This Privacy Policy (the "Policy") describes how Zyvenxa Technologies Private Limited ("MyGully11", "we", "us", or "our") collects, uses, discloses, stores, and protects information when you use the MyGully11 mobile application (the "App"), our website at https://mygully11.com (the "Site"), and any related services we offer (collectively, the "Services").
By downloading, accessing, or using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree, please do not use the Services.
What changed on 2 September 2026. The App now shows advertising. Free-tier tournaments carry ads served by Google AdMob. The ads are non-personalised: no behavioural profile is built from your use of the App, and nothing you do here is used to target you across other companies' apps or websites. Tournaments on a paid organiser plan show no ads at all. See Sections 4.2, 5, 6, 12 and 23, and Section 12 of the Terms.
What changed on 1 September 2026. Three things worth reading even if you have seen this Policy before:
- Where your data lives has moved. Our application server and database are now hosted in Singapore (AWS and TiDB Cloud), not in Mumbai as before. Images you upload are still stored in India. See Section 8.
- The App now has optional paid plans for tournament organisers. Playing fantasy remains free. Apple and Google handle the payment; we never see your card details. See Sections 2 and 4.
- New providers handle purchase verification (RevenueCat) and support tickets (Zoho Desk). See Section 6.
1. Who We Are (Data Controller / Data Fiduciary)
The entity responsible for your personal data is:
- Legal entity: Zyvenxa Technologies Private Limited
- Registered address: Kerala, India 682308
- Country of incorporation: India
- Contact email (all enquiries, including privacy and grievances): support@zyvenxa.in
2. About the App and the Nature of the Data
MyGully11 is a cricket community app for fans and grassroots ("gully") cricket. It lets you create a player profile, follow other players, organise and join local cricket tournaments, record live match scoring and commentary, build fantasy cricket teams, and view leaderboards and standings.
MyGully11 is free to play and is not a real-money game. There are no entry fees, deposits, withdrawals, wagering, betting, or cash prizes anywhere in the App. Fantasy contests are skill-based games offered for entertainment only, and no one ever stakes money on an outcome.
The App does contain optional paid plans for tournament organisers, which raise the number of fantasy players a tournament can hold and unlock organiser features such as an ad-free experience, a sponsor slot and analytics. These are one-off purchases per tournament, charged by the Apple App Store or Google Play. Playing fantasy is free regardless. Because Apple and Google process the payment, we never see or store your card, bank, UPI or KYC details.
The personal data we handle is ordinary account, profile, and usage data. We do not intentionally collect "sensitive" or "special category" personal data (such as health, financial, biometric, religious, or political data). Please do not enter such information into free-text fields like your bio or bug reports.
3. Who May Use the App
The App is intended for users aged 13 years or older. If you are under the age of 18 (or the age of majority in your jurisdiction), you may use the App only with the involvement and consent of a parent or legal guardian. The App is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us at support@zyvenxa.in and we will take appropriate steps to delete it.
4. Information We Collect
4.1 Information you provide directly
- Account & sign-in: your mobile phone number (used as your primary identifier and verified by a one-time password / OTP), and the OTP you enter.
- Profile details: display name, optional email address, profile photo, location (e.g. your city/area), short bio, and your cricket attributes (playing role, batting style, bowling style, player type).
- Cricket activity: tournaments you create or join, teams and squads, match scoring events and commentary you record as a scorer, fantasy teams you build (player selections, captain/vice-captain), and your follows of other players.
- Contacts you choose to invite: when an organiser/captain invites players to a tournament, the App lets you pick people from your device's contacts. Only the contacts you explicitly select (their name and phone number) are sent to us to create or invite those players. We do not upload or store your entire address book, and we do not use your contacts for advertising. See Section 7.
- Support & bug reports: when you submit an in-app bug report or contact support, we receive your description, the bug category, and basic device context (platform, OS version, app version, device model), plus your email and message contents if you email us.
