Handyman Puzzle

Privacy policy

Privacy Policy for Handyman Puzzle

Effective date: July 1, 2026

Handyman Puzzle is published by stackwiz labs OÜ (`stackwiz labs`, "we", "us", or "our"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use Handyman Puzzle, our related services, and our support website.

Contact

Summary

Handyman Puzzle is a puzzle game with optional sign-in, in-app purchases, rewarded ads, leaderboards/missions when enabled, push notification support, and backend-synced inventory. We use Firebase and Google AdMob services to operate the game, authenticate players, sync purchases and inventory, show ads on supported mobile platforms, measure basic gameplay events, and diagnose service issues.

We do not sell personal information for money. Some advertising identifiers, ad interactions, or device information may be shared with advertising partners to show, measure, and improve ads. Depending on your location, this may be treated as "sharing", "targeted advertising", or similar terms under privacy laws.

Scope

This policy applies to Handyman Puzzle on iOS, Android, macOS, and other native platforms we may support. The first public beta may be iOS-only, but this policy covers the product as implemented in the app.

This policy does not cover third-party websites, stores, or services that have their own privacy policies, including Apple, Google, Firebase, Google AdMob, Facebook, or other sign-in providers.

Information We Collect

Account and Authentication Data

Handyman Puzzle can create a Firebase anonymous guest account automatically so the game can sync backend inventory and purchases. If you choose a sign-in provider, we may receive account information from that provider through Firebase Authentication.

Depending on the sign-in method, this may include:

  • Firebase user ID.
  • Anonymous account identifier.
  • Provider identifiers such as Apple, Google, or Facebook provider ID.
  • Display name, email address, and profile photo URL if supplied by the provider and allowed by you.
  • Account metadata such as creation time and last sign-in time.
  • IP address, user agent, and security signals processed by Firebase Authentication to provide authentication and prevent abuse.

Supported sign-in options may vary by platform and release. Current app features may include anonymous guest accounts, Sign in with Apple, Google Sign-In, and Facebook Login where available.

Gameplay, Inventory, and Progress Data

We collect and store gameplay-related information needed to operate the game and its backend features, including:

  • Player ID.
  • Puzzle mode activity such as Carpentry, Bricklaying, and Plumbing play.
  • Scores, level starts, level completions, puzzle failures, and selected gameplay events.
  • Inventory counts for consumable items.
  • Ad-free entitlement status.
  • Rewarded-ad grant status.
  • Purchase fulfillment status.
  • Leaderboard and mission summaries when those backend features are enabled.

When a backend URL is configured, inventory, purchases, rewards, and paid consumable spending are backend-authoritative. The app sends authenticated requests to our backend, and the backend derives player identity from the Firebase ID token.

Purchase Data

Handyman Puzzle offers in-app purchases for consumable game items and may offer an ad-free entitlement on ad-supported mobile platforms.

For Apple App Store purchases, the app sends purchase verification information to our backend, including:

  • Product ID.
  • App Store transaction ID.
  • Local App Store verification data.
  • Purchase status needed to complete or restore purchases.

For Google Play purchases, the app may send:

  • Product ID.
  • Google Play purchase token.
  • Purchase status needed to complete or restore purchases.

We use this information to verify purchases, grant inventory or entitlements, prevent duplicate grants, process restores, and investigate purchase support requests. Apple and Google process payment details directly; we do not receive your full payment card or bank account details.

Advertising Data

Handyman Puzzle uses Google AdMob on iOS and Android. Ads are not supported on macOS/desktop in the current implementation.

AdMob and related advertising partners may collect or process information such as:

  • IP address, which may be used to estimate general location.
  • Device identifiers, including the advertising identifier when available and permitted.
  • Advertising data such as ads shown, ad views, ad interactions, and video reward completion.
  • App interaction and performance data, such as app launches, ad interactions, and ad performance.
  • Crash logs and diagnostic information related to the ad SDK.

Before mobile ad requests, the app uses Google's User Messaging Platform to check whether consent or privacy-choice messages are required. If required, the app presents Google's consent form and only requests ads after UMP reports that ads may be requested. If UMP reports that privacy options must remain available, the app shows an in-app privacy-options entry point.

By default, Handyman Puzzle requests non-personalized ads. On ad-supported mobile platforms, the app asks whether you allow personalized ads. You can keep non-personalized ads or allow personalized ads where supported by the app configuration, your choices, platform permissions, Google's consent flow, and applicable law. You can change this app-level choice later in the Profile screen.

