Privacy Policy

The complete Privacy Policy will be supplied by Margin War before launch.

LEGAL & PRIVACY

PRIVACY POLICY - MARGIN WAR

This PRIVACY POLICY (this "Policy") explains how Distour LLC ("Distour", the "Company", "we", "us" or "our"), a company incorporated under the laws of the Republic of Serbia and having its registered office at Desanke Maksimović 2, Belgrade, Republic of Serbia, collects, uses, discloses, stores, transfers and protects personal information relating to individuals ("User", "you" or "your") who download, register for, access or use the Margin War mobile application for Android (the "App" or the "Service").

Margin War is a cryptocurrency futures trading simulator. The App allows you to view candlestick price charts for digital assets selected through an in-App search function, to acquire and use in-game virtual coins ("Coins"), to place simulated long or short positions using a leverage value of your choosing, to close or liquidate those positions, and to review your position history and performance statistics. The App is a game. It does not provide access to any real cryptocurrency, security, derivative, exchange or financial market, and no real trading, investment, custody, transfer or withdrawal of digital assets or funds takes place through the App.

For the purposes of the Serbian Law on Personal Data Protection ("Official Gazette of the Republic of Serbia", No. 87/2018) (the "LPDP"), Regulation (EU) 2016/679 (the "GDPR"), the United Kingdom General Data Protection Regulation and the Data Protection Act 2018 (together, the "UK GDPR"), and all other privacy and data protection laws applicable to the App (together, the "Applicable Data Protection Laws"), Distour LLC is the data controller in respect of the personal information described in this Policy.

The App is distributed worldwide through the Google Play Store. This Policy is accordingly drafted to apply to Users located in any jurisdiction and contains supplemental disclosures for Users located in the Republic of Serbia, the European Economic Area, the United Kingdom, the State of California and other jurisdictions conferring specific statutory privacy rights.

By downloading, registering for, accessing or using the App, you confirm that you have read and understood this Policy. Where we rely on your consent as the legal basis for processing, you may withdraw that consent at any time in the manner described in this Policy. If you do not agree with this Policy, you must not download or use the App.

This Policy should be read together with the Terms of Use of the App, which govern your use of the Service, the Coins, the simulated positions and the interaction features. For any privacy-related question, request or complaint, you may contact us at crypto@distour.com.

1. DEFINITIONS
  1. In this Policy, unless the context requires otherwise, the following terms shall have the meanings set out below:
    1. "Account" means the user account created and accessed through Google Sign-In in order to use the App.
    2. "Coins" means the in-game virtual currency used within the App to place simulated positions and to access paid in-App features. Coins are a licensed in-game item only. Coins carry no monetary value outside the App, are not legal tender, are not a digital or virtual asset, cryptocurrency, e-money, stored value or financial instrument, and are not redeemable, exchangeable, transferable or withdrawable for fiat currency, cryptocurrency or any other thing of value.
    3. "Commissioner" means the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia.
    4. "Google Services" means, collectively, Google Sign-In, Google Play Billing, Google Pay and Firebase, each operated by Google LLC or its affiliates.
    5. "Interaction Features" means the paid in-App features by which a User may influence the gameplay outcome or statistics of another User, including by increasing that User's likelihood of loss or increasing the acting User's own likelihood of a winning outcome.
    6. "Personal Information" or "Personal Data" means any information relating to an identified or identifiable natural person, as defined under Article 4 of the LPDP and Article 4(1) of the GDPR.
    7. "Position" means a simulated long or short futures position placed within the App, together with its associated attributes, including the number of Coins committed, the leverage value, the entry price, the liquidation price, the profit or loss and the status of the Position.
    8. "Processing" means any operation performed on Personal Information, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure or destruction.
    9. "Third-Party Payment Provider" means the bank or payment service provider engaged by the Company to process card payments initiated through a payment link, being UniCredit Bank Serbia JSC.
2. SCOPE AND APPLICATION OF THIS POLICY
  1. This Policy applies to all Personal Information processed by the Company in connection with the App, including information processed through the App interface, our servers and backend infrastructure, our email correspondence with Users, and our records of in-App purchases.
  2. This Policy does not apply to:
    1. the independent data processing carried out by Google LLC and its affiliates in connection with your Google account, Google Sign-In, Google Play Billing and Google Pay, which is governed by Google's own privacy policy;
    2. the independent data processing carried out by the Third-Party Payment Provider or by your card issuer or bank in connection with a card payment, which is governed by their respective privacy notices and banking terms;
    3. any third-party website, application or service which may be linked to or accessible from the App; or
    4. anonymised, aggregated or statistical data which does not identify, and cannot reasonably be used to identify, any individual.
  3. Where this Policy refers to a specific statutory right, that right applies only to those Users to whom the relevant law applies. Nothing in this Policy is intended to grant rights beyond those conferred by Applicable Data Protection Laws, or to limit any right which cannot lawfully be limited.
3. INFORMATION WE COLLECT

We collect only such Personal Information as is necessary to create and operate your Account, to run the simulator, to process purchases of Coins, to secure the Service and to comply with our legal obligations. The categories of Personal Information we collect are set out below.

