DishMesh · Player information
Privacy Policy
How DishMesh handles game information, support enquiries and your privacy choices.
1. Who is responsible for your information
DishMesh is a game from VaultSun Games, operated by PROLOGO SOLARENGO – UNIPESSOAL LDA, a Portuguese company with NIPC 518816893 and D-U-N-S 348512284. We are the controller of the personal information described in this notice.
Registered address: Rua Joaquim António de Aguiar 43, R/C Esq., 1070-150 Lisboa, Portugal. Contact us at team@the-vault.life or +506 8635 7310. Use “DishMesh privacy” in your email subject so we can identify your request.
This notice covers DishMesh and related player support. The website privacy policy covers this studio website. The linked The Vault service has its own notices. Reading this policy or accepting the game's terms does not, by itself, give consent to optional tracking.
2. Information in device-local play
The current review build stores your career progress, restaurant state, earned and spent game currency, inventory, settings and save/recovery information on your device. Its account and commerce screens do not establish a live online account, cloud backup, advertisement service or purchase service.
We do not receive your local save simply because you play. If you send a save, screenshot or log to support, the information you send is handled as a support enquiry. Your device and app store may separately operate their own backup or diagnostic services under their own settings and privacy notices.
3. Information for the proposed online features
The following categories apply only when the relevant feature is offered and used in a released version. Information required for an optional feature is not a requirement for device-local play.
- Sign-in and cloud saves: your game account identifier, email address and display name supplied by your chosen sign-in provider; authentication status; progress, inventory, game balances, save versions and synchronization times. We do not need access to your contacts, social friend list or unrelated files.
- Service operation: connection IP address, app version, device/operating-system details, request times and security events needed to operate accounts, deliver saves and investigate misuse.
- Rewarded advertisements: an advertising or app-instance identifier where permitted, IP address, approximate region inferred from that address, device/app details, consent choices, advertisement interactions and reward confirmations. The planned service does not request precise GPS location.
- Purchases: the item purchased, store order or purchase token, purchase time, verification/refund status and the game account or installation receiving the entitlement. The app store processes payment credentials; we do not receive your full card number.
- Optional crash reports: crash traces, device model, operating-system and app versions, diagnostic identifiers and the relevant events preceding an error. Crash-report collection is proposed as opt-in, with messages and unnecessary personal information excluded.
The exact provider settings and collection in the released app must match this notice and its Google Play Data safety declaration before these features become available.
4. Information you give us for support
If you email or call, we use the contact details you supply, your message, necessary notes and any attachments you choose to send. Please share only what is relevant. An order reference or game identifier may help us investigate; your password, one-time sign-in code and complete payment-card details are never needed in a support message.
Contacting team@the-vault.life or +506 8635 7310 does not subscribe you to marketing. We would obtain any separate permission required before sending promotional messages.
5. Purposes and legal bases
- Provide requested accounts, cloud saves and purchased entitlements: performance of our contract with you, or steps you ask us to take before entering one, where those features are available.
- Answer support requests: the relevant contract when the request concerns the game service; otherwise our legitimate interest in answering people who contact us.
- Protect services and investigate fraud or errors: our legitimate interest in maintaining reliable, secure services, balanced against your rights. We use only information necessary for that purpose.
- Optional diagnostics and non-essential advertisement tracking: your consent where required. A reward-video choice is separate from permission to personalize advertisements or track you.
- Accounting, lawful requests and legal claims: compliance with applicable legal obligations, or our legitimate interest in establishing or defending a claim where permitted.
If information is required for a feature, we explain that when it is requested. Withholding it may prevent that feature from working. Refusing or withdrawing optional consent does not remove your data-protection rights.
6. Advertisement and diagnostic choices
Rewarded advertisements are a proposed optional feature: you choose whether to view one for the stated game reward. Where consent is required for device storage, advertising identifiers or personalization, the game must ask before that processing begins and provide a way to change the choice. Declining personalization must not be represented as agreeing to it.
You can also manage advertising identifiers and relevant permissions in your device settings. Those controls may affect the advertisements available. If optional crash reporting is offered, its control must allow you to turn collection off; turning it off does not necessarily erase reports already submitted.
We do not propose a separate general-purpose player analytics service, contact-list collection, precise-location collection or a public social feed for this launch scope.