On iOS, the app may request App Tracking Transparency permission when personalized ads are allowed and platform permission is needed before accessing the advertising identifier for tracking. If you deny permission, you may still see ads, but they should not use the IDFA for cross-app tracking. The app also uses Apple's SKAdNetwork framework for ad attribution where available.

Rewarded ads may use server-side verification data so our backend can validate that a reward was earned before granting inventory.

Analytics and Remote Configuration Data

We use Firebase Analytics to understand gameplay behavior and improve the app. The app currently logs events such as:

  • Session start.
  • Sign-in provider used.
  • Backend bootstrap success or failure.
  • Level start and completion.
  • Puzzle failure reason.
  • Consumable use.
  • Rewarded ad start/completion/grant.
  • In-app purchase start, verification, and failure.
  • Leaderboard opened.
  • Mission completed.
  • Notification permission result.

We use Firebase Remote Config to fetch configuration values such as ad cadence, reward amounts, mission count, and puzzle-mode weighting. Remote Config may use Firebase installation identifiers to return configuration values.

Push Notification Data

The app includes Firebase Cloud Messaging support. If messaging is available, the app may request notification permission and register a device token with our backend.

We may collect:

  • Notification permission status.
  • Firebase Cloud Messaging token.
  • Device platform, such as iOS, Android, or macOS.

We use this data to send app-related messages if notifications are enabled.

Device, Network, and Diagnostic Data

We and our service providers may process technical data needed to operate and secure the app, including:

  • Device model, operating system, app version, bundle ID, and platform.
  • IP address and approximate region derived from IP address.
  • Firebase installation identifiers.
  • Backend request metadata and error responses.
  • Crash, performance, and diagnostic data from service providers where enabled.

Google AdMob and Firebase services may process diagnostic data as part of their SDK operation. If we add additional crash or performance monitoring services, we will update this policy as needed.

Local Device Storage

The app uses local device storage to keep gameplay state available between app sessions. This includes local inventory cache, ad-free status, ad pacing counters, and local purchase replay-protection keys. When the backend is configured, local inventory is treated as a cache and fallback, not as the source of truth.

Support Communications

If you contact support, we may collect the information you provide, such as:

  • Name or display name.
  • Email address.
  • Device and app information you include.
  • Support message content.
  • Screenshots, logs, or purchase details you choose to send.

We use support information to respond to your request, troubleshoot issues, verify purchases, and improve the app.

Information We Do Not Intentionally Collect

The app does not intentionally request access to precise location, contacts, calendar, photos, camera, microphone, health data, or financial account data. Apple and Google may process payment information separately when you make an in-app purchase.

How We Use Information

We use the information described above to:

  • Provide and operate the game.
  • Create and maintain guest or signed-in player sessions.
  • Sync inventory, purchases, rewards, missions, and leaderboard data.
  • Verify purchases and prevent duplicate purchase or reward grants.
  • Authorize backend-controlled consumable spending.
  • Show interstitial and rewarded ads on supported mobile platforms.
  • Measure app usage, gameplay balance, and feature reliability.
  • Fetch Remote Config values.
  • Send push notifications if enabled.
  • Detect, prevent, and investigate fraud, abuse, security issues, and service failures.
  • Respond to support requests.
  • Comply with legal obligations and app-store requirements.

Legal Bases for Processing

Where GDPR, UK GDPR, Swiss data protection law, or similar laws apply, our legal bases may include:

  • Contract: to provide the game, account, purchases, inventory, rewards, and support you request.
  • Legitimate interests: to secure the service, prevent fraud, maintain backend reliability, diagnose bugs, and improve gameplay.
  • Consent: for optional tracking, push notifications, personalized advertising, or other processing where consent is required.
  • Legal obligation: to comply with payment, tax, fraud-prevention, consumer protection, and app-store obligations.

How We Share Information

We may share information with:

  • Firebase and Google Cloud services, for authentication, backend operation, Firestore storage, Remote Config, messaging, analytics, and infrastructure.
  • Google AdMob and advertising partners, to show, measure, and improve ads.
  • Apple App Store and Google Play, to process purchases, validate transactions, and support restores.
  • Sign-in providers such as Apple, Google, or Facebook, when you choose to sign in or link an account through those providers.
  • Service providers that host, monitor, secure, or support the app and website.
  • Legal, safety, or compliance recipients when required by law, legal process, or to protect rights, users, or service security.
  • A successor entity if the business is involved in a merger, acquisition, reorganization, or asset transfer.

