Data Protection and Privacy Policy

Effective: 15 July 2026

This Privacy Policy sets out how, why and to what extent personal data is processed through the mobile application “MoneyTime” and the games referenced within it (the “Company’s Games”) (together, the “App“), and in connection with the associated loyalty and rewards program (the “Loyalty Program“, the rules of which are available at https://www.moneytime.games/loyalty-program-rules). We aim to keep this Policy clear and understandable, and we generally use the terms of the General Data Protection Regulation (GDPR).

You can access this Policy at any time within the App and at https://www.moneytime.games/privacy-policy.

You can also access our General Terms & Conditions at https://www.moneytime.games/terms.

We may update this Policy where necessary to reflect legal requirements or changes to our services; the most current version applies.

California Notice: California residents can learn more about our practices in Section B (Additional provisions for California users).

Other U.S. States Privacy Rights: If you live in one of certain U.S. states outside California, you may hold further rights, which are set out in Section C.

A. General provisions relating to the GDPR (all users)

1. General information and controllers

1.1 Joint controllers

The following companies act as joint controllers for the processing of personal data described in this Policy:

  • Hideseek Games Limited, a company registered in Ireland under number 760481, with its registered office at Connaught House, 1 Burlington Road, Dublin 4, D04 C5Y6, Ireland; and
  • Earnify Limited, a company registered in Ireland under number 776117, with its registered office at 5th Floor Rear, Connaught House, 1 Burlington Road, Dublin 4, D04 C5Y6, Ireland.

Together, “Hideseek Games Limited” and “Earnify” are referred to as the “Controllers“, “we”, “us” or “our”. The Controllers work closely together to provide the App, the Company’s Games and the associated Loyalty Program, and have agreed between themselves which of them fulfils which obligations under the GDPR. The essence of that arrangement can be provided on request. The Controllers can be contacted using the details at the end of this Policy.

The Controllers determine the purposes and means of the processing of personal data, take responsibility for that processing, and act as the main point of contact for users of the App (the “Users“, “Data Subjects” or “You“).

By way of exception, for the App as made available on Apple iOS devices, Earnify Limited acts as the sole controller for the related data-processing activities and responsibilities. To that extent, references in this Policy to the Controllers acting jointly do not apply to that processing, and Earnify Limited alone determines the purposes and means of, and takes responsibility for, that processing.

1.2 Data Protection Officer

You can contact our Data Protection Officer at raffaello@hideseek.lol. When contacting the Data Protection Officer, please indicate the App or service your request relates to, and please do not include sensitive information such as a copy of an identity document. Please indicate your account number that you can find in your profile in the App.

2. Collection of personal data

We take the protection of your personal data seriously and process it confidentially and in accordance with data-protection law and this Policy. When you download and use the App, certain personal data — data by which you can be identified — is processed as described below.

2.1 Access to and storage of information on your device

When you use the App, information may be accessed (for example your IP address) or stored (for example cookies or similar technologies) on your device. Where this is strictly necessary to deliver the App properly, we rely on our legitimate interest in the technically faultless provision of our services and, where required, the applicable ePrivacy rules. Where access or storage serves other purposes — such as designing the App to meet your needs or analysing your usage — we do so only with your consent, which you can withdraw at any time with effect for the future. Further detail on the relevant processing and legal bases is set out in the sections below.

2.2 Information collected when you download the App

When you download the App, certain information is transmitted to the App Store you have chosen (Google Play Store or Apple App Store). To our knowledge this includes your IP address, a unique device identifier, location, the date and time of the request, the time-zone difference from Greenwich Mean Time, the content of the request, access status, the amount of data transferred, usage data, the operating system and its interface language. We have no influence over, and are not responsible for, this collection: the contract is concluded with the relevant store and governed by that store’s terms and privacy policy. Within your use of a store, we process only the reviews and associated data you publish, and we receive anonymous statistics (for example on downloads, uninstalls and crashes).

