Privacy Policy
Qinhuangdao Doudou Technology Co., Ltd ("Doodlejay", "兜兜科技", "we", "us", or "our") operates websites, mobile applications published on the Google Play Store and Apple App Store, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services.
By accessing or using our Services you agree to this Privacy Policy. If you do not agree, please discontinue use of the Services.
1. Information we collect
1.1 Information you provide directly
- Account information: name, email, phone, profile photo (when you register for our Services).
- Communications: messages and attachments you send us via forms, email, chat, or support tickets.
- Payment information: billing details processed through PCI-DSS compliant third-party payment processors; we do not store full card numbers.
- Business information: company name, role, project requirements you share when requesting quotes or proposals.
1.2 Information collected automatically
- Device information: device model, operating system and version, unique device identifiers (IDFA, GAID, OAID, IMEI where permitted), language, time zone.
- Log information: IP address, access times, pages viewed, referring URLs, app crash logs and performance data.
- Location information: country, region, city-level geolocation derived from IP; precise GPS only with your explicit consent.
- Usage information: features used, buttons tapped, session length, ad interactions (impressions, clicks, completions).
- Cookies, mobile SDK identifiers, and similar tracking technologies (see §12).
1.3 Information from third parties
- Social login providers (e.g., Apple, Google, Facebook) when you sign in via those services.
- Analytics and crash-reporting providers (e.g., Firebase, Google Analytics, Sentry, Bugsnag).
- App store platforms (Google Play, Apple App Store) — basic app installation and update metadata.
- Advertising networks and measurement partners (see §6).
2. How we use information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve the Services.
- To process transactions and fulfill orders or service contracts.
- To authenticate users and prevent fraud or abuse.
- To respond to comments, questions, and customer support requests.
- To send administrative information, including updates to our terms and policies.
- To deliver and measure advertising (subject to applicable consent rules — see §4, §6).
- To perform analytics, research, and product development.
- To comply with legal obligations and enforce our terms.
We do not sell your personal information for money. Where advertising is involved, we act as a controller of first-party data and may share hashed identifiers with ad partners under the lawful bases described in §4.
3. App store policies (Google Play & Apple App Store)
Our mobile applications are published on Google Play (operated by Google LLC) and the Apple App Store (operated by Apple Inc.). We commit to full compliance with the following store policies, in their latest published versions:
3.1 Google Play Developer Program Policies
- User Data Policy — we only access the minimum data necessary, declare all data access in the Play Console, and never sell personal data.
- Permissions Policy — runtime permissions are requested only when needed, with clear in-context explanations.
- Ad Policy — ads are clearly distinguishable from app content, do not interfere with navigation, and follow the Families Policy where applicable.
- Families Policy — apps intended for children comply with COPPA and the Google Play Families Policy.
- Privacy Policy & Data Safety Form — we maintain a current Privacy Policy and a complete Data Safety form for every app listing.
- Device & Network Abuse Policy — no covert data collection, no background listening, no undisclosed network usage.
- Deceptive Behavior Policy — no impersonation, no misleading claims, no undisclosed in-app functionality.
3.2 Apple App Store Review Guidelines
- Guideline 1.x (Objectionable Content) — content moderation in any user-generated features.
- Guideline 2.x (Functionality) — apps perform as advertised; beta features are clearly marked; no placeholders.
- Guideline 3.x (Required Information) — accurate metadata, working websites, complete privacy policy URL.
- Guideline 4.x (Design) — adherence to the Apple Human Interface Guidelines and the iOS Privacy policy.
- Guideline 5.x (Legal) — privacy, intellectual property, gambling, and other legal compliance.
- Guideline 5.1.1 (Privacy — Data Collection and Storage) — minimal data collection, clear consent, no covert tracking, all required usage strings provided via
NSPrivacyAccessedAPITypesandNSPrivacyTracking. - App Tracking Transparency (ATT) — we request tracking permission only after a clear ATT prompt; if denied, we honor the user's choice across the entire app and all integrated SDKs.
- Privacy Nutrition Labels — every App Store listing accurately reports the data we collect and how it is used.
4. Global privacy laws we comply with
Depending on your jurisdiction, the following laws may apply to your use of our Services. We design our practices to satisfy each.
