IceBreakerz legal
Privacy Policy
Effective July 31, 2026 · Version 2026-07-31.1
Market: South Africa · Locale: en
Browser checkout is unavailable. Use the IceBreakerz mobile app and an available App Store or Google Play listing.
This policy explains what IceBreakerz processes, why it is needed, who receives it, how long it is retained, and the choices and rights available to you.
Who is responsible for your information
Eased Software (Pty) Ltd, registration number 2026/505508/07, is the responsible party and data controller for IceBreakerz. Its physical address is 948 Bizana Street, Moreleta Park, Pretoria, Gauteng, 0044, South Africa.
Product support: support@icebreakerzgames.com. Privacy, data-rights, and safeguard-copy requests: privacy@easedsoftware.com. Loftie Willem Fourie is the registered POPIA Information Officer under reference 2026-063500. The company panel identifies any EU, UK, or Swiss representative required for your market.
Information we process
Account data includes your name or display name, username, email address, Firebase and IceBreakerz user identifiers, sign-in provider, age-gate country or region, date of birth, time zone, settings, entitlements, and account security records.
App activity and live room data includes pages or screens used, game choices and actions, lobby membership, route, readiness, game state, answers, drawings, prompts, clues, votes, results, scores, and moderation actions needed to run the room. Player-created content can be visible to the other players in that room.
Signed-in progression contains completed game, mode, time, round, role, result, points, and limited numeric counters. It excludes raw answers, drawings, prompts, clues, secret topics, individual votes, card IDs, room credentials, drinking quantities, and another player’s account identity.
Payment and refund records include product, amount, currency, status, provider references, billing jurisdiction, policy evidence, refund reason and decision, and accounting timestamps. We do not receive or store full card numbers or card security codes.
Technical, security, and advertising data may include IP address, approximate country or area inferred from IP, browser or device type, operating system, app version, app launches and interactions, ad interactions, diagnostic or performance information, App Check or integrity signals, cookies, installation identifiers, and advertising or app-set identifiers where available.
IceBreakerz does not request precise GPS location, contacts, calendar, installed-app lists, web-browsing history, microphone or audio recordings, or access to your photo library. Drawings in Down the Line are created inside IceBreakerz and uploaded only when a player submits them.
For web regional availability, we transiently use the public network IP address supplied by Google Cloud to resolve only its country through IPinfo. We do not store the raw IP address in the region decision, account, gameplay history, analytics, or application logs.
Guests
Guests are not linked to durable progression. We retain a display name and only the short-lived room, security, and eligibility state necessary for the lobby. We do not later match guest activity to an account through names, IP addresses, devices, cookies, advertising IDs, or fingerprints.
Purposes and lawful bases
Contract is the basis for account authentication, rooms, requested gameplay, progression, customer support, entitlement verification, and supplying purchases. Steps requested before entering a contract also use this basis where applicable.
Legal obligation is the basis for required tax, accounting, store, consumer-rights, data-rights, regulator, and law-enforcement records and responses.
Legitimate interests support service security, abuse and fraud prevention, minimal operational measurement, room recovery, legal-claim handling, and improvement of a safe and reliable service. Those interests are balanced against user rights, use minimised data, and include objection or human-review routes where applicable.
Consent is used only for optional PostHog analytics, optional marketing, and browser or device storage where consent is required. Withdrawing consent does not affect prior lawful processing or disable core gameplay.
Advertising is requested only in non-personalised or limited mode. Google may process the categories described below for delivery, aggregate measurement, security, fraud prevention, and compliance subject to consent signals, age treatment, and device settings.
- Accounts, authentication, rooms, progression, entitlements, requested support, and supplying purchases — contract or requested pre-contract steps — account, identity, room, progression, support, and store evidence.
- Tax, accounting, consumer remedies, legal acceptance, regulator and lawful requests — legal obligation — transaction, refund, policy-evidence, identity-verification, and correspondence records.
- Security, integrity, fraud and abuse prevention, service recovery, aggregate operations, and legal claims — legitimate interests — device, network, integrity, room-control, pseudonymous event, and audit data, subject to balancing, minimisation, objection, and human review.
- Optional PostHog analytics, optional marketing, and non-essential browser or device storage — consent where required — allowlisted analytics events and the selected preference; refusal leaves core gameplay available.
Providers and international processing
Google Firebase and Google Cloud provide authentication, App Check, application hosting, Firestore, Cloud Storage, messaging, and operational infrastructure. They process account identifiers, tokens, device and integrity signals, live room state, submitted drawings, and service logs in configured Google regions and supporting global infrastructure.