2.3 Data processing when you use the App

When you use the App we collect the data needed to provide it and its functions, including an internal device identifier, the version of your operating system, the time and content of access, your IP address (including approximate location and country), exact geolocation data (longitude and latitude where enabled), your advertising identifier (for example the Google advertising ID) or other unique identifiers, your device model and language, and log data. This data is processed to deliver the service and to detect, prevent and remedy misuse and technical faults. This processing is based on the performance of our contract with you and on our legitimate interest in improving our product and ensuring the App’s functionality and faultless operation. You can adjust some of this collection through the settings on your device and within the App.

The App is hosted by Amazon Web Services (AWS), which processes data on servers as described in Section 6. We have concluded data-processing agreements with our processors, requiring them to protect your data and not to disclose it without our instructions. For the internal management of our users we may process data in systems we use for that purpose, on the basis of our contract with you and our legitimate interest in managing our user relationships.

2.4 Technical functions of the App

Beyond its basic functions, the App may request access to the following, each of which is explicitly requested and can be granted or refused:

  • Push notifications — to keep you informed about matters such as changes to your earnings, reminders relating to your account or activity, updates to the App, and promotions or offers that may interest you.
  • Camera — for the identity-verification purposes described in the Facial Mapping Notice in Section D.
  • Location — to determine your market for a more tailored experience, give you access to our Loyalty Program and for security and fraud-prevention purposes.

Where you grant a permission, the related processing is based on your consent — in the case of location data, also on our legitimate interest in preventing fraud. You can withdraw consent at any time for the future, and can usually cancel a permission in your device settings, though this depends on your device and operating system. Withdrawing consent does not affect the lawfulness of processing carried out beforehand. Permissions that are not granted may limit your use of the App.

2.5 Contact

If you contact us through a contact form, by email or through a messaging service, we store the details you provide in order to handle your request and any follow-up questions. The legal basis is our legitimate interest in responding to you and, where your request concerns entering into or performing a contract, the performance of that contract. We will not pass this data on without a legal basis.

2.6 Payout functionality

If you wish to exchange the Monies you collect for payments or other rewards through the payout options in the App, we process the data needed to make the payment. To receive certain payouts, we may ask for your full name, email address and, where required, address details, and pass this information to the external payment provider. Our payment providers are PayPal (2211 N 1st St, San Jose, CA, USA; https://www.paypal.com/us/legalhub/privacy-full), Tango Card (4700 42nd Ave SW #430, Seattle, WA, USA; https://www.tangocard.com/legal/privacy-notice) and Tremendous (LLC, 118 W 22nd St, New York, NY, USA; https://www.tremendous.com/privacy/). We also collect the related transaction IDs. We do not process your payment-card or bank-account details ourselves; these are handled by the external providers. This processing is based on the performance of a contract with you or pre-contractual measures. We display your cash-out history so that you can review past payouts, based on our legitimate interest in providing convenient tools. You may change the email address linked to payouts at any time by contacting dataprotection@moneytime.dev.

2.7 Direct marketing to existing users

We may use the email address you provided during the payout process to send you information about products and services similar to those you have already used, on the basis of our legitimate interest in promoting our services and in accordance with applicable law. You may object to this at any time, and every marketing email contains an unsubscribe link. Where marketing is sent before any reward has been paid to you, or where the law otherwise requires it, we rely on your consent, which you can withdraw at any time.

3. Recipients and transfer of personal data

We do not transfer your personal data to third parties except where: we have said so in the description of the relevant processing; you have given your explicit consent; the transfer is necessary to establish, exercise or defend legal claims and is not overridden by your interests; we are under a legal obligation to transfer it; or it is necessary to perform a contract with you.

