Skip to content
♥Solitaire Club

Legal

Privacy Policy

Effective October 3, 2026

This Privacy Policy explains how SmartPref S.àr.l.-S, Luxembourg, LBR B308734 ("SmartPref", "we", "us" or "our"), processes personal data when you use the Solitaire Club mobile application, its online services, or this website (together, the "Service"). SmartPref is the controller of the data described here.

1. Data we collect

Data you provide

  • Account data: email address and password, or identity information returned by Apple or Google sign-in. Passwords are stored only as salted cryptographic hashes.
  • Password recovery: your primary email address, a hashed one-time recovery token, and its creation and expiry times. Recovery links expire after ten minutes.
  • Profile data: an optional username and profile image.
  • Support communications: information you include when you contact us or report an ad.

Data created when you use the Service

  • Device and service data: an app-generated opaque device identifier, platform, app version, locale, account and session records, and timestamps such as account creation and last activity. If you enable flower reminders, we also store this installation's push token, device language, and delivery state.
  • Gameplay data: game variant and deal seed, an opaque attempt identifier, outcome, duration, move counts, Undo and Hint use, score, rules version, completion time, and the move log needed to validate a submitted result. Saved in-progress games and preferences generally stay on your device unless a sync feature sends the relevant data to us.
  • Purchase data: store, product and transaction identifiers, purchase token or signed store record, purchase and verification times, and entitlement status. Apple or Google handles your payment details; we do not receive your full card number.
  • Analytics and diagnostics: app screens, settings and feature interactions, gameplay milestones, bounded error categories, performance and crash information, device and app characteristics, and the opaque device identifier used as the Firebase user ID. We do not send email, username, password, session token, profile image, full move log, free-form text or raw API bodies as analytics event parameters.
  • Advertising data: consent choices, ad eligibility and interaction events, and information processed by Appodeal and its approved demand partners, which may include IP-derived approximate location, device characteristics, product interactions, diagnostics, and device or advertising identifiers allowed by your platform settings and consent. Solitaire Club does not request device location, Apple App Tracking Transparency permission, or IDFA for this integration.
  • Website and server data: IP address and basic browser or device information needed to deliver and secure the website; requested path, response status and timing; and, for app API requests, the opaque device identifier. The public landing page may also request fonts from Google.

2. Why we use data

We use data to provide and secure the Service; create and authenticate accounts; sync profiles and progress; validate results and calculate community statistics; process and restore purchases; provide support; prevent abuse and fraud; diagnose crashes; understand and improve features; select and measure advertising; comply with law; and establish or defend legal claims.

Where the GDPR applies, our legal bases are performance of our contract with you, our legitimate interests in operating, securing and improving the Service, compliance with legal obligations, and your consent where required for optional advertising or similar processing. You may withdraw consent through the app's ad privacy choices or your device settings without affecting earlier lawful processing.

3. How we share data

We do not sell your account or profile data. We share data only as needed with:

  • Infrastructure providers that host, deliver, monitor, back up or secure the Service.
  • Brevo to deliver requested password-recovery emails. The email provider receives the recipient address and the recovery message, including its one-time link.
  • Google Firebase for analytics, crash reporting, and optional Android flower reminder delivery, subject to our configuration and Google's terms.
  • OpenAI to check a proposed public username for profanity or slurs before we save it. We send the proposed username for this check.
  • Appodeal and advertising partners to request, deliver, limit and measure ads according to applicable consent and platform settings.
  • Apple and Google for app distribution, purchases, purchase verification, and optional sign-in.
  • Professional advisers, authorities or other parties where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a merger, financing, reorganization or sale, subject to appropriate safeguards.

Community views may show a chosen username and profile image with aggregated play statistics. We do not publicly display your email address or opaque device identifier.

4. Third-party privacy information

  • Google Firebase privacy and security
  • Appodeal Privacy Policy
  • Apple Privacy Policy
  • Google Privacy Policy

Third parties process data under their own notices and may update their practices. The advertising partners actually available can vary by platform, region and Appodeal configuration; the in-app consent and privacy interface provides the applicable choices.

5. International transfers

We and our providers may process data outside your country, including outside the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard. You may contact us for more information about applicable safeguards.

6. Retention

We retain personal data only as long as needed for the purposes above, including providing the Service, maintaining security and backups, resolving disputes, enforcing agreements and meeting legal, accounting or fraud-prevention requirements. Retention varies by data type and provider.

Sessions remain until you unlink the device, reset your password, or delete the account. Recovery records are removed after a successful reset or account deletion; an expired unused record may remain until a replacement request. Gameplay results may remain after account deletion so submitted results, anti-fraud records and anonymous community aggregates remain consistent. Verified purchase evidence is retained and detached from the deleted account so ownership can be restored and transaction abuse prevented. Analytics, crash and advertising providers retain information under their own settings and policies.

7. Account deletion

You may delete a credentialed account in the app. Deletion removes the account's email, password hash, sign-in identity, username and profile image; ends its sessions; and removes device links. Purchase evidence is unlinked rather than erased, and accepted gameplay records remain attached to a non-identifying tombstone account. We retain a one-way salted hash of the former email address for support, abuse prevention and a possible verified restoration request; it cannot be used to sign in or recover the plain email.

Deleting the app alone does not delete server data. You can also contact us at pro@smartpref.ru for help with a privacy request.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing; receive a portable copy of data you provided; withdraw consent; and complain to a supervisory authority. These rights can have legal exceptions. We may need to verify your identity before acting on a request.

In the European Economic Area, you may complain to the Luxembourg National Commission for Data Protection (CNPD) or your local data-protection authority. Contact us first if you can, so we have an opportunity to address your concern.

9. Security

We use reasonable technical and organizational measures designed to protect data, including hashed passwords, random session tokens, access controls and encrypted network transport. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child provided personal data without appropriate permission, contact us and we will take appropriate steps.

11. Changes to this Policy

We may update this Policy to reflect changes to the Service, law or our practices. We will post the revised version and update the effective date. We will provide additional notice of material changes where reasonably possible or legally required.

12. Contact

SmartPref S.àr.l.-S
Luxembourg
LBR B308734
pro@smartpref.ru

Solitaire Club·Terms & Conditions