Mighty Kingdom Privacy Policy

Last update: May 24, 2018

Mighty Kingdom Pty Ltd ACN 149 485 165 (“Mighty Kingdom”, “us”, “our” or “we”) is committed to safeguarding your (“users”, “you”) privacy online. It is very important to us that you should be able to use and enjoy this website and our apps, without having to worry about your privacy in any way. Please also view our children’s privacy policy located here.

We want to be transparent in explaining how and why we handle your personal information. Accordingly, this Privacy Policy (the “Privacy Policy”) describes the ways we collect, store, use, and manage the information, including personal information and data that you provide or that we collect in connection with our websites, including www.mightykingdom.com, www.kittykeeper.com (the “Sites”), or any apps published by Mighty Kingdom, including, but not limited to, Kitty Keeper: Cat Collector, Shopkins World!, Shopkins World Vacation, Shopkins: Chef Club, Shopkins: Shoppie Style, Shopkins Dash!, Shopkins: Shoppie Dash!, Shopkins Run!, Shopkins: Sticker Fun!, Cutie Cars, LEGO Friends: Heartlake Rush, Wild Life: Puzzle Story (the “Apps”).

In this Privacy Policy, the Site and Apps are referred to collectively as the “Platforms”.

This Privacy Policy also helps you understand how you can update the information we collect and how you can manage and request the export and/or deletion of your personal information.

This Privacy Policy does not apply to the collection, use or disclosure of personal and non-personal information through any apps for which Mighty Kingdom is not the publisher.

By using the Platforms, you, and, where applicable, your parent/guardian (for themselves and on your behalf) acknowledge that you have read and agreed to our Privacy Policy. If you do not agree to this Privacy Policy, please do not use any of our Platforms.

We reserve the right to make changes to this Privacy Policy at any time. Please check the Privacy Policy each time you use our Platforms to ensure you are aware of any changes in our privacy practices. Our Privacy Policy will indicate the date it was last updated. Your continued use of our Platforms will constitute your acceptance of the changes to our Privacy Policy. If there is a substantive or material change in the way that we use your personal information, we will notify you via email of the relevant changes or otherwise provide a prominent notice. If you choose to opt-out of or not opt-in to our changed practice, our email communication (if applicable) will contain instructions on how to do so. If such change affects children users, we will first notify and obtain the prior verifiable consent of the child’s parent or legal guardian.

WHAT DOES MIGHTY KINGDOM DO?
Mighty Kingdom successfully develop and publish mobile apps with quality brands licensed by others, as well as our own developed brands. We are known for creating successful games with brands such as Disney, LEGO, Moose Toys, and KitCatCo.

HOW WE PROTECT THE ONLINE PRIVACY OF CHILDREN UNDER 13

Mighty Kingdom takes many precautions to protect the online privacy of children. Whenever we refer to “children” in this Privacy Policy, we mean children under the age of 13. Please help us in protecting children’s privacy by instructing them to never provide any personal information (full name, email address, home address, phone number, etc.) without your permission.

Mighty Kingdom follows the principles of the Children’s Online Privacy Protection Act (“COPPA”), a U.S. law designed to protect the online privacy of children, in our online services and Apps that are directed to children. If you would like to learn more about COPPA, you can refer to the “Children’s Privacy” section of the United States Federal Trade Commission’s website.

Mighty Kingdom also implements technical and organisational measures to help protect children’s personal data in accordance with the new General Data Protection Regulation (GDPR). The GDPR is the new European Union (EU) data protection law that becomes effective on May 25, 2018.

Currently, Mighty Kingdom does not knowingly collect any personally identifiable information from children or within the child-directed portions of our Platforms except as otherwise outlined in this Privacy Policy. Where we collect and store personal information from children, we do so in accordance with the requirements of COPPA and the GDPR (to the extent they are applicable) by obtaining the consent of the child’s parent or legal guardian before such collection, unless the collection of information falls within an exception that is permitted under COPPA or GDPR (as applicable).