- Account-deletion requests: if you request account deletion, we record the request, its status, and any reason you provide.
- Organiser plan purchases: if you upgrade a tournament to a paid plan, we record which tournament and plan you bought, the store you bought it through (Apple or Google), the store's transaction identifier, the product identifier, whether the purchase was made in the live or sandbox environment, and the resulting entitlement. We never receive or store your card number, bank details, UPI ID, or any other payment instrument — Apple and Google process the payment and share only the confirmation described here. See Section 4.4.
- Sales enquiries: if you contact us about a Season Pass or a Custom plan, we record the plan you enquired about, your message, and the contact email and phone number you give us.
4.2 Information collected automatically
- Device & technical data: device model, operating system and version, app version and build, language, region, time zone, a device identifier, crash logs, diagnostic logs, and performance metrics.
- Usage data: features used, screens viewed, taps, navigation paths, session duration, and in-app events (see Microsoft Clarity and Firebase Analytics in Section 6).
- Push notification token: a Firebase Cloud Messaging device token (and platform) so we can deliver match, tournament, and service notifications.
- Approximate location: derived from your IP address (we do not collect precise GPS location).
- Attribution data: install source and marketing-attribution signals, where install attribution is enabled for a given build (see AppsFlyer in Section 6).
- Advertising data (free-tier tournaments only): when the App requests an ad, the Google Mobile Ads SDK sends Google your device's advertising identifier (the Android Advertising ID, or Apple's identifier for advertisers where one is available), IP address, device and app information, and coarse location derived from that IP address, so that an ad can be selected and measured. Every ad request the App makes is marked non-personalised, so this data is not used to build an interest profile of you or to target you across other apps and websites; it is used to fill the ad slot, cap how often you see ads, and detect invalid traffic. We separately record that an ad was shown, and which moment in the App triggered it, as an analytics event. The App also keeps counters on your device — ads shown in this match, this session and today — purely to enforce the frequency limits described in Section 5; those counters never leave your phone.
- Ad-consent status: where Google's User Messaging Platform asks for your consent to ads (see Section 12), your answer is stored on your device by that framework and shared with Google.
- Sponsor banner metrics: when a tournament displays an organiser's sponsor banner, we count that it was shown and whether it was tapped. These counts are stored in aggregate per sponsor, per placement, per day — they are not stored against your identity, and sponsors never receive personal data about you. We separately keep a short-lived per-account counter purely to stop the counts being inflated by abuse; it is deleted after 7 days.
4.3 Information from third parties
- Apple App Store / Google Play: aggregate install, crash, and review metrics. Where you buy an organiser plan, we also receive the purchase confirmation and transaction identifier described in Section 4.1, and — from Google Play — notice that a purchase was later refunded or charged back, so we can withdraw the corresponding entitlement.
- RevenueCat, Inc.: our purchase-verification provider. It validates receipts with Apple and Google and tells us which entitlement to grant, identifying you to us by your MyGully11 account identifier.
- OTP delivery provider (MessageCentral): delivery status of the verification SMS sent to your phone number.
4.4 What we do not collect
- We do not collect payment-card numbers, bank account details, UPI IDs, PAN, Aadhaar, or other KYC/financial identifiers. The App does contain optional paid organiser plans, but these are charged through the Apple App Store and Google Play, which handle the payment instrument entirely — it never reaches our servers. There are still no entry fees, deposits, withdrawals, wagering, or cash prizes anywhere in the App.
- We do not collect precise GPS location, your full contacts list, calendars, microphone audio, or photo library content (other than a profile photo or attachment you actively choose).
- We do not sell your personal information for money.
- We do not request personalised or interest-based ads, build advertising profiles of our users, give any advertiser or ad network your account details, phone number, email or contacts, or allow anyone to track you across other companies' apps and websites.