7. Providers and other recipients
Only recipients needed for the service concerned should receive the relevant information. Our current email provider is Google Workspace; the studio website is prepared for Cloudflare Pages. Providers proposed for the online game are:
- Google Firebase Authentication and Cloud Firestore for identity and cloud saves.
- Google AdMob for rewarded advertisements and their consent-dependent processing.
- Google Play Billing for store transactions and purchase verification.
- Firebase Crashlytics for optional crash reporting.
This list describes the proposed launch configuration, not services already running in the review build. Firebase and hosting providers act under applicable processing arrangements for the functions we configure; app stores, sign-in platforms and advertising providers may also act independently for activities governed by their own notices.
We may disclose necessary information to professional advisers or competent authorities where legally justified. A business transfer would require appropriate safeguards and any notice required by law. We do not propose selling your personal information or sharing it for cross-context behavioral advertising; any change requires an updated notice and applicable choices before it starts.
Provider information: Firebase privacy, Google privacy, AdMob privacy information, Google processing terms, and Cloudflare privacy.
8. International processing
Our company is in Portugal, while providers may process information in other countries. Any transfer of personal data from the European Economic Area must have a valid transfer mechanism, such as an applicable adequacy decision or the European Commission's standard contractual clauses, together with additional safeguards where needed.
The final service configuration must identify the relevant processing locations and safeguards before online processing starts. You can ask us for information about a transfer concerning your data and for a copy of the relevant safeguards, with confidential details removed where appropriate.
9. How long information is kept
Information is retained only while needed for the purpose described here, with the following proposed rules:
- Local saves: remain on your device until replaced or erased through its app-storage controls. Device or store backups may have separate retention settings.
- Online account and progress: remain while the account is used to provide the requested service, and are erased following a verified deletion request unless a specific legal exception applies.
- Routine support: erased when no longer needed and, as the proposed maximum, within 12 months after the enquiry is resolved.
- Transaction and legal records: retained only for the applicable accounting obligation, an active dispute or the period necessary to exercise or defend a legal claim.
- Security and diagnostic records: kept only for the investigation or reliability purpose concerned. The final notice must state the configured retention or relevant criteria before those services are activated.
Backups and records held independently by a provider may take longer to expire. They must not be restored for an unrelated purpose. If an exception prevents complete erasure, we explain the affected category, reason and retention period or criteria.
10. Your rights and deletion requests
Depending on the applicable law and processing, you may request access, correction, deletion, restriction or a portable copy of your information; object to processing based on legitimate interests; and withdraw consent without affecting processing that was lawful before withdrawal. You may exercise your rights without being penalized for doing so.
Email team@the-vault.life or use our DishMesh account and data deletion page. We may ask for proportionate information to identify the relevant record and verify that it belongs to you. Do not send a password or a sign-in verification code.
For GDPR requests, we normally respond within one month. If the law permits an extension, we explain it within that first month. You can complain to Portugal's Comissão Nacional de Proteção de Dados (CNPD) or another competent supervisory authority.
If a release allows account creation within the game, it must also let you initiate account deletion there. Uninstalling the game or signing out is not a request to erase a server account. The current review build has no live server account to delete.
11. Age and younger players
The proposed DishMesh audience is teenagers and adults. The draft access rule is age 13 or older, increased to 16 or older for residents of the European Economic Area, and any higher minimum required in your country. If you are below the age of legal majority, a parent or guardian must permit your use and any purchases. These are proposed product rules, not a statement that one age threshold applies everywhere by law.
We do not intend to collect personal information from children below the applicable minimum. A parent or guardian who believes a child has provided information can contact team@the-vault.life so we can investigate and remove information where required. The store audience settings, age controls and advertising configuration must implement the final age rule before release.
12. Protecting information
Access to support correspondence is limited to people who need it; the owner's Google Workspace access is protected by two-factor authentication. The online game design must use encrypted network connections, restricted access and appropriately verified purchase and recovery requests before going live.
No system guarantees absolute security. Tell us promptly if you suspect unauthorized account use. Avoid sending sensitive information unless it is necessary and we have explained a suitable way to provide it.
13. Changes to this notice
We will update the date and notice when practices change, and provide additional notice or request new consent when the law requires it. Planned processing does not become authorized merely because a draft describes it. The notice accompanying the released version must describe that version's actual practices.