Bump And Merge β€” Privacy Policy

Bump And Merge Privacy Policy

Last updated: September 8th, 2026

Bump And Merge collects certain data to operate β€” to run bump-and-merge boards, save your progress, deliver advertising, and handle optional rewards. This policy explains what, why, and how, along with the rights you can exercise under the GDPR, CCPA/CPRA, and VCDPA.

πŸ“– Definitions

Here is what the recurring terms mean throughout this policy:

  • Application β€” Bump And Merge, the mobile merge puzzle we provide
  • Personal Data β€” any information that could identify you
  • Usage Data β€” information collected automatically as you play, such as merges, session length, and diagnostics
  • Device β€” the phone, tablet, or other hardware running the Application
  • Service Provider β€” a third party that helps us operate the service
  • Account β€” the profile or session used to reach features, progress, and withdrawals

πŸ“Š What We Collect

Automatically gathered

When you open Bump And Merge, our systems automatically record:

  • Device Info β€” model, operating system, WebView, screen size
  • Network details β€” IP address and connection type
  • Identifiers β€” GAID, ANDROID_ID, or platform equivalents
  • Usage Data β€” boards played, merges completed, session length, timestamps
  • Diagnostics β€” crash logs and performance data

With your permission

  • Advertising identifiers (GAID on Android, IDFA on iOS)
  • Engagement and in-app event signals
  • PayPal account email and name, used solely for withdrawals

🎯 How We Use It

Your Personal Data keeps Bump And Merge working, handles your Account and transactions, sends relevant updates, and improves the experience over time.

Core operations
  • Running merge gameplay and syncing progress
  • Managing Accounts, authentication, and settings
  • Processing PayPal withdrawals and verification
  • Handling support requests and service notices
Improvement & growth
  • Analyzing usage to refine boards and stability
  • Measuring promotions and campaign performance
  • Sharing news about related features or offers
  • Supporting mergers, acquisitions, or restructuring

🀝 When We Share

We are selective about sharing β€” Personal Data leaves us only in the situations below.

  • Service Providers β€” analytics, hosting, customer support, and payment processing
  • Business Transfers β€” merger, acquisition, financing, or sale of assets
  • Affiliates β€” entities under common ownership, subject to this policy
  • Business Partners β€” parties with whom we jointly offer products or promotions
  • Legal Obligations β€” where law, regulation, or valid legal process requires it
  • Consent β€” any purpose disclosed at collection or later approved by you
PayPal data protection. We do not sell or rent user PayPal account email addresses to anyone. That information is disclosed only with your explicit consent or where applicable law requires it.

πŸ” App Permissions

Every permission is disclosed before installation, limited to the stated purpose, and aligned with Google Play Developer Program Policies.

PermissionPurposeData collected
INTERNETNetwork access for ads, updates, and gameplayNetwork status, transfer statistics
ACCESS_NETWORK_STATEAdapt behavior to connection typeNetwork type and status
ACCESS_WIFI_STATEKeep Wi-Fi sessions stableWi-Fi status, signal strength
AD_IDAdvertising identifier for personalizationResettable device ad ID
VIBRATEHaptic feedback when pieces bump and mergeNone
ACCESS_ADSERVICES_TOPICSAd interest topic signalsAdvertising topic data
ACCESS_ADSERVICES_ATTRIBUTIONCampaign attribution measurementAttribution data
BIND_GET_INSTALL_REFERRER_SERVICEIdentify install sourceInstall source, campaign parameters
BIND_APPHUB_SERVICEOptimize ad delivery via AppHubAd parameters, impression data
ACCESS_ADSERVICES_AD_IDComply with modern ad API requirementsAd service identifiers
FOREGROUND_SERVICEMaintain critical functions when backgroundedNone
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONSecure internal broadcast communicationNone

πŸ“‘ Analytics & Endpoints

Analytics and game services are delivered through https://dyxa.bumpmerge.com. Payloads handled by the analytics layer are anonymized and are not designed to carry personally identifiable information. The same endpoint supports core gameplay delivery, progress synchronization, stability work, and support tooling.

