Web shop update — September 22, 2026
This policy also applies to the LINN website. The website and Android app share the same Firebase account, wallet, orders and referral records. The website sends the Player ID and Zone ID to FazerCards for verification before every purchase, including packages fulfilled by Smile.One. We retain the returned nickname, country (when supplied), checked account identifiers and a short-lived checkout authorization record. Regional fulfillment may also be provided by FazerCards.
The website uses Firebase Authentication browser persistence to keep you signed in, local storage for a pending invite code, and session storage for payment request identifiers and retry details. Google reCAPTCHA Enterprise and Firebase App Check process browser/security signals to protect requests. The website does not load advertising or analytics SDKs and has no ad-earning section. Existing app promotional credit remains part of the shared account. Web invitations record the invite code and claim time without requiring Play Store installation information.
1. Information we handle
Account and authentication data
The App supports email-and-password and Google authentication. We process your email address, Firebase user ID, account status, profile timestamps, and any profile name associated with the account. Passwords are submitted directly to Firebase Authentication and are not stored in the App's Firestore records or shown to shop administrators. Firebase and Google may process IP addresses, device or browser information, and security logs to authenticate users and prevent abuse.
Game account, order, and fulfillment data
When you check a player or place an order, we process the Mobile Legends Player ID and Zone ID you enter, the selected package, quantity, price, currency, request and order identifiers, status, timestamps, balance allocation, and fulfillment result. The optional player checker may return a nickname, region, last-login location, and checker-data date for display. If you use ad promo credit, the first promo-funded Player ID and Zone ID are stored as the permanent account binding for future promo purchases.
Wallet, top-up, and transaction data
We process main-balance and promo-credit amounts and itemized wallet, payment, refund, and commission history. If manual top-up is enabled and you submit a request, we collect the receipt transaction ID, amount in MMK, Firebase user ID, request identifier, submission time, review or delivery state, anti-spam counters, and limited diagnostics. Do not submit a payment PIN, password, OTP, full account credentials, or unrelated personal information. Manual submissions are reviewed by an administrator and do not credit the balance automatically.
Referral and install data
For referrals, we process referral codes, linked referrer and referred-user IDs, claim status and timestamps, friend and earnings totals, and commission records. The App reads the lin_ref value and referral click and install timestamps from Google Play Install Referrer. A pending referral is stored locally until submitted or discarded.
Rewarded-ad and consent data
If rewarded ads are enabled, we process one-time reward-session identifiers, verification status, LevelPlay or legacy AdMob event and ad-network identifiers, reward value, cooldown and daily counters, and timestamps. The current App uses Unity LevelPlay mediation; an earlier supported App version may continue using Google AdMob during the migration period. These providers, enabled demand partners, and consent tools may process IP address, approximate location derived from it, advertising or app-set identifiers and other device identifiers, app launches, taps, video views, consent choices, and diagnostic or performance information for advertising, measurement, delivery, mediation, and fraud prevention. Ad availability and personalization depend on region, consent choices, network configuration, and provider settings.
App and device security data
Firebase App Check with Google Play Integrity processes app metadata, package, version and signing information, license status, device-attestation material, integrity tokens, IP address, and related security signals. We use these signals to verify genuine app requests, protect accounts and transactions, and prevent fraud or abuse.
Local and technical data
The App stores retry identifiers for uncertain order or top-up submissions, a pending install referral, and related state on your device to help avoid duplicates and securely verify ad rewards. App backup is disabled. Infrastructure and content or image hosts may receive ordinary network information such as IP address, request time, app version, response status, and diagnostics.
2. Why we use information
- create, authenticate, and secure accounts;
- display products, balances, rewards, referrals, and history;
- check player details and fulfill orders;
- verify manual payments, credit main balance after administrator approval, and prevent duplicate or spam submissions;
- deliver, verify, and limit rewarded-ad promo credit;
- attribute valid referrals and calculate eligible commissions;
- investigate failed or uncertain orders, provide support, issue balance refunds, and maintain transaction records;
- detect fraud, tampering, and violations of the Terms of Use; and
- comply with legal obligations and enforce our rights.
Where applicable law requires a legal basis, processing may be necessary to provide the service you request, comply with law, protect legitimate interests such as fraud prevention and service operation, or act on your consent, particularly for advertising.