MongoDB Atlas hosts account profiles, progression, entitlement, purchase-reference, refund, audit, and operational records in the production cluster region. PostHog EU Cloud receives only consented allowlisted analytics and, for eligible signed-in adults, an internal account identifier; its person data is configured for EU processing.
Google advertising services supply limited or non-personalised voluntary rewarded ads through AdMob on supported mobile devices and, only after separate approval and feature enablement, the H5 Games Ad Placement API in the browser. Mobile rewards use Google's signed server-side verification. H5 rewards use Google's client adViewed callback with a single-use server challenge and do not have equivalent cryptographic server-side verification. IPinfo receives a transient public IP address to return only a country code and does not receive an IceBreakerz account identifier.
Apple App Store and Google Play process store-account, payment, tax, receipt, subscription, cancellation, and refund information under their own terms, and share signed purchase and lifecycle evidence with IceBreakerz. Any production transactional-email or support provider is named in the deployed provider register before it receives user information.
Providers receive only information needed for their contracted function. Apple and Google act under their own store terms for payment and may act independently for some billing data; other suppliers generally process on our instructions under data-protection terms.
Information may be processed in South Africa, the EEA, United Kingdom, United States, or another disclosed provider region. Where a restricted transfer requires safeguards, we use an applicable adequacy decision, standard contractual clauses, UK transfer mechanism, or another lawful instrument, with supplementary measures where appropriate. You may request information about the applicable safeguard from the legal email.
Cookies, advertising, and analytics
Necessary web storage maintains sign-in, lobby sessions, security, purchases, settings, and a short-lived signed country decision so the service does not repeat a network lookup on every request. Optional analytics and personalised offers remain off unless enabled.
If you accept optional product analytics, approved screen, game-flow, and purchase-flow events are sent directly to PostHog EU Cloud. Autocapture, session replay, heatmaps, web-vitals capture, automatic error capture, and automatic lifecycle tracking are disabled. These events exclude names, emails, dates of birth, room codes, full URLs, payment references, advertising IDs, private game content, and precise location.
Consented signed-in adults may be identified in PostHog only by their internal IceBreakerz account ID. Known under-18 players remain anonymous. Refusing or withdrawing consent does not affect gameplay, account progression, purchases, security processing, or anonymous server-authoritative room totals.
Public marketing, game-guide, legal, and account pages are ad-free. The playable web app may load Google's H5 Games ad library only when the H5 feature is approved and enabled on both the client and server and the configured Google-certified consent platform has resolved the applicable consent requirements. A voluntary H5 request may involve permitted browser storage, IP-derived approximate location, browser/device data, game placement context, ad impressions and interactions, diagnostics, and fraud-prevention signals.
Advertising consent provides accept, refuse, and manage choices where required. In regulated regions, H5 advertising fails closed until the certified consent status is available. Refusing does not block public content or free gameplay, but a rewarded allowance is not granted unless the voluntary ad is completed. IceBreakerz honours a recognised Global Privacy Control signal by keeping optional analytics off and blocking H5 ad requests rather than enabling advertising storage contrary to that signal.
H5 advertising choices, optional PostHog analytics, and marketing choices are separate. Changing one does not silently enable another.
Mobile choices use Google User Messaging Platform controls where required, and browser H5 choices use Google's certified consent platform. IceBreakerz does not copy advertising-consent strings to its backend. Ads are requested only when Google reports that requests are permitted and always as non-personalised or limited ads.
Google advertising services may collect and receive an IP address used to infer approximate location, app or browser interactions such as launches, taps, video views and ad views, diagnostic and performance information, and permitted device, browser, advertising, or app-set identifiers. Google uses these categories for advertising or marketing, analytics, and fraud prevention, security, and compliance.
IceBreakerz does not include your name, email address, date of birth, room code, invite token, payment reference, or private game content in an ad request. Users under 18, and users whose age is not yet known, receive conservative under-age treatment. On iOS, an eligible adult may first see Google's explanation and then Apple's App Tracking Transparency prompt. Refusing tracking does not prevent gameplay or limited advertising.
Rewarded ads are requested only after an explicit Watch ad action following a game-specific allowance prompt. The request can include consent signals and an opaque one-time challenge. IceBreakerz retains the provider, evidence type, challenge and claim timestamps, mobile verification result and Google transaction reference where supplied for access control and fraud prevention. Browser H5 evidence records only the adViewed client callback claim and is not represented as signed server-side verification.
Sharing and disclosures
We disclose information to contracted service providers where needed to host data, authenticate users, run and secure rooms, process payments and refunds, send messages, provide consented analytics, serve ads, and support users. Other room participants receive only the player content and room state needed for that shared game.