4.1 GDPR — General Data Protection Regulation (European Economic Area & UK)
For users in the EEA, UK, and Switzerland we act as a data controller. Our legal bases are: (a) consent (for non-essential cookies, advertising, marketing), (b) contract performance (to deliver the Services you request), (c) legitimate interests (security, fraud prevention, product improvement, balanced against your rights), and (d) legal obligation.
We honor the following GDPR rights: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection (including objection to direct marketing and profiling), withdrawal of consent at any time, and the right to lodge a complaint with a supervisory authority. Our EU representative is identified in §16 on request.
4.2 UK GDPR & Data Protection Act 2018 (United Kingdom)
For UK users we apply the same protections as the GDPR, with the UK Information Commissioner's Office (ICO) as the competent supervisory authority. We support the international data transfer mechanisms approved for the UK (UK IDTA, UK Addendum to the EU SCCs).
4.3 CCPA / CPRA — California Consumer Privacy Act (USA, California)
For California residents we honor the rights to: know what personal information is collected, sold, or shared; delete personal information; correct inaccurate information; limit the use of sensitive personal information; opt out of the sale or sharing of personal information; and non-discrimination for exercising rights.
We do not sell personal information for money. We may share identifiers with advertising partners as described in §6, which California law may treat as "sharing for cross-context behavioral advertising". California residents may opt out via the in-app "Privacy Choices" link or the web form at privacy@doodlejay.com.
4.4 VCDPA, CPA, CTDPA, UCPA, TDPSA — other US state laws (Virginia, Colorado, Connecticut, Utah, Texas, etc.)
For residents of US states with comprehensive privacy laws we honor rights of access, correction, deletion, data portability, and opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling producing legal or similarly significant effects. We process universal opt-out signals (e.g., Global Privacy Control) where required.
4.5 COPPA — Children's Online Privacy Protection Act (USA)
Our general-audience apps and websites are not directed at children under 13. We do not knowingly collect personal information from children under 13 in a general-audience context. For apps we publish that are designed for children or that we identify as falling under the Google Play Families Policy or Apple Kids Category, we comply fully with COPPA: verifiable parental consent before collection, minimal data collection, no behavioral advertising in child-directed contexts, and a clear parental dashboard. See §5 for the full age policy.
4.6 PIPL — Personal Information Protection Law (Mainland China)
For users in Mainland China we comply with PIPL and the related CAC, CSL, and DSL regulations. Legal bases include consent, contract necessity, legal obligation, and public interest. We provide rights of access, correction, deletion, portability, withdrawal of consent, and explanation of processing rules. Cross-border transfers occur only via CAC-assessed mechanisms (security assessment, Standard Contract, certification) with appropriate impact assessments.
4.7 LGPD — Lei Geral de Proteção de Dados (Brazil)
For Brazilian users we honor the rights under LGPD, including confirmation of existence, access, correction, anonymization, portability, deletion, and information about sharing. The ANPD is the supervisory authority.
4.8 PDPA — Personal Data Protection Act (Singapore, Thailand, Malaysia)
For users in Singapore, Thailand and Malaysia we honor PDPA rights, including access, correction, and withdrawal of consent, and we publish a clear Data Protection Notice on request.
4.9 PIPEDA — Personal Information Protection and Electronic Documents Act (Canada)
For Canadian users we follow the principles of PIPEDA and applicable provincial laws (including Quebec Law 25), with a designated privacy officer responsible for compliance.
4.10 APPI — Act on the Protection of Personal Information (Japan)
For Japanese users we comply with APPI, including proper handling of "Personal Information" and "Anonymously Processed Information", and respect the rights of disclosure, correction, and cessation of use.
4.11 PIPA — Personal Information Protection Act (South Korea)
For Korean users we comply with PIPA, including rights of access, correction, deletion, suspension of processing, and the requirement for explicit consent for cross-border transfers.
4.12 Other jurisdictions
We extend substantively equivalent protections to users in jurisdictions with similar laws, including but not limited to: Australia (Privacy Act 1988), New Zealand (Privacy Act 2020), India (DPDPA 2023), Indonesia (UU PDP), Philippines (DPA 2012), Vietnam (PDPD 2023), UAE (DPL), Saudi Arabia (PDPL), Turkey (KVKK), South Africa (POPIA), Nigeria (NDPR), Kenya (DPA 2019), Argentina (Ley 25.326), Chile (Ley 19.628), Mexico (LFPDPPP), Israel (PPL), Switzerland (nDSG/FADP), and any other jurisdiction in which we operate.
