← BekpaRewards

Privacy Policy — BekpaRewards

Controller / the business responsible: Pavel Beke, trading as BekpaGames,

Trnava 298, 674 01 Trnava, Czech Republic, business ID (IČO) 87074494

Contact for privacy matters: info@bekpagames.com

In force from: 2026-08-24

This policy covers the BekpaRewards app and the loyalty programme it operates.

We have not appointed a Data Protection Officer and are not required to; write to

the address above and a person will answer.


1. What we collect and why

We try to collect as little as possible. The app requires no registration and

collects no name and no location. We process the advertising identifier only

with your consent — see below.

Data Category (US terms) Why we have it Legal basis (EU/UK) How long
Device fingerprint (hashed) identifier one account per device, abuse prevention legitimate interest (Art. 6(1)(f)) while the account exists
Game progress (counts, timestamps) internet or app activity evaluating tasks performance of a contract (Art. 6(1)(b)) while the account exists
Google Play Integrity verdict identifier / device data deciding payout eligibility legitimate interest (Art. 6(1)(f)) while the account exists
IP address of requests identifier abuse prevention legitimate interest (Art. 6(1)(f)) 90 days in full, then shortened to the network block
Email address identifier verifying you, delivering the payout performance of a contract (Art. 6(1)(b)) while the account exists
Payout records commercial information accounting, defending legal claims legal obligation (Art. 6(1)(c)); Art. 17(3)(b),(e) 10 years

We collect this from you and from your device as you use the app, and from

Google when it returns a Play Integrity verdict. We collect it from no other

source and we buy no data about you.

Where we rely on legitimate interest, that interest is keeping the programme

solvent and fair: without device binding and abuse signals, one person could

drain the reward budget with automated accounts, at the expense of everyone

playing honestly. You can object to it at any time — see §6.

The device fingerprint

We use ANDROID_ID, which is **specific to this app and to your user profile on

the phone. It does not identify your device to any other app. We hash it on

the phone** before it is sent, and hash it again on our server with a secret key.

We never hold the original value and it cannot be recovered from what we store.

Advertising identifier

Android gives the phone an advertising identifier (AAID). You can reset or

delete it at any time in your phone's settings.

We process it only with your consent, which the app asks for before it shows

the first ad. Without consent it is not sent anywhere and ads are

non-personalised.

It is used for two things:

1. Matching an install to a campaign. If you installed the app after seeing

an ad, we need to know which one — otherwise we cannot tell which advertising

is worth paying for and which is wasted money.

2. Measuring and personalising ads inside the app.

You can withdraw consent at any time in the app under **My account → Privacy

settings**. From that moment the identifier is no longer sent.

What we do not collect

US state privacy laws, no special-category data in the sense of GDPR Art. 9

specific games in our catalogue are present, because each is named

individually in its manifest; it cannot enumerate anything else.

2. Who we share it with

Recipient What Where Safeguard
Google (Play Integrity) device attestation token outside the EEA/UK EU Standard Contractual Clauses, UK Addendum
PayPal email address and amount, only when a payout is made outside the EEA/UK EU Standard Contractual Clauses, UK Addendum
Tenjin (ad measurement) advertising identifier, device details, install and launch events outside the EEA/UK EU Standard Contractual Clauses, UK Addendum
AppLovin (ad network) the fact that an install came from its campaign — passed on by Tenjin outside the EEA/UK EU Standard Contractual Clauses, UK Addendum
Google (AdMob) advertising identifier and the data needed to serve an ad outside the EEA/UK EU Standard Contractual Clauses, UK Addendum
Our own server everything else Germany (EU)

We share with nobody else. The last three receive data only if you consented

to the advertising identifier; without that consent nothing identifying you is

sent to them.

We do not sell your personal information. We never have and we never will.

We do, however, **share the advertising identifier with the advertising partners

listed above so that ads can be measured and personalised** — which counts as

“sharing for cross-context behavioural advertising” under the California

Consumer Privacy Act and comparable US state laws. Your balance, your rewards

and your email address are never part of that.

How to opt out: open the app and go to My account → Privacy settings.