3. When information is disclosed
We do not sell personal information for money. Advertising-related processing by Unity LevelPlay, its enabled demand partners, or legacy Google AdMob may be considered sharing or targeted advertising under some laws. Depending on the feature you use, information may be disclosed to:
- Google Firebase and Google Cloud for authentication, Firestore storage, Cloud Functions, App Check, hosting, infrastructure, and security. See Firebase Privacy and Security and the Google Privacy Policy.
- Google Play for Install Referrer and Play Integrity referral, license, app, and device-security processing.
- Unity LevelPlay and enabled demand partners for rewarded-ad mediation, delivery, measurement, server-side reward verification, and fraud prevention. See the Unity Privacy Policy.
- Google AdMob only for rewarded ads requested by the earlier supported App version during the migration period. See How Google uses information from apps.
- PizzoShop when you deliberately select “Check player account.” The Player ID and Zone ID are sent to its player-check service and the response is displayed in the App. See PizzoShop.
- Smile.One to validate and fulfill a selected game package using the Player ID, Zone ID, and package information. See the Smile.One Privacy Policy.
- Telegram when you submit a manual top-up. A bot sends the administrator a cloud-chat message containing the submission ID, Firebase user ID, receipt transaction ID, amount, and submission time. See the Telegram Privacy Policy.
- KPay/KBZPay or Wave Money when you independently use their services to transfer money. The App displays recipient instructions but does not collect your payment PIN, OTP, or provider password. See the KBZPay policy or Wave Money Privacy Policy.
- authorized administrators and support personnel who need access to verify payments, reconcile orders, prevent fraud, or assist you; and
- authorities or other parties when required by law or necessary to protect users, the service, or legal rights.
When you use Android's share chooser for a referral link, you choose the recipient app and people. Their handling of the shared text is governed by their own policies.
4. Data retention
- Account, profile, referral, reward, order, wallet, payment, refund, manual top-up, and related App database records are kept while the account is active and are deleted by the implemented account-deletion process described below.
- Pending local retry and referral data remains until processed or cleared, or until you clear App data or uninstall.
- Messages or payment evidence already delivered to support or Telegram are kept only as long as reasonably necessary for payment verification, accounting, fraud prevention, security, dispute handling, or another legal obligation, then deleted or minimized.
- Infrastructure, security, and provider diagnostics are kept according to operational need and the applicable provider's retention and backup cycles.
Service providers may retain information under their own policies. After a deletion request, a narrowly limited support or processor record may remain where legally required or necessary for an unresolved payment, fraud, security, or dispute matter.
5. Account and data deletion
Request deletion in Profile > Delete account, or use the account-deletion page if you cannot access the App. We may verify account ownership for an emailed request. An active paid order must finish or be resolved before deletion so fulfillment is not lost.
The in-App process deletes the Firebase Authentication account and associated profile, wallet, order, payment, reward, referral, manual top-up, rate-limit, and related diagnostic records from the App database. Verified email requests are normally completed within 7 days. Support or provider records may remain only for the limited reasons described in Section 4.
Uninstalling the App or signing out does not delete the account or server records.
6. Your choices and rights
You may choose not to submit an optional player check, manual top-up, rewarded-ad request, or referral share. Where available, use the advertising consent controls presented for your region. Android or Google settings may allow you to reset or delete the advertising ID.
You may contact us to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where your law provides those rights. Withdrawing consent does not affect processing already lawfully completed.
7. Security and international processing
We use authenticated access, Firestore security rules, server-controlled wallet writes, App Check and Play Integrity, encrypted network connections, restricted administrator access, secret management, idempotency controls, and rate limits. No internet or storage system is completely secure.
Firebase Authentication uses infrastructure in the United States, while other providers may process information in multiple countries. Where required, information is processed using safeguards recognized by applicable law.
8. Children
The App is not directed to children who cannot legally create an account or make the relevant purchase in their country. A minor may use the App only where local law permits and with any required parent or guardian permission. If you believe a child provided information contrary to applicable law, contact us so it can be reviewed and deleted.
9. Changes and contact
We may update this policy when the App, providers, or law changes. We will publish the revised version at this URL, change the effective date, and provide additional notice or consent where required.
Privacy contact: gha289861@gmail.com
Developer: Noob Dance
App: LINN - Diamond Shop