5. Age restrictions & children's privacy
5.1 Minimum age
Our general-audience Services are not directed at children. You must be at least 13 years old (or older where required by local law — e.g., 14 in the PRC/Korea under certain statutes, 16 in the EU under GDPR if consent is the legal basis) to use the Services without parental consent.
5.2 Regional age thresholds (where higher than 13)
- EEA / UK — 16 by default; member states may lower to 13 (and we accept 13 where lawful).
- Mainland China (PIPL) — 14.
- South Korea (PIPA) — 14.
- California (COPPA + CCPA) — under 13 requires verifiable parental consent; 13–15 may consent with affirmative authorization under CCPA.
- Australia — we treat 15 as the minimum for consent under the Privacy Act.
- Brazil (LGPD) — 13 for consent via parental authorization; we treat this as a minimum.
5.3 Child-directed apps
For apps that are designed for children or that we identify in store metadata as targeting a child audience, we:
- Obtain verifiable parental consent before any personal data collection.
- Disable behavioral advertising and all cross-context tracking.
- Disable ad personalization and remarketing in child-directed contexts.
- Avoid persistent identifiers where possible; use only essential identifiers.
- Provide a parental dashboard to review, export, and delete the child's data.
5.4 If we learn we have collected data from a child in violation of this policy
We will delete that information as soon as possible. Parents may contact us at privacy@doodlejay.com to request review or deletion.
6. Advertising networks & SDKs we integrate
To support our Services, we integrate the following advertising and analytics SDKs. Each SDK may collect device identifiers, IP address (truncated), coarse location, and ad-interaction events. For each partner we provide an opt-out path and link to the partner's own privacy policy.
6.1 Google AdMob / Google Ad Manager
AdMob serves ads, performs ad attribution, and (where consent is granted) personalizes ads. Google's use of advertising identifiers is governed by the Google Privacy Policy and Google Ads Policy. We serve ads in "non-personalized" mode by default for users in the EEA, UK, and other jurisdictions requiring consent, until consent is obtained through our CMP (Consent Management Platform).
6.2 Meta Audience Network (formerly Facebook Audience Network)
Meta serves display, native, and video ads. The Meta Data Policy governs their data use. We use Meta's "Limited Data Use" flag for California users and the Meta LDU controls where applicable.
6.3 Unity Ads
Unity Ads serves video and playable ads. See the Unity Privacy Policy. Unity supports CCPA opt-out signals.
6.4 AppLovin / MAX (AppLovin Exchange)
AppLovin serves ads across formats and partners. See the AppLovin Privacy Policy. AppLovin participates in IAB Europe TCF v2.2 and honors CMP signals.
6.5 ironSource (now part of Unity)
ironSource serves ads via mediation. See the ironSource Privacy Policy. ironSource honors user opt-outs via the SDK.
6.6 Pangle (ByteDance / TikTok)
Pangle serves video, native and rewarded ads. See the Pangle Privacy Policy. Pangle supports IAB TCF signals and offers a user opt-out.
6.7 Mintegral
Mintegral serves ads globally. See the Mintegral Privacy Policy. Mintegral is a member of the IAB Europe TCF and supports CMP signals.
6.8 InMobi
InMobi serves display, video, and native ads. See the InMobi Privacy Policy. InMobi supports the IAB CCPA Compliance Framework.
6.9 Chartboost (now part of Zynga / Take-Two)
Chartboost serves in-app advertising for games. See the Chartboost Privacy Policy.
6.10 Vungle (now Liftoff)
Vungle serves video and playable ads. See the Vungle Privacy Policy.
6.11 Tapjoy
Tapjoy serves rewarded ads and offerwalls. See the Tapjoy Privacy Policy. Tapjoy supports user opt-out.
6.12 AdColony (now part of Digital Turbine)
AdColony serves video and interactive ads. See the AdColony Privacy Policy.
6.13 Fyber (now part of Digital Turbine)
Fyber serves ads and offers mediation. See the Fyber Privacy Policy.
6.14 Digital Turbine
Digital Turbine provides monetization and ad mediation. See the Digital Turbine Privacy Policy.
6.15 Smaato
Smaato is a real-time ad exchange. See the Smaato Privacy Policy.
6.16 Verizon Media / Yahoo (now part of Microsoft / MSN)
Where used, see the Verizon Media Privacy Policy.
