Privacy Policy — BekpaRewards
Controller / the business responsible: Pavel Beke, trading as BekpaGames,
Trnava 298, 674 01 Trnava, Czech Republic, business ID (IČO) 87074494
Contact for privacy matters: info@bekpagames.com
In force from: 2026-08-24
This policy covers the BekpaRewards app and the loyalty programme it operates.
We have not appointed a Data Protection Officer and are not required to; write to
the address above and a person will answer.
1. What we collect and why
We try to collect as little as possible. The app requires no registration and
collects no name and no location. We process the advertising identifier only
with your consent — see below.
| Data | Category (US terms) | Why we have it | Legal basis (EU/UK) | How long |
|---|---|---|---|---|
| Device fingerprint (hashed) | identifier | one account per device, abuse prevention | legitimate interest (Art. 6(1)(f)) | while the account exists |
| Game progress (counts, timestamps) | internet or app activity | evaluating tasks | performance of a contract (Art. 6(1)(b)) | while the account exists |
| Google Play Integrity verdict | identifier / device data | deciding payout eligibility | legitimate interest (Art. 6(1)(f)) | while the account exists |
| IP address of requests | identifier | abuse prevention | legitimate interest (Art. 6(1)(f)) | 90 days in full, then shortened to the network block |
| Email address | identifier | verifying you, delivering the payout | performance of a contract (Art. 6(1)(b)) | while the account exists |
| Payout records | commercial information | accounting, defending legal claims | legal obligation (Art. 6(1)(c)); Art. 17(3)(b),(e) | 10 years |
We collect this from you and from your device as you use the app, and from
Google when it returns a Play Integrity verdict. We collect it from no other
source and we buy no data about you.
Where we rely on legitimate interest, that interest is keeping the programme
solvent and fair: without device binding and abuse signals, one person could
drain the reward budget with automated accounts, at the expense of everyone
playing honestly. You can object to it at any time — see §6.
The device fingerprint
We use ANDROID_ID, which is **specific to this app and to your user profile on
the phone. It does not identify your device to any other app. We hash it on
the phone** before it is sent, and hash it again on our server with a secret key.
We never hold the original value and it cannot be recovered from what we store.
Advertising identifier
Android gives the phone an advertising identifier (AAID). You can reset or
delete it at any time in your phone's settings.
We process it only with your consent, which the app asks for before it shows
the first ad. Without consent it is not sent anywhere and ads are
non-personalised.
It is used for two things:
1. Matching an install to a campaign. If you installed the app after seeing
an ad, we need to know which one — otherwise we cannot tell which advertising
is worth paying for and which is wasted money.
2. Measuring and personalising ads inside the app.
You can withdraw consent at any time in the app under **My account → Privacy
settings**. From that moment the identifier is no longer sent.
What we do not collect
- no location, at any precision
- no contacts, photos, files or device content
- no name, date of birth or government identifier
- no biometric data, no sensitive personal information in the sense of
US state privacy laws, no special-category data in the sense of GDPR Art. 9
- no list of the apps installed on your phone. The app can check whether the
specific games in our catalogue are present, because each is named
individually in its manifest; it cannot enumerate anything else.
2. Who we share it with
| Recipient | What | Where | Safeguard |
|---|---|---|---|
| Google (Play Integrity) | device attestation token | outside the EEA/UK | EU Standard Contractual Clauses, UK Addendum |
| PayPal | email address and amount, only when a payout is made | outside the EEA/UK | EU Standard Contractual Clauses, UK Addendum |
| Tenjin (ad measurement) | advertising identifier, device details, install and launch events | outside the EEA/UK | EU Standard Contractual Clauses, UK Addendum |
| AppLovin (ad network) | the fact that an install came from its campaign — passed on by Tenjin | outside the EEA/UK | EU Standard Contractual Clauses, UK Addendum |
| Google (AdMob) | advertising identifier and the data needed to serve an ad | outside the EEA/UK | EU Standard Contractual Clauses, UK Addendum |
| Our own server | everything else | Germany (EU) | — |
We share with nobody else. The last three receive data only if you consented
to the advertising identifier; without that consent nothing identifying you is
sent to them.
We do not sell your personal information. We never have and we never will.
We do, however, **share the advertising identifier with the advertising partners
listed above so that ads can be measured and personalised** — which counts as
“sharing for cross-context behavioural advertising” under the California
Consumer Privacy Act and comparable US state laws. Your balance, your rewards
and your email address are never part of that.
How to opt out: open the app and go to My account → Privacy settings.
Opting out stops the identifier from being sent; the app keeps working and you
still see ads, just non-personalised ones.