5. How We Use Your Information (Purposes & Legal Bases)
We use personal data for the purposes below. Where the GDPR/UK GDPR applies, the corresponding legal bases are indicated.
| Purpose | Legal basis (EEA/UK) |
|---|---|
| Create and authenticate your account via phone-number OTP, and keep you signed in | Performance of a contract (Art. 6(1)(b)) |
| Provide core features: profiles, follows, tournaments, live scoring, fantasy teams, leaderboards | Performance of a contract |
| Send the verification SMS / OTP (via MessageCentral) | Performance of a contract |
| Deliver push notifications and in-app messages about matches, tournaments, and service updates (Firebase Cloud Messaging) | Performance of a contract; consent for any marketing messages |
| Maintain security, prevent fraud and abuse, and debug crashes (Firebase Crashlytics) | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable |
| Understand product usage and improve features (Firebase Analytics, Microsoft Clarity) | Legitimate interests; consent where required by local law |
| Show advertising in free-tier tournaments (Google AdMob) — a banner in the promo slot, and full-screen ads at over, innings and match breaks and on fantasy-team submission, subject to frequency limits | Legitimate interests (funding a product that is free to play); consent where the ad-consent framework requires it (see Section 12) |
| Limit how often ads are shown to you, and detect invalid or fraudulent ad traffic | Legitimate interests; legal obligation where applicable |
| Measure marketing and install attribution (AppsFlyer) | Consent where required; otherwise legitimate interests |
| Provide customer support and resolve bug reports | Performance of a contract; legitimate interests |
| Comply with legal obligations, respond to lawful requests, and enforce our Terms | Legal obligation (Art. 6(1)(c)); legitimate interests |
Automated decision-making (GDPR Art. 22). We do not carry out solely automated decision-making — including profiling — that produces legal effects concerning you or similarly significantly affects you. Fantasy points, leaderboards, and standings are calculated from public cricket-scoring rules and are informational only.
6. Third-Party Services and Processors
To deliver the Services, we share limited personal data with carefully selected third-party providers acting as our processors or as independent controllers. We require each provider to maintain appropriate security and confidentiality measures.
| Provider | Purpose | Data involved | Provider's policy |
|---|---|---|---|
Amazon Web Services, Inc. — EC2 application server and container registry (Asia Pacific, Singapore, ap-southeast-1) | Runs our application backend | All account and activity data described in Section 4, in transit and in process | aws.amazon.com/privacy |
PingCAP, Inc. — TiDB Cloud Serverless (managed MySQL-compatible database, Asia Pacific Singapore, ap-southeast-1) | Stores your account, profile, tournament, match, fantasy and purchase records | All account and activity data described in Section 4 | pingcap.com/privacy-policy |
Amazon Web Services, Inc. — S3 object storage (Asia Pacific, Mumbai, ap-south-1) and CloudFront content delivery (global edge network) | Stores and serves images you upload (profile photos, tournament and sponsor logos); delivers API traffic over HTTPS | Uploaded images; IP address and request metadata at the edge | aws.amazon.com/privacy |
| Google LLC — Firebase Cloud Messaging, Firebase Crashlytics, Firebase Analytics (Google Analytics for Firebase) | Push delivery, crash reporting, product analytics | Push token, device data, crash logs, app-instance identifiers, IP address, in-app events | firebase.google.com/support/privacy |
| Google LLC — Google AdMob / Google Mobile Ads SDK, and Google's User Messaging Platform (UMP) | Serves non-personalised ads in free-tier tournaments, caps ad frequency, detects invalid traffic, and — where required — collects and records your ad-consent choice | Advertising identifier, device and app data, IP address and IP-derived coarse location, ad request/impression/click events, consent status. No account identifier, phone number, email, contacts or tournament data. | policies.google.com/technologies/ads · business.safety.google/privacy |
| MessageCentral (Communication App Services Pvt. Ltd.) | Delivery of OTP / verification SMS | Mobile phone number, message delivery metadata | messagecentral.com/privacy-policy |
| Microsoft Corporation — Clarity | Product analytics and session insights. Clarity is configured with Microsoft's default masking, which masks text inputs and content marked sensitive in the SDK; only UI interaction events, screen navigation, and aggregate performance metrics are recorded. | Pseudonymous session data, masked screen interactions, device data, truncated IP | privacy.microsoft.com |