6.17 Google AdSense / AdX / Authorized Buyers
Where we display ads in our web properties, we may use Google AdSense or Authorized Buyers, governed by the Google Privacy Policy.
6.18 Other partners (transparency list)
We may also integrate: Microsoft Advertising (Bing Ads), Amazon Publisher Services, Criteo, Taboola, Outbrain, Snap, X (Twitter), Pinterest, Reddit, TikTok, LinkedIn, BidSwitch / Xandr (Microsoft), OpenX, PubMatic, Index Exchange, Magnite (formerly Rubicon), Sovrn, TripleLift, Verizon Media, Lotame, Nielsen DAR, Oracle Advertising, and similar partners — each governed by their own privacy policies, accessible from the partner's website.
6.19 Ad mediation & programmatic monetization platforms (aggregators)
To maximize fill rate, eCPM and global coverage while keeping SDK weight under control, we route ad requests through one or more ad mediation layers. A mediation platform ("aggregator") is an SDK/server that calls multiple demand sources (ad networks, SSPs, DSPs) in a single auction, then returns the winning ad. Each aggregator may itself collect device identifiers, IP address (truncated), coarse location, app bundle id, ad size, and user consent state, and may pass this data to its child demand partners in the auction. Below is the global list of mediation platforms we may integrate, with their privacy policies.
6.19.1 AppLovin MAX (AppLovin Exchange mediation)
AppLovin's unified bidding mediation. Connects to 25+ ad networks, supports in-app bidding and waterfall. Privacy Policy.
6.19.2 Google AdMob Mediation (now Google Mobile Ads SDK with mediation)
Google's official mediation, with first-price and second-price auction support. TCF v2.2 compliant. Privacy Policy.
6.19.3 Unity LevelPlay (formerly ironSource mediation)
Unity's unified auction mediation. Integrates with ironSource, Unity Ads and 20+ third-party networks. Privacy Policy.
6.19.4 Pangle Mediation (bytedance / TikTok)
ByteDance's mediation platform, primarily serving the APAC region and increasingly globally. Privacy Policy.
6.19.5 Mintegral Mediation
Mintegral's in-app bidding mediation with strong APAC/LATAM presence. Privacy Policy.
6.19.6 TopOn (bytengine / 广州塔酷信息)
Asia-Pacific focused aggregation platform with strong support for mainland China and SEA. Privacy Policy.
6.19.7 TradPlus (众连科技 / Shanghai TradPlus)
Cross-regional ad mediation, popular with Chinese outbound developers. Privacy Policy.
6.19.8 InMobi Mediation
InMobi's unified auction layer. Privacy Policy.
6.19.9 Liftoff Monetize (Vungle mediation)
Liftoff's mediation platform, integrated with Vungle, Liftoff Direct and external networks. Privacy Policy.
6.19.10 Chartboost Mediation (Take-Two Interactive)
Chartboost's unified auction platform for game publishers. Privacy Policy.
6.19.11 Digital Turbine Mediation (AdColony + Fyber)
Digital Turbine's unified mediation combining AdColony, Fyber and DT Exchange. Privacy Policy.
6.19.12 Tapjoy Offerwall & Mediation
Tapjoy's mediation layer plus the Tapjoy offerwall reward path. Privacy Policy.
6.19.13 Smaato Mediation (now part of Verve Group)
Smaato's real-time bidding mediation for in-app and mobile web. Privacy Policy.
6.19.14 Meta Bidding (formerly FAN Bidding)
Meta Audience Network's in-app bidding, which can be invoked through AdMob/MAX/LevelPlay as a demand source. Privacy Policy.
6.19.15 BidMachine
An independent header-bidding-style SDK and SSP, with a mediation layer. Privacy Policy.
6.19.16 Moloco (DSP + Moloco Cloud)
AI-driven programmatic monetization platform, primarily for e-commerce and apps. Privacy Policy.
6.19.17 Yandex Ads (formerly Yandex Advertising Network)
Yandex's mediation and ad serving for the Russia/CIS region. Privacy Policy.
6.19.18 VK Ads (formerly myTarget / VKontakte Ad Network)
VK / Mail.ru Group's ad network and mediation, serving Russia and CIS. Privacy Policy.
6.19.19 PubMatic (SSP / OpenWrap SDK)
Header-bidding wrapper and supply-side platform, used in mobile and CTV. Privacy Policy.