Subject to those principles and only to the extent necessary for the purposes described in this Policy, personal data may be shared with:

  • our affiliates;
  • authorised staff, contractors and agents who need access for the purposes above;
  • third-party service providers acting as processors or controllers, in particular AWS (hosting), FaceTec (identity-verification technology), Usercentrics (consent-management platform) and VERISOUL (fraud prevention);
  • third-party analytics and advertising partners (including, among others, Google and Meta and their sub-processors), which you can review and to which you can grant or refuse consent at any time through the in-app consent-management platform;
  • payment providers (PayPal, Tango Card and Tremendous) for the purpose of paying rewards;
  • police, administrative or judicial authorities and other public bodies where we are legally required to disclose data;
  • our insurers, lawyers and legal advisers, where needed to establish, exercise or defend our rights; and
  • any acquirer or successor in the context of a merger, acquisition or reorganisation.

Because our advertising and analytics partners generally act as independent controllers, we are not responsible for their processing, and we recommend reviewing each partner’s privacy notice to understand how they handle your data and the choices they offer.

4. Storage period

We keep personal data only for as long as necessary to achieve the purposes for which it is processed, plus any applicable legal retention or limitation periods, after which it is deleted or irreversibly anonymised. The retention period depends on the type of data and the purpose, and in particular on the duration of the contractual relationship, the regularity of your use of the App, any legal or contractual retention obligations, and whether the data requires special protection (such as banking information). In particular:

  • Personal data concerning Users is kept for the duration of the contractual relationship — that is, for as long as you keep the App on any device. We delete or anonymise the data of any User who uninstalls the App from all devices, or who does not use the App, for a period of three (3) years, subject to the points below.
  • Data used for marketing is kept for at most three (3) years following the end of the relationship or your last marketing-related interaction with us.
  • Data on our objection (opt-out) list is kept for five (5) years from the date of your objection.
  • Data that must be retained for accounting, legal, dispute-resolution or fraud-prevention reasons is kept for the period required by law or for the applicable limitation period, usually five (5) years.
  • Invoices are kept for ten (10) years from their date of issue.
  • Facial-geometry templates and photographs are kept for the period described in Section D (up to three months from collection), and are then irreversibly deleted.

5. Cookies, similar technologies and advertising partners

The App uses cookies and similar technologies. Some are technically necessary for the App to function; others are used to analyse usage or to display advertising. Processing based on strictly necessary technologies relies on our legitimate interest in the faultless delivery of the App and, where applicable, the ePrivacy rules. Processing for other purposes is based on your consent, which you can give or withdraw — for all purposes or granularly (for example, statistics, comfortable use of the App, and marketing) — at any time with effect for the future, including through the in-app consent-management platform provided by Usercentrics (https://usercentrics.com/privacy-policy/).

We integrate the technology of certain advertising partners so that they can deliver ad services within the App and show you ads relevant to your interests. Our advertising partners are listed in the table below, together with links to their privacy policies:

Advertising partnerPrivacy policy
AdColonyhttps://www.adcolony.com/privacy-policy/
AdMobhttps://policies.google.com/privacy?hl=en
AppLovinhttps://www.applovin.com/privacy/
Audience Network (Meta)https://www.facebook.com/privacy/policy/
BidMachinehttps://bidmachine.io/privacy-policy/
Chartboosthttps://answers.chartboost.com/en-us/articles/200780269
Digital Turbinehttps://www.digitalturbine.com/privacy-policy/
Facebook Ads (Meta)https://www.facebook.com/privacy/policy/
Fyberhttps://www.digitalturbine.com/privacy-policy/
InMobihttps://www.inmobi.com/privacy-policy
ironSourcehttps://www.is.com/privacy-policy/
Liftoffhttps://liftoff.io/privacy-policy/
Mintegralhttps://www.mintegral.com/en/privacy/
Mistplayhttps://www.mistplay.com/legal/privacy
Molocohttps://www.moloco.com/privacy-policy
Panglehttps://www.pangleglobal.com/privacy
Tapjoyhttps://www.is.com/privacy-policy/
TikTokhttps://www.tiktok.com/legal/page/us/privacy-policy/en
Unity Adshttps://unity.com/legal/privacy-policy
Vunglehttp://privacy.vungle.com/