  1. Information Collected Through Google Sign-In: Registration for the App is carried out exclusively through Google authorisation. When you authorise the App, Google shares the following information with us:
    1. First Name and Last Name: the given name and family name associated with the Google account you use to register.
    2. Email Address: the email address associated with that Google account, which serves as the primary identifier of your Account and as our means of contacting you.
    3. Google Account Identifier: the unique identifier assigned by Google to your account, which we use to authenticate you on subsequent logins.
    4. We do not receive, collect or store your Google password, your Google two-factor authentication credentials or any other Google account credential. Authentication is performed entirely by Google.
  2. Device and Technical Information: When you access the App, we collect or receive the following technical information:
    1. Device Language: the language setting of your device, used to display the App in an appropriate language.
    2. Device and Operating System Information: the device model, operating system and operating system version, and the version of the App installed, collected for compatibility, support and diagnostic purposes.
    3. Internet Protocol (IP) Address: your IP address, which is received automatically by our servers as an inherent feature of internet communication and is recorded in our server logs for security, abuse prevention and troubleshooting purposes.
    4. Crash Logs and Diagnostic Data: technical information relating to App crashes, errors, latency and performance, collected through Firebase and our analytics tooling.
    5. Session Data: the date and time of your logins and logouts, session duration and the App screens accessed.
  3. Account, Gameplay and Statistics Information: In order to operate the simulator and maintain your Account, we collect and store on our servers:
    1. Coin Balance and Coin Ledger: your current Coin balance, the initial complimentary allocation of one hundred (100) Coins credited on registration, all subsequent credits (including purchased Coins and Coins won) and all debits (including Coins committed to Positions, Coins lost and Coins spent on Interaction Features).
    2. Position Data: for each Position, the asset selected, the direction (long or short), the number of Coins committed, the leverage value selected, the entry price, the liquidation price, the realised or unrealised profit or loss, the status of the Position and the timestamps on which the Position was opened and closed or liquidated.
    3. Position History: the cumulative record of your Positions, displayed to you on the bet history page.
    4. Performance Statistics: derived statistics generated from your Position History and displayed on the statistics page of the App.
    5. Interaction Feature Records: records of any Interaction Feature purchased or used by you, including the identity of the User affected, the effect applied and the date and time of use, retained for the purposes of operating the feature, preventing abuse and resolving disputes.
    6. Search and Selection Data: the assets you search for and select for display within the App.
  4. Transaction Information: Coins may be purchased through two channels. In respect of each channel we collect the limited information described below:
    1. Purchases Through Google Play Billing and Google Pay: the transaction identifier, the transaction status, the amount and currency paid, the digital product purchased, the date and time of the transaction, and the email address associated with the purchase. Payment itself is processed entirely by Google.
    2. Purchases Through a Card Payment Link: confirmation that payment has been made, the payment reference or transaction identifier assigned by the Third-Party Payment Provider, the amount and currency paid, the date of payment, and the email address associated with your Account.
    3. We do not collect, receive, process or store your full payment card number, card verification value (CVV/CVC), card expiry date, cardholder authentication data, bank account number or online banking credentials. All such data is collected and processed directly by Google or by the Third-Party Payment Provider, each of which maintains its own security and compliance framework.
  5. Communications: Where you contact us by email or through any support channel, we collect your email address, the content of your message and any attachments or account details you choose to provide, together with our response and any related records.
  6. Special Categories of Personal Data: We do not seek, require or knowingly collect any special category of Personal Data, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning a natural person's sex life or sexual orientation. You should not submit any such data to us.
4. INFORMATION WE DO NOT COLLECT

For the avoidance of doubt, and to enable you to make an informed assessment of the App before installing it, we confirm that we do not collect the following categories of information:

  1. Payment Card and Banking Data: as set out above, full card numbers, security codes, expiry dates and banking credentials are never received or stored by us.
  2. Government Identification Data: we do not collect passport numbers, national identification numbers, tax identification numbers, driving licence numbers or any equivalent government-issued identifier.
  3. Precise Location Data: we do not collect GPS coordinates or any precise geolocation data, and the App does not request location permissions. Approximate country-level information may be inferred from your IP address for security and compliance purposes only.
  4. Device Content and Permissions: we do not access your contacts, photographs, media library, files, calendar, microphone, camera, call logs or SMS messages.
  5. Cryptocurrency Wallet Data: the App does not connect to, and we do not collect, any cryptocurrency wallet address, private key, seed phrase, exchange account credential or real trading account. No real digital assets are held, transferred or transacted through the App.
  6. Biometric Data: we do not collect fingerprints, facial geometry, voiceprints or any other biometric identifier.
5. HOW WE USE YOUR INFORMATION

We process Personal Information only for the specified, explicit and legitimate purposes set out below, and we do not further process it in a manner incompatible with those purposes.

