PLAY PARK STUDIO · SNOWBALL SQUAD

Snowball Squad privacy policy

Last updated: 20 September 2026 · Version 1.0.1

Who runs the game

Snowball Squad is operated by Michael Robinson, trading as Play Park Studio, not by an incorporated company. Business address: 27 Langley Road, Newton Aycliffe, County Durham, DL5 5RJ, United Kingdom. Contact pacman@ascentterminal.com about your data or a privacy request.

A short guide for players and parents

Online play needs an account and game records. Other players can see your game name and appearance. Keep your login and recovery key private, even from someone claiming to be support. You do not have to buy anything or agree to optional analytics to play. If something about your information worries you, ask a trusted adult to help you contact pacman@ascentterminal.com. We do not ask you to email passwords, recovery keys or full payment details.

Your account and device

Online play uses a random account ID, your chosen display name, login and recovery credentials, progress, balances, owned and equipped items, match results, rank, friends and invitations. The server stores hashes of login and recovery secrets. These records provide online play, account recovery, rewards and protection against duplicate rewards. Other players can see your public gameplay identity, appearance and relevant match or ranked results.

Campaign progress and preferences are saved on your device. A protected saved login lets the game reconnect your online account. Windows uses DPAPI and Android uses Keystore-backed protection for this credential; this is not a promise that every game record is encrypted on disk.

The game asks for an age category, not a date of birth. This category stays on the installation, is not verified or synced, and controls the app's adult-only rewarded-ad request path. The saved category cannot currently be changed in Settings. Resetting settings or deleting your online account does not clear it or your local campaign save. This is an app control, not verified age or parental permission.

In app version 1.0.1 and later, online play and account creation are available to players aged 13 and up. The app asks players to choose an age group before connecting. Players under 13 can use offline Campaign and Practice. This restriction does not delete existing local saves or online account records. Parents and guardians can still contact us for privacy or account help and use the account-deletion page. Earlier app versions do not have this restriction.

Optional gameplay analytics

Optional gameplay analytics is unavailable in the initial version 1 release. The version 1 service does not collect new optional gameplay events or activity, including from an account that opted in on an older version. Necessary account, match, security and purchase records remain separate.

Older versions offered analytics off by default, with an explicit opt-in. These account-linked records described battle starts/outcomes, tutorial throws/hits, time played, active days and shop, pass or locker visits. Friend-challenge analytics required a separate expanded choice. These event records exclude chat, display names, invitation codes and login secrets.

Disabling collection does not itself erase previously collected records. You can withdraw an existing choice in Settings → Privacy, where available, or contact us. Withdrawal removes optional event history, activity and analytics cohort records while keeping the disabled preference. Account deletion and the retention limits below also apply. Withdrawal does not affect the lawfulness of earlier processing based on valid consent.

Sharing, safety and support

Shared-result links are created when you request them. Anyone with the link can view the result card until its 30-day expiry or revocation. Copies or screenshots saved by others cannot be recalled. Challenge invitation links have a seven-day use limit; expiry does not itself delete the database record.

Player reports store the reporting and reported accounts, the reported display name, a selected reason, dates, status and any moderation action. They support player-safety review. When an account is deleted, its identity is removed from these report records; the remaining report may be retained.

If you contact support, we receive your email address and what you send, such as your game version, device details and problem description. Do not send passwords, recovery keys, confirmation codes, purchase tokens or full payment details.

Where the support-ticket feature is available, retrieving eligible refunded gem-pack records creates or reuses a random reference linked to the purchase and your game account. The app shows the gem amount and receipt-record time. You can copy the reference to include in a support message. Loading or copying does not send a message, request a store refund or change gems.

If we approve a correction to an in-game refund adjustment, we record the decision, amount, date and balance change with the purchase/accounting record. Protected approval and safety records preserve the decision through retries or restored backups. These include hashed account/purchase references and a fingerprint of support evidence. Hashes are safeguards, not a guarantee of anonymity.

Purchases and optional rewarded ads

Availability depends on the app and server configuration. Where purchases are offered, Google Play handles payment details. The game receives a purchase token, product and payment state, and sends the token and account binding for server verification. The service keeps purchase, delivery, reward and refund records to deliver items and reconcile payments. Native store messages alone cannot grant items. Where gem packs are enabled, a refund after gems have been spent may create an in-game adjustment reduced by later gem credits. It is not cash debt; the Refund Policy explains review and correction.