We also work with data-processing partners that help us build and improve demographic and interest profiles, drawing on device identifiers, location and other data, in order to refine our products and services. Our data partners are listed in the table below, together with links to their privacy policies:

Data partnerPrivacy policy
Adjusthttps://www.adjust.com/terms/
Amazon Redshifthttps://aws.amazon.com/compliance/data-privacy/
Amplitudehttps://amplitude.com/privacy
AppLovinhttps://www.applovin.com/privacy/
AWS Athenahttps://aws.amazon.com/compliance/data-privacy/
Firebasehttps://policies.google.com/privacy
Google Analyticshttps://policies.google.com/privacy
OneSignalhttps://onesignal.com/privacy_policy
Tableauhttps://www.salesforce.com/ap/company/privacy/
ThinkingDataThinkingData privacy notice
Usercentricshttps://usercentrics.com/privacy-policy/
VERISOULVERISOUL terms & conditions

You can review the current list of these partners, access their privacy notices, and grant or refuse consent to their processing at any time through the in-app settings (Usercentrics consent-management platform).

6. Data hosting and transfers outside the EEA

Personal data is hosted by our external provider AWS, whose servers are located in the United States. Some data may also be transferred to the service providers mentioned above outside the European Economic Area (the “EEA”), mainly to the United States, and some data may be processed by our maintenance providers in Ukraine and Estonia. You can find the location of processing by these third parties in the in-app Usercentrics settings.

As an entity based in the EEA, we comply with the GDPR. Where personal data for which we are responsible is transferred outside the EEA to a country that does not offer an equivalent level of protection, we ensure an adequate level of protection by relying on one of the following: transfer to a recipient certified under the EU–US Data Privacy Framework, where the recipient is so certified and the transfer falls within the scope of its certification; a European Commission adequacy decision; binding corporate rules compliant with the GDPR; or the European Commission’s standard contractual clauses, supplemented by additional technical, contractual or organisational measures where necessary. A copy of the standard contractual clauses can be requested using the contact details below. Data may also be transferred on the basis of another derogation under Chapter V GDPR.

7. Data security

We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with the state of the art. We notify the competent supervisory authority — and, where required, affected Data Subjects — of any personal-data breach within the applicable time limits.

8. Your rights

Subject to the conditions in the GDPR, you have the following rights in relation to your personal data: the right to information; the right of access; the right to rectification; the right to erasure; the right to restriction of processing; the right to data portability; the right to object, including an unconditional right to object to processing for direct-marketing purposes; the right to withdraw consent at any time, without affecting the lawfulness of prior processing; and, in some jurisdictions, the right to give instructions on what happens to your data after your death.

You also have the right to lodge a complaint with a supervisory authority. In Ireland, this is the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland (www.dataprotection.ie), although we invite you to contact us first so that we can try to resolve your concern.

Opt-out. You can opt out of data sharing and of marketing communications (including emails and newsletters) using the link in the App’s settings, Usercentrics, by following the unsubscribe instructions in any marketing email, or by contacting us.

You can exercise your rights free of charge (except for manifestly unfounded, excessive or repeated requests) by contacting us at the details at the end of this terms. If you no longer wish to provide us with information through the App, you can uninstall it, although this does not delete data we have already collected.

9. Necessity of providing personal data

Providing personal data for a decision on entering into, or the performance of, a contract, or for pre-contractual steps, is voluntary. However, you will only be able to collect Monies and use the payout functions if you provide the necessary personal data.

10. Automated decision-making and profiling

To detect and prevent fraud, certain criteria — such as IP addresses, email addresses and gaming behaviour — are evaluated automatically. Where several indicators of fraudulent behaviour apply, a User’s access to the App may be restricted in part or blocked entirely. This processing is necessary to perform the contract with the User and to pursue our legitimate interest in preventing fraud. Data produced by this evaluation is generally deleted once it is complete.

