Privacy Policy
(Mobile Game: Maze Hunter)
- Last updated: August 19, 2026
- Effective date: August 19, 2026
Maze Hunter (the “Company,” “we,” “us,” or “our”) values your privacy and complies with applicable data protection laws and regulations, including the Personal Information Protection Act and other relevant laws. This Privacy Policy explains how we collect, use, store, disclose, and protect personal data in connection with the mobile game service we provide.
1. Categories of Personal Data Collected
We may collect the following categories of personal data in connection with your use of the Service.
(1) Information Collected as Necessary
- Login identifiers, including OAuth-based account identifiers (such as Google, Apple, or Kakao)
- Nickname and profile information
- Device information, including operating system version, device model, and advertising identifiers
- Gameplay records and log data
(2) Information Generated in the Course of Using the Service
- Access logs and usage history
- IP address, cookies, and device identifiers
- Error reports and crash logs
(3) Optional Information, Where Applicable
Depending on the features you use, we may also collect the following information:
- In-app purchase information, including purchase history and transaction IDs
- When you use the walking reward feature:
- The observed step total for the 24-hour economy reward-day interval provided by a device health data service, such as Health Connect or HealthKit
- The reward interval start and end times, time-zone offset, health aggregation method, whether manual entries were excluded, and mobile platform
- A random app-installation identifier used to prevent duplicate rewards and abuse, processed as a hash on the server
- Information required to deliver event rewards (such as gift certificates), including:
- Name
- Mobile phone number or email address
- Email address and inquiry details submitted through customer support
2. Purposes of Collection and Use
We may collect and use personal data for the following purposes:
- To provide the game service and manage user accounts
- To save, synchronize, and maintain gameplay data
- To process payments and manage purchase history
- To operate events and provide rewards
- To calculate and grant in-game Roll rewards based on step counts
- To prevent and audit duplicate walking rewards, multi-account use, and abnormal requests
- To improve the Service and develop new features
- To prevent unauthorized or fraudulent use and maintain security
- To respond to user inquiries and deliver notices
- To provide personalized advertisements and analyze advertising effectiveness, where consent is obtained as required
2-1. Access to and Processing of Health Data
The walking reward feature is optional and is provided only when the user explicitly selects it and grants separate consent and operating-system permissions.
- On Android, the app uses read access to Steps in Health Connect and the activity-recognition permission required to access step-related fitness data. On iOS, the app uses read access to steps in HealthKit.
- The app reads the step total supplied by the health data service for a fixed-offset 24-hour economy reward-day interval determined by the server from the account country code. This interval may differ from the device-local “current day.”
- Steps marked by the health data service as manually entered are excluded where possible. Some Android data providers may identify manual entries as having an unknown source.
- The observed step total and reward-interval information are transmitted using encrypted communications to the Company’s Firebase-based backend and used to calculate rewards, prevent duplicate grants, and detect abnormal requests.
- The server does not retain a complete history of observed step totals for each reward day. It stores up to 3,000 recognized steps required for the daily reward cap, together with the reward interval and grant status, in the account’s progress data. The current policy grants 10 Rolls per 1,000 steps, up to 30 Rolls per reward day.
- Random installation and account identifiers are processed as hashes in an abuse-prevention ledger configured to be retained for up to 32 days after creation.
- Health data is not used for medical diagnosis or treatment, credit or insurance decisions, personalized advertising, advertising measurement, or sale of data.
- If consent or permission is denied or withdrawn, only the walking reward feature becomes unavailable; the game’s other core features remain available.
Additional details are provided in the separate Walking Reward Feature Consent displayed in the app.
3. Retention and Use Period
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and will delete or destroy such data without undue delay once those purposes have been achieved.
However, where retention is required under applicable law, we may retain certain information for the following periods:
- Records related to contracts or withdrawal of subscription/purchase: up to 5 years
- Records related to consumer complaints or dispute resolution: up to 3 years
- Access log records: up to 3 months
- Hashed installation and account abuse-prevention ledger for walking rewards: up to 32 days after creation
- Any other records required to be retained by applicable law: for the legally required retention period
Upon account deletion or withdrawal from the Service, related personal data, including account-linked recognized-step records, will be deleted without undue delay. Minimum records required for settlement of rewards already granted, audits of consent or withdrawal, abuse response, or compliance with applicable law may be segregated and retained only for the period necessary for those purposes, and then deleted.
4. Disclosure of Personal Data to Third Parties
As a general rule, we do not provide personal data to third parties without your consent.
However, personal data may be disclosed in limited circumstances, including the following:
- Service providers responsible for processing event rewards, such as the delivery of gift certificates
- App marketplace and payment processors, including Google and Apple
- Advertising and analytics service providers
- Where disclosure is required by applicable law or requested by law enforcement or other competent authorities in accordance with applicable legal procedures
In all such cases, only the minimum amount of personal data necessary for the relevant purpose will be disclosed.
5. Outsourcing of Personal Data Processing
To operate the Service efficiently, we may entrust certain personal data processing activities to third-party service providers.
Examples may include:
- Cloud infrastructure and server operations (such as Firebase)
- Push notification services
- Customer support systems
- Advertising platform operations
Where we outsource processing activities, we take reasonable steps to ensure that such service providers handle personal data securely and in compliance with applicable data protection laws.
6. International Transfer of Personal Data
In the course of operating the Service, certain personal data may be transferred to or stored on servers located outside your country of residence.
Examples may include:
- Firebase (Google LLC)
- Global advertising platforms
Where personal data is transferred internationally, we will implement reasonable safeguards and handle such transfers in accordance with applicable laws and regulations.
7. Data Deletion Procedures and Methods
Personal data is deleted without undue delay once the purpose of collection and use has been fulfilled, unless retention is required by applicable law.
Methods of Deletion
- Electronic data: permanently deleted using commercially reasonable measures designed to prevent recovery
- Printed materials: shredded or otherwise destroyed
8. User Rights and How to Exercise Them
Subject to applicable law, users may exercise the following rights at any time:
- To request access to their personal data
- To request correction or deletion of personal data
- To request suspension or restriction of processing
- To withdraw consent, where processing is based on consent, and to request account deletion
Such requests may be submitted through the in-game customer support service or by email.
Consent to the walking reward feature may be withdrawn at any time in the app settings. Permissions granted to Health Connect or HealthKit may be managed or revoked through the operating system’s health data permission settings. After revocation, the app will not read new step data.
9. Security Measures
We implement reasonable technical, administrative, and physical safeguards to protect personal data, including:
- Encryption of data during storage and transmission, where appropriate
- Restriction of access to personal data on a need-to-know basis
- Operation of security systems and monitoring tools
- Periodic security reviews and internal training
10. Advertising and Cookie Policy
We may use advertising identifiers, cookies, and similar technologies to provide advertisements and improve the Service.
This may include:
- Delivery of personalized advertisements, where permitted by law and based on consent where required
- Measurement of advertising performance and user engagement
Users may limit ad tracking or personalized advertising through their device settings, operating system privacy controls, or in-app settings where available.
Step data read from Health Connect or HealthKit is not used to serve or personalize advertisements or to measure advertising performance.
11. Children’s Privacy
If we collect personal data from children under the age of 14, we will obtain consent from a parent or legal guardian where required by applicable law.
Where necessary, we may implement additional age verification or consent procedures.
12. Privacy Officer
We have designated a person responsible for overseeing personal data protection and handling privacy-related inquiries, complaints, and requests for relief.
Privacy Officer
- Name: Chan-yong Park
- Title/Department: Assistant Operator
- Contact: support@p2egames.co.kr (or the in-app customer support channel)
For any questions, complaints, or requests regarding personal data protection, you may contact us through the above contact information or the in-game inquiry feature.
13. Changes to This Privacy Policy
This Privacy Policy may be amended from time to time in response to changes in applicable laws, regulations, or our service practices. Any material changes will be notified through in-game notices or other official communication channels.
Supplementary Provision
This Privacy Policy shall become effective on August 19, 2026.