Because our server is in the EU, data from every country we operate in is
transferred to and stored in the European Union. For users in Australia this is
a disclosure to an overseas recipient under APP 8; for users in New Zealand it is
a disclosure under IPP 12; for users in Canada it is processing outside Canada.
Our server is subject to EU law, which provides comparable protection.
3. How we protect it
- All traffic between the app, the games and our server is encrypted with TLS.
The server accepts nothing over plain HTTP.
- Email addresses are encrypted at rest with AES-256-GCM under a key held
outside the database. A copy of the database alone does not reveal them.
- Progress reports from games are cryptographically signed; an unsigned or
altered report is rejected.
- The credit ledger is append-only and the database enforces it, so a balance
cannot be silently rewritten.
- Access to the production server is limited to the operator.
No system is perfectly secure and we do not claim otherwise. If a breach affects
your data and is likely to put you at risk, we will notify you and the relevant
authority within the time each applicable law requires.
4. How long we keep it
- While your account exists, then deleted or anonymised when you close it —
see §7.
- IP addresses are shortened to the network block after 90 days, so they no
longer identify a single connection.
- Payout records survive account closure for 10 years. They record where
money went, and without them we could not answer a later claim that we never
paid. GDPR Art. 17(3)(b) and (e) permit this, and tax and accounting law
requires it. The recipient address inside them is erased automatically once
that period ends.
5. Children
The programme is for people aged 18 and over. We do not knowingly collect
personal information from children, and we do not knowingly collect the personal
information of anyone under 13 in the sense of the US Children's Online Privacy
Protection Act. If you believe a child has created an account, write to us and we
will delete it.
6. Your rights
Wherever you live, you can ask us to show you the data we hold about you,
correct it, delete it, or stop processing it. Write to
info@bekpagames.com. We answer within one month; if a request is complex we will
tell you and may take up to two further months, as GDPR allows.
We will not treat you differently for exercising these rights: no worse service,
no different rate, no loss of credits.
We verify a request by matching it against the account it concerns — usually the
verified email address, or the account identifier shown on the My account screen.
We do this so that nobody else can obtain or delete your data.
If you are in the EU or the UK
You have the rights of access, rectification, erasure, restriction, data
portability, objection to processing based on legitimate interest, and withdrawal
of consent where consent is the basis (at present we rely on consent for
nothing).
You can complain to a supervisory authority. In the Czech Republic it is the
Office for Personal Data Protection (www.uoou.cz); in
Ireland, the Data Protection Commission (www.dataprotection.ie);
in the United Kingdom, the Information Commissioner's Office
(ico.org.uk). You may also complain to the authority in the
country where you live.
If you are in the United States
You have the right to know what personal information we collect, use and
disclose; to obtain a copy of it; to correct it; to delete it; and to limit the
use of sensitive personal information. **We collect no sensitive personal
information and we sell nothing.** We do share the advertising identifier for
cross-context behavioural advertising, and you can opt out at any time in the app
under My account → Privacy settings — see §2.
The categories of personal information we have collected in the last 12 months
are listed in §1. We disclosed them for a business purpose only to the recipients
in §2. You may make a request yourself or through an authorised agent, and you
may ask us to go back further than 12 months where your state's law provides it.
If you are in Canada
You may access and correct your personal information and challenge our handling
of it. If we cannot resolve your concern, you can complain to the Office of the
Privacy Commissioner of Canada (priv.gc.ca) or, in
Quebec, to the Commission d'accès à l'information.
If you are in Australia or New Zealand
You may access and correct your personal information. If we cannot resolve your
complaint, you can contact the Office of the Australian Information Commissioner
(oaic.gov.au) or the New Zealand Office of the Privacy
Commissioner (privacy.org.nz).
7. Deleting your data
You can close your account, and with it your personal data:
- in the app: My account → Delete account
- on the web: https://rewards.bekpagames.com/delete-account
Deletion through the app is immediate and irreversible. It removes or anonymises
your email address, device fingerprint, IP addresses and the identifying content
of your progress records. Unpaid credits are cancelled. What survives is
described in §4.
8. Automated decisions
Two things are decided without a person: whether a device passes Google Play
Integrity, and whether reported progress looks automated. Either can block a
payout or hold it for review.
Neither ever takes back money already paid, and **no payout is ever approved
automatically** — a person reviews every one. If a decision goes against you, the
app tells you why, and you can ask us to look again at the address above. A
person will.
9. Changes to this policy
If we change how we handle your data, we will update this page and, where the
change is significant, announce it in the app before it takes effect. The date at
the top always shows the version in force.
*Version of 2026-08-24.*