B. Additional provisions for California users

These provisions supplement the rest of this Policy and apply only to residents of California. They describe how we collect, use and share personal information under the California Consumer Privacy Act and its implementing regulations (the “CCPA”). Some of the ways in which we disclose personal information are treated as a “sale” or “sharing” under the CCPA. We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age.

1. Personal information we collect, use and disclose

We may collect the following categories of personal information from California residents through the App, and use and disclose them for the purposes indicated:

  • Identifiers (such as name, email address, telephone number, mailing address, unique and online identifiers and IP address) — to communicate with you and provide customer service; to operate our business and provide the App; for marketing, personalisation and advertising; for research and analytics; to develop and improve the App; to measure advertising effectiveness; for safety and security; and to meet our legal obligations.
  • Customer records (such as name, address and financial information as defined in Section 1798.80(e) of the California Civil Code) — for the purposes listed under Identifiers.
  • Internet or other electronic network activity (such as your interactions with the App and advertisements, and usage information) — to provide and operate the App; for marketing and advertising; for research and analytics; to develop and improve the App; to measure advertising; for safety and security; and to meet our legal obligations.
  • Geolocation data (approximate location, which may be derived from your IP address or device) — for the purposes above and to verify your identity.
  • Inferences (profiles reflecting your preferences and interests) — for the purposes above and to verify your identity.
  • Sensitive personal information (as described in the Facial Mapping Notice in Section D) — for internal business purposes and to meet our legal obligations.

For cross-context behavioural advertising or other “sales”, we may disclose identifiers, internet or other electronic network activity, and geolocation data to third-party advertisers, advertising networks, analytics providers and social networks, in order to show you relevant ads and carry out related marketing, analytics, reporting and attribution.

2. Your California privacy rights

Under the CCPA you have the right to: know the categories and specific pieces of personal information we have collected, their sources, our purposes, and the categories of recipients (including those to whom we have sold or shared personal information); delete the personal information we have collected from you, subject to exceptions; correct inaccurate personal information; opt out of the sale of your personal information and of its sharing for cross-context behavioural advertising; and non-discrimination for exercising your rights. Where we process sensitive personal information (such as the biometric data described in Section D), you may also limit its use to the purposes permitted under the CCPA.

You can opt out using the opt-out link in the App’s settings, Usercentrics, by following the unsubscribe instructions in any marketing email, or by contacting us.

To exercise your rights, email dataprotection@moneytime.dev with the subject line “CCPA and US Rights Request” and your account number. We may need to verify your identity by matching the information you provide with our records, and may decline a request where we cannot do so. You may use an authorised agent where you provide sufficient evidence of their authority and verify your own identity. We will respond within the time permitted by law and will tell you if we need an extension.

“Shine the Light”. California residents may request information about our disclosure of personal information to third parties for their own direct-marketing purposes. Such requests should be sent to dataprotection@moneytime.dev with “California Shine the Light Request” in the subject line and should include your name and postal address. We are required to respond to only one such request per customer each calendar year.

C. Additional provisions for residents of Other U.S. States

These provisions supplement the rest of this Policy and apply only to residents of U.S. states other than California that have a comprehensive privacy law to which we are subject (the “Other U.S. States“). California residents should refer to Section B.

1. Your rights

Subject to your state of residence, you may have the right to: confirm and access the personal data we process and obtain a portable copy of data you provided; delete your personal data, subject to exceptions; correct inaccuracies in your personal data; opt out of the sale of your personal data and of its use for targeted advertising; and appeal a decision on your request. Where we process sensitive data, including biometric data, we do so with your consent as described in Section D. Oregon residents may request a list of the specific third parties to which we disclose personal data, and Delaware residents may request the categories of third parties to which we disclose personal data. Depending on your state, you may also designate an authorised agent to make certain requests on your behalf.