| AppsFlyer Ltd. | Mobile install attribution and marketing analytics. The SDK ships inside the App but stays dormant unless attribution is configured for that build; when it is dormant it collects nothing. | Device identifiers, IP address, install/attribution events | appsflyer.com/legal/services-privacy-policy |
| RevenueCat, Inc. | Verifies App Store and Google Play purchase receipts and tells us which organiser-plan entitlement to grant | Your MyGully11 account identifier, store transaction and product identifiers, purchase status. No payment instrument data. | revenuecat.com/privacy |
Zoho Corporation Private Limited — Zoho Desk (India data centre, zoho.in) | Handles support tickets you raise with us | Your name, contact email, and the contents of your support request | zoho.com/privacy |
| Our email provider (SMTP relay) | Sends operational email — support replies and internal notifications such as account-deletion requests | Email address and message contents | — |
| Apple Inc. & Google LLC — App Store / Google Play, push services | App distribution, updates, crash/usage metrics, push delivery | Device identifiers, purchase and download metadata for organiser plans | apple.com/legal/privacy · policies.google.com/privacy |
We do not authorise these providers to use your personal data for their own independent marketing purposes.
7. Contacts Permission (Tournament Invites)
To make it easy to add players to a local tournament, the App can show your device contacts so you can pick people to invite. This feature is optional and only runs when you choose to invite players.
- We request contacts permission only at the moment you open the contact picker; you can decline and add players manually instead.
- Only the name and phone number of the contacts you explicitly select are sent to our server to create or invite those players. Your full address book is never uploaded.
- We use selected-contact data solely to create the tournament/player records you requested. We do not use it for advertising, profiling, or unsolicited messaging.
- You can revoke contacts permission at any time in your device settings.
8. How We Store and Secure Your Data
8.1 Storage locations
- Our backend: our application server runs on Amazon Web Services in the Asia Pacific (Singapore) region (
ap-southeast-1), and your account, profile and activity data are stored in a TiDB Cloud Serverless managed database, also in Singapore. API traffic reaches the server through Amazon CloudFront, a global edge network. - Images you upload: profile photos and tournament or sponsor logos are stored in a private Amazon S3 bucket in the Asia Pacific (Mumbai) region (
ap-south-1), India, and served through CloudFront. The bucket blocks all public access; images are reachable only through their CloudFront address, which is not publicly listed but is not secret either — treat anything you upload as visible to anyone who has the link. - On your device: authentication tokens are stored securely on your device (using platform secure storage/Keychain/Keystore), and some data is cached locally for performance.
- Our processors: limited operational data (push tokens, crash logs, analytics events, attribution data, SMS-delivery metadata) is processed by the providers listed in Section 6, which may store data in India, the United States, the European Union, or other jurisdictions.
- Website hosting: the Site at mygully11.com serves these legal pages and marketing content as static content.
8.2 International data transfers
This has changed. Our application server and database are now both located in Singapore; images you upload remain in India. If you are in India, this means your account and activity data is stored outside India. Indian law permits such transfers except to countries the Central Government has restricted by notification, and no such restriction currently applies to Singapore.
Where personal data is transferred outside your country of residence — including to Singapore (AWS, PingCAP), the United States (Google, Microsoft, RevenueCat, AppsFlyer), or other jurisdictions — we rely on appropriate safeguards such as:
- the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum for transfers from the EEA/UK;
- the EU–U.S. Data Privacy Framework (and the UK and Swiss extensions) for certified U.S. providers;
- adequacy decisions where applicable; and
- your consent, where consent is the lawful basis we rely on.
You may request a copy of the relevant safeguards by contacting us at support@zyvenxa.in.
