Privacy Policy
This Privacy Policy explains how QR (“QR,” “we,” “us”) collects, uses, and shares information when you use pushthrugames.com/qr/ and related pages. It is designed to be transparent for users in the United States (including California) and other regions with strong privacy expectations. This is not legal advice. Rights that cannot be waived still apply.
We never sell your data. Opt-out of sale is always on in our view — we do not run a data-selling business. Our Privacy Stance.
1. Who we are
QR is a free browser game (sectors, modules, exploration, optional accounts) published under Push Thru Games at pushthrugames.com. QR uses its own cloud backend (separate from the Push Thru game at pushthrugame.com).
Privacy requests (access, deletion, correction, do-not-sell/share): use the contact form and choose topic Privacy / data deletion, or see Your Privacy Choices.
2. Information we collect
We collect information in these categories (CCPA/CPRA-style groupings):
A. Identifiers
- Account ID (from our auth provider, when you sign in)
- Player / friend code and optional synthetic login address used only for code+password-style accounts
- Optional real email if you create an account or sign in with email
- Display name you choose
- IP address and basic request metadata as processed by our hosting/auth providers (not used by us for ads)
B. Gameplay & progress
- Best sector, sectors cleared, threats purged, runs started (cloud profile when signed in)
- Account level / XP and aggregated lifetime stats you generate while playing
- Optional cloud meta snapshot of stats (when signed in and features are enabled)
- Local-only progress: Memory/RAM unlocks, save slots, run state, welcome-skip flags (device storage)
C. Internet / device activity
- Browser type and basic technical logs from hosting providers
- Auth session tokens needed to keep you signed in
D. Support communications
- Name, email, and message content you send via the contact form
We do not intentionally collect precise geolocation, government IDs, payment card numbers in the current free web build, or biometric identifiers. Mobile is not yet supported; if apps ship later, this policy will be updated.
3. How we use information
- Operate and improve the game (accounts, progress, anti-abuse, debugging)
- Remember preferences and legal notices on your device
- Respond to support and privacy requests
- Secure the Service and enforce Terms
- Comply with law
We do not use your data for cross-context behavioral advertising in the current web build.
4. Cookies, local storage & similar tech
QR relies mainly on local storage and auth session storage — not advertising cookies. Details: Cookie & Storage Notice.
- Auth session (online sign-in)
- Local game saves, Memory/RAM unlocks, account-level meta stats, privacy preference flags
5. When we share information
We share information only as needed to run the Service:
- Infrastructure providers — e.g. website hosting (GitHub Pages or successor) and auth/database (Supabase project dedicated to QR)
- Support routing — contact form delivery (e.g. FormSubmit or similar)
- Legal — if required by law or to protect rights and safety
- Business transfer — if the Service is transferred, with notice where practical
We do not sell personal information to data brokers.
6. Do we sell or “share” data? (California)
No. We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising in the current web build. Opt-out is treated as always on; you can confirm preferences on Your Privacy Choices. We honor Global Privacy Control (GPC) when present.
7. Your privacy rights & choices
Depending on where you live, you may have rights to:
- Access, correct, or delete personal information
- Opt out of sale/share (default protected here)
- Limit use of sensitive personal information where applicable
- Appeal a denied request where required
Exercise rights via contact (topic: Privacy / data deletion) or account deletion RPCs when signed in. We will not discriminate against you for exercising privacy rights.
8. Children
The Service is not directed to children under 13. You must meet the age requirement in our Terms. If you believe a child under 13 provided data, contact us to delete it.
9. Security & retention
We use reasonable technical measures (HTTPS, provider auth, RLS on cloud tables). No method is 100% secure. We retain account and gameplay data while your account is active and as needed for the Service, security, and legal obligations; local device data remains until you clear it or uninstall/clear site data.
10. International users
Servers and providers may process data in the United States or other countries. If you use the Service from elsewhere, you understand that information may be processed where our providers operate, with safeguards as required by law.
11. Contact & complaints
Privacy questions and requests: contact form · topic Privacy / data deletion.