Legal
Privacy Policy
Effective date: September 24, 2026 · Last updated: September 24, 2026
This Privacy Policy explains how BE PLUS S.R.L. ("we", "us", "our") collects, uses and protects information when you use the BomberzTD mobile game (the "App") and the website bomberztd.com (the "Site").
BomberzTD is not released yet
The App is in development and is not available in any store. This policy describes the App as we are building it. Before the first release we check every statement here against the build that ships, and if anything changes, the "Last updated" date above changes with it.
The policy covers both editions of the App, which are the same game on the same backend:
- iOS: bundle identifier
com.pydevsolutions.bomberztd, to be distributed through the Apple App Store. - Android: application ID
plus.beplus.bomberztd, to be distributed through Google Play.
Everything below applies to both unless a point is marked iOS only or Android only.
What other players can see
Your player name is generated by our server; the App has no field anywhere that accepts free text from a player, so there is no chat, no messages and no custom names. In the modes that involve other players (friend challenges, leaderboards, and later raids and the league), other players see that generated name, your results, and the defences you choose to share or build for those modes.
1. Information we collect
1.1 Account
- Account ID: a unique identifier we generate for your account, so your progress follows you across sessions and devices.
- Guest account: the App creates your account on first launch with no email, name or password. It is bound to a cryptographic key held on your device (in the iOS Keychain, or generated inside the Android Keystore, where it cannot be exported), which is how the device proves on later launches that the account is yours. You can play without ever identifying yourself to us.
- Sign-in (optional): you may link the guest account to Sign in with Apple (iOS only; we receive an opaque identifier, and an email address only if you choose to share one) or to Google Sign-In (we receive your email address and Google profile name). Signing in lets you recover your progress on another device.
- Player name: generated by our server in a fixed form. You cannot type one.
- Game Center (iOS only) and Google Play Games (Android only): optional. If you are signed in to one of them, the App reports your achievement unlocks to it. We do not receive your real name, Apple ID or Google account email through them.
1.2 Device
- Install identifier: used to measure retention (how many players come back) and to group installs by cohort. On iOS it is a random identifier we create and keep in the Keychain. On Android it is
Settings.Secure.ANDROID_ID, which Android scopes to our signing key: it is unique to our apps on that device, other developers' apps cannot see it, and a factory reset changes it. - Device and app details: device model, operating system version, app version, and the language and country set in your device settings (never derived from your IP address). They come with analytics events and help us reproduce bugs.
- Advertising identifier: the IDFA on iOS, only if you allow tracking in the App Tracking Transparency prompt; the Advertising ID on Android, read by our advertising partner Google AdMob. Whether ads may be personalised depends on your consent (section 5).
The App does not collect your contacts, photos, files, microphone, calendar, health data or location.
1.3 Gameplay and purchases
- Progress: campaigns and stages cleared, stars, your collection and its levels, in-game resources and items, daily missions and the login chain.
- Battles: each battle is sent to our server as the moves you made, so the server can replay it and grant exactly what the replay earns. This is what keeps rankings fair and makes a tampered App useless.
- Friends: the account IDs of players you connect with, and the challenges you send and receive.
- Purchases: which product you bought, when, and whether it was completed, refunded or restored. Payment is processed by Apple on iOS and by Google Play on Android; we never see your card number or billing address. We receive the store's signed transaction and verify it with the store before crediting anything.
- Rewarded ads: when an ad you chose to watch is shown and completed, so the reward can be verified by our server and ad performance measured.
- Product analytics: first-party events such as screens viewed, buttons tapped, battles started and finished, purchases and ads watched. They are sent to our own analytics service on our own infrastructure, never to a third-party analytics or advertising network. The App never sends your account ID with them; our server attaches it after checking your session. No event carries your name, email, address or precise location.
1.4 Diagnostics
The App has no crash-reporting SDK of its own. If you have allowed your device to share crash data with app developers, Apple or Google sends us crash reports under their own terms.
2. How we use it
| Data | Purpose |
|---|---|
| Account and sign-in | Keeping your progress and purchases attached to you, restoring them on another device, and showing your generated name in modes with other players. |
| Install identifier, device and app details | Retention and cohort analytics, diagnosing bugs, preventing fraud. |
| Advertising identifier (only with consent where required) | Personalised rewarded ads through Google AdMob. |
| Gameplay and battles | Running the game, checking every result on our server, rankings, rewards, support. |
| Purchases | Crediting what you bought, restoring it, handling refunds, preventing purchase fraud, meeting tax law. |
| Rewarded ads and product analytics | Verifying rewards, understanding how the game is played, and improving it. |
3. Service providers
Each of these works under its own privacy policy, and each processes data only to provide its service to us:
- Apple Inc.: Sign in with Apple, Game Center and in-app purchases (iOS only). Apple Privacy Policy
- Google LLC: Google Sign-In, Google Play Games and Google Play Billing (Android only), and Google AdMob with its consent platform (both editions). Google Privacy Policy · AdMob and your data
- Amazon Web Services: hosts our backend, our analytics service and the Site, in the United States (region us-east-1). The backend is the one that also runs our game BomberzBoard.