In our Apps directed to children users, we may collect pseudonymised information which includes persistent identifiers such as a transaction ID to verify purchases, which is encrypted upon collection. This information is collected solely for the purpose of providing functionality and support for our internal operations and optimising our users’ game experience.

The Apps may contain advertisements or advertising messages about Mighty Kingdom or third party products and services. In any case, Mighty Kingdom does not permit behaviourally-targeted advertising to children in the Apps or in the Platforms where user is under the age of 13.

THE TYPES OF INFORMATION WE COLLECT AS YOU USE OUR PLATFORMS
Mighty Kingdom collects and holds personal information (which includes information that can be used to identify a specific individual) about people who come into contact with us, including users of the Platforms. Mighty Kingdom does not knowingly collect any personally identifiable information from children outside of the information required for the support of internal operations. You may view our children’s privacy policy here.

We collect information to provide better services to all of our users – from delivering advertising that you want to see, to understanding how you play our games and what we can do to make the experience better for you.

Mighty Kingdom may collect non-personal information about your use of the Platforms to help us improve our services or for other purposes as described in this Privacy Policy. We may combine the non-personal and personal information you provide us through our Platforms and third party services, such as via a support email. Information collected will vary depending upon the user’s activity.

APPS, BROWSERS AND DEVICES
The information we collect includes the following:

  • Contact information (such as name and email address). In the case of Apps directed to children users, the child’s name and/or email addresses is only collected after express parental consent from the child’s parent or legal guardian has been provided. Contact information may be used for the purposes of email marketing. Contact information may also be required for users to create an account with us or to otherwise use our Platforms;
  • Game data (such as your interactions with the game and with the other players inside the game via server log files, your player ID);
  • We may also collect information about your computer, hardware, software, platform, media, connection, IP address or Device ID to enable you to use our Platforms over the internet (unless the Platforms is directed at children under 13). An IP address or Device ID is a number that is automatically assigned to your computer or device when you use the Internet. We use an IP address or Device ID to help diagnose problems with our servers, administer our Platforms, analyse trends, track users’ movement on our Platforms, gather broad demographic information for aggregate use in order for us to improve the Platforms, and deliver customised, personalised content. We do not link IP addresses or Device IDs with any personally identifiable information.
  • We collect a Transaction ID for the purposes of verifying legitimate transactions from app stores.

We may collect this information when you install an app via the android and iTunes stores, and other platforms like Facebook.

YOUR EMAIL ADDRESS

With your express consent, we may collect your email address on behalf of clients like Moose Toys for the Shopkins games so that they can contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. A parent gate for verification will be in place in order to opt-in.

You may opt out of receiving any, or all, of these communications by following unsubscribe links or instructions provided in any email sent.

YOUR ACTIVITY
We may also collect information about online activity such as feature usage, game play statistics and scores, user rankings, click paths, and in-app purchases. We use this information to enable you to play our game over the Internet. We also use this information to better understand the behaviour and preferences of our customers, so that we can improve our products and services. We work with third party ad providers analytics companies such as, but not limited to: The Fyber Group, AdColony, Inc., Chartboost, Unity 3D/Unity Technologies ApS, ironSource Mobile Ltd., Vungle, Inc., HyperMX Mobile LLC, Tenjin, Inc., Facebook, and App Annie, to help us collect and analyse this information with the goal of improving our Platforms and providing you with the best services.

COOKIES
Our Sites may use first-party cookies (set by the website owner) to enhance your experience while using them. Cookies are pieces of information that some websites transfer to the computer that is browsing that website, and are used for record-keeping purposes on many websites. Use of cookies makes Web-surfing easier by performing certain functions such as saving language preferences and maintaining your sessions while you are on our Site.

The cookies used on our Site, contain generic information used for page navigation. If you would prefer not to receive cookies, you can disable cookies on your browser. If you choose to have your browser refuse cookies, some areas of our Site may not function properly.

We also use cookies related to the use of Google Analytics on our Site. Google Analytics uses first-party cookies to report on visitor interactions. These cookies are used to collect information about how visitors use our Site. We use the information to compile reports and to help us improve the Site. You can opt out of tracking by Google Analytics by visiting: http://tools.google.com/dlpage/gaoptout?hl=en-GB.