  1. Provision and Operation of the Service:
    1. To create, authenticate and maintain your Account and to enable you to log in and log out.
    2. To credit the initial complimentary allocation of Coins on registration and to maintain an accurate Coin balance.
    3. To operate the simulator, display charts and prices, accept and record your Positions, calculate simulated profit, loss and liquidation values, and update your balance accordingly.
    4. To generate and display your bet history and performance statistics.
    5. To operate the Interaction Features and to apply and record their effects.
  2. Purchases of Coins:
    1. To verify and reconcile purchases made through Google Play Billing, Google Pay or the Third-Party Payment Provider and to credit the corresponding Coins to your Account.
    2. To maintain accounting and tax records of purchases and to handle refunds, reversals, chargebacks and payment disputes.
    3. To detect and prevent fraudulent, duplicated or unauthorised transactions.
  3. Support and Communication:
    1. To respond to your enquiries, support requests and data subject requests.
    2. To send you service-related communications concerning your Account, purchases, security, material changes to this Policy or the Terms of Use, or the suspension or discontinuation of the Service. These communications are not marketing communications and you cannot opt out of them while you maintain an Account.
  4. Security, Integrity and Abuse Prevention:
    1. To protect the App, our servers and our Users against unauthorised access, account takeover, fraud, exploitation of the game mechanics, manipulation of statistics, use of multiple or automated accounts and other abusive conduct.
    2. To investigate suspected breaches of the Terms of Use and to enforce them, including by restricting, suspending or terminating an Account.
  5. Analytics and Improvement:
    1. To understand how the App is used, which features are used most frequently and where Users encounter errors or difficulties.
    2. To diagnose faults, improve stability and performance, and develop new or improved features. Wherever practicable, this analysis is carried out on aggregated or anonymised data.
  6. Legal and Regulatory Purposes:
    1. To comply with our obligations under applicable law, including accounting, tax, consumer protection and data protection law.
    2. To respond to lawful requests from courts, regulators, tax authorities and law enforcement agencies.
    3. To establish, exercise or defend legal claims and to obtain professional legal, accounting or audit advice.
  7. Automated Processing: The outcome of a Position is determined by the rules of the game as applied to the simulated price data and, where applicable, to any Interaction Feature used. Such processing is automated but does not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 38 of the LPDP or Article 22 of the GDPR, as it affects only in-game outcomes and Coins which carry no value outside the App. We do not carry out profiling for the purpose of evaluating your creditworthiness, employment prospects or any comparable matter.
  8. No Sale of Personal Information: We do not sell, rent, lease or licence your Personal Information, and we do not share it with third parties for their own cross-context behavioural advertising or direct marketing purposes.
6. LEGAL BASES FOR PROCESSING

Where the LPDP, the GDPR or the UK GDPR applies to our processing of your Personal Information, we rely on the following legal bases:

  1. Performance of a Contract (Article 12(1)(2) of the LPDP; Article 6(1)(b) of the GDPR) - for the creation and operation of your Account, the provision of the Service, the crediting and debiting of Coins, the operation of Positions and the Interaction Features, the processing of purchases and the provision of support.
  2. Legitimate Interests (Article 12(1)(6) of the LPDP; Article 6(1)(f) of the GDPR) - for security, fraud and abuse prevention, network and information security, product analytics and improvement, internal administration, and the establishment, exercise or defence of legal claims. In each case we have assessed that our legitimate interests are not overridden by your interests or fundamental rights and freedoms. You may request further information about that assessment at crypto@distour.com.
  3. Compliance with a Legal Obligation (Article 12(1)(3) of the LPDP; Article 6(1)(c) of the GDPR) - for the retention of accounting and tax records, responses to lawful requests from competent authorities, and compliance with our obligations under Applicable Data Protection Laws.
  4. Consent (Article 12(1)(1) of the LPDP; Article 6(1)(a) of the GDPR) - for any optional analytics, personalisation or promotional communications for which consent is required under applicable law. Where we rely on consent, you may withdraw it at any time by contacting crypto@distour.com or, where available, by adjusting the relevant setting in the App or on your device.
  5. Protection of Vital Interests or Public Interest (Article 12(1)(4) and (5) of the LPDP; Article 6(1)(d) and (e) of the GDPR) - only in the exceptional circumstances contemplated by those provisions.
  6. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of that consent before its withdrawal. Where you withdraw consent or object to processing necessary for the provision of the Service, we may be unable to continue providing the App to you.
7. IN-APP PURCHASES AND PAYMENT INFORMATION
  1. Coins may be purchased within the App through either of the following channels:
    1. Google Play Billing and Google Pay: the Coins are offered as a digital product registered in the Google Play Console. You pay Google, and Google processes the payment in accordance with its own terms and privacy policy. Google acts as an independent controller in respect of the payment data it collects from you. We receive from Google only the limited transaction information described in Clause 3 above.
    2. Card Payment via Payment Link: payment is processed by the Third-Party Payment Provider through a secure payment page or link. Your card data is submitted directly to that provider and is not transmitted through, or accessible to, the App or our servers. We receive only confirmation of payment and the limited transaction information described in Clause 3 above.
  2. We do not store, and have no technical means of accessing, your full card number, card verification value, expiry date or banking credentials. Responsibility for the security of payment card data rests with Google and with the Third-Party Payment Provider, each of which is required to maintain the security standards applicable to it, including the Payment Card Industry Data Security Standard where applicable.
  3. We retain records of purchases, including the transaction identifier, amount, currency, date and associated email address, for the purposes of reconciliation, customer support, refund and chargeback handling, fraud prevention and compliance with accounting and tax legislation.
  4. Coins are an in-game item only. Purchases of Coins are purchases of a licence to use an in-game item and are not deposits, investments, payments for financial services or purchases of any digital or virtual asset. Refund entitlements, where any exist, are governed by the Google Play refund policy applicable to the relevant purchase, by the Terms of Use and by any mandatory consumer protection law applicable to you.
  5. Unused Coins are forfeited on closure, termination or deletion of your Account and are not refundable, exchangeable or transferable, save to the extent that a refund is required by mandatory applicable law.
8. COINS, SIMULATED POSITIONS, STATISTICS AND INTERACTION FEATURES
  1. All prices, charts and market data displayed within the App are used solely to drive a simulation. Your Positions are not transmitted to, executed on, or matched against any exchange, broker, liquidity provider or real market, and no order, trade or settlement occurs outside the App.
  2. Position Data and Position History are stored against your Account for so long as the Account remains active, in order to operate the history and statistics functions of the App and to permit the investigation of disputes and suspected abuse.
  3. Your display name and performance statistics may be visible to other Users of the App to the extent necessary to operate the competitive and statistics features. You should not use your full legal name, email address, telephone number or any other personal identifier as your display name if you do not wish that information to be visible to other Users.
  4. Where an Interaction Feature is used, the record of that use is associated with both the acting User and the affected User. The affected User may be informed that an Interaction Feature has been applied to them. We retain these records to operate the feature, to enforce the Terms of Use, to investigate complaints of abuse and to resolve disputes between Users.
  5. No real money can be won through gameplay. The only financial exposure arising from your use of the App is the price you elect to pay for Coins and for Interaction Features. Coins lost in gameplay are not recoverable and no compensation is payable in respect of them.
9. THIRD-PARTY SERVICES AND SUB-PROCESSORS

We engage a limited number of third-party providers to deliver the Service. Each provider has access only to the Personal Information necessary to perform its function and is prohibited from using that information for its own independent purposes, except where it acts as an independent controller as stated below.

