Last updated 2026-09-04.
Zaparo WingRush collects the following, and nothing else.
| What | Specifically | Why | Shared |
|---|---|---|---|
| App activity | A score this user submitted to an app-defined board, when they achieved it, and an optional opaque proof string the app supplies - keyed on their Zaparo ID user id; Level, experience points and the number of races played; Link token opened, and the Play install referrer used to match a deferred link after install; Race results: pipes passed, how long the run lasted, and the tap timings the run is verified from; The message payloads, opaque to this module and relayed rather than stored; Which applications within this one tenant the account has been seen in. Recorded when an application registers a device or completes a sign-in under its own application id, so `me().apps` can answer it back to the person.; Who a signed-in user is friends with, who they have a pending request with, and the short code they hand out - all keyed on their Zaparo ID user id | Account management, App functionality | No |
| Device or other IDs | FCM registration token; The account identifier, and the public half of a key generated in the device key store; The caller's user id, carried on each message so the other players know who sent it | Account management, App functionality, Fraud prevention, security, and compliance | Yes |
| Personal info | Display name - generated by default, editable by the user; Email address, and the name a provider reported, from the sign-in the person chose. Those two and nothing else: a browser provider is asked for `openid email profile` and only the address and the name are read out of what comes back. | Account management, App functionality, Personalization | No |
| Photos and videos | Profile photo the user chose to upload | App functionality, Personalization | No |
You can ask for your data to be deleted at any time, at the address below.
Questions about this policy, or a deletion request: privacy@kbsoap.com