Privacy
Privacy Policy
Last updated 12 September 2026
Translations are provided for convenience. If there is any conflict, the English version prevails.
CRAVA PTE. LTD. (“Company”, “we”, “us”, or “our”), registered in Singapore, respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and disclose information when you use our mobile game PuppyKitchen (the “App”).
By using the App, you agree to this Policy. If you do not agree, please do not use the App.
1. Who we are
We are the controller of personal data processed for the App. Third-party SDKs listed in Section 5 act as processors or independent controllers under their own policies.
- Company: CRAVA PTE. LTD.
- Country: Singapore
- Privacy / DPO email: privacy@thecrava.com
- Player support email: hello@thecrava.com
2. Information we collect
We do not ask you to create a profile with your name, and we do not collect or store credit card numbers. Payments are handled by Google Play or Apple.
2.1 Data you provide
- Support messages: If you contact us from Settings → Support, your email app may send us the message plus automatically attached technical details (Unity Player ID, app version, build number, language, session id, and advertising campaign identifiers if available). You choose what else to write.
- Account linking (optional, when enabled): If you later link Google Play Games or Sign in with Apple, we receive the account identifiers those services provide so we can restore progress. Until then, play continues with an anonymous Unity Player ID.
2.2 Data collected automatically
- Device and App data: IP address (via our service providers), advertising ID (GAID / IDFA where permitted), OS version, device model, app version, build number, language, and coarse country/region inferred by SDKs.
- Account and gameplay: Anonymous Unity Gaming Services (UGS) Player ID; local and cloud save of game progress (gold, gem, tickets, stalls, regions, settings, entitlements such as No Ads / 2× gold); in-game activity needed to run the game.
- Purchases: Product IDs, transaction tokens/receipts, and entitlement status processed through Google Play Billing and/or Apple In-App Purchase. We do not receive your full payment card number.
- Ads: Ad placement, load/show/reward/failure events, and whether ads can be requested after Google’s User Messaging Platform (UMP) consent flow.
- Analytics: Session start/pause/resume/end; tutorial completion; in-app purchase events; rewarded-ad events; occasional economy snapshots used to operate and balance the game.
- Crash and diagnostics: Stack traces, breadcrumbs, Player ID, app version, and device/OS information via Sentry and Firebase Crashlytics.
2.3 Data we do not collect
We do not request your contacts, photos, microphone, precise GPS location, or government ID. We do not sell your personal information.
3. How we use information and legal bases
We process data to:
Where a law requires consent (for example personalized advertising in the EEA/UK), we rely on Google UMP. You can change ad consent in your device settings or by resetting the App’s consent form if the OS provides that option.
Ads vs. core service: Advertising and AppsFlyer measurement start only after ads may be requested under UMP (CanRequestAds). Operating the game still requires authentication, cloud/local save, and crash reporting so we can provide and repair the service.
| Purpose | Examples | Legal basis (GDPR / similar) |
|---|---|---|
| Provide the game | Anonymous sign-in, cloud save, gameplay, restore progress | Contract / legitimate interest |
| In-app purchases | Verify receipts via Cloud Code; grant gems, tickets, No Ads, 2× gold | Contract |
| Rewarded ads | Show ads via Google AdMob; grant in-game rewards after a completed view | Consent (where required) and/or legitimate interest |
| Personalized or non-personalized ads | AdMob; UMP consent where required (EEA/UK and similar) | Consent (personalized ads); legitimate interest (limited non-personalized ads where allowed) |
| Measure marketing | AppsFlyer attribution (install source, campaign) | Consent where required; legitimate interest otherwise |
| Analytics and live ops | Unity Analytics, Firebase Analytics | Legitimate interest (service improvement); consent where required |
| Stability and security | Sentry, Crashlytics; abuse/fraud checks on purchases and ad rewards | Legitimate interest |
| Support | Answer tickets using Player ID and build info | Legitimate interest / contract |
| Legal | Comply with store and accounting rules | Legal obligation |
4. Local storage and cloud save
- On device: Progress is stored locally (encrypted save file and PlayerPrefs). This stays on your device unless you use cloud save or send us a support email.