To exercise these rights, email dataprotection@moneytime.dev. We may need to authenticate your identity before acting on a request. You can opt out through the opt-out link in the App’s settings, by following the unsubscribe instructions in any marketing email, or by contacting us.

2. Miscellaneous

If you make a privacy-rights request, we will retain the data submitted with your request for record-keeping purposes. You will not be discriminated against for exercising your rights, and we will not deny you services or charge you different prices in retaliation.

D. Biometric Data Notice

1. Introduction

This Biometric Data Notice (the “Notice”) describes how the Controllers gather, process, retain and safeguard the facial-mapping data captured through the FaceTec software (“FaceTec”) (https://dev.facetec.com/privacy-sdk) when you use the MoneyTime App. Where there is any inconsistency between this Notice and the rest of this Policy, this Notice governs facial-mapping data and photographs collected through FaceTec. This Notice is intended to comply with any applicable federal, state or local laws that apply to facial-mapping data, including the Illinois Biometric Information Privacy Act and comparable biometric-privacy laws. By using FaceTec, you represent that you are not accessing it from any jurisdiction in which such use is unlawful.

2. Consent

Before any facial-mapping template or photograph is collected, we present you with this Notice and ask you to give your express, informed and written consent to the collection, storage and use of your facial-mapping data for the purposes described below by clicking “Proceed”. You are not required to provide facial-mapping data in order to use the App generally, but you will not be able to use the cash-out feature without completing identity verification. You may withdraw your consent at any time as described in Section D.6 (Your rights); withdrawing consent does not affect the lawfulness of processing carried out beforehand.

3. Collection of facial-mapping data and photographs

To use the cash-out feature within the App for the first time, you must use your device’s camera and the FaceTec software embedded in the App to scan your face, which produces (a) a facial-mapping template unique to you and (b) a photograph of your face. We use this data solely to: verify that you are a real person; prevent fraud; and confirm that you are not an underage minor. We do not use facial-mapping data for any advertising, marketing, profiling or other purpose.

4. Storage, protection and retention

Your facial-mapping template and photograph are stored on server space we rent from Amazon Web Services (AWS) (see Section 6 above). We apply strong technical and organisational safeguards, such as encryption and protected storage, to protect this information from unauthorised access, disclosure or misuse, using the reasonable standard of care applicable to our industry and at least the standard we use for other confidential and sensitive information. Your facial-mapping template and photograph are stored for up to three (3) months from collection, after which each is permanently and irreversibly deleted. In any event, we will permanently destroy your facial-mapping data no later than three years after your last interaction with us, or sooner where required by law.

5. Sharing

We do not sell, rent, exchange or otherwise derive any profit from your facial-mapping data or photographs. We do not disclose your facial-mapping data or photographs unless: you consent to the disclosure; the disclosure is required to complete a financial transaction you requested or authorised; or the disclosure is required by law, regulation or valid legal process, such as a court order or subpoena. FaceTec operates entirely inside our own environment, and your facial-mapping data and photographs are never shared with FaceTec itself. As noted above, the data is stored on AWS acting as our processor under a written data-processing agreement.

6. Your rights

Depending on where you live, you may have the right to: access your facial-mapping data and information about how and why it was collected and to whom it has been disclosed; request correction of inaccurate or incomplete data; request deletion of your data, subject to legal exceptions; and withdraw your consent to the collection and use of your data, bearing in mind that doing so may limit your ability to use FaceTec and the cash-out feature.

7. How to exercise your rights

To exercise any of these rights, or if you have questions about this Notice, please contact us at dataprotection@moneytime.dev.

Contact and Data Protection Officer

For more information about the processing of your personal data, or to exercise your rights, you can contact us:

We reserve the right to update this Policy where necessary to comply with applicable data-protection law and to reflect changes to our services. The most current version applies to your use of the App.