Skip to content
Richie Games
Privacy PolicyTerms
← Back to home

Richie Games · Your data, explained

Privacy Policy

How Richie Games collects, uses and protects information across the app, rewards, games, offers and related services.

Effective date: 24 August 2026 · Last updated: 24 August 2026

On this page

    On this page

      1. Who we are and what this Policy covers

      This Privacy Policy explains how Mega Fortuna Teknoloji ve Yazılım Anonim Şirketi (“Mega Fortuna”, “we”, “us” or “our”) processes personal data when you use the Richie mobile application, Richie websites, rewards and loyalty features, game and offer discovery, surveys, customer support and related services (together, “Richie” or the “Services”).

      For the processing described in this Policy, Mega Fortuna is the data controller unless we expressly state that another party acts as an independent controller. Third-party games, offerwalls, surveys, advertisements, app stores, payment services and linked websites may process data under their own privacy notices. Their processing is not controlled by this Policy.

      Controller: Mega Fortuna Teknoloji ve Yazılım Anonim Şirketi
      Address: Odunluk Mah. Akpınar (180) Cad., Green White Plaza, No. 5/25, Bursa, Türkiye
      Privacy contact: [email protected]

      2. Eligibility and children

      The Services are intended only for people aged 18 or older. We do not knowingly permit children to create an account or intentionally collect personal data from children. If we learn that a child has provided personal data, we will take appropriate steps to delete it. A parent or guardian may contact us using Section 16.

      3. Personal data we collect

      CategoryExamplesHow obtained
      Account and profileName, username, email, phone number, age/date-of-birth or age band, gender where optional, country, language, profile image, authentication provider ID, preferences, account status.From you; Google/Apple/Facebook login where selected.
      Device and networkIP address, user agent, device manufacturer/model, OS and app version, language, time zone, network type, device/app installation identifiers, Firebase Installation ID, advertising identifier (GAID/IDFA where available), approximate location inferred from IP.Automatically from the app, SDKs and servers.
      Usage and gameplayApp opens, sessions, clicks, screens, referral source, game/offer views, installs, play time, progress, level or milestone events, purchase-event metadata, crashes and diagnostics.Automatically; game, attribution and offer partners.
      Installed-app and usage-access dataPackage names, installation source, application certificate signature and app usage history made available through Android permissions. Usage information may be grouped by day, week, month or year. Collection may continue in the background after permission is granted, as permitted by Android settings.Your device, subject to OS controls and the prominent in-app disclosure and permission flow.
      Offerwall, advertising and surveyOffer/campaign ID, impression, click, conversion, survey eligibility/completion, postback, reward amount/status, fraud and quality signals.Offerwall, ad, survey and attribution partners.
      Rewards and transactionsPoints/balance, earning history, redemption request, gift-card/payment method, transaction reference, delivery status, reversals and tax/compliance records.From you and fulfilment/payment partners.
      Identity and anti-fraudVerification result, duplicate-account/device signals, risk score, IP/proxy/VPN indicators and selfie/video verification data.From you and verification/fraud providers.
      CommunicationsSupport requests, emails, survey feedback, promotion entries, consent and preference records.From you and support systems.

      We do not collect IMEI. We process app-scoped installation identifiers, identifiers made available by the operating system, and advertising identifiers where available and permitted. We use approximate location rather than continuous precise GPS location. Camera access is used for identity and liveness verification. Payment-card credentials are processed by the applicable app store or payment provider rather than stored by us.

      Identity and liveness verification

      We use camera-based selfie or video verification for liveness detection, age estimation or verification, profile-photo verification, duplicate-account detection, identity-fraud prevention and protection of accounts and rewards. The verification provider processes captured images or video, may create or compare biometric data, and returns verification, duplicate-account and fraud-risk results. We store verification-session identifiers, status and fraud-result metadata. Verification data is not sold or used for advertising or marketing.

      Biometric verification data is ordinarily retained for approximately 30 days, subject to a shorter deletion request where applicable and limited extensions necessary for trust and safety, dispute handling or legal compliance. Where biometric or other sensitive-data processing requires consent, we request explicit authorization through a separate in-app disclosure. Refusing verification may prevent redemption where the required security review cannot lawfully and reasonably be completed by another method.

      Information received from other sources

      We receive personal data from authentication providers, game and offer partners, survey providers, attribution and advertising services, app stores, payment and reward-fulfilment providers, identity-verification providers and fraud-prevention services. This may include account identifiers, campaign and referral information, installation and completion events, reward status, verification results, transaction status and security signals. Where applicable law requires a separate notice for data obtained from another source, we provide that notice within the required period.

      If you choose Google, Apple, Facebook or another third-party sign-in service, we receive the account identifier and profile fields that service makes available under your settings and authorization. We do not receive your third-party password. You can manage the connection through the relevant provider, but disconnecting it does not automatically delete data already lawfully received by Richie.