6.19.20 OpenX
OpenX's mobile SDK and SSP. Privacy Policy.
6.19.21 Index Exchange (Index Exchange Mobile SDK)
Index Exchange's mobile header bidding SDK. Privacy Policy.
6.19.22 Magnite (formerly Rubicon Project / Magnite Mobile)
Magnite's mobile SSP, often called as a demand source in mediation. Privacy Policy.
6.19.23 Equativ (formerly Smart AdServer / EQUATIV)
Independent ad serving and mediation platform. Privacy Policy.
6.19.24 Ogury
Personified ads platform for mobile, with strong EU presence. Privacy Policy.
6.19.25 Criteo (Criteo SDK / Retail Media)
Retargeting and shopping-focused ad platform, used in both app and web mediation. Privacy Policy.
6.19.26 Taboola
Native content recommendation platform, used in mobile in-app and mobile web. Privacy Policy.
6.19.27 Outbrain
Native content recommendation and amplification platform. Privacy Policy.
6.19.28 Microsoft Advertising (formerly Bing Ads / Microsoft Monetize)
Microsoft's ad serving, bidding and mediation for MSN, Outlook, and partner apps. Privacy Statement.
6.19.29 Amazon Publisher Services & Amazon Ads
Amazon's programmatic ad offerings for publishers. Privacy Notice.
6.19.30 Yahoo / Verizon Media (now part of Yahoo / Apollo)
Yahoo's programmatic monetization stack. Privacy Policy.
6.19.31 Reddit Ads
Reddit's first-party ad platform, integrated in app mediation for off-app audience extension. Privacy Policy.
6.19.32 Snap Ads (Snapchat Audience Network — limited availability)
Snap's limited audience network for in-app video. Privacy Policy.
6.19.33 LinkedIn Audience Network
LinkedIn's B2B-focused audience extension, where available. Privacy Policy.
6.19.34 TikTok Ads (Pangle outside China, TikTok Ads SDK in some regions)
TikTok / ByteDance ad SDK, sometimes integrated in mediation outside of Pangle. Privacy Policy.
6.19.35 X (Twitter) Ads (via MoPub/Meta Bidding, pre-shutdown)
Where historical integrations remain in place, see X Privacy Policy. Note: MoPub was sunset by X in 2022; some mediation layers may still carry the integration.
6.20 Offerwall, survey & rewarded-task platforms
In addition to standard ad formats, we may integrate offerwall and survey-based monetization partners. These platforms present users with a list of third-party tasks (installs, surveys, sign-ups) in exchange for in-app rewards. Each task is fulfilled by a downstream partner that operates its own data practices.
6.20.1 Tapjoy Offerwall
Tapjoy's offerwall reward path. Privacy Policy.
6.20.2 Adjoe (offerwall, by adjoe GmbH)
Playtime-based offerwall for mobile games. Privacy Policy.
6.20.3 OfferToro (offerwall, by ironSource/Unity)
OfferToro's offerwall integration through ironSource / Unity. Privacy Policy.
6.20.4 Pollfish (surveys)
Survey-based monetization with pay-per-completion. Privacy Policy.
6.20.5 Theorem Reach (surveys)
Survey-based monetization. Privacy Policy.
6.20.6 BitLabs (surveys)
Survey-based offerwall for game publishers. Privacy Policy.
6.20.7 YSO Networks (offerwall)
Offerwall and CPA monetization. Privacy Policy.
6.20.8 Cashwalk / Cashyy / Mistplay (playtime-based reward platforms)
Playtime- and milestone-based reward platforms. Each is governed by its own privacy policy, accessible from the partner's website.
6.21 IAB Europe Transparency & Consent Framework
Our CMP is configured to operate in line with the IAB Europe TCF v2.2. Signals (TC String, AC String) are propagated to all TCF-registered SDKs integrated in our apps — including the mediation and offerwall platforms listed in §6.19 and §6.20. Vendors that are not TCF-registered receive consent via our internal consent surface. The current list of TCF-registered vendors we invoke is published in our app's "Privacy Choices" panel and updated as integrations change.
6.22 IAB Tech Lab Open Measurement (OM SDK)
To support viewability, fraud prevention, and brand-safety measurement without leaking user-level identifiers, we integrate the IAB Tech Lab Open Measurement SDK. The OM SDK does not itself collect user data; it provides a technical interface through which third-party measurement vendors (e.g., IAS, DoubleVerify, MOAT) can verify ad impressions. See the OM SDK specification.