We do not link information collected through cookies with any personally identifiable information.

We may work with third parties (such as Ad providers), that use cookies to make advertising messages more relevant to the user. They may perform functions like preventing the same ad from continuously appearing in one of our Apps. Other third parties such as Facebook, use similar tracking technologies like pixel tags that can collect and use certain information about your online activities on our websites and apps, in order to deliver you targeted advertisements that are tailored to your browsing activities and interests – see below for more details on in-game advertising.

PURPOSES FOR WHICH WE USE THE INFORMATION COLLECTED

The personal information we collect and hold about you depends on your interaction with us. Generally, we will collect, hold and use personal information about you if it is directly related to, or reasonably necessary for, the performance of our functions and activities and for the purposes of:

  • providing you with our goods and services (including with respect to the Platforms);
  • answering any questions or inquiries you direct to us;
  • facilitating our internal business operations, including the fulfilment of any legal requirements;
  • for other purposes which are reasonably necessary in connection with our normal functions and activities;
  • to provide you with marketing materials in relation to offers, specials, products and services we consider may be of interest to you;
  • analysing our services and customer needs with a view to developing new or improved services (including with respect to the Platforms); and
  • as otherwise required or permitted by applicable laws and regulations.

You are not required to provide personal information to us to obtain access to any of our Platforms; however, the collection, storage, use and disclosure of your personal information may be required for registration and/or to access certain areas or features of our Platforms and, if you do not provide the required information, you will not have access to these areas or features.

The following provides more information regarding the purposes for which we use your personal information:

PLAY STATISTICS AND USAGE

  • Registration for games or special game-specific event participation for parents and users over 13;
  • Processing your order(s) of products or subscriptions from us online;
  • Responding to or forwarding your request(s) for services from third party service providers on our Site;
  • Enabling your use of our software or online services and access to certain areas of our Site, Apps, features or programs;
  • Beta-testing;
  • We may use an IP address or Device ID to help diagnose problems with our servers, administer our Platforms, analyse trends, track users’ movement on our Platforms, gather broad demographic information for aggregate use in order for us to improve the Platforms, and deliver customised, personalised content. We do not link IP addresses or Device IDs with any personally identifiable information.

CUSTOMER SUPPORT

  • Warranty registration and/or providing customer support or responding to technical service requests;
  • Providing online services for parents and users over 13;
  • We collect a Transaction ID for the purposes of verifying legitimate transactions from app stores. Once verified, the transaction ID is deleted and removed from any records.

THIRD PARTY SERVICE PROVIDERS

IN GAME ADVERTISING
Our Platforms may incorporate advertising serving technology offered by our third party service providers, including: The Fyber Group, AdColony, Inc., Chartboost, Unity 3D/Unity Technologies ApS, ironSource Mobile Ltd., Vungle, Inc., HyperMX Mobile LLC, Tenjin, Inc., Facebook, which enable advertising to be temporarily uploaded into the game and replaced while you play. The data collected for this purpose may include IP address or persistent identifiers, to notably allow our third party service providers to calculate the number of views, to cap ads and to serve ads in a format that fits your device. However, in no case will this data be associated with any of your personal information, nor used for behavioural advertising or to build a profile on your online practices. None of the information collected and used for advertising purposes is used to personally identify you. These advertising serving technologies are integrated into the Apps; if you do not want to use these technologies, do not play the Apps while connected to the Internet. In certain areas of our Apps, you may be able to turn off advertising from our third party service providers via the settings screen. Please see below for links to privacy policies for all the service providers noted above:

The Fyber Group https://www.fyber.com/legal/gdpr-faqs/
https://www.fyber.com/legal/privacy-policy/
AdColony, Inc. https://www.adcolony.com/gdpr/
https://www.adcolony.com/privacy-policy/
Chartboost https://answers.chartboost.com/en-us/articles/115001489623
Unity 3D/Unity Technologies ApS https://unity3d.com/legal/gdpr
https://unity3d.com/legal/privacy-policy
ironSource Mobile Ltd. http://www.ironsrc.com/wp-content/uploads/2017/01/ironSource-Privacy-Policy.pdf
Vungle, Inc. http://vungle.com/privacy/
https://vungle.com/gdpr-faq/
HyperMX Mobile LLC https://www.hyprmx.com/pp.html
Tenjin, Inc. https://www.tenjin.io/privacy/
Flurry, Inc. https://policies.oath.com/us/en/oath/privacy/index.html/
Facebook https://www.facebook.com/policy.php
https://www.facebook.com/business/gdpr

PARTICIPATION ON SOCIAL MEDIA

  • The Sites include Social Media Features, such as the Facebook Like button and Widgets, such as the Share this button or interactive mini-programs that run on our Sites. These Features may collect your IP address, which page you are visiting on our Sites, and may set a cookie to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our Sites. Your interactions with these Features are governed by the privacy policy of the company providing it. Mighty Kingdom may use collected data to analyse social media campaign outcomes. This information will not be stored on Mighty Kingdom servers.
  • Mighty Kingdom may offer you the opportunity to invite your contacts from a Social Network Service (such as your Facebook friends) so that those contacts can be located in Mighty Kingdom games and/or you can invite them to join you in Mighty Kingdom games. Such contact information will be used only for the purpose of sending communications to the addressee. You or the third party may contact us to request the removal of this information from our database to the extent Mighty Kingdom stores any of this information.

SWEEPSTAKES AND CONTESTS

  • We may provide you the opportunity to participate in a sweepstakes or contest through our Service. If you participate, we will may request certain personal information from you. Participation in these sweepstakes and contests are voluntary and you therefore have a choice whether or not to disclose this information. The requested information typically includes contact information (such as name and shipping address), and demographic information (such as zip code).
  • We use this information to notify winners and award prizes, to monitor traffic or personalise the Service. We may use engage a third party service provider to conduct these sweepstakes or contests; that company is prohibited from using your users’ personal information for any other purpose.

You are not required to provide personal information to us to obtain access to any of our Platforms; however, the collection, storage, use and disclosure of your personal information is required for registration and to access certain areas or features of our Platforms and, if you do not provide the required information, you will not have access to these areas or features.

HOW WE STORE THE INFORMATION COLLECTED

We are committed to protecting your personal information. We implement appropriate technical and organisational measures to help protect the security of your personal information; however, please note that no system is ever completely secure. We have implemented various policies including pseudonymisation, encryption, access, and retention policies to guard against unauthorised access and unnecessary retention of personal information in our systems (see also the ‘Retention’ section below).

  • We run all data processing for our platforms via Amazon Web Services, a professional, third-party data center with a defined and protected physical perimeter, strong physical controls including access control mechanisms, controlled delivery and loading areas, and surveillance. Amazon Web Services (AWS) cloud which is Privacy Shield certified. We will may also use server space to and storage services of a company in Sydney called VentraIP.
  • We use keys for authentication to access our servers/cloud platforms via SSH and two factor authentication to access administration consoles as well as user permission management.
  • Our network is protected by a robust firewall configuration with exclusive access to our personnel.

HOW WE SHARE OR DISCLOSE INFORMATION COLLECTED

Generally, we will only use or disclose personal information about you for the purposes for which it was collected (as set out above). We may disclose personal information about you to:

  • service providers and partners, who assist us in operating our business;
  • any industry body, tribunal and/or court in connection with any complaint made by you about us; and
  • any other organisation or person with your consent or as permitted or required by law.

