DishMesh · Player information

Privacy Policy

How DishMesh handles game information, support enquiries and your privacy choices.

1. Who is responsible for your information

DishMesh is a game from VaultSun Games, operated by PROLOGO SOLARENGO – UNIPESSOAL LDA, a Portuguese company with NIPC 518816893 and D-U-N-S 348512284. We are the controller of the personal information described in this notice.

Registered address: Rua Joaquim António de Aguiar 43, R/C Esq., 1070-150 Lisboa, Portugal. Contact us at team@the-vault.life or +506 8635 7310. Use “DishMesh privacy” in your email subject so we can identify your request.

This notice covers DishMesh and related player support. The website privacy policy covers this studio website. The linked The Vault service has its own notices. Reading this policy or accepting the game's terms does not, by itself, give consent to optional tracking.

2. Information in device-local play

The current review build stores your career progress, restaurant state, earned and spent game currency, inventory, settings and save/recovery information on your device. Its account and commerce screens do not establish a live online account, cloud backup, advertisement service or purchase service.

We do not receive your local save simply because you play. If you send a save, screenshot or log to support, the information you send is handled as a support enquiry. Your device and app store may separately operate their own backup or diagnostic services under their own settings and privacy notices.

3. Information for the proposed online features

The following categories apply only when the relevant feature is offered and used in a released version. Information required for an optional feature is not a requirement for device-local play.

The exact provider settings and collection in the released app must match this notice and its Google Play Data safety declaration before these features become available.

4. Information you give us for support

If you email or call, we use the contact details you supply, your message, necessary notes and any attachments you choose to send. Please share only what is relevant. An order reference or game identifier may help us investigate; your password, one-time sign-in code and complete payment-card details are never needed in a support message.

Contacting team@the-vault.life or +506 8635 7310 does not subscribe you to marketing. We would obtain any separate permission required before sending promotional messages.

5. Purposes and legal bases

If information is required for a feature, we explain that when it is requested. Withholding it may prevent that feature from working. Refusing or withdrawing optional consent does not remove your data-protection rights.

6. Advertisement and diagnostic choices

Rewarded advertisements are a proposed optional feature: you choose whether to view one for the stated game reward. Where consent is required for device storage, advertising identifiers or personalization, the game must ask before that processing begins and provide a way to change the choice. Declining personalization must not be represented as agreeing to it.

You can also manage advertising identifiers and relevant permissions in your device settings. Those controls may affect the advertisements available. If optional crash reporting is offered, its control must allow you to turn collection off; turning it off does not necessarily erase reports already submitted.

We do not propose a separate general-purpose player analytics service, contact-list collection, precise-location collection or a public social feed for this launch scope.

7. Providers and other recipients

Only recipients needed for the service concerned should receive the relevant information. Our current email provider is Google Workspace; the studio website is prepared for Cloudflare Pages. Providers proposed for the online game are:

This list describes the proposed launch configuration, not services already running in the review build. Firebase and hosting providers act under applicable processing arrangements for the functions we configure; app stores, sign-in platforms and advertising providers may also act independently for activities governed by their own notices.

We may disclose necessary information to professional advisers or competent authorities where legally justified. A business transfer would require appropriate safeguards and any notice required by law. We do not propose selling your personal information or sharing it for cross-context behavioral advertising; any change requires an updated notice and applicable choices before it starts.

Provider information: Firebase privacy, Google privacy, AdMob privacy information, Google processing terms, and Cloudflare privacy.

8. International processing

Our company is in Portugal, while providers may process information in other countries. Any transfer of personal data from the European Economic Area must have a valid transfer mechanism, such as an applicable adequacy decision or the European Commission's standard contractual clauses, together with additional safeguards where needed.

The final service configuration must identify the relevant processing locations and safeguards before online processing starts. You can ask us for information about a transfer concerning your data and for a copy of the relevant safeguards, with confidential details removed where appropriate.

9. How long information is kept

Information is retained only while needed for the purpose described here, with the following proposed rules:

Backups and records held independently by a provider may take longer to expire. They must not be restored for an unrelated purpose. If an exception prevents complete erasure, we explain the affected category, reason and retention period or criteria.

10. Your rights and deletion requests

Depending on the applicable law and processing, you may request access, correction, deletion, restriction or a portable copy of your information; object to processing based on legitimate interests; and withdraw consent without affecting processing that was lawful before withdrawal. You may exercise your rights without being penalized for doing so.

Email team@the-vault.life or use our DishMesh account and data deletion page. We may ask for proportionate information to identify the relevant record and verify that it belongs to you. Do not send a password or a sign-in verification code.

For GDPR requests, we normally respond within one month. If the law permits an extension, we explain it within that first month. You can complain to Portugal's Comissão Nacional de Proteção de Dados (CNPD) or another competent supervisory authority.

If a release allows account creation within the game, it must also let you initiate account deletion there. Uninstalling the game or signing out is not a request to erase a server account. The current review build has no live server account to delete.

11. Age and younger players

The proposed DishMesh audience is teenagers and adults. The draft access rule is age 13 or older, increased to 16 or older for residents of the European Economic Area, and any higher minimum required in your country. If you are below the age of legal majority, a parent or guardian must permit your use and any purchases. These are proposed product rules, not a statement that one age threshold applies everywhere by law.

We do not intend to collect personal information from children below the applicable minimum. A parent or guardian who believes a child has provided information can contact team@the-vault.life so we can investigate and remove information where required. The store audience settings, age controls and advertising configuration must implement the final age rule before release.

12. Protecting information

Access to support correspondence is limited to people who need it; the owner's Google Workspace access is protected by two-factor authentication. The online game design must use encrypted network connections, restricted access and appropriately verified purchase and recovery requests before going live.

No system guarantees absolute security. Tell us promptly if you suspect unauthorized account use. Avoid sending sensitive information unless it is necessary and we have explained a suitable way to provide it.

13. Changes to this notice

We will update the date and notice when practices change, and provide additional notice or request new consent when the law requires it. Planned processing does not become authorized merely because a draft describes it. The notice accompanying the released version must describe that version's actual practices.