Where rewarded ads are offered, the app checks its local age category, server availability and Google's consent status before requesting an ad. Google User Messaging Platform supplies consent forms and privacy options. The service sends a random reward-attempt code to AdMob and checks Google's signed completion callback before awarding coins. It stores attempt records and transaction hashes to prevent duplicate rewards. Ad privacy options are available from the shop where supported.

The Android app includes Google Play Billing, Google Mobile Ads and Google's consent SDK, including when paid offers or ad requests are unavailable. Google describes Mobile Ads processing including IP-derived approximate location, app/ad interactions, diagnostics and device or account identifiers for advertising, analytics and fraud prevention. SDK startup can occur before Unity's gameplay controls; turning off gameplay analytics is not a control for Google's separate services. Read Google's privacy policy and Mobile Ads data disclosure.

Why we use this information

Under UK data-protection law, we rely on these bases for the purposes described:

Without account/authentication records we cannot provide online account features; without required purchase-verification records we cannot deliver or reconcile that purchase. You can still use available offline gameplay. Support messages and optional choices are not required merely to play.

Purchase/refund checks and reward limits use automated records and rules. A refunded pack can remove gems and pause new gem spending as explained in the Refund Policy. Contact us to dispute an incorrect result or request human review; a refund is not itself misconduct.

Providers, transfers and security

Our hosting provider processes the game-server data; support email is routed through Google, which processes support correspondence. Google describes its international-transfer arrangements and safeguards in its data transfer frameworks. This does not mean that support email is stored only in the UK. Google receives the payment/advertising data described above. Other players or link recipients see the public game information you use or choose to share. Relevant information may also be disclosed where a lawful legal or regulatory request requires it. We do not use support messages as a marketing mailing list.

We limit access to operational records and protect account credentials as described above. Online account connections use encrypted transport. Restricted support evidence should not be posted in public issues or game diagnostics. Contact us for details about providers or any applicable international-transfer safeguards.

Hosting and retention

The game server is on the operator's Fasthosts VPS in the United Kingdom. Fasthosts provides hosting infrastructure. Google operates separate payment and advertising services and may process information outside the UK, as described in its privacy policy. The UK game-server location does not mean every provider processes data only in the UK.

The service processes connection IP addresses for rate limiting. Hosting and proxy systems may also process request and error metadata. Current game diagnostics retain a timestamp and fixed event code for seven UTC dates, subject to a one MiB daily cap. That limit does not cover older logs, host logs or backups.

Account and progression records generally remain until account deletion; there is no automatic inactive-account expiry. Analytics event and activity records are pruned after 90 days; consent and cohort information can remain until withdrawal or account deletion. Deletion receipt codes are valid for 30 days. Deletion hashes remain while older backups can be restored. Where the new purchase service is enabled, terminal purchase-token hashes also remain to prevent erased or refunded purchases from being granted again.

Account deletion removes account-linked support-case and correction-audit rows from the active player database. Independent approval and safety records may remain to preserve authorised decisions during backup recovery and prevent duplicate rewards or restoration of erased accounts. They have no automatic expiry in the current implementation.

Historical backups/logs, support correspondence, safety reports and some anti-abuse transaction records also have no single fixed automatic expiry. The criteria for retaining them are whether a support case, dispute or security incident remains unresolved; whether a backup can still be restored; whether a record is needed to prevent a duplicate or restored reward; and any applicable legal recordkeeping or claims requirement. Retention must remain necessary for that purpose. Contact us to ask about or challenge continued retention of a particular record. This notice does not promise that every copy disappears immediately after deletion. Google's retention is governed by its own policy.

Your choices and requests

You can withdraw an older optional-analytics choice in Settings → Privacy, where available, or contact us. You can delete an online account through Account → Delete Online Account, or use your current recovery key on the account-deletion page. Deletion requires proof of account ownership and confirmation. It removes account-owned online data, invalidates result links and removes your identity from shared match records. Local campaign progress remains on the device. Deletion does not itself request a Google Play refund or erase Google's own records.

Email pacman@ascentterminal.com to ask about access, correction, deletion, restriction or a copy of your information, or to raise an objection to its use. Rights depend on the circumstances and applicable law. You can object to our use of your information based on legitimate interests. Explain your particular concern; we will consider whether we must stop that use. You can withdraw consent where we rely on it without losing ordinary gameplay. A parent or guardian can help a child make a request. We ask only for proportionate evidence needed to verify the request, not secrets by email. Support currently cannot override account ownership when neither usable saved credentials nor a recovery key remains. Do not email the key itself.

You can also raise a data-protection concern with the UK Information Commissioner's Office. Changes to this notice will carry an updated date.