Mighty Kingdom may share your information with third parties for the limited purposes described below:

  • Third Parties: You may register for other services from via our Platforms which are offered by third parties. If you opt in to any of these third party services, we may collect additional information requested by this third party and pass this information, together with all other registration information (including personal information), to that third party. Use of your information by such a third party will be governed by that third party’s terms of service and privacy policy. Participation in these other related services is optional and is not required to play or participate in any of our Platforms.
  • Partners: Mighty Kingdom may also share non-personal information with our brand partners, which may include without limitation game session information, retention, purchases, gameplay events and de-identified information about user behaviour.
  • Marketing: The personal information you provide will allow us to alert you to new products, features and enhancements; special offers; upgrade opportunities; and contests and events of interest. We may also inform you on other companies and organizations that provide products or services that we believe may be of interest to you. We see this as a value-added service helping you to find useful products or services. We strive to limit use of the information you provide to those offers that we think you would appreciate receiving. You may opt out of this service by contacting us as set out in the opt-out provision below. Currently, Mighty Kingdom may provide certain personal information (such as your email address) with its third party service providers (including Moose Toys) for their own marketing purposes (except to the extent required by law, court order, or as requested by other government or law enforcement authority).
  • Service Providers: We may transfer personal information to third party service providers that perform services on our behalf or otherwise collect, use, disclose, store or process personal information on our behalf for the purposes described in this Privacy Policy. Some of these service providers may be located in a country other than where you reside, including in the United States, and your personal information may be stored or processed in those countries (see also the ‘International Data Transfers’ section below). We take reasonable contractual measures to ensure that our service providers provide appropriate protection for your personal information and use your personal information only for the purpose of providing the services to us. Your personal information is subject to the legal requirements of the country in which it is located, including lawful requirements to disclose information to government authorities in those countries. Our employees and those of our agents and service providers who require it in order to fulfil their job requirements, will have access to your personal information.
  • Legal Rights and Obligations: We may use and/or disclose your personal information to enforce legal rights and comply with the law, or to comply with an order from a government entity or other competent authority, or when we have reason to believe that a disclosure is necessary to address potential or actual injury or interference with our rights, property, operations, users or others who may be harmed or may suffer loss or damage. When necessary, we may also disclose personal information to law enforcement, or to the appropriate civil authorities.

We will only collect and use personal information in accordance with this Privacy Policy to the extent deemed reasonably necessary to serve our legitimate business purposes, and we will maintain appropriate safeguards to ensure the security, integrity, accuracy and privacy of the information you have provided. In addition, we will take reasonable steps to assure that third parties to whom we transfer any personal information will provide sufficient protection of that information. Mighty Kingdom does not knowingly share or disclose personal information other than as set forth in this Privacy Policy.

INTERNATIONAL DATA TRANSFERS

When we share personal information, it may be transferred to, and processed in, countries other than the country you live in, which may have laws that are different to what you are familiar with. You can be comfortable that where we disclose personal information to a third party in another country, we put safeguards in place to ensure your personal information remains protected.

For individuals in the European Economic Area (‘EEA’), this means that your data may be transferred outside of the EEA. Where your personal data is transferred outside the EEA, we will ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, that appropriate contractual, technical, and organisational measures are in place (such as the Standard Contractual Clauses approved by the EU Commission).

YOU HAVE CHOICES REGARDING THE INFORMATION WE COLLECT AND HOW IT IS USED

YOUR RIGHTS
Under European Union law, the General Data Protection Regulation or “GDPR” gives certain rights to applicable individuals in relation to their personal data. Accordingly, we have implemented additional transparency and access measures to help you take advantage of those rights (to the extent they are applicable).

Depending on the country in which you live in, the rights you have may include:

  • Accessing, correcting, updating, or requesting deletion of your information.
  • Objecting to processing of your information, asking us to restrict processing of your information, or requesting the portability of your information.
  • Opting out from receiving marketing communications that we send you at any time.
  • Withdrawing your consent at any time if we have collected and processed your information with your consent. Withdrawing your consent will not affect the lawfulness of any processing that we conducted prior to your withdrawal, nor will it affect processing of your information conducted in reliance on lawful processing grounds other than consent.
  • Complaining to a data protection authority about our collection and use of your information. For more information, please contact your local data protection authority. Contact details for data protection authorities in the European Union are available at: http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.

We respond to all requests that we receive from individuals who wish to exercise their data protection rights in accordance with applicable data protection laws. You can contact us by sending an email to privacy@mightykingdom.com.

