- Running merge gameplay and syncing progress
- Managing Accounts, authentication, and settings
- Processing PayPal withdrawals and verification
- Handling support requests and service notices
Bump And Merge Privacy Policy
Last updated: September 8th, 2026
π Definitions
Here is what the recurring terms mean throughout this policy:
- Application β Bump And Merge, the mobile merge puzzle we provide
- Personal Data β any information that could identify you
- Usage Data β information collected automatically as you play, such as merges, session length, and diagnostics
- Device β the phone, tablet, or other hardware running the Application
- Service Provider β a third party that helps us operate the service
- Account β the profile or session used to reach features, progress, and withdrawals
π What We Collect
Automatically gathered
When you open Bump And Merge, our systems automatically record:
- Device Info β model, operating system, WebView, screen size
- Network details β IP address and connection type
- Identifiers β GAID, ANDROID_ID, or platform equivalents
- Usage Data β boards played, merges completed, session length, timestamps
- Diagnostics β crash logs and performance data
With your permission
- Advertising identifiers (GAID on Android, IDFA on iOS)
- Engagement and in-app event signals
- PayPal account email and name, used solely for withdrawals
π― How We Use It
Your Personal Data keeps Bump And Merge working, handles your Account and transactions, sends relevant updates, and improves the experience over time.
- Analyzing usage to refine boards and stability
- Measuring promotions and campaign performance
- Sharing news about related features or offers
- Supporting mergers, acquisitions, or restructuring
π App Permissions
Every permission is disclosed before installation, limited to the stated purpose, and aligned with Google Play Developer Program Policies.
| Permission | Purpose | Data collected |
|---|---|---|
INTERNET | Network access for ads, updates, and gameplay | Network status, transfer statistics |
ACCESS_NETWORK_STATE | Adapt behavior to connection type | Network type and status |
ACCESS_WIFI_STATE | Keep Wi-Fi sessions stable | Wi-Fi status, signal strength |
AD_ID | Advertising identifier for personalization | Resettable device ad ID |
VIBRATE | Haptic feedback when pieces bump and merge | None |
ACCESS_ADSERVICES_TOPICS | Ad interest topic signals | Advertising topic data |
ACCESS_ADSERVICES_ATTRIBUTION | Campaign attribution measurement | Attribution data |
BIND_GET_INSTALL_REFERRER_SERVICE | Identify install source | Install source, campaign parameters |
BIND_APPHUB_SERVICE | Optimize ad delivery via AppHub | Ad parameters, impression data |
ACCESS_ADSERVICES_AD_ID | Comply with modern ad API requirements | Ad service identifiers |
FOREGROUND_SERVICE | Maintain critical functions when backgrounded | None |
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Secure internal broadcast communication | None |
π‘ Analytics & Endpoints
Analytics and game services are delivered through https://dyxa.bumpmerge.com. Payloads handled by the analytics layer are anonymized and are not designed to carry personally identifiable information. The same endpoint supports core gameplay delivery, progress synchronization, stability work, and support tooling.
- Transport Layer Security (TLS) 1.2 or higher on every transmission
- Role-based access controls restricting data to authorized personnel
- Data minimization applied across all processing activities
- Recurring security reviews and vulnerability assessments
- Data Processing Agreements executed with third-party handlers
π£ Third-Party Services & Ad Partners
Advertising is served through AppLovin and its mediated partner network. Only limited categories reach advertising partners.
- Resettable advertising identifiers
- Device model, OS, screen size
- Session frequency and duration
- Ad impressions and clicks
- Non-precise demographics
- Email addresses or phone numbers
- Account credentials
- Detailed merge progress or balances
- User-generated content
- Precise geolocation data
Advertising partner privacy policies
π‘οΈ Data Security
We maintain commercially reasonable physical, administrative, and technical safeguards: encryption of sensitive data in transit, TLS 1.2 or higher, need-to-know access controls, periodic audits, and contractual security obligations for partners. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.
ποΈ Data Retention
Not playing Bump And Merge? After 90 days of inactivity we remove your Personal Data permanently from our systems. Anything retained beyond that is anonymized or aggregated Usage Data that can no longer identify you.
βοΈ Your Rights
Depending on where you live, local law gives you tools to access, correct, delete, or restrict how we use your Personal Data.
GDPR Β· EEA
- Access
- Rectification
- Erasure
- Restrict processing
- Object
CCPA / CPRA Β· CA
- Know
- Delete
- Opt-Out of sale
- Non-Discrimination
VCDPA Β· VA
- Access
- Correct
- Delete
- Portability
- Opt-Out
To exercise any of these, email goldahuyettvu19975@gmail.com and name the right you want to use.
π« Opting Out
- Android: Settings β Google β Ads β βOpt out of Ads Personalizationβ
- iOS: Settings β Privacy β Advertising β βLimit Ad Trackingβ
- Sale of Personal Data: email goldahuyettvu19975@gmail.com with the subject line Do Not Sell
π International Transfers
Personal Data may be transferred to and processed on servers outside your country of residence. Such transfers are protected by TLS 1.2 or higher and, where required, by appropriate contractual safeguards including Standard Contractual Clauses.
π§ Children's Privacy
Bump And Merge is not directed to individuals under the age of thirteen (13), and we do not knowingly collect Personal Data from children under 13. A parent or guardian who believes a child has provided Personal Data should contact goldahuyettvu19975@gmail.com; the data will be deleted promptly once verified.
π Disclosures
- Business transactions β Personal Data may transfer to an acquiring entity, with prior notice where practicable
- Law enforcement β disclosure may follow law, subpoena, court order, or governmental request
- Rights and safety β disclosure may occur in good faith to protect the rights, property, or personal safety of us, our users, or the public
π External Links
The Application may link to websites or services we do not operate. We are not responsible for their content, privacy practices, or security, so please review the privacy policy of any external destination you open.
π¨ Data Breach Notification
If a data breach affects your Personal Data, we will notify you within 72 hours of becoming aware of the incident where applicable law requires it, describing the nature of the breach, its likely consequences, and the measures taken or proposed in response.
π§ Do Not Track Signals
No consistent industry standard governs responses to browser Do Not Track (DNT) signals. Bump And Merge operates primarily as a native mobile experience, and where WebViews appear we do not currently alter practices based solely on DNT headers. Please use the device-level and email opt-out routes described above instead.
βοΈ Policy Changes
This policy may be revised as features or laws change, with amendments taking effect once the updated text appears on this page and the "Last updated" line is refreshed. Material changes may be announced in-app or by other reasonable means.
βοΈ Contact Us
Β© 2026 Bump And Merge Β· Privacy Policy Β· September 8th, 2026