Last updated 2026-10-02.
Zaparo WingRush collects the following, and nothing else.
| What | Specifically | Why | Shared |
|---|---|---|---|
| App activity | A score this user submitted to an app-defined board, when they achieved it, and an optional opaque proof string the app supplies - keyed on their Zaparo ID user id; App interactions, as AdMob measures them: that an ad was requested, shown, watched or dismissed; Level, experience points and the number of races played; Link token opened, and the Play install referrer used to match a deferred link after install; Race results: pipes passed, how long the run lasted, and the tap timings the run is verified from; The message payloads, opaque to this module and relayed rather than stored; Which applications within this one tenant the account has been seen in. Recorded when an application registers a device or completes a sign-in under its own application id, so `me().apps` can answer it back to the person.; Who a signed-in user is friends with, who they have a pending request with, and the short code they hand out - all keyed on their Zaparo ID user id | Account management, Advertising or marketing, Analytics, App functionality, Fraud prevention, security, and compliance | Yes |
| App info and performance | App sessions, as Firebase Sessions reports them to Crashlytics: when the app came to the foreground and started a session, with the package name, OS and SDK versions, network type, and device manufacturer and model; Crash stack traces, ANRs and breadcrumbs; Diagnostics the SDK reports on the app and on itself: app launch time, hang rate and energy usage | Advertising or marketing, Analytics, Fraud prevention, security, and compliance | Yes |
| Device or other IDs | Advertising ID (AD_ID), used by AdMob to serve and measure ads; An identifier for the phone, sent with an ad request and with the report that an ad was shown or tapped. It is the advertising identifier only where the app has been declared for it in Play; everywhere else it is an identifier this SDK generates for that install alone, which no other app can read and which dies when the app is removed. Neither is stored as it arrives: the server keeps a keyed hash of it, so the ads cannot be traced back to the identifier.; Crashlytics installation UUID; FCM registration token; Firebase installation ID, from the Firebase Installations SDK that Crashlytics brings in; it is sent with each app session and used to renew the Crashlytics installation UUID; The account identifier, the public half of a key generated in the device key store, and what registered it: the kind of client (phone app, browser, desktop app), its operating system and the app version; The caller's user id, carried on each message so the other players know who sent it | Account management, Advertising or marketing, Analytics, App functionality, Fraud prevention, security, and compliance | Yes |
| Location | Approximate location, derived by AdMob from the IP address an ad request arrives on | Advertising or marketing, Analytics, Fraud prevention, security, and compliance | Yes |
| Personal info | Display name - generated by default, editable by the user; Email address, and the name a provider reported, from the sign-in the person chose. Those two and nothing else: a browser provider is asked for `openid email profile` and only the address and the name are read out of what comes back. | Account management, App functionality, Personalization | No |
| Photos and videos | Profile photo the user chose to upload | App functionality, Personalization | No |
Who holds each kind of data listed above, and when it is deleted:
You can ask for your data to be deleted at any time, at the address below.
Questions about this policy, or a deletion request: privacy@kbsoap.com