  • Transport Layer Security (TLS) 1.2 or higher on every transmission
  • Role-based access controls restricting data to authorized personnel
  • Data minimization applied across all processing activities
  • Recurring security reviews and vulnerability assessments
  • Data Processing Agreements executed with third-party handlers

πŸ“£ Third-Party Services & Ad Partners

Advertising is served through AppLovin and its mediated partner network. Only limited categories reach advertising partners.

May be shared
  • Resettable advertising identifiers
  • Device model, OS, screen size
  • Session frequency and duration
  • Ad impressions and clicks
  • Non-precise demographics
Never shared
  • Email addresses or phone numbers
  • Account credentials
  • Detailed merge progress or balances
  • User-generated content
  • Precise geolocation data

Advertising partner privacy policies

πŸ›‘οΈ Data Security

We maintain commercially reasonable physical, administrative, and technical safeguards: encryption of sensitive data in transit, TLS 1.2 or higher, need-to-know access controls, periodic audits, and contractual security obligations for partners. No transmission or storage method is completely secure, so absolute security cannot be guaranteed.

πŸ—‚οΈ Data Retention

Not playing Bump And Merge? After 90 days of inactivity we remove your Personal Data permanently from our systems. Anything retained beyond that is anonymized or aggregated Usage Data that can no longer identify you.

βš–οΈ Your Rights

Depending on where you live, local law gives you tools to access, correct, delete, or restrict how we use your Personal Data.

GDPR Β· EEA

  • Access
  • Rectification
  • Erasure
  • Restrict processing
  • Object

CCPA / CPRA Β· CA

  • Know
  • Delete
  • Opt-Out of sale
  • Non-Discrimination

VCDPA Β· VA

  • Access
  • Correct
  • Delete
  • Portability
  • Opt-Out

To exercise any of these, email goldahuyettvu19975@gmail.com and name the right you want to use.

🚫 Opting Out

  • Android: Settings β†’ Google β†’ Ads β†’ β€œOpt out of Ads Personalization”
  • iOS: Settings β†’ Privacy β†’ Advertising β†’ β€œLimit Ad Tracking”
  • Sale of Personal Data: email goldahuyettvu19975@gmail.com with the subject line Do Not Sell

🌍 International Transfers

Personal Data may be transferred to and processed on servers outside your country of residence. Such transfers are protected by TLS 1.2 or higher and, where required, by appropriate contractual safeguards including Standard Contractual Clauses.

πŸ§’ Children's Privacy

Bump And Merge is not directed to individuals under the age of thirteen (13), and we do not knowingly collect Personal Data from children under 13. A parent or guardian who believes a child has provided Personal Data should contact goldahuyettvu19975@gmail.com; the data will be deleted promptly once verified.

πŸ“œ Disclosures

  • Business transactions β€” Personal Data may transfer to an acquiring entity, with prior notice where practicable
  • Law enforcement β€” disclosure may follow law, subpoena, court order, or governmental request
  • Rights and safety β€” disclosure may occur in good faith to protect the rights, property, or personal safety of us, our users, or the public

🚨 Data Breach Notification

If a data breach affects your Personal Data, we will notify you within 72 hours of becoming aware of the incident where applicable law requires it, describing the nature of the breach, its likely consequences, and the measures taken or proposed in response.

🧭 Do Not Track Signals

No consistent industry standard governs responses to browser Do Not Track (DNT) signals. Bump And Merge operates primarily as a native mobile experience, and where WebViews appear we do not currently alter practices based solely on DNT headers. Please use the device-level and email opt-out routes described above instead.

✏️ Policy Changes

This policy may be revised as features or laws change, with amendments taking effect once the updated text appears on this page and the "Last updated" line is refreshed. Material changes may be announced in-app or by other reasonable means.

βœ‰οΈ Contact Us

Β© 2026 Bump And Merge Β· Privacy Policy Β· September 8th, 2026