CrimsonFlame Privacy Notice
This Privacy Notice for CrimsonFlame LLC (doing business as CrimsonFlame) ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you download and use our mobile application (Crimson Protocol), our web applications, the CrimX Identity & Developer Platform, access our online websites (including crimsonflame.net), dashboard, APIs, and gaming ecosystems.
- Personal Information We Process: Usernames, contact authentication credentials, profile banners, handles, and basic device diagnostics needed for gameplay sync.