      4. Why we process data and our legal bases

      PurposeDataEEA/UK legal basis
      Create and administer accounts; provide game, offer, survey and reward functions.Account, device, usage, offer and transaction data.Performance of a contract.
      Attribute installs/actions, validate milestones, calculate and deliver rewards.Identifiers, IP address, campaign/offer events, gameplay and transaction data.Contract; legitimate interests in accurate attribution and preventing loss.
      Secure the Services; detect bots, duplicate accounts, abuse, VPN/proxy manipulation and fraud.Device/network, IP, usage, verification and risk signals.Legitimate interests; legal obligations where applicable.
      Operate, troubleshoot, measure and improve the Services.Usage, diagnostic and aggregated analytics data.Legitimate interests; consent where required for SDK/device storage access.
      Serve contextual or personalised advertising and measure advertising.IP address, advertising/device identifiers, consent signal, approximate location, ad interaction and conversion data.Consent where required; otherwise legitimate interests only where law permits.
      Send push, email or SMS marketing.Contact details, preferences and engagement.Consent or soft opt-in where legally available.
      Meet tax, accounting, consumer, sanctions and legal requirements; defend claims.Account, transaction, verification and communications data.Legal obligation; legitimate interests.

      Where consent is the basis, you may withdraw it at any time without affecting earlier lawful processing. Refusing optional consent does not block unrelated core functions, though a feature that technically requires the data may be unavailable.

      5. Advertising, offerwalls and full IP-address sharing

      The Services use advertising and offerwall partners to display offers, match campaigns, measure impressions, clicks, installs and qualifying actions, validate completion, prevent fraud and fund rewards. Our servers and integrated SDKs share the user’s IP address with relevant partners together with a device or advertising identifier, user agent, app, campaign and placement identifiers, consent status, timestamp, country or region, and relevant conversion or reward events.

      Google AdMob processes the IP address for ad delivery and measurement, permitted personalised advertising, non-personalised or limited advertising, frequency capping, reporting, approximate geolocation, service improvement, security and fraud or invalid-traffic prevention. Google may also process device and application information, permitted advertising identifiers, app-scoped identifiers, consent signals, ad-request and interaction data and diagnostic information.

      AdMob mediation

      We use AdMob as an advertising mediation platform. For an eligible ad request, AdMob may make relevant ad-request, device, consent, identifier and interaction data available to eligible advertising demand sources to select and deliver an advertisement. The receiving source may vary, and not every source receives every request.

      Google User Messaging Platform

      We use Google’s User Messaging Platform (“UMP”) to present privacy and consent messages where required and to record your advertising privacy choices. Depending on your location, these choices may be stored and communicated using Google or IAB Europe Transparency and Consent Framework signals and made available to eligible advertising partners to determine the permitted advertising mode.

      Personalised advertising is used only where permitted by your consent choices, device settings and applicable law. You can change advertising choices through the privacy options presented in the Services and your device’s advertising controls. Resetting an advertising ID or limiting tracking does not stop contextual ads, essential security logs or reward-validation processing.

      6. Recipients and third-party integrations

      We disclose only data reasonably necessary for the stated purpose. A provider may act as our processor or as an independent controller under its own privacy notice.

      Recipient/categoryPurpose and typical dataPrivacy information
      Google AdMob / Google Mobile AdsAd delivery and measurement, fraud and security; IP address, device/ad IDs, approximate location, app/ad events and consent signals. Mediation demand sources include AppLovin, InMobi, ironSource, Liftoff/Vungle, Meta, Mintegral, Moloco, Pangle and Unity.Google Privacy Policy; How Google uses partner data
      BitLabs (BitBurst GmbH)Survey matching/completion and rewards; identifiers, IP, device data, demographic/survey data and completion signals.BitLabs Privacy Policy
      MAF / MyAppFreeOffer discovery, attribution and reward validation; identifiers, IP, device/app and conversion data.MAF privacy notice
      TyrAds Pte. Ltd.Offerwall, attribution, post-install events and reward validation; identifiers, IP, device, location and usage/conversion data.TyrAds Privacy Policy
      ExmoxOfferwall/campaign delivery and attribution; identifiers, IP, device, click/install/conversion and reward data.Exmox Privacy Policy
      AdGemOfferwall, advertising, attribution and reward validation; cookies/SDK IDs, IP, user agent, device and event data.AdGem Privacy Policy
      Ayet StudiosOfferwall, attribution, fraud prevention and rewards; IP, identifiers, device/app, click and conversion data.Ayet Studios privacy notice
      PollfishOptional surveys and participation validation; survey responses and related technical, device, identifier, location, quality and fraud-prevention data.Pollfish Respondent Terms
      StorylyInteractive content and engagement measurement; device, application, identifier, interaction, diagnostic and approximate-location data.Storyly Privacy Policy
      Besitos, BigTreeAds, WDigital and Adwake PlaybackOffer and advertising delivery, attribution, campaign measurement and reward validation; IP address, device/app identifiers and offer interaction or conversion data.The privacy notice presented with the relevant offer or service.
      AppsFlyerMobile attribution, analytics and fraud prevention; IP, ad/device/install identifiers and app events.AppsFlyer Privacy Policy
      Firebase/Google Cloud, AWS and AzureAuthentication, hosting, notifications, analytics, diagnostics and security.Applicable Google, Amazon and Microsoft privacy notices.
      App stores, fulfilment/payment, identity verification and support vendorsDistribution, redemption/payment, compliance, support and communications.Notice shown at collection and applicable provider policy.