YOUR PERSONAL INFORMATION

Opt-Out Provision: Mighty Kingdom may share your email address with third parties for marketing purposes. Mighty Kingdom will obtain your consent prior to any such disclosure. If you do not want Mighty Kingdom to send you postal mail about our products and services, you can opt out at any time and choose to have your name removed from our mailing list. You can do so by contacting Mighty Kingdom by email to privacy@mightykingdom.com. By providing us your email when specifically signing up to our newsletters or email marketing campaigns, you accept to receive emails from Mighty Kingdom with respect to our products and services. Additionally, by providing Mighty Kingdom with your email on Facebook, such as through a customer service enquiry, you accept to receive emails from Mighty Kingdom with respect to that enquiry. If you opt to receive such communications, you may opt out of this consent at any time by contacting us via privacy@mightykingdom.com. You may withdraw your consent to our collection, use and disclosure of personal information at any time, subject to contractual and legal restrictions and reasonable notice, by contacting us as described above. Please note that if you withdraw your consent to certain uses of your personal information, we may no longer be able to provide certain of our products or services.

If you wish to opt-out from collection and use of precise location data for advertising, you can turn location services off through your device settings. The latest versions of iOS and Android allow you to limit which particular applications can access your location information. You can configure your browser to block all cookies from a specific domain or all domains.

User Accounts: If you have an account on our Platforms, at any time, you may disable your account through your account page. Thereafter, Fyber will stop collecting any personal information from you.

REMOVING YOUR INFORMATION

If you wish to request access to your personal information or request that such information be corrected or deleted, or if you have any questions, comments, or concerns about this Privacy Policy or the information practices of Mighty Kingdom, please contact Mighty Kingdom (contact information below). Your right to access or correct your personal information is subject to applicable legal restrictions. We may take reasonable steps to verify your identity before granting access or making corrections. If we have unintentionally collected and stored any personal information from children under 13, parents can request access to review such information, have it deleted, or stop our further collection or use of such information. To make any of these requests (when applicable), please use the contact information below.

RETENTION

We retain your personal data only as long as necessary to provide you with our services and for legitimate and essential business purposes (such as maintaining the performance of our services), making data-driven business decisions about new features and offerings, complying with our legal obligations, and resolving disputes. Following this period, we will make sure the relevant personal data is deleted or anonymised.

OTHER INFORMATION

Business Transactions: We reserve the right to transfer any personal information we have about you in connection with the sale or transfer of all or a portion of our business or assets or rights relating thereto.
Third Party Sites: If you click on a link to a third party site, including on an advertisement, an Ad Provider link, or other third party service, you will leave the Mighty Kingdom Platform you are visiting and go to the site you selected. Because we cannot control the activities of third parties, we cannot accept responsibility for any use of your personal information by such third parties, and we cannot guarantee that they will adhere to the same privacy and security practices as Mighty Kingdom. We encourage you to review the privacy policies of these third party sites from whom you request services. If you visit a third party website that is linked to on a Mighty Kingdom Platform, you should consult that site’s privacy policy before providing any personal information on that site.

Generally, by providing us with personal information, we will assume that you consent to our collection, use and disclosure of such information for the purposes identified at the time that we collect the information from you or as otherwise described in this Privacy Policy. We will make all effort to be clear about what data we are collecting and how we are storing and using that data. In the case of children under 13, as applicable, we will obtain a parent or legal guardian’s verifiable consent prior to the collection of personal information from such users, unless the collection of such information falls within an exception that is permitted under COPPA and/or GDPR (as applicable).

HOW TO MAKE A COMPLAINT ABOUT A BREACH OF YOUR PRIVACY RIGHTS BY US

If you are of the view we have breached the Privacy Act 1988 (Cth), the Australian Privacy Principles any related privacy code, or the GDPR (to the extent that they are applicable to us) in dealing with your personal information, you may make a complaint by writing to us using the contact details below and we will take reasonable steps to investigate the complaint and respond to you.

CONTACT INFORMATION

For any questions on this Privacy Policy, please do not hesitate to contact us!
Our Data Protection Officer can be contracted by email at: privacy@mightykingdom.com