We require service providers to process information only for the services they provide to us, subject to their terms and applicable law.

International Transfers

We may process and store information in countries other than your own. Firebase and Google services may process data on global infrastructure unless a service or configuration provides a specific location selection. When required, we rely on appropriate transfer mechanisms such as data processing agreements, standard contractual clauses, or recognized transfer frameworks.

Retention

We keep information only as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required by law, fraud prevention, dispute resolution, tax/accounting, or app-store obligations.

Current intended retention:

  • Account and backend profile data: retained while your account is active, then deleted or anonymized after account deletion where technically and legally possible.
  • Active inventory, active entitlements, leaderboard scores, mission progress, and push notification tokens: retained while your account is active, then deleted or anonymized after account deletion where technically and legally possible.
  • Purchase, reward, spend, fraud-prevention, tax/accounting, support, and dispute records: retained as long as reasonably needed to restore purchases, prevent duplicate grants, prevent fraud, resolve disputes, provide support, and satisfy legal or app-store obligations.
  • Support messages: retained for 24 months, unless needed longer for an unresolved issue, dispute, legal obligation, security issue, or fraud-prevention reason.
  • Firebase/Google Analytics user-level and event-level data: configured to 2 months where product settings allow this.
  • Normal backend application/request logs: retained for 30 days.
  • Security, fraud, abuse-prevention, and audit logs: retained for 90 days, unless a longer legal, dispute, security, or fraud-prevention hold is needed.
  • AdMob data: retained according to applicable Google AdMob settings and policies.
  • Local device data: remains on your device until deleted by the app, app data reset, uninstall, or operating system cleanup. After successful account deletion, the app clears local gameplay cache on the current installation.

More detail is available at: Handyman Puzzle Data Retention.

Your Choices and Rights

Depending on where you live, you may have rights to:

  • Access personal information we hold about you.
  • Correct inaccurate information.
  • Delete information.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Receive a portable copy of certain information.
  • Opt out of sale, sharing, targeted advertising, or profiling where applicable.
  • Appeal a privacy request decision where applicable.

To make a privacy request, contact privacy@stackwiz.io. We may need information to verify your request, such as your Firebase user ID, App Store or Google Play purchase details, or the email address used for support.

You can request account deletion in the app from Profile -> Delete account. If you cannot access the app, contact support at support@stackwiz.io or use the StackWiz contact page.

You can also control certain data uses through your device or app settings:

  • iOS tracking permission: Settings -> Privacy & Security -> Tracking.
  • iOS notifications: Settings -> Notifications -> Handyman Puzzle.
  • Advertising personalization: Apple or Google advertising settings.
  • App data: uninstall the app or clear app data where your platform supports it.

Children

Handyman Puzzle is intended for a general audience and is not directed to children. The puzzles are designed for a broad casual-game audience rather than for small children.

We do not knowingly collect personal information from children below the age at which parental consent is required without appropriate consent.

If you believe a child has provided personal information without required parental consent, contact privacy@stackwiz.io. We will review and delete the information where required.

Security

We use reasonable technical and organizational measures to protect information. Backend requests use HTTPS, Firebase ID tokens are used for authenticated app API calls, and the backend is expected to derive player identity from Firebase Authentication rather than trusting client-submitted user IDs.

No system is perfectly secure. If you believe your account or data has been compromised, contact support@stackwiz.io.

Third-Party Services

Handyman Puzzle currently uses or may use these service providers:

  • Firebase Authentication
  • Firebase Analytics
  • Firebase Cloud Messaging
  • Firebase Remote Config
  • Google Cloud / Cloud Run / Firestore backend services
  • Google AdMob
  • Apple App Store / StoreKit / In-App Purchase
  • Google Play Billing / In-App Purchase, if Android IAP is released
  • Sign in with Apple
  • Google Sign-In
  • Facebook Login, where available

These providers may process information under their own privacy policies and terms. You should review their privacy practices if you use those features.

Changes to This Policy

We may update this Privacy Policy when the app, website, services, or legal requirements change. We will update the effective date and, when required, provide additional notice.

Contact Us

For privacy questions or requests: privacy@stackwiz.io

For support: support@stackwiz.io

Postal address: Uus tn 2-11, Ervita 73002 Järva county, Estonia