Privacy Policy
Effective Date: December 2, 2025
Last Updated: December 2, 2025
Welcome to Multiplay Games ("we," "us," or "our"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and safeguard your personal information. This Privacy Policy explains our practices regarding data collection and use when you access or use our website and multiplayer gaming platform located at grahammakesgames.com (the "Service").
1. Information We Collect
1.1 Information You Provide
- Email Address: When you create an account, we collect your email address for authentication purposes using magic link login (passwordless authentication).
- Display Name: You may optionally provide a display name (up to 32 characters) which will be visible to other players in game rooms.
- Feedback: Premium subscribers can submit feedback, bug reports, and feature requests, which include the content you provide and associated metadata.
1.2 Automatically Collected Information
- Device Identifier: We generate and store a unique device ID (UUID) in your browser's local storage to enable anonymous gameplay and prevent abuse.
- Game Data: We collect gameplay information including:
- Room codes and game session data
- Player scores and game events
- Join and completion timestamps
- Game settings (time limits, player caps)
- Subscription Data: For premium subscribers, we store subscription status, billing cycle information, and Stripe customer identifiers.
- Usage Information: Standard web server logs including IP addresses, browser type, device information, and access times.
1.3 Cookies and Local Storage
We use browser local storage and cookies to:
- Maintain your login session
- Store your device ID for anonymous play
- Remember your display name preference
- Enable proper functionality of our authentication system
Third-party cookies may be set by Google AdSense for advertising purposes (see Section 3 below).
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: To enable you to create and join game rooms, play multiplayer games, and track scores and leaderboards.
- Authentication: To verify your identity and send magic link login emails.
- Payment Processing: To process subscription payments and manage billing through Stripe.
- Communication: To send transactional emails related to account access, subscription receipts, and service-related notifications. We do not send marketing emails.
- Security and Fraud Prevention: To prevent cheating, abuse, replay attacks, and unauthorized access using device IDs and nonce validation.
- Improving the Service: To analyze usage patterns, fix bugs, and develop new features based on user feedback.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
3. Third-Party Services
We share your information with the following third-party service providers who help us operate the Service:
3.1 Stripe (Payment Processing)
We use Stripe to process subscription payments. When you subscribe to our premium service, Stripe collects your payment information directly. We receive only your Stripe customer ID and subscription status. Stripe's use of your information is governed by their Privacy Policy at stripe.com/privacy.
3.2 Google AdSense (Advertising)
We display ads through Google AdSense on our free, ad-supported games. Google may use cookies and similar technologies to serve personalized ads based on your browsing activity. You can learn more about Google's advertising practices and opt-out options at policies.google.com/technologies/ads.
3.3 Google Analytics (Future Implementation)
We plan to implement Google Analytics to understand how users interact with our Service. When implemented, Google Analytics will collect information about your usage patterns. Google's Privacy Policy is available at policies.google.com/privacy.
3.4 Supabase (Backend Infrastructure)
We use Supabase for database hosting, authentication, and real-time functionality. Your data is stored on Supabase's secure servers. Supabase's Privacy Policy is available at supabase.com/privacy.
4. Data Retention
We retain your information for as long as necessary to provide the Service and comply with our legal obligations:
- Game Data: Game rooms and associated data are automatically deleted 24 hours after the game ends. Abandoned lobbies are deleted after 24 hours of inactivity.
- User Accounts: Inactive accounts (no login activity and no gameplay activity) are deleted after 6 months of inactivity, unless you have an active subscription or subscription history.
- Subscription Data: We retain subscription and billing information for accounts with current or past subscriptions for legal and accounting purposes.
- Security Data: Nonces used for replay protection are deleted after 3 hours.
5. Data Security
We implement industry-standard security measures to protect your information:
- All game score data is encrypted using AES-256-GCM encryption before transmission
- Passwords are never stored (we use magic link authentication)
- Database access is restricted using row-level security policies
- API keys and sensitive credentials are stored securely and never exposed to the client
- HTTPS/TLS encryption for all data in transit
However, no method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Your Privacy Rights
6.1 All Users
- Access: You can request a copy of the personal information we hold about you.
- Correction: You can update your display name and email address through your profile settings.
- Deletion: You can request deletion of your account and associated data at any time.
- Objection: You can object to certain processing of your information.
6.2 EU/EEA Users (GDPR Rights)
If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to data portability
- Right to restrict processing
- Right to lodge a complaint with a supervisory authority
- Right to withdraw consent at any time
6.3 California Users (CCPA Rights)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to deletion of personal information
- Right to non-discrimination for exercising your rights
6.4 Canadian Users (PIPEDA)
As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to access, correct, and request deletion of your personal information.
6.5 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@alienplanetgames.com. We will respond to your request within 30 days.
7. Children's Privacy
Our Service is not intended for children under the age of 13 (or under 16 in the European Union). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@alienplanetgames.com, and we will delete such information from our systems.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your jurisdiction. By using the Service, you consent to the transfer of your information to these countries. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
9. Do Not Track
Some browsers have a "Do Not Track" feature that signals to websites you visit that you do not want to have your online activity tracked. Our Service does not currently respond to Do Not Track signals, as we do not track users across third-party websites.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you by email (if you have an account) or by posting a notice on our website. Your continued use of the Service after such changes constitutes your acceptance of the updated Privacy Policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Alien Planet Games
Vancouver, British Columbia, Canada
Email (General): hello@grahammakesgames.com
Email (Privacy): privacy@alienplanetgames.com
Email (Legal): legal@alienplanetgames.com
This Privacy Policy is designed to comply with GDPR (EU), PIPEDA (Canada), CCPA (California), and COPPA (United States). By using Multiplay Games, you acknowledge that you have read and understood this Privacy Policy.