  1. Google Sign-In (Google LLC) - user authentication and account creation. Google acts as an independent controller in respect of your Google account.
  2. Google Play Billing and Google Pay (Google LLC) - processing of in-App purchases. Google acts as an independent controller in respect of payment data.
  3. Firebase (Google LLC) - backend services, crash reporting and diagnostics. Firebase acts as our processor in respect of the data it handles on our behalf.
  4. Analytics Provider Firebase - measurement of App usage and performance, acting as our processor.
  5. Hosting and Infrastructure Provider webtropia ( Germany) - hosting of our servers and database, acting as our processor.
  6. Third-Party Payment Provider UniCredit Bank Serbia JSC - processing of card payments made through a payment link.
  7. Where a third party acts as our processor, we have in place a written agreement satisfying the requirements of Article 45 of the LPDP and Article 28 of the GDPR, under which the processor is required to process Personal Information only on our documented instructions, to impose confidentiality obligations on its personnel, to implement appropriate technical and organisational security measures, to assist us with data subject requests and breach notification, and to delete or return the data at the end of the engagement.
  8. The processing carried out by Google in respect of your Google account and your payments is governed by the Google Privacy Policy, available at https://policies.google.com/privacy. We recommend that you review that policy and the privacy notice of the Third-Party Payment Provider.
  9. An up-to-date list of our sub-processors is available on request at crypto@distour.com.
10. DISCLOSURE OF PERSONAL INFORMATION
  1. We do not sell your Personal Information and we do not disclose it other than as described in this Clause.
  2. Service Providers: We disclose Personal Information to the providers identified in Clause 9, strictly for the purposes described there.
  3. Other Users: We disclose the limited information described in Clause 8 to other Users, to the extent necessary to operate the statistics and Interaction Features of the App.
  4. Legal and Regulatory Disclosure: We may disclose Personal Information where we are required or permitted to do so by law, including in response to a court order, subpoena, regulatory demand, tax enquiry or lawful request by a competent public authority. Where we receive such a request we will: (i) satisfy ourselves that the request is lawful and properly issued; (ii) disclose only the minimum information required; and (iii) notify you of the request where we are legally permitted and reasonably able to do so.
  5. Protection of Rights: We may disclose Personal Information where necessary to protect the rights, property or safety of the Company, our Users or any other person, or to prevent, detect or investigate fraud, abuse or unlawful conduct.
  6. Professional Advisers: We may disclose Personal Information to our legal advisers, accountants, auditors and insurers, each of whom is bound by professional or contractual duties of confidentiality.
  7. Corporate Transactions: If the Company is involved in a merger, acquisition, restructuring, sale of assets, insolvency or similar transaction, Personal Information may be disclosed to a prospective or actual counterparty and its advisers, subject to appropriate confidentiality undertakings. Where your Personal Information becomes subject to a different privacy policy as a result of such a transaction, we will notify you.
  8. With Your Consent: We may disclose Personal Information for any other purpose disclosed to you at the time and with your consent.
  9. Aggregated and Anonymised Information: We may use and disclose aggregated or anonymised information, which does not identify any individual, for any lawful purpose, including analytics, research, reporting and the description of the Service.
11. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION
  1. The Company is established in the Republic of Serbia. Our servers and database are located in Germany. Certain of our service providers, including Google LLC, process data in the United States and in other countries.
  2. Because the App is available worldwide, your Personal Information may be transferred to, stored in and processed in a country other than the country in which you are located, including a country which may not provide the same level of protection for personal data as your own.
  3. Where Personal Information is transferred out of the European Economic Area or the United Kingdom, we rely on an appropriate safeguard permitted by Article 46 of the GDPR or the UK GDPR, being the European Commission Standard Contractual Clauses or, for transfers from the United Kingdom, the International Data Transfer Agreement or the UK Addendum, supplemented where necessary by additional technical and organisational measures identified through a transfer risk assessment.
  4. Where Personal Information is transferred out of the Republic of Serbia, the transfer is made in accordance with Articles 64 to 70 of the LPDP, including, as applicable, transfers to States party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, transfers to States recognised by the Government of the Republic of Serbia as providing an adequate level of protection, or transfers made subject to standard contractual clauses adopted by the Commissioner.
  5. You may request a copy of the safeguards applied to a specific transfer by writing to crypto@distour.com.
12. DATA RETENTION

We retain Personal Information only for as long as is necessary for the purposes for which it was collected, or for such longer period as is required by law. Our retention periods are as follows:

  1. Account Data (name, email address, Google account identifier) - retained for so long as your Account remains active, and thereafter deleted or irreversibly anonymised within thirty (30) days of a verified deletion request or of closure of the Account, subject to the exceptions below.
  2. Coin Ledger, Position Data, Position History, Statistics and Interaction Feature Records - retained for so long as your Account remains active, and thereafter deleted or irreversibly anonymised within thirty (30) days of a verified deletion request or of closure of the Account.
  3. Transaction and Financial Records - retained for the period prescribed by applicable Serbian accounting and tax legislation, being 113105334 years from the end of the financial year to which the record relates. Deletion of your Account does not and cannot extinguish this statutory retention obligation.
  4. Server, Security and Access Logs - retained for 1 month from the date of the relevant event, for security monitoring and abuse investigation purposes.
  5. Support Correspondence - retained for 1 month from the closure of the relevant enquiry.
  6. Records Relating to Legal Claims - where Personal Information is relevant to an actual or reasonably anticipated legal claim, investigation, regulatory enquiry or audit, it will be retained until the matter is finally resolved and any applicable limitation period has expired.
  7. Anonymised Data - data which has been irreversibly anonymised may be retained indefinitely, as it no longer constitutes Personal Information.
  8. At the expiry of the applicable retention period, Personal Information is securely deleted or irreversibly anonymised. Where immediate deletion is not technically feasible, for example in respect of encrypted backup media, the data is isolated from further processing and deleted on the next scheduled backup cycle.
13. YOUR DATA PROTECTION RIGHTS
  1. Rights Available to All Users: Regardless of your location, you may at any time request that we:
    1. confirm whether we process Personal Information relating to you and provide you with a copy of that information;
    2. correct any inaccurate or incomplete Personal Information relating to you;
    3. delete your Account and the Personal Information associated with it, in accordance with Clause 14 below;
    4. restrict or cease particular processing activities; and
    5. provide you with your Personal Information in a structured, commonly used and machine-readable format.
  2. Additional Rights for Users in the Republic of Serbia: If you are located in the Republic of Serbia, you have the rights conferred by Articles 21 to 38 of the LPDP, including the right to be informed, the right of access, the right to rectification and erasure, the right to restriction of processing, the right to be notified of rectification, erasure or restriction, the right to data portability, the right to object, and the right not to be subject to a decision based solely on automated processing. You also have the right to lodge a complaint with the Commissioner.
  3. Additional Rights for Users in the European Economic Area and the United Kingdom: If you are located in the EEA or the United Kingdom, you have the rights conferred by Articles 15 to 22 of the GDPR or the UK GDPR, as applicable, being:
    1. Right of Access: to obtain confirmation of processing and a copy of your Personal Information, together with information about the purposes, categories, recipients, retention periods and the sources of that information.
    2. Right to Rectification: to have inaccurate Personal Information corrected and incomplete Personal Information completed.
    3. Right to Erasure: to have your Personal Information erased where it is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, where you object and there are no overriding legitimate grounds, or where the information has been unlawfully processed.
    4. Right to Restriction of Processing: to require us to limit our processing while the accuracy of the data or the validity of an objection is verified.
    5. Right to Data Portability: to receive Personal Information which you have provided to us, and which we process by automated means on the basis of consent or contract, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
    6. Right to Object: to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, and to object at any time and without reason to processing for direct marketing purposes.
    7. Right to Withdraw Consent: to withdraw consent at any time where processing is based on consent.
    8. Right to Lodge a Complaint: to lodge a complaint with the supervisory authority of the Member State of your habitual residence, place of work or the place of the alleged infringement, or with the Information Commissioner's Office in the United Kingdom.
  4. Additional Rights for Residents of California: If you are a resident of the State of California, the California Consumer Privacy Act as amended by the California Privacy Rights Act confers on you the right to know what Personal Information we collect, use and disclose about you and the purposes for which we do so; the right to request deletion of your Personal Information, subject to statutory exceptions; the right to correct inaccurate Personal Information; the right to opt out of the sale or sharing of Personal Information; the right to limit the use and disclosure of sensitive personal information; and the right not to receive discriminatory treatment for exercising any of these rights. We confirm that we do not sell or share Personal Information as those terms are defined under that legislation, and that we do not collect sensitive personal information as so defined.
  5. Exercising Your Rights: To exercise any right, please write to crypto@distour.com with the subject line "Data Subject Request", stating the right you wish to exercise and the email address associated with your Account. We may request further information in order to verify your identity before acting on a request, and will use that information solely for verification. We will respond:
    1. within thirty (30) days of receipt of a verified request, where the LPDP, the GDPR or the UK GDPR applies, which period may be extended by a further sixty (60) days where the request is complex or numerous, in which case we will notify you of the extension and the reasons for it; and
    2. within forty-five (45) days of receipt of a verifiable request, where the California Consumer Privacy Act applies, which period may be extended by a further forty-five (45) days upon notice to you.
  6. We will not charge a fee for responding to a request unless the request is manifestly unfounded or excessive, in particular because of its repetitive character, in which case we may charge a reasonable fee or refuse to act on the request, giving reasons.
