This version takes effect when published as the Game's Privacy Policy. Where applicable law requires advance notice or renewed consent, the relevant change takes effect only after those requirements have been met.
ADISOFT GAMING Company Limited ("Adisoft", "we", "us") is responsible for the personal information described in this policy in connection with Merge Miko: Spirit Rush (the "Game"), its account services, and related player support.
Our address is 9 Ramintra 5 Yak 15, Ram Intra Road, Anusawari, Bang Khen, Bangkok 10220, Thailand. Contact privacy@adisoft.io about privacy or your information and info@adisoft.io for general enquiries.
This policy applies specifically to the Game. Other Adisoft games and our general website may have different features and separate privacy notices. Where a general Adisoft privacy notice also applies, this Game-specific policy takes precedence for the Game to the extent of a conflict.
Reading or accepting our Terms of Service does not itself give consent to optional analytics or advertising tracking. We request consent separately where required.
The Game stores progress and settings on your device. Guest play is available without connecting an Apple or Google account. Guest access may still use a pseudonymous Firebase account identifier for online services; guest play does not mean that no identifiers are processed.
If you connect an account, we and our authentication providers process the identifiers and authentication credentials needed to sign you in and associate your progress with that account. Depending on the provider and your choices, the sign-in process may also provide profile information such as a name or email address, including an Apple private relay address. We do not receive your Apple or Google password.
Cloud saves contain gameplay information such as your heroes, resources, stage progress, reward state, and save metadata, associated with an account identifier. These records let us save, restore, and synchronize progress. Online leaderboard records contain the player identifier, ranking/progress information, and the display information shown in the leaderboard.
Other players who open the leaderboard can see the display information you choose to show, such as your display name and avatar, together with your ranking and progress on that leaderboard. We do not publish your authentication credentials, private cloud saves, contact details, or purchase history. If you would rather not be identifiable, use a display name that does not reveal who you are.
If you allow Data Analytics, we use Google Analytics for Firebase to understand how the Game is used. This includes gameplay events, stage results, time spent in gameplay, hero progression, and interactions with screens and controls. The SDK also processes installation/app-instance identifiers and technical information such as app version, device characteristics, and operating system information. This information is pseudonymous and should not be understood as fully anonymous.
Optional analytics collection starts only after you allow it. You can change your choice in Settings → Data Analytics. Declining does not prevent normal play. Turning it off stops subsequent optional analytics collection; it does not automatically delete information previously collected. Events suppressed while collection is disabled are not replayed later.
Our custom UI events identify screens and actions. They do not include copied account IDs, passwords, or the text of your support messages.
We use Firebase Crashlytics to identify crashes and improve reliability. Reports can contain crash traces, technical error information, app and operating system versions, device characteristics, and SDK-generated installation identifiers. We do not deliberately attach your player account ID to crash reports.
The mobile Game sends a request when a new app process starts so we can count total launches. Our counter stores a daily total rather than a record of each launch. The request does not include an application-supplied account ID, device ID, or other persistent identifier, and the counter does not create a local tracking identifier.
This count operates separately from Data Analytics and continues when optional analytics is off. The network and cloud providers necessarily receive IP addresses and ordinary connection information to deliver and secure the request. The aggregate counter database does not store those identifiers. Daily totals cannot identify an individual player and cannot be used by us to remove a particular person's launches from the total.
Mobile versions may display interstitial advertisements and optional advertisements that provide in-game rewards. We use Google AdMob, including mediation with Unity Ads, to deliver and measure ads and help prevent fraud.
Depending on your region, permission settings, and the ad service involved, advertising providers may process IP addresses, approximate location inferred from IP, device and app information, advertising identifiers where permitted, ad impressions, interactions, and diagnostic or fraud-prevention information. Advertising has separate privacy controls from gameplay analytics.
Where required, we present an advertising consent or opt-out message. You can revisit available choices through Settings → Support → Ad privacy choices. On iOS, Apple's tracking permission is controlled separately through iOS Settings. Refusing tracking permission does not prevent normal play or reduce the reward attached to an available rewarded ad. Ad availability can vary, and refusing personalization does not necessarily prevent all ad-related processing.
The privacy message identifies applicable advertising partners and choices. We update our disclosures when the services or purposes change.
If a version of the Game offers in-app purchases, Apple or Google processes payment under its own terms and privacy policy. We may process transaction references, product identifiers, purchase status, and entitlement information to deliver, validate, and restore purchases and prevent fraud. We do not receive your full payment card number or security code through these store purchases.
If you contact us, we process your contact details, message, and any information you choose to provide to investigate and respond. Please do not send passwords, payment card details, or unnecessary sensitive information.
Our online providers also process connection and security information needed to operate authentication, cloud storage, and other online services. Our app-open counter practices do not describe or disable logging for these other services.
The Game does not request access to your contacts, camera, microphone, or precise GPS location for its current gameplay features. Opening external websites, including legal pages, may involve those sites' own network, cookie, and privacy practices.
We use information to provide accounts and requested online features, save progress, display rankings, deliver rewards and purchases, respond to support requests, maintain security and reliability, understand optional gameplay analytics, and provide advertising according to applicable choices.
Where the applicable law requires a legal basis, we rely on performance of our agreement for services you request; consent for optional analytics and advertising activities requiring consent; legitimate interests in operating, securing, diagnosing, and improving the Game where permitted and balanced against your rights; and compliance with legal obligations where necessary. Withdrawal of consent does not affect processing that was lawful before withdrawal.
