01Who we are
The controller responsible for your personal data is Centrul de Terapie si Masaj Dora Cocis SRL (“Napoca Interactive”, “we”, “us”), a company registered with the Romanian Trade Register (Registrul Comerțului) under no. J2020002841126, sole registration code (CUI) RO43044221, with its registered office at Str. Fabricii nr. 7, 400620 Cluj-Napoca, jud. Cluj, Romania.
- General contact: hello@napocainteractive.com
- Privacy / data requests: hello@napocainteractive.com
- Data Protection Officer: We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. For any data-protection matter, contact us at hello@napocainteractive.com.
We are established in the European Union, so this policy is written to comply with the GDPR (Regulation (EU) 2016/679) and Romanian implementing law (Law no. 190/2018).
02Scope
This policy explains how we handle personal data in two places:
- The website at napocainteractive.com — a mostly static marketing site with no accounts, no sign-up forms and no advertising trackers.
- Our games and applications — every game and app we develop and distribute, on Steam (PC), Google Play (Android) and other platforms. Our current title is CRUDE: From Wildcat to Tycoon. Depending on the title, a game may use analytics and crash reporting, provide online accounts, cloud features and leaderboards, and offer in-app purchases. Where a specific title differs materially, we will say so in that title’s store listing or an addendum.
Where the storefront (Valve/Steam or Google) processes data as its own controller — for example when you buy the game — that processing is governed by their privacy policies, which we link to below. This policy covers only the data we control.
03Data the website processes
3.1 Local storage in your browser
The site stores a single value in your browser’s sessionStorage under the key napoca-intro-seen. It records that you have already seen the intro animation so we can skip it on the next page within the same tab session. It is not a cookie, it is not sent to any server, it contains no personal data, and it is cleared automatically when you close the tab. See Cookies & local storage for how to clear it.
3.2 Server / edge access logs
The site is hosted and served through Cloudflare. Like any web server, Cloudflare’s edge automatically records standard technical access data — your IP address, the requested URL, timestamp, referrer, and user-agent string — for security, abuse-prevention and reliability. These logs are short-lived and are not used to profile or identify individual visitors.
3.3 Website analytics
For the website we intend to use a privacy-friendly, cookieless third-party analytics provider that reports aggregate, non-identifying usage statistics and does not build cross-site profiles of you. This is separate from the in-game analytics described in section 6.
04Data the game CRUDE processes
CRUDE is a drilling and management simulation with online features. The list below is an overview of the categories of data the game processes; the sections that follow (accounts, analytics, crash reporting, in-app purchases) describe each activity, its purpose and its legal basis in detail. The exact set of data depends on which features and SDKs ship in a given build and, on mobile, on the platform and the consent choices you make.
4.1 Overview of categories
- Account & profile data — email address, username/display name, and authentication data for online accounts, cloud saves and leaderboards (see section 5).
- Device & technical identifiers — device model, operating-system version, language, screen/hardware capabilities, and a random or platform-provided installation identifier used to keep telemetry and diagnostics consistent across sessions (see sections 6–7).
- Gameplay / telemetry — session and usage data, in-game events and performance metrics about how the game is played, so we can balance and improve it (see section 6).
- Crash & diagnostic logs — crash reports, device/OS state and stack traces generated when the game crashes or errors, so we can fix bugs (see section 7).
- Purchase & entitlement records — records of in-app purchases and what you are entitled to, received from the store (see section 8).
- Support correspondence — if you email us for support, we process the contents of your message and your contact details to answer you.
4.2 What we do not do
- We do not sell your personal data.
- We do not store your payment-card or bank details — purchases are handled by the store (Valve/Steam Wallet or Google Play Billing); see section 8.
- The Game does not currently display third-party advertising. If we introduce advertising in the future, we will update this Policy and obtain any consent required by law before doing so.
05Accounts & online services
To use online features — online accounts, cloud saves, multiplayer and/or leaderboards — the game processes account and profile data through our online-services provider.
- What we process: email address, username and/or display name, an account identifier, authentication data (e.g. tokens), and online status/session data. Where you sign in through the store (Steam or Google Play) we may receive a platform account identifier rather than a password.
- Leaderboards & multiplayer: your display name and scores (and, in multiplayer, in-session presence) are shared publicly with other players by design. Do not use a display name that reveals more about you than you want shown. See section 5.1 for what is public.
- Anti-cheat / fair-play data: to keep leaderboards and multiplayer fair, we may process integrity signals (e.g. anomalous gameplay data, submission validation).
- User-generated content: a display name (or any other text you choose to make visible) is user-generated content. Our content rules are in the Terms & EULA.
Legal basis: providing the online account, cloud save, multiplayer and leaderboard features you ask for is performance of a contract (Art. 6(1)(b) GDPR). Anti-cheat and platform-integrity processing relies on our legitimate interests (Art. 6(1)(f)) in keeping the service fair and secure. Online accounts, cloud features and leaderboards are optional; you can play without signing in, though online features will be unavailable.
5.1 What is public vs. private
- Public: your display name, leaderboard scores/rankings, and (in multiplayer) in-session presence.
- Not public: your email address, authentication data and account identifiers are used to run the service and are not shown to other players.
06Gameplay analytics & telemetry
The game uses a third-party analytics provider to understand how CRUDE is played so we can balance, debug and improve it.
- What we process: device identifiers (e.g. a random installation ID), session and usage data, in-game events (progression, feature usage, settings), and performance metrics (frame rate, load times, hardware capabilities).
- Legal basis: where telemetry is non-essential and not consent-exempt, we rely on your consent (Art. 6(1)(a) GDPR); otherwise on our legitimate interests (Art. 6(1)(f)) in understanding and improving the product, balanced against your rights.
Consent mechanism. Where analytics/telemetry relies on consent (in the EEA), the game will present an in-game consent prompt and process this data only after you agree; you can change your choice at any time in the in-game privacy settings, and withdrawing consent stops future collection.
07Crash & diagnostics reporting
The game uses a third-party crash-reporting provider to capture technical reports when the game crashes or errors, so we can diagnose and fix faults.
- What we process: crash logs, stack traces, device and OS information (model, OS version, memory, locale), the app version/build, and the state of the game at the time of the fault. These reports are technical and are not intended to identify you, though a device identifier may be attached to de-duplicate reports.
- Legal basis: our legitimate interests (Art. 6(1)(f) GDPR) in keeping the game stable and fixing faults.
08In-app purchases & financial data
CRUDE offers in-app purchases beyond the base game. All payments are processed by the store, not by us:
- Steam (PC): purchases are processed through Valve (Steam Wallet).
- Android: purchases are processed through Google Play Billing.
We do not receive or store your card, bank or full payment details. From the store we receive purchase and entitlement records — for example that a purchase or refund occurred, an order/transaction reference, and what content you are entitled to — so we can deliver what you bought, restore purchases, provide support and handle refunds/chargebacks.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) to deliver purchases and entitlements, and legal obligation (Art. 6(1)(c)) for tax and accounting records.
09Data the stores collect (Steam / Google)
When you buy or download CRUDE, the store platform processes data as its own independent controller. We do not receive your payment-card details; the store handles the transaction and gives us only aggregated or limited sales and refund information.
- Steam (Valve Corporation) — account, purchase, payment, refund, playtime and platform data are governed by the Valve/Steam Privacy Policy and Steam Subscriber Agreement.
- Google Play (Google Ireland/LLC) — account, purchase, payment, refund and device data are governed by the Google Privacy Policy and Google Play Terms of Service.
10Purposes & legal bases (GDPR)
Under Article 6 GDPR we rely on the following legal bases for each purpose:
- Running the website & game (functionality), security and abuse prevention — our legitimate interests (Art. 6(1)(f)) in providing a working, secure product; and, for the technically-necessary sessionStorage value, the fact that it is strictly necessary to deliver a service you requested.
- Online accounts, cloud saves, multiplayer & leaderboards — performance of a contract (Art. 6(1)(b)) to provide the online features you request; and our legitimate interests (Art. 6(1)(f)) in anti-cheat and platform integrity.
- Gameplay analytics / telemetry & product improvement — your consent (Art. 6(1)(a)) where consent is required (including in the EEA), or otherwise our legitimate interests in understanding and improving the product, balanced against your rights. See section 6 for the consent mechanism.
- Crash & diagnostic reporting — our legitimate interests in keeping the game stable and fixing faults.
- In-app purchases & entitlements — performance of a contract (Art. 6(1)(b)) to deliver purchases and restore entitlements.
- Answering support requests — our legitimate interests in helping players, and where relevant taking steps in relation to a contract.
- Complying with legal obligations (e.g. tax records for sales, answering lawful requests) — legal obligation (Art. 6(1)(c)).
11Cookies & local storage
The website does not set advertising or cross-site tracking cookies. The only client-side storage we set ourselves is the technically-necessary napoca-intro-seen value described in section 3.1. In-game analytics and account features (sections 5–8) use their own on-device storage and identifiers rather than website cookies, and, where consent is required, run only after you agree in the in-game consent prompt.
You can control or clear this at any time:
- Clear your browser’s site data / storage for napocainteractive.com in your browser settings, or simply close the tab — sessionStorage is wiped when the tab closes.
- Use your browser’s “clear browsing data” controls at any time.
12Third parties & processors
We keep the number of third parties small. The parties below either process data on our behalf (processors) or receive data as their own independent controllers where noted.
- Cloudflare — website hosting, self-hosted font delivery, edge delivery and access logging (processor for our site).
- Third-party analytics / telemetry provider — website and in-game gameplay analytics (processor for the telemetry it handles for us). See section 6.
- Third-party crash-reporting provider — crash and diagnostics reporting (processor). See section 7.
- Third-party online-services provider — online accounts, cloud saves, multiplayer and leaderboards (processor). See section 5.
- Valve / Steam (Steam Wallet) — game distribution, payments and in-app purchases on PC (independent controller for store transactions). See sections 8–9.
- Google Play (Play Billing / Play Services) — game distribution, payments and in-app purchases on Android, and platform services (independent controller for store transactions). See sections 8–9.
13International transfers
Some of our providers — in particular analytics and crash-reporting vendors, as well as Cloudflare, Google and Valve — are based in, or transfer data to, countries outside the European Economic Area, including the United States. Where that happens, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and/or the provider’s certification under the EU–U.S. Data Privacy Framework (DPF). You can ask us for more detail, or a copy of the relevant safeguards, using the contact details below.
14Data retention
- Browser sessionStorage — deleted automatically when you close the tab.
- Edge/access logs — retained for a short period for security and diagnostics, then deleted or anonymised.
- Account & profile data — kept while your account is active; deleted or anonymised within a reasonable period after you delete your account or it becomes inactive.
- Telemetry & crash logs — retained only as long as needed to improve and debug the game, then deleted or aggregated.
- Purchase & entitlement records — kept while you hold the entitlement and as needed for support, refunds and to meet legal (tax/accounting) obligations.
- Support emails — kept for as long as needed to resolve your request and a reasonable period afterwards.
- Sales/tax records — kept for the period required by Romanian law.
15Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete your data (“right to be forgotten”) where the law allows.
- Restriction — ask us to limit how we use your data.
- Portability — receive certain data in a portable, machine-readable format.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
To exercise any of these rights, email hello@napocainteractive.com. We will respond within one month, as required by the GDPR. You can withdraw consent for analytics/telemetry at any time in the in-game privacy settings (see section 6). Note that for data the store platforms (Steam, Google Play) control, you should also exercise your rights directly with them under their own policies.
16Children’s privacy
CRUDE is a business/management simulation aimed at a general, mainly adult audience and is not directed to children. Because the game includes online accounts and in-app purchases, we take particular care here. Its content/age rating (assigned via IARC) will be confirmed before release.
- Not for children & age-gating: the game and website are not directed to children, and we do not knowingly collect personal data from children. Access to age-restricted features is subject to age-gating and the store’s minimum-age requirements.
- EU / Romania: under the GDPR and Romanian Law 190/2018, the age of digital consent in Romania is 16. We do not target or knowingly process data of users under 16 on a consent basis without appropriate parental consent.
- United States (COPPA): we do not knowingly collect personal information from children under 13.
- Google Play target audience: we declare the app’s target audience as an adult/general audience and set content settings so that it is not classified under the Google Play Families / “Designed for Families” program, and our IAP configuration follows the Google Play Families policy.
If you believe a child has provided us with personal data, contact hello@napocainteractive.com and we will delete it.
17Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/TLS across the website and store connections), access controls, and data minimisation — we try not to collect data we do not need. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify the authority and affected users of any qualifying breach as required by the GDPR.
18Changes to this policy
We may update this policy as the site, the game, or the law changes. When we do, we will revise the “Last updated” date at the top. Material changes will be highlighted on this page. The current effective date is 13 August 2026.
19Contact & complaints
Questions about this policy or your data? Contact hello@napocainteractive.com (or hello@napocainteractive.com for general enquiries), or write to Centrul de Terapie si Masaj Dora Cocis SRL, Str. Fabricii nr. 7, 400620 Cluj-Napoca, jud. Cluj, Romania.
You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP):
- B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
- Website: www.dataprotection.ro
If you are in another EU/EEA country, you may also complain to your local data protection authority.