The Google advertising categories and purposes described above are shared with Google when a voluntary browser H5 or mobile ad request is permitted. PostHog receives only allowlisted optional analytics after consent. Neither provider receives raw answers, drawings, prompts, clues, secret topics, room passwords, invite tokens, or full payment credentials from IceBreakerz.
We do not sell personal information. We may disclose information where required by law, to protect users or the service, investigate abuse, enforce these Terms, or as part of a lawful restructuring, merger, acquisition, or sale, subject to applicable notice and protection requirements.
Retention
Guest lobby credentials expire within 12 hours or earlier when the room closes or the guest leaves. Rewarded-ad challenges expire after 10 minutes. An unstarted gate expires after 30 minutes; after the first protected action, an activated allowance remains valid only for that active game session and ends when the room returns to the lobby, switches games, or closes. Pseudonymous reward evidence expires after 90 days.
Inactive live-room state and player-created content are scheduled for deletion within 10 days. De-identified server-authoritative room summaries expire after 180 days, and an account-derived hash is removed when that account is deleted.
Primary account, profile, progression, statistics, benefits, custom games, and account-linked content remain for the account lifetime and are removed promptly after verified deletion, with primary-system completion within 30 days. Encrypted backup copies expire through the backup cycle within 90 days and are not restored to active use.
Consented PostHog person and event data uses 12-month rolling retention and is queued for provider deletion after a verified account request. Security logs are retained for 12 months and closed support records for 24 months unless a live incident, request, or claim requires longer.
Pseudonymised purchase, store, refund, tax, fraud, and immutable legal-acceptance evidence is retained for seven years after the relevant transaction or account closure. A record may remain longer only while a legal claim, chargeback, investigation, or statutory duty is active, then is deleted or irreversibly anonymised.
Security and incidents
We use access controls, hashed secrets where appropriate, encrypted transport, short-lived tokens, audit records, provider security controls, and least-privilege administration. No online system can guarantee absolute security.
We investigate suspected incidents and notify affected people and regulators when applicable law requires it.
Your choices and rights
Depending on your region, you may request access, correction, deletion, restriction, objection, portability, consent withdrawal, or information about disclosure. You may also complain to the privacy regulator in your jurisdiction.
Use the authenticated Account export, correction, privacy-preference, or deletion controls; visit https://icebreakerzgames.com/delete-account; or email privacy@easedsoftware.com. We verify requests proportionately, respond within the applicable legal period, and explain a refusal or extension. A denied restriction, objection, or automated decision can be escalated for human review.
Deleting an account removes or anonymises its profile, progression, statistics, benefits, active sessions, custom content, provider analytics identifier, and other account links. Minimum pseudonymised legal and financial evidence may remain for the retention period above. Store purchase history may permit a later restoration through the same store account.
Account deletion does not cancel an App Store or Google Play subscription. Cancel renewal in the applicable store before deletion and request any eligible store refund first.
Automated controls and human review
Rules may automatically check account age, drinking-mode eligibility, room authority, entitlement validity, apparently unused purchases, store receipt integrity, abuse signals, and refund eligibility. These rules can allow, restrict, or route an action for review.
IceBreakerz does not use automated profiling to make credit, employment, insurance, or similarly unrelated decisions. Contact support to contest a material automated restriction or refund signal and request human review.
Children and drinking eligibility
Accounts are limited to people aged 16 or older. Younger party-game guests participate without an account under the host's or guardian's responsibility. We do not knowingly create durable profiles for them.
Drinking modes use a separate country safety threshold. Guests, people under 18, and people whose age is unknown are not identified in PostHog and receive conservative advertising treatment. If a child's information was provided improperly, contact the privacy address so it can be investigated and deleted or restricted.
Policy changes
We publish the effective date and archived version of each policy. Material new processing is notified before it begins, and fresh consent is requested only where legally required.
South Africa addendum
South African users may exercise rights under POPIA and may complain to the Information Regulator South Africa.
Company details
Eased Software (Pty) Ltd · Registration 2026/505508/07
948 Bizana Street, Moreleta Park, Pretoria, Gauteng, 0044, South Africa
Telephone: +27 76 238 8089
Office bearers: Loftie Willem Fourie — Director and Information Officer
support@icebreakerzgames.com · privacy@easedsoftware.com
POPIA Information Officer
Loftie Willem Fourie · privacy@easedsoftware.com
Archived policies
These immutable records remain available for historical access and support. They do not make an unavailable market active.
Version 2026-07-30.2 · Effective July 30, 2026
Version 2026-07-30.1 · Effective July 30, 2026
Delete your account
You can permanently delete your IceBreakerz profile and personal game progression without installing the app.