8.3 Security measures
We implement administrative, technical, and physical safeguards designed to protect your information, including: encryption in transit (TLS) for every connection to our API and content delivery network, token-based authentication using JWTs held in your device's secure storage (Keychain on iOS, Keystore on Android), a private image bucket that blocks all public access, managed secrets, principle-of-least-privilege access for staff, secure software-development practices, dependency monitoring, and incident-response procedures. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
8.4 Data breach notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (including, where applicable, the Indian Computer Emergency Response Team (CERT-In) and the Data Protection Board of India) and affected users without undue delay and, where feasible, within 72 hours, as required by applicable law.
9. How Long We Keep Your Data (Retention)
- Account & profile data: retained for as long as your account is active. When you delete your account (see Section 10), we delete or anonymise your personal data, subject to the limited exceptions below.
- Cricket activity (tournaments, matches, scoring, fantasy teams, follows): retained while your account is active. Note that some records (e.g. a completed tournament's results or a match scorecard you contributed to) may be retained in anonymised or aggregated form so that shared community records remain intact for other participants.
- OTP / verification codes: short-lived; they expire shortly after issuance, are marked used once redeemed, and are deleted outright when your account is deleted.
- Sign-in sessions: an authentication token lasts up to 180 days before you must sign in again. Deleting your account invalidates every issued token immediately.
- Push notification tokens: retained until you disable notifications, sign out, or the token becomes invalid.
- Support tickets & bug reports: retained for up to 24 months after resolution.
- Crash logs and diagnostic data: retained for up to 90 days, then aggregated or deleted.
- Analytics & session insights: retained per the retention schedules of Firebase and Microsoft Clarity (and AppsFlyer, where attribution is enabled).
- Purchase records: records of organiser-plan purchases — the tournament, plan, store, and transaction identifiers — are retained for as long as needed for the entitlement, and thereafter for up to 8 years to meet tax, accounting and audit obligations. These records survive account deletion in the reduced form required by law.
- Advertising data: the ad request data described in Section 4.2 is held by Google under its own retention schedule; we do not receive or store it. The on-device frequency counters reset each day, session or match, and are cleared when you uninstall the App.
- Sponsor banner metrics: the aggregate per-sponsor daily counts are retained for the life of the tournament record and are not linked to you. The per-account anti-abuse counter is deleted after 7 days.
- Sales enquiries: retained for up to 24 months after the enquiry is closed.
- Account-deletion records: a minimal record of your deletion request may be retained to evidence compliance.
When retention periods expire, we delete or anonymise the data so that it can no longer be associated with you.
10. Your Rights & How to Delete Your Account
Depending on where you live, you may have some or all of the following rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.
Deleting your account. You can request deletion directly in the App via Profile → Delete Account, or by emailing support@zyvenxa.in from your registered details. You may cancel a pending request at any time before it is processed.
What deletion actually does. We want to be precise here, because cricket records are shared between people and cannot simply vanish without damaging other participants' scorecards. When your deletion request is processed:
- Your name, phone number, email address, profile photo, bio, location, and batting and bowling styles are erased from your account and from your player record.
- Your notification settings, your follows and followers, and your verification (OTP) records are deleted outright.
- Every sign-in session is invalidated, and your phone number and email are released so they can be used to sign up again later.
- Your account is marked deleted and your cricket history is kept but detached from you: scorecards, match events, tournament results and fantasy entries you took part in remain, attributed to "Deleted User", so that other participants' records stay complete and correct.
- A minimal record of the deletion request itself, and the purchase records described in Section 9, are retained where we are legally required to keep them.
This means deletion anonymises your participation rather than erasing shared match history. If you need something beyond this, contact us and we will consider the request on its merits under the law that applies to you.
Requests are reviewed and completed by our team. We will action your request and respond within the period required by applicable law — typically 30 days (GDPR, and the DPDP Act), or 45 days under the CCPA, extendable once where permitted.
