mobile & Game Services (App & WebGL)
These services operate when you play the game on mobile or in the browser.
- Google Analytics for Firebase: Analyzes user engagement, retention, and in-game behavior on mobile devices.
- Google AdMob / Unity Ads / AppLovin: Mobile ad networks that may access your Advertising ID to show rewarded videos or interstitials. On mobile devices, consent for personalized advertising may be managed through the in-app consent dialog and your device privacy settings.
- GameAnalytics / ByteBrew: Game-specific analytics to track difficulty curves (e.g., “How many players fail Level 5?”).
- Crashlytics (Firebase): Reports app crashes so we can fix bugs.
4. How We Process Your Information
We process data for the following specific purposes:
- To Provide the Service: Storing your game progress locally so you don’t lose progress.
- To Improve the Game: Using PostHog, Firebase, and GameAnalytics to see where players get stuck.
- To Fund the Service: Using AdSense (Web) and AdMob (Mobile) to generate revenue via ads.
- Security: Using Cloudflare to block bots and DDoS attacks.
5. International Data Transfers
Our servers and third-party service providers (like Google, PostHog, and Cloudflare) are primarily located in the United States. If you are accessing our Services from the EEA or UK, please note that your data is transferred to the US. We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (where applicable for certified providers like Google) to safeguard these transfers.
6. Your Rights (GDPR, UK & Global)
If you are located in the EEA, UK, or Switzerland, you have the following rights:
- Right to Access: Request a copy of your personal data.
- Right to Rectification: Correct inaccurate data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your data (e.g., reset game stats).
- Right to Withdraw Consent: You can withdraw your consent for ads/analytics at any time via the “Consent Preferences” link (Web) or “Manage Consent” (Mobile).
- Right to Restrict Processing: Ask us to pause processing your data.
- Right to Object: Object to processing based on “legitimate interest” or direct marketing.
- Right to Portability: Request your data in a structured, machine-readable format.
- Right to Complain: Lodge a complaint with your local Data Protection Authority (DPA).
To exercise these rights, email [email protected].
7. U.S. State Privacy Rights (California, Virginia, Colorado, etc.)
Global Privacy Control (GPC)
We honor the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, we will automatically treat it as a request to opt-out of the “sale/sharing” of your personal information (turning off tracking cookies/ads).
Do Not Track Signals
Our Services do not respond to traditional “Do Not Track” browser signals. However, we honor Global Privacy Control (GPC) signals where required by law.
Your CCPA/CPRA Rights regarding “Sale” vs. “Sharing”
We do not sell personal information for monetary value (we don’t sell your email list). However, allowing ad networks (like Google or Unity) to place cookies or access your Advertising ID to show personalized ads may be considered “sharing” or a “sale” under California law.
- Right to Opt-Out of Sale/Sharing: You can opt-out of this ad targeting at any time.
- Web: Click the “Do Not Sell or Share My Personal Information” link in the website footer.
- Mobile: Go to Settings > “Manage Consent” or “Do Not Sell My Info”.
- Right to Know & Delete: You may request to know what data we hold and ask for it to be deleted.
- Response Timeline: We will respond to verified requests within 45 days.
8. Automated Decision-Making
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
9. Data Retention
We keep your information only as long as necessary:
- Game Save Data (Local): Stored on your device indefinitely until you clear your browser cache or uninstall the app.
- Analytics Data: Retained by our partners (Google, PostHog) for a period of 14 to 26 months before being automatically deleted or anonymized.
- Contact Form Data: Retained for as long as necessary to resolve your support inquiry, then archived or deleted.
10. Children’s Privacy (COPPA)
Our Services are not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you are a parent and believe we have collected data from a child, contact us immediately at [email protected], and we will delete it.
11. Data Security
We implement reasonable security measures, including HTTPS encryption for web traffic and secure storage for game data. However, no method of transmission over the internet is 100% secure.
12. Changes to This Policy
We may update this privacy notice from time to time. The updated version will be indicated by an updated “Revised” date at the top of this policy. If we make material changes, we may notify you via a prominent notice on our Service.
13. Contact Us
If you have questions about this policy, please contact us:
Lemon Crate Studio LLC 2108 N ST STE N, Sacramento, CA 95816, USA Email: [email protected]