- Cloud: When online, we sync a progress blob (gameSave) and server-side premium balances (premiumBalances) to Unity Cloud Save, keyed by your UGS Player ID. Cloud Code uses these keys to grant purchases, ad rewards, and mail/gem operations.
5. Third-party services and international transfers
Your information may be transferred to and processed in countries outside your residence, including the United States, Singapore, and other locations where our providers operate. We use:
Each provider has its own privacy policy. We do not sell personal information to data brokers.
| Provider | Role | Typical data |
|---|---|---|
| Unity Technologies (UGS: Authentication, Cloud Save, Cloud Code, Analytics; Unity Engine) | Account, save, server logic, analytics | Player ID, save payload, events, device/app metadata, IP |
| Google (Play Games, Play Billing, AdMob, UMP, Firebase Analytics, Crashlytics) | Store, payments, ads, consent, analytics, crashes | Advertising ID, IP, device data, purchase tokens, analytics/crash/ad events |
| Apple (App Store / IAP, Sign in with Apple — when the iOS build is live) | Store, payments, optional account link | Purchase receipts, Apple account identifiers if you link |
| AppsFlyer | Mobile measurement (UA) | Advertising ID, IP, device data, install/campaign, in-app conversion events when ads consent allows |
| Functional Software, Inc. (Sentry) | Crash reporting | Crash dumps, breadcrumbs, Player ID, app version, device/OS |
6. Your rights (GDPR / UK GDPR / CCPA / PDPA / other)
Depending on your location, you may have the right to:
- Access, correct, or delete personal data we hold
- Withdraw consent or object to certain processing (especially advertising)
- Restrict processing or request portability
- Lodge a complaint with a supervisory authority
California
We do not sell or share your personal information for cross-context behavioral advertising as “sale/share” is defined under the CCPA/CPRA, except to the extent advertising SDKs use identifiers for ads after you consent. You may opt out of personalized ads via UMP / device ad settings.
How to exercise rights
Email privacy@thecrava.com with your Unity Player ID (Settings shows it) and your request. For deletion of the in-game account and cloud save, you can also use Settings → Delete Account in the App (two-step confirmation). Analytics and crash logs held by Google, Unity, AppsFlyer, or Sentry follow those providers’ retention schedules after deletion.
7. Account deletion
Google Play requires an in-app deletion path. In the App:
This deletes your UGS Authentication player, associated Cloud Save we control, local save, and local entitlement snapshot. It cannot reverse store charges already processed by Google or Apple. Some aggregated or legally required records may remain.
You may also request deletion by emailing privacy@thecrava.com.
- Open Settings
- Tap Delete Account
- Confirm the warning, then enter the confirmation code
8. Data retention and security
We keep account and save data while your account exists and for a short period afterward as needed to complete deletion or resolve disputes. Analytics, ads, and crash data are kept only as long as needed for the purposes above or as required by law, subject to each SDK’s retention.
We use industry-standard measures (HTTPS to Unity/Google services, encrypted local saves, server-side checks for purchases and ad rewards). No method of transmission is 100% secure.
9. Children
The App is not directed at children under 13 (or the equivalent minimum age in your country). We set Google’s under-age-of-consent flag to false. If you believe we have collected data from a child, contact privacy@thecrava.com and we will delete it.
10. Changes to this policy
We may update this Policy. The “Last Updated” date will change. Material changes will be reflected on this page, which the App opens from the title-screen agreement and from Settings.
11. Contact
Data Protection Officer / privacy — CRAVA PTE. LTD., Singapore — privacy@thecrava.com
Player support (gameplay, purchases, bugs) — hello@thecrava.com
Player information