      External services and links

      The Services may link to or open third-party games, surveys, offerwalls, app stores, payment services and websites. Those services control their own collection and use of personal data under their privacy notices. Review the notice shown by the third party before submitting information. A link or integration does not make Mega Fortuna responsible for an independent service’s privacy practices.

      7. Data sharing, sale and targeted advertising

      We do not sell personal data for money. Some US state laws may define disclosure of identifiers or internet activity to advertising partners for cross-context behavioural advertising as a “sale”, “sharing” or “targeted advertising”, even where no money changes hands. Where applicable, you may opt out through the privacy choices available in the Services or by contacting us. We do not knowingly sell or share personal data of people under 18.

      8. International transfers

      We and our providers may process data in Türkiye, the EEA, United Kingdom, United States, Singapore and other countries where they operate. Where required, we use an adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum/IDTA, Türkiye’s approved transfer mechanism, or another lawful safeguard, and apply supplementary security measures as appropriate. You may request information about the relevant safeguard.

      9. Retention

      We retain personal data only for as long as necessary to provide the Services and fulfil the purposes described in this Policy. Account data is retained while the account is active; reward, transaction, tax and fraud records are retained as required for accounting, security and legal obligations; advertising, attribution, IP and diagnostic logs are retained only as needed for measurement, security and disputes and are then deleted or aggregated. Support and consent records are retained as needed to respond and demonstrate compliance. Backup copies are deleted through the regular backup-overwrite cycle.

      We may preserve limited data longer when reasonably required for a legal hold, dispute, fraud investigation or statutory obligation. Deletion from active systems may not immediately remove data from encrypted backups, which remain access-restricted until overwritten.

      10. Security

      We use administrative, technical and organisational safeguards appropriate to the risk, including access controls, encryption in transit, monitoring, supplier review and incident response. No system is completely secure. If a breach triggers a legal notification duty, we will notify the relevant authority and affected individuals as required.

      Data minimisation and access

      Access to personal data is limited to personnel and providers who need it for an authorised purpose. We review access rights, limits collection to relevant fields and uses aggregation or pseudonymous identifiers where reasonably possible. Personal data is not used for a materially incompatible purpose without a further lawful basis and notice.

      11. Automated decisions and profiling

      We may use automated rules or models to rank offers, personalise content, detect fraud, validate rewards or restrict suspicious activity. Signals may include device, IP, account, usage and transaction patterns. A material adverse decision should not rely solely on automation where prohibited. You may contact support to request human review of an account or reward decision, subject to fraud-prevention and legal limitations.

      12. Your choices and rights

      Depending on your location, you may have rights to access, correct, delete, restrict or object to processing; receive portable data; withdraw consent; opt out of targeted advertising/sale/sharing or certain profiling; appeal a denied request; and complain to a regulator. Türkiye residents also have the rights provided by Article 11 of Law No. 6698 (KVKK). EEA/UK residents may complain to their local supervisory authority. Brazilian residents may exercise LGPD rights and contact the ANPD. Applicable US residents may use an authorised agent and will not be discriminated against for exercising a right.

      Submit a request to [email protected] with “Privacy Request” in the subject. We may verify your identity and authority, request only information reasonably necessary for verification, and respond within the legally required time. Appeals may be sent to the same address with “Privacy Appeal”.

      If you are not satisfied with our response, you may complain to the data protection authority in your country. Türkiye residents may apply to the Turkish Personal Data Protection Authority; EEA residents may contact their local supervisory authority; UK residents may contact the Information Commissioner’s Office; and Brazilian residents may contact the ANPD.

      13. Permissions and platform controls

      Where a feature needs an Android permission—such as notifications, installed-app and usage access, camera or approximate location—we provide a just-in-time explanation and request the permission before access. You can revoke permissions in device settings. Google Play Data safety disclosures describe the corresponding collection and sharing.

      Marketing and push notifications

      You can opt out of promotional email or SMS using the unsubscribe method in the message or by contacting us, and you can disable push notifications in device settings. We may still send non-promotional messages needed to operate your account, complete a transaction, provide security alerts or answer a request. Withdrawing marketing consent does not affect processing already carried out lawfully.