Opting out stops the identifier from being sent; the app keeps working and you

still see ads, just non-personalised ones.

Because our server is in the EU, data from every country we operate in is

transferred to and stored in the European Union. For users in Australia this is

a disclosure to an overseas recipient under APP 8; for users in New Zealand it is

a disclosure under IPP 12; for users in Canada it is processing outside Canada.

Our server is subject to EU law, which provides comparable protection.

3. How we protect it

The server accepts nothing over plain HTTP.

outside the database. A copy of the database alone does not reveal them.

altered report is rejected.

cannot be silently rewritten.

No system is perfectly secure and we do not claim otherwise. If a breach affects

your data and is likely to put you at risk, we will notify you and the relevant

authority within the time each applicable law requires.

4. How long we keep it

see §7.

longer identify a single connection.

money went, and without them we could not answer a later claim that we never

paid. GDPR Art. 17(3)(b) and (e) permit this, and tax and accounting law

requires it. The recipient address inside them is erased automatically once

that period ends.

5. Children

The programme is for people aged 18 and over. We do not knowingly collect

personal information from children, and we do not knowingly collect the personal

information of anyone under 13 in the sense of the US Children's Online Privacy

Protection Act. If you believe a child has created an account, write to us and we

will delete it.

6. Your rights

Wherever you live, you can ask us to show you the data we hold about you,

correct it, delete it, or stop processing it. Write to

info@bekpagames.com. We answer within one month; if a request is complex we will

tell you and may take up to two further months, as GDPR allows.

We will not treat you differently for exercising these rights: no worse service,

no different rate, no loss of credits.

We verify a request by matching it against the account it concerns — usually the

verified email address, or the account identifier shown on the My account screen.

We do this so that nobody else can obtain or delete your data.

If you are in the EU or the UK

You have the rights of access, rectification, erasure, restriction, data

portability, objection to processing based on legitimate interest, and withdrawal

of consent where consent is the basis (at present we rely on consent for

nothing).

You can complain to a supervisory authority. In the Czech Republic it is the

Office for Personal Data Protection (www.uoou.cz); in

Ireland, the Data Protection Commission (www.dataprotection.ie);

in the United Kingdom, the Information Commissioner's Office

(ico.org.uk). You may also complain to the authority in the

country where you live.

If you are in the United States

You have the right to know what personal information we collect, use and

disclose; to obtain a copy of it; to correct it; to delete it; and to limit the

use of sensitive personal information. **We collect no sensitive personal

information and we sell nothing.** We do share the advertising identifier for

cross-context behavioural advertising, and you can opt out at any time in the app

under My account → Privacy settings — see §2.

The categories of personal information we have collected in the last 12 months

are listed in §1. We disclosed them for a business purpose only to the recipients

in §2. You may make a request yourself or through an authorised agent, and you

may ask us to go back further than 12 months where your state's law provides it.

If you are in Canada

You may access and correct your personal information and challenge our handling

of it. If we cannot resolve your concern, you can complain to the Office of the

Privacy Commissioner of Canada (priv.gc.ca) or, in

Quebec, to the Commission d'accès à l'information.

If you are in Australia or New Zealand

You may access and correct your personal information. If we cannot resolve your

complaint, you can contact the Office of the Australian Information Commissioner

(oaic.gov.au) or the New Zealand Office of the Privacy

Commissioner (privacy.org.nz).

7. Deleting your data

You can close your account, and with it your personal data:

Deletion through the app is immediate and irreversible. It removes or anonymises

your email address, device fingerprint, IP addresses and the identifying content

of your progress records. Unpaid credits are cancelled. What survives is

described in §4.

8. Automated decisions

Two things are decided without a person: whether a device passes Google Play

Integrity, and whether reported progress looks automated. Either can block a

payout or hold it for review.

Neither ever takes back money already paid, and **no payout is ever approved

automatically** — a person reviews every one. If a decision goes against you, the

app tells you why, and you can ask us to look again at the address above. A

person will.

9. Changes to this policy

If we change how we handle your data, we will update this page and, where the

change is significant, announce it in the app before it takes effect. The date at

the top always shows the version in force.


*Version of 2026-08-24.*