6.23 IAB CCPA Compliance Framework
For California residents, ad partners participating in the IAB CCPA Compliance Framework honor our opt-out signal (via the CMP or GPC) as a valid request not to "sell" or "share" personal information.
6.24 Data passed in a bid request
When an ad slot is auctioned, the following categories of data may be passed in the bid request to each demand source listed above (subject to applicable consent):
- App bundle id, app version, store URL.
- Device identifiers: IDFA, GAID, OAID, and app-specific IDs.
- Device model, OS, OS version, screen size, language, time zone.
- IP address (typically truncated to /24 or /48) and inferred country / region.
- Coarse location (city-level) when consent is granted for location-based ads.
- Ad slot id, size, format, position, and floor price.
- User consent state (TC String, GPC signal, age-gate state).
- Frequency-capping, sequence, and contextual signals.
We do not pass precise GPS location, contact lists, or biometric data in bid requests. Where a child-directed context is active (§5.3), bid requests are stripped of any identifier usable for cross-context behavioral advertising and behaviorally targeted bids are blocked.
7. Ad formats we display
Our mobile apps and, where applicable, our websites may display the following ad formats. We describe how each format is delivered, what data is used, and how you can opt out.
7.1 App open / Splash ads
Displayed when a user opens or returns to the app. May be skippable after a short interval. Uses device identifiers and coarse location for frequency capping and personalization. Honored by all integrated networks.
7.2 Rewarded video ads
Opt-in: the user explicitly chooses to watch a video in exchange for an in-app reward. The ad SDK records the watch event for verification of the reward. Required disclosure of reward value is shown before playback.
7.3 Interstitial ads
Full-screen ads displayed at natural transition points (e.g., between levels, after content). We respect frequency caps and avoid interstitials that interrupt critical user flows.
7.4 Banner ads (including MREC)
Inline display ads. May be static, animated, or native. Refreshes may be limited or disabled to reduce intrusiveness.
7.5 Native ads
Ads rendered to match the visual design of the host app and clearly marked as "Sponsored" or "Ad". We do not allow native ads to masquerade as editorial content.
7.6 Playable ads
Interactive try-before-you-install ads. Use of playable ads is opt-in or limited to appropriate contexts.
7.7 In-app offerwalls
Where integrated, the user completes tasks (surveys, app installs, etc.) for in-app rewards. We disclose reward values and partner identities before participation.
8. Data sharing & disclosure
We share information only as described below, and we do not sell personal information for money.
- Service providers / processors — cloud hosting, analytics, customer support, payment processing, email delivery. Bound by data processing agreements.
- Advertising partners — as described in §6, with appropriate consent.
- App store operators — Google and Apple receive crash, install, and update metadata as part of normal store operation.
- Legal and safety — when required by law, valid legal process, or to protect the safety, rights, or property of Doodlejay, our users, or others.
- Business transfers — in a merger, acquisition, or sale of assets, with continued protection of personal information per this Policy.
- With your consent — for any other purpose disclosed at the time of collection.
9. International data transfers
We are a globally distributed company. Your information may be transferred to, stored, and processed in countries other than your own, including the United States, the European Economic Area, Singapore, Japan, Mainland China, and the United Kingdom. We use the following transfer mechanisms as applicable:
- EU Standard Contractual Clauses (SCCs) 2021/914 (Module 1 and Module 2).
- UK International Data Transfer Agreement (IDTA) and the UK Addendum to the EU SCCs.
- China's CAC Standard Contract for cross-border transfers (when PIPL applies).
- APEC Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) where applicable.
- Data Privacy Framework (DPF) for transfers from the US to participating countries where our processors are certified.
We conduct Transfer Impact Assessments (TIAs) as required and apply supplementary technical and organizational measures (encryption, access controls, minimization) to protect your information.
10. Data retention & security
We retain personal information only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention windows:
- Account data: for the life of the account, plus up to 24 months after deletion for backup, legal, and audit purposes.
- Server logs: up to 12 months.
- Ad interaction events (impressions, clicks): up to 13 months unless local law requires a shorter period.
- Support correspondence: up to 36 months for quality and training.
- Financial records: per the applicable tax and accounting laws (typically 5–10 years).