      Browser and universal opt-out signals

      Because there is no uniform industry standard for legacy “Do Not Track” signals, our websites do not respond to DNT alone. Where applicable law requires it, we process a recognized universal opt-out mechanism, such as Global Privacy Control, as a request to opt out of sale, sharing or targeted advertising for the browser or device that sends the signal. You may need to apply the signal separately to each browser or device. A signal does not disable processing needed for security, fraud prevention, service delivery or contextual advertising.

      14. Regional privacy notices

      This Section supplements the rest of the Policy. It applies only where the relevant law covers our processing and does not limit rights available under another applicable law.

      California

      During the preceding 12 months, we may have collected the categories described in Section 3: identifiers; customer-record information; characteristics such as age range, gender or country where provided; commercial and transaction information; internet or other electronic-network activity; approximate geolocation; audio, electronic, visual or similar verification information; biometric information used for verification; and inferences used for personalization, security or fraud prevention. Some account credentials, precise account-access information and biometric information may be treated as sensitive personal information. We collect these categories from you, your device and the sources described in Section 3, use them for the purposes in Sections 4 and 5, and retain them as described in Section 9.

      We may disclose these categories for business purposes to the recipients in Section 6. Advertising disclosures involving identifiers, internet activity, approximate location or inferences may be considered “selling” or “sharing” under California law even though we do not receive money for personal data. We do not knowingly sell or share personal information of people under 18. We use or disclose sensitive personal information only for permitted purposes, such as providing requested services, verification, security, fraud prevention and legal compliance, unless we provide a legally required right to limit additional use.

      California residents may request to know, access, correct or delete personal information; receive specific pieces of information in a portable format; opt out of sale or sharing; limit certain uses of sensitive personal information where applicable; and receive equal service and pricing without unlawful discrimination. We generally respond to verifiable access, correction and deletion requests within 45 days and may extend once where legally permitted after giving notice. We process opt-out requests within the period required by law. You may use an authorized agent; we may request proof of authority and may verify your identity directly. Qualifying Global Privacy Control signals are treated as opt-out requests for the browser or device that sends them.

      Richie rewards are provided for eligible participation and transactions, not as payment for agreeing to the sale or sharing of personal information. If we introduce a program that qualifies as a financial incentive under California law, we will provide its material terms and obtain any required opt-in before enrollment, and participants may withdraw as described in that notice.

      Colorado, Connecticut and Virginia

      Residents covered by these state laws may request access, correction, deletion and portability and may opt out of targeted advertising, sale of personal data and profiling in furtherance of decisions that produce legal or similarly significant effects. We respond within 45 days, subject to a legally permitted extension, and provide a process to appeal a denied request. We respond to appeals within the period required by the applicable state law. Where required in Colorado or Connecticut, we recognize qualifying universal opt-out mechanisms for targeted advertising or sale.

      Other United States jurisdictions

      Residents of another US state with an applicable comprehensive privacy law may exercise the rights that law grants, including any applicable rights to access, correct, delete, obtain a portable copy, opt out or appeal. We honor these rights and recognized opt-out preference signals to the extent required in the relevant jurisdiction.

      Brazil

      Under the LGPD, eligible data subjects may request confirmation of processing; access; correction; anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data; portability where regulated; information about sharing and consent choices; withdrawal of consent; review of qualifying automated decisions; and information about decision criteria, subject to lawful protections. A simplified confirmation or access response may be provided immediately, and a complete declaration will be provided within 15 days where that LGPD deadline applies. Requests are handled free of charge as required by law. You may complain to Brazil’s Autoridade Nacional de Proteção de Dados (ANPD).

      Republic of Korea

      Where Korea’s Personal Information Protection Act applies, the categories collected, purposes, retention approach and recipients are described in Sections 3, 4, 6 and 9. Overseas recipients may process data in the countries described in Section 8 for service delivery, advertising, attribution, verification, support, security and reward fulfilment, using the transfer basis and safeguards required by applicable law. Eligible data subjects may request access or transmission, correction, deletion, suspension of processing and an explanation or review of a qualifying fully automated decision. We will provide any additional transfer notice or consent required for a particular recipient or transfer.

      15. Changes to this Policy

      We may update this Policy to reflect product, vendor or legal changes. We will publish the new effective date and, for material changes, provide prominent in-app notice and request renewed consent where required. We maintain an internal version and change log. Continued use is not treated as consent where applicable law requires an affirmative choice.

      16. Contact

      Questions and rights requests: [email protected].
      Postal contact: Mega Fortuna Teknoloji ve Yazılım Anonim Şirketi, Odunluk Mah. Akpınar (180) Cad., Green White Plaza, No. 5/25, Bursa, Türkiye.

      © 2026 Richie Games

      [email protected]