4. Sharing
We do not sell your personal information. We share it only:
- with other players, as described in the box at the top;
- with the service providers in section 3, under contracts that limit their use of it;
- when the law requires it, for a valid legal process or regulatory request, or to investigate fraud or abuse;
- in a corporate transaction: if BE PLUS S.R.L. is merged, acquired or sells the App, your data may pass to the successor, and this policy will say so.
5. Advertising and your consent
BomberzTD shows only rewarded video ads: short, optional ads you choose to watch for an in-game reward, a limited number of times a day. There are no banners and no interstitials. Ads are never offered during a battle, before your first victory, or in duels.
- Consent (both editions). Where the law requires it (the EEA, the UK, Switzerland, and the US states whose privacy laws apply), Google's consent form is shown before any ad is requested, and your choice decides whether ads may be personalised. Without consent, ads are not personalised.
- App Tracking Transparency (iOS only). The tracking prompt appears the first time you tap a rewarded-ad offer, never at launch. It only governs whether AdMob may use your IDFA.
- Changing your mind. Both choices can be reopened at any time from Settings in the App. On iOS you can also change tracking in the system Settings app, under Privacy & Security → Tracking.
- Your rewards are the same whichever way you choose.
Product analytics (section 1.3) is our own record of how the game is played. It is not advertising tracking, and it does not depend on the tracking prompt.
6. Children
BomberzTD is not directed at children and is not intended for anyone under 13. It is listed as 13+ and is not part of either store's family programme. We do not knowingly collect personal information from children under 13. If you believe a child has given us information, write to privacy@bomberztd.com and we will delete it.
7. Your rights
7.1 EEA, UK and Switzerland (GDPR)
You have the right to access your data and receive a copy of it, to have it corrected, to have it erased, to restrict or object to its processing, to data portability, to withdraw consent at any time, and to complain to your data protection authority. In Romania, that is the ANSPDCP (dataprotection.ro).
Our legal bases are: contract for your account, gameplay and purchases; consent for personalised advertising; legitimate interests for product analytics, security and fraud prevention; and legal obligation for purchase records.
7.2 United States
If you live in California or another US state with a comparable law, you have the right to know what we collect, to have it deleted, to opt out of the sale or sharing of personal information, and not to be treated differently for using these rights. We do not sell personal information. You can refuse the sharing of your data for advertising in the consent form described in section 5.
7.3 How to use them
Write to privacy@bomberztd.com. We answer within one month, and may ask you to show that the account is yours before acting on it.
8. How long we keep it
- Account and progress: while your account exists. After you delete it, your personal data is removed within 30 days.
- Battles: 30 days, then deleted automatically.
- Raw analytics events: 90 days, then deleted automatically. Aggregated figures that identify no one may be kept longer.
- Purchase records: as long as tax and consumer law require, even after the account is deleted.
9. International transfers
Our servers are in the United States. For transfers from the EEA, the UK and Switzerland we rely on the EU–US Data Privacy Framework and its UK and Swiss extensions, to which Amazon Web Services is certified, and on the European Commission's Standard Contractual Clauses in AWS's data processing terms.
10. Security
Everything between the App and our servers travels over HTTPS. Data is encrypted at rest. Your session tokens are kept in the iOS Keychain or encrypted with an Android Keystore key, and sessions expire and can be revoked. Our server checks every battle and every purchase itself instead of trusting the App, and no secret key is built into the App. No system is perfectly secure: if a breach puts your data at risk, we notify the supervisory authority within 72 hours and tell you without undue delay where the law requires it.
11. Deleting your account
- In the App: Settings → Account → Delete account, then confirm. The path is the same on iOS and Android.
- By email: privacy@bomberztd.com with the subject "Delete my account", if you no longer have the App.
Deletion is permanent. It erases your progress, items, friends and any sign-in link on our servers; purchase records are kept as section 8 says. The App then starts again as a new guest account.
12. This website
bomberztd.com sets no cookies, runs no analytics and loads nothing from other companies: its fonts and images are served from our own hosting. Amazon CloudFront, which delivers the pages, necessarily processes your IP address to send them to you; we do not keep access logs.
13. Changes
We will update this policy as the App changes, and the "Last updated" date will say when. A material change is announced in the App before it takes effect.
14. Contact
- Privacy: privacy@bomberztd.com
- Support: support@bomberztd.com
- Controller: BE PLUS S.R.L., Str. Dealul Țugulea nr. 77, etaj 1, birou 2, sector 6, 060865 București, Romania. Trade register J2026039087001, CUI 54913206.