We use service providers for authentication, hosting, storage, analytics, diagnostics, advertising, payment, and support. Key services include:
| Provider or service | Purpose | Further information |
|---|---|---|
| Google Firebase and Google Cloud | Authentication, cloud saves, online rankings, infrastructure, aggregate launch counting, and Crashlytics | Firebase privacy information |
| Google Analytics for Firebase | Optional gameplay and usage analytics | Google Privacy Policy |
| Google Play Games and Sign in with Apple | Account authentication and linking | Google, Apple |
| Google AdMob and Unity Ads | Advertising, mediation, ad measurement, and fraud prevention | Google, Unity player privacy policy |
| Apple App Store and Google Play, where purchases are offered | Payments and purchase entitlements | Apple, Google |
Some providers process information on our instructions; others also act independently for purposes described in their policies. We do not characterize every provider as acting exclusively on our instructions.
We may disclose information where necessary to comply with law, protect rights and security, or handle a business transfer, subject to applicable safeguards. We do not sell player data for money. Advertising disclosures may nevertheless qualify as a "sale", "sharing", or "targeted advertising" under certain privacy laws; applicable opt-out choices are available through the advertising privacy controls and by contacting us.
We are based in Thailand. Google, Apple, Unity, and other service providers may process information in Singapore, the United States, and other countries where they operate. Selecting a particular server region does not mean that all authentication, analytics, diagnostic, advertising, support, or backup processing takes place in that region.
International transfers must meet the requirements of applicable data protection law. Depending on the service and jurisdiction, relevant protections may include contractual data-protection commitments or a recognized transfer mechanism. Contact privacy@adisoft.io for information about the arrangements applicable to your information or to request a copy or description of available safeguards. Accepting these Terms or continuing to play is not a blanket consent to international transfers.
We retain information only for the purpose for which it is needed, considering the service relationship, support needs, security, legal obligations, and applicable deletion requests.
| Information | Retention approach |
|---|---|
| Local saves and preferences | Kept on the device until reset or removed, subject to operating-system backup and restore behavior. |
| Account, cloud save, and leaderboard records | Kept while the account/service relationship continues. On an applicable deletion request, the account enters a 30-day pending deletion period (cancelled if you sign in again during that time), after which the records are permanently deleted or de-identified, subject to justified legal or security exceptions. |
| Optional analytics | Event-level and user-level information is subject to the retention controls of our Google Analytics service. We retain it to evaluate gameplay, compare releases, and investigate usage trends, subject to those controls and applicable deletion rights. Aggregated reports can have a different retention lifecycle and may remain for historical comparisons after the underlying event-level information expires. Contact us for the currently applicable retention period. |
| Crash diagnostics | Firebase currently describes retention of crash traces and associated identifiers for 90 days before starting removal from live and backup systems; see its linked privacy information. |
| Aggregate app-open totals | Daily totals are retained for historical usage reporting without a player-level record. |
| Support messages | Kept while resolving your request and for follow-up, disputes, or related claims; retention takes account of whether the matter remains open and applicable claim deadlines. |
| Purchase records, where applicable | Kept to provide and restore an active entitlement, handle refunds or disputes, prevent fraud, and meet applicable accounting or legal requirements. After an account is deleted, we keep a de-identified transaction reference (store transaction ID and product ID, with no link to you) so the same store receipt cannot be redeemed again on a new account. |
| Security records | Kept for investigating incidents and preventing abuse, considering the incident's status, ongoing risk, and any applicable legal preservation requirement. |
Deletion from active systems and expiry from provider backups may take different amounts of time. We do not promise that deleting a Game account instantly removes every independent provider record. If we must retain identifiable information after a deletion request, we explain the applicable reason and restrict its use accordingly.
Depending on applicable law, you may have rights to access, correct, delete, obtain a portable copy of, restrict, or object to processing of your information, withdraw consent, and complain to a competent data protection authority, including Thailand's Personal Data Protection Committee where applicable. Some rights have legal exceptions.
You can:
To request deletion without access to the Game, email privacy@adisoft.io with the subject Merge Miko — Account Deletion. State whether you want to delete the Game account and its associated data or request deletion of a particular category of information. We will tell you if additional verification or information is needed. For requests submitted by email, we aim to verify the request and place the account into the 30-day pending deletion period described above within 14 business days of receiving it.
Signing out, unlinking a provider, or uninstalling the Game does not by itself request deletion of server-side information. Deleting the Game account does not delete your Apple or Google account. Previously collected analytics and diagnostics may require separate handling because they use different identifiers. If we cannot reasonably identify records as yours, we will explain that limitation rather than request excessive identifying information.
We may verify identity before acting and respond within the period required by applicable law. We do not penalize you for exercising your privacy rights. Where applicable, you may use an authorized agent or appeal a decision by contacting us.
If you are a minor under the laws where you live, a parent or legal guardian must review these documents with you, permit your use of the Game, and supervise your use as required by our Terms and applicable law.
A parent's permission to play is separate from any parental consent required for processing a child's personal information. Where applicable law requires verified parental consent, ordinary acceptance of the Terms or an analytics or advertising choice does not replace that requirement.
Parents and guardians can contact privacy@adisoft.io to ask about information relating to their child, request access or deletion, or withdraw an applicable consent. We may need to verify the requester's identity and authority before acting.
If you believe a child has provided personal information in circumstances that require parental authorization and that authorization was not obtained, contact privacy@adisoft.io so we can investigate and take appropriate action.
We use access controls and other reasonable technical and organizational measures to protect information. No system can guarantee absolute security.
We may update this policy as the Game or our practices change. We will identify the effective date and provide notice of material changes as required. Where a new purpose requires consent, we will request it rather than treat continued play as consent.
For privacy questions or requests, contact privacy@adisoft.io at the address in section 1.