We employ industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, role-based access control, MFA on all administrative accounts, regular vulnerability scanning and penetration testing, and an incident response plan with 72-hour breach notification where required.
11. Your rights & choices
Depending on your jurisdiction, you may have the following rights. We provide a single intake to exercise all of them.
- Access — request a copy of the personal information we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal information, subject to legal exceptions.
- Restriction — limit how we process your data while a complaint is investigated.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests, including profiling.
- Opt out of sale or sharing — California residents may opt out at any time.
- Limit use of sensitive personal information — California residents may direct us to limit our use of SPI to that necessary to provide the Services.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Non-discrimination — we will not deny service, charge different prices, or provide a different level of quality for exercising your rights.
To exercise these rights, email privacy@doodlejay.com or use the in-app "Privacy Choices" link. We respond within 30 days; for complex requests, we may extend by up to 60 days with notice. We may need to verify your identity before acting on the request.
12. Cookies & similar technologies
Our website uses cookies, local storage, and similar technologies. We classify them as:
- Strictly necessary — required for the site to function (session, security, load balancing). Always on.
- Functional — remember your preferences (language, region). Optional.
- Analytics — anonymized or pseudonymous usage statistics. Optional.
- Advertising — used to deliver and measure ads. Requires consent where applicable (EEA, UK, etc.).
You can manage cookie preferences via the in-page "Cookie preferences" link, or via your browser settings (including blocking all cookies — note this may break some site features).
13. Third-party links & services
Our Services may contain links to third-party websites or services we do not operate. We are not responsible for their privacy practices. We encourage you to read the privacy policy of every site and service that collects your personal information.
14. Do Not Track & global opt-outs
- We honor Global Privacy Control (GPC) as a valid opt-out signal under CCPA/CPRA and equivalent US state laws.
- We honor Apple's App Tracking Transparency (ATT) prompt — your choice is propagated to all integrated SDKs.
- We honor Android's "Opt out of Ads Personalization" setting in Google Settings.
- Where required, we participate in industry opt-out mechanisms: DAA (US), EDAA (EU/UK), DAAC (Canada), and the IAB TCF.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Effective date" at the top indicates the latest revision. For material changes, we will provide additional notice (e.g., in-app banner, email, or push notification) where required by law. Continued use of the Services after the effective date constitutes acceptance.
16. Contact us
If you have any questions about this Privacy Policy, your rights, or our practices, please contact us:
- Privacy & Data Protection Officer — privacy@doodlejay.com
- General support — support@doodlejay.com
- Sales & partnerships — contact@doodlejay.com
- VIP inquiries — vip@doodlejay.com
- Postal mail — Qinhuangdao Doudou Technology Co., Ltd, Qinhuangdao, Hebei Province, China · 秦皇岛兜兜科技有限公司
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. We will provide a list of relevant authorities on request.
中文摘要 (Chinese summary)
本政策是 Doodlejay (秦皇岛兜兜科技有限公司) 就其网站、移动应用及广告变现产品所收集、使用、共享和保护用户个人信息所遵循的完整规则。我们在全球范围内遵守适用的隐私法律,包括但不限于欧盟 GDPR、英国 GDPR、美国 CCPA/CPRA、COPPA、各州隐私法、中国 PIPL、巴西 LGPD、新加坡/泰国 PDPA、加拿大 PIPEDA、日本 APPI 与韩国 PIPA。儿童(未满 13 周岁,或当地法律规定的更高年龄)需在监护人同意下使用我们的服务,且儿童定向应用严格遵守相关儿童保护法规,不进行行为广告或跨上下文追踪。我们在应用中集成了 Google AdMob、Meta Audience Network、Unity Ads、AppLovin/MAX、ironSource、Pangle、Mintegral、InMobi、Chartboost、Vungle、Tapjoy、AdColony、Fyber、Digital Turbine、Smaato 等广告 SDK,并展示开屏、激励视频、插屏、Banner、原生、可玩广告与 Offerwall 等广告形式。我们不为金钱出售您的个人信息;但会基于您的同意(在 EEA/UK 等地区通过 CMP 平台获取)向广告伙伴共享必要的设备标识与广告事件。您的权利(访问、更正、删除、可携带、反对、撤回同意、退出出售/共享)以及投诉渠道在第 11、16 节详细说明。政策如有重大变更,我们将通过应用内通知或邮件等方式另行告知。