11. California Residents (CCPA / CPRA)
If you are a California resident, the CCPA (as amended by the CPRA) gives you rights to know/access, delete, correct, opt out of "sale"/"sharing", and non-discrimination. In the last 12 months we have collected the categories: identifiers (phone, email, device IDs), customer records (profile fields), internet/network activity (app usage, crash logs), and limited geolocation (IP-derived region).
We do not "sell" your personal information for money. Use of analytics/attribution identifiers (Firebase Analytics, AppsFlyer) may be considered "sharing" for cross-context behavioural advertising under the CPRA. Ads shown in free-tier tournaments are served by Google AdMob and are always requested as non-personalised, which is designed to exclude cross-context behavioural advertising; we nevertheless treat the advertising identifier used to serve them as within the scope of your opt-out right. You can opt out by turning on "Limit ad tracking" or deleting/resetting the advertising ID in your device settings, by taking part in tournaments on a paid organiser plan (which show no ads at all), by disabling analytics where offered, or by emailing support@zyvenxa.in. We honour Global Privacy Control (GPC) signals on our Site. Authorised agents may submit requests with proof of authorisation.
12. European Economic Area, United Kingdom & Switzerland (GDPR / UK GDPR / FADP)
If you are located in the EEA, UK, or Switzerland, the legal bases for processing are listed in Section 5, and you have all the rights listed in Section 10. For all data-protection enquiries, contact support@zyvenxa.in. You may also lodge a complaint with your local supervisory authority, including the UK ICO (ico.org.uk), Ireland's DPC (dataprotection.ie), or another EU member-state authority (edpb.europa.eu).
Ad consent. Where the EEA, UK or Swiss rules require it, the App shows you Google's User Messaging Platform consent message when it first starts, and does not request ads until you have answered it. You can change your answer at any time from Profile → About → Ad Privacy Settings in the App; that entry appears only in the regions where the framework requires it, because it is the only place the form can be shown. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
Because we are established outside the EEA/UK but may offer the Services to users there, the requirement under Article 27 GDPR to designate a representative may apply. In the meantime, EEA/UK/Swiss users may exercise all rights directly with us at support@zyvenxa.in.
13. India — Digital Personal Data Protection Act 2023
As we are incorporated in India, our processing is also governed by the Digital Personal Data Protection Act, 2023 ("DPDP Act"). As a Data Principal you have the right to: obtain a summary of the personal data we process and our processing activities; request correction, completion, updating, and erasure of your personal data; nominate another individual to exercise your rights in the event of death or incapacity; and readily-available grievance redressal.
Our designated grievance officer under the DPDP Act and the Information Technology Act, 2000 (and rules thereunder) is:
- Grievance Officer: The Designated Officer, Zyvenxa Technologies Private Limited
- Email: support@zyvenxa.in
- Address: Zyvenxa Technologies Private Limited, Kerala, India 682308
We will acknowledge grievances within 48 hours and resolve them within 30 days of receipt. Unresolved complaints may be escalated to the Data Protection Board of India.
14. Other Jurisdictions
- Brazil (LGPD): rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. ANPD: gov.br/anpd.
- Canada (PIPEDA / Quebec Law 25), Australia (Privacy Act 1988), Singapore (PDPA), South Africa (POPIA), UAE, Saudi Arabia (PDPL), and others: you have rights substantially similar to those described above and may contact your national data-protection authority.
- U.S. state laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others): rights of access, correction, deletion, portability, and opt-out of targeted advertising and sale, exercisable as described in Section 11.
15. Children's Privacy
The App is intended for users aged 13 and over, and for users under 18 only with parental/guardian involvement. We do not knowingly collect personal data from children under 13. We do not profile any user for advertising: no user's data — child or adult — is used to build an advertising profile or to target them across other apps and websites. Free-tier tournaments do show ads, but they are non-personalised and contextual only. Because gully cricket is watched by families and played by under-18s, we cap the content rating of ads served in the App at the equivalent of "PG" and block gambling and real-money-gaming advertisers in our ad-network settings. Under the U.S. Children's Online Privacy Protection Act (COPPA) and India's DPDP Act, if we learn we have collected personal data from a child without the required consent, we will delete it. If you believe a child has provided us data, contact support@zyvenxa.in.
16. Push Notifications & Communications
With your permission, we send push notifications (for example, match updates, tournament reminders, or service messages) via Firebase Cloud Messaging. You can disable notifications at any time in your device settings or in the App's notification settings. We do not currently send marketing emails; if this changes, you will receive a clear opt-in and an unsubscribe mechanism.
17. Public & Community Information
MyGully11 includes community features. Your display name, profile photo, cricket attributes, follower/following relationships, tournament participation, and match/leaderboard performance may be visible to other users of the App. Please consider what you choose to make public. We are not responsible for how other users use information you choose to share within the community.
18. "Do Not Track" Signals
Because there is no industry consensus on how to respond to browser "Do Not Track" (DNT) signals, we currently do not respond to them, but we honour the Global Privacy Control (GPC) signal on our Site as described in Section 11.
19. Third-Party Links
The App and Site may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties; please review their privacy policies before providing them with information.
20. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the App, by email, or by prominent notice on our Site before the changes take effect, and we will update the "Last updated" date above. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.
21. How to Contact Us
For any questions, complaints, privacy requests, data-subject-rights requests, or grievances relating to this Policy or our handling of your personal data, please contact us:
- Email (all enquiries): support@zyvenxa.in
- Postal address: Zyvenxa Technologies Private Limited, Kerala, India 682308
22. Governing Law & Jurisdiction
This Policy is governed by the laws of India, without regard to its conflict-of-laws principles, and subject to the exclusive jurisdiction of the competent courts at Ernakulam, Kerala, India, except where mandatory local consumer-protection or data-protection law in your country of residence grants you additional rights or a different forum.
23. App Store & Play Store Privacy Labels
For convenience, the data categories shown in our Apple App Privacy labels and Google Play Data Safety section reflect the practices described in this Policy. In the event of any conflict between the labels and this Policy, this Policy controls.
The table below maps what we collect to the store categories. Free-tier tournaments show ads served by Google AdMob, so a device advertising identifier is used for third-party advertising. Those ads are always requested as non-personalised: nothing about you is sold, and no data is used to track you across other companies' apps or websites in the sense used by Apple's App Tracking Transparency framework — which is why the App never asks you for tracking permission.
| Category | Collected | Linked to you | Used for |
|---|---|---|---|
| Contact info — phone number, email | Yes | Yes | Account & sign-in, support |
| User content — profile photo, bio, tournament and sponsor images, match commentary, bug reports | Yes | Yes | App functionality |
| Contacts | Only those you explicitly select | Yes | Creating and inviting players |
| Identifiers — account ID, device identifier, push token, device advertising ID | Yes; the advertising ID only in free-tier tournaments | Yes for your account ID, device identifier and push token. The advertising ID is not linked to your account — it is sent to the ad network on its own. | App functionality, notifications, third-party advertising (non-personalised), frequency capping, fraud prevention |
| Purchases — plan, store transaction ID | Yes | Yes | Granting organiser entitlements |
| Usage data & diagnostics — screens, taps, crashes, performance | Yes | Pseudonymous | Analytics, stability |
| Coarse location (from IP) | Yes | Pseudonymous | Security, regional defaults, ad delivery |
| Tracking you across other companies' apps or websites | No | — | — |
| Precise location, health, financial, biometric data | No | — | — |
Why the store labels look less detailed than this table. Apple's App Privacy label puts every device-level identifier — your push token, our internal device identifier, and the advertising ID — into a single "Device ID" category, and asks one question about whether that category is linked to your identity. Because the push token and device identifier are tied to your account, we answer that question yes for the whole category, even though the advertising ID by itself is not linked to you. Google Play's Data Safety section groups them the same way, under "Device or other IDs". The row above describes what actually happens to each one.