  7. You may exercise your rights through an authorised agent, provided that the agent furnishes written authority signed by you and that we are able to verify both your identity and the authority of the agent.
14. ACCOUNT MANAGEMENT, LOGOUT AND ACCOUNT DELETION
  1. Logout: You may log out of the App at any time using the logout function within the App, and may thereafter log in using the same or a different Google account. Logging out does not delete your Account, your Coin balance, your Position History or any other Personal Information.
  2. Account Deletion: You may request the deletion of your Account and of the Personal Information associated with it by any of the following means:
    1. by using the account deletion function within the App, accessible at [Insert in-App navigation path];
    2. by submitting a request through the account deletion web page at https://margin-war.distour.com/, which is accessible without installing the App and without logging in; or
    3. by writing to crypto@distour.com with the subject line "Account Deletion Request" from the email address associated with your Account.
  3. Upon receipt of a verified deletion request, we will delete or irreversibly anonymise your Account data, Coin ledger, Position Data, Position History, statistics and Interaction Feature records within thirty (30) days, and will confirm completion to you by email.
  4. Information Retained Following Deletion: Notwithstanding deletion of your Account, we will retain:
    1. transaction and financial records, for the statutory retention period referred to in Clause 12;
    2. a minimal record of the fact and date of deletion, together with a hashed or pseudonymised identifier, where necessary to evidence our compliance with your request and to prevent circumvention of a suspension or ban; and
    3. any information which we are required to retain by law or which is necessary for the establishment, exercise or defence of legal claims.
  5. Consequences of Deletion: Deletion of your Account is permanent and irreversible. All unused Coins, including purchased Coins, are forfeited without refund or compensation, save to the extent that a refund is required by mandatory applicable law. Your Position History, statistics and any in-game standing will be permanently lost and cannot be restored, including if you subsequently create a new Account.
  6. Uninstalling the App: Uninstalling or deleting the App from your device does not delete your Account or the Personal Information held on our servers. You must submit a deletion request in accordance with this Clause in order to have that information deleted.
15. AGE RESTRICTION AND CHILDREN'S PRIVACY
  1. The App is intended solely for use by persons who have attained the age of eighteen (18) years. The App is not directed to children, is not designed to appeal to children, and must not be used by any person under the age of eighteen (18) years.
  2. By registering for and using the App, you represent and warrant that you are at least eighteen (18) years of age and have the legal capacity to enter into a binding agreement and to make purchases through the App.
  3. We do not knowingly collect Personal Information from any person under the age of eighteen (18) years. Where we become aware that we have collected Personal Information from such a person, we will delete that information and terminate the associated Account without undue delay and without liability for any forfeited Coins.
  4. Without prejudice to the age restriction in this Clause, we acknowledge that the age at which an individual may validly consent to the processing of personal data in connection with information society services is fifteen (15) years under Article 16 of the LPDP, and between thirteen (13) and sixteen (16) years in the Member States of the European Economic Area. Nothing in this Policy shall be construed as permitting the use of the App by any person below the age restriction stated above.
  5. If you are a parent or legal guardian and believe that a person under the age of eighteen (18) years has registered for the App or made a purchase through it, please contact us immediately at crypto@distour.com. We will investigate the matter, delete the relevant Account and Personal Information, and address any purchase made through the Account in accordance with applicable law and the refund policies of Google Play or the Third-Party Payment Provider.
  6. The content rating assigned to the App on the Google Play Store reflects, among other things, the presence of simulated trading and purchasable in-game items. You should review that rating before installing the App.
16. SECURITY OF YOUR INFORMATION
  1. We implement appropriate technical and organisational measures, as required by Article 50 of the LPDP and Article 32 of the GDPR, to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include:
    1. Encryption in Transit: all communications between the App and our servers are encrypted using industry-standard Transport Layer Security protocols.
    2. Delegated Authentication: authentication is performed by Google. We do not create, store or have access to any password for your Account, which materially reduces the risk of credential compromise.
    3. Access Controls: access to Personal Information is restricted to those personnel and service providers who require it in order to perform their functions, on a least-privilege basis, and is subject to authentication controls and access logging.
    4. Server and Network Security: our servers are protected by firewall, intrusion detection and monitoring controls, and are subject to regular patching and security updates.
    5. Segregation of Payment Data: payment card data is never transmitted through or stored on our infrastructure, and is handled exclusively by Google and by the Third-Party Payment Provider.
    6. Backups: data is backed up on a regular basis, and backup media are protected by equivalent security controls.
    7. Confidentiality: all personnel and contractors with access to Personal Information are bound by written confidentiality obligations.
  2. Notwithstanding these measures, no method of transmission over the internet and no method of electronic storage is entirely secure. While we take all reasonable steps to protect your Personal Information, we cannot and do not guarantee absolute security, and any transmission of information to us is at your own risk.
  3. You are responsible for maintaining the security of the Google account used to access the App, including by enabling two-factor authentication where available and by not permitting any other person to use that account. You must notify us promptly at crypto@distour.com if you believe that your Account has been accessed without your authorisation.
17. PERSONAL DATA BREACH NOTIFICATION
  1. In the event of a personal data breach, we will document the breach, assess the risk to the rights and freedoms of affected individuals, and take prompt steps to contain the breach and mitigate its effects.
  2. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the Commissioner without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of it, in accordance with Article 52 of the LPDP, and will notify any other competent supervisory authority as required under Article 33 of the GDPR or the UK GDPR.
  3. Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will communicate the breach to the affected Users without undue delay, in accordance with Article 53 of the LPDP and Article 34 of the GDPR or the UK GDPR, describing the nature of the breach, the likely consequences, the measures taken and the contact point from which further information may be obtained.
  4. We maintain an internal record of all personal data breaches, including those which are not notifiable, together with the facts, effects and remedial action taken.
18. COOKIES, IDENTIFIERS AND SIMILAR TECHNOLOGIES
  1. The App is a native Android application and does not use browser cookies. It does, however, rely on the following comparable technologies:
    1. Local Storage and Session Tokens: authentication tokens and preference data stored locally on your device in order to keep you logged in and to remember your settings. These are strictly necessary for the operation of the App.
    2. Software Development Kit Identifiers: identifiers generated by the Google Services and our analytics tooling, used to recognise your installation of the App for diagnostic, security and analytics purposes.
  2. You may manage or reset advertising and diagnostic identifiers through the privacy settings of your Android device, and may withdraw consent to optional analytics where such consent is required in your jurisdiction. Disabling strictly necessary identifiers will prevent the App from functioning.
  3. Any website operated by the Company at https://margin-war.distour.com/ may use cookies and similar technologies, in which case a separate cookie notice will be made available on that website.
19. THIRD-PARTY LINKS AND CONTENT
  1. The App and any related communications may contain links to third-party websites, applications or resources, including the Google Play Store, the payment page of the Third-Party Payment Provider and sources of market data.
  2. We do not control and are not responsible for the content, privacy practices or security of any third party. The provision of a link does not constitute an endorsement.
  3. When you leave the App and access a third-party service, the privacy policy and terms of that third party govern your relationship with it. We encourage you to review them before providing any information.
20. SIMULATED NATURE OF THE SERVICE AND ABSENCE OF FINANCIAL ADVICE
  1. The App is a game and an educational simulation. Nothing displayed within the App, and nothing in this Policy, constitutes financial, investment, trading, tax or legal advice, or a recommendation, offer or solicitation to buy, sell or deal in any cryptocurrency, security, derivative or other financial instrument.
  2. The Company is not a bank, payment institution, investment firm, broker, dealer, exchange, custodian or other regulated financial services provider, does not accept deposits, does not hold client money or client assets, and does not execute, transmit or arrange any order in any real market.
  3. Simulated results within the App do not reflect the outcomes that would be achieved in a real market and must not be relied upon as an indication of future performance. Leverage in real markets carries a substantial risk of loss.
  4. This Clause is included for the avoidance of doubt and does not limit any provision of the Terms of Use.
21. CHANGES TO THIS POLICY
  1. We may amend this Policy from time to time to reflect changes in the App, in our data practices, in the services of our providers, or in applicable law.
  2. Where we make a material change, we will notify you by one or more of the following means: by email to the address associated with your Account; by a prominent notice within the App; or by requiring you to acknowledge the revised Policy before continuing to use the App.
  3. The revised Policy will take effect on the date stated as the "Effective Date", and in any event not earlier than thirty (30) days after notification where the change materially reduces your rights, unless an earlier effective date is required by law.
  4. Your continued use of the App after the effective date of a revised Policy constitutes your acknowledgement of it. Where the change requires your consent under Applicable Data Protection Laws, we will obtain that consent separately.
  5. Previous versions of this Policy are available on request at crypto@distour.com.
22. COMPLAINTS
  1. If you are dissatisfied with the manner in which we have handled your Personal Information or a request made by you, please contact us first at crypto@distour.com. We will investigate the matter and respond to you within thirty (30) days.
  2. If you remain dissatisfied, you may lodge a complaint with the competent supervisory authority:
    1. Republic of Serbia: the Commissioner for Information of Public Importance and Personal Data Protection (https://www.poverenik.rs).
    2. European Economic Area: the data protection supervisory authority of the Member State of your habitual residence, place of work or the place of the alleged infringement.
    3. United Kingdom: the Information Commissioner's Office (https://ico.org.uk).
    4. State of California: the California Privacy Protection Agency or the Office of the Attorney General of California.
  3. The exercise of your right to complain to a supervisory authority is without prejudice to any other administrative or judicial remedy available to you.
23. CONTACT DETAILS
  1. All questions, requests and notices relating to this Policy should be addressed to:
    1. Data Controller: Distour LLC
    2. Registered Address: Desanke Maksimović 2, Belgrade, Republic of Serbia
    3. Email: crypto@distour.com
    4. Application: Margin War (Android)
  2. We endeavour to acknowledge privacy enquiries within five (5) business days and to respond substantively within the periods set out in Clause 13.
24. ACKNOWLEDGMENT
  1. By downloading, registering for, accessing or using the Margin War application, you acknowledge that you have read and understood this Privacy Policy and that you understand how, and for what purposes, we collect, use, disclose, retain and protect your Personal Information.
  2. If you do not agree with this Privacy Policy, you must not download, register for, access or use the App, and you should uninstall it and submit an account deletion request in accordance with Clause 14.

Make your next market move.

Practice futures mechanics with virtual coins. No real-money risk.

Get it on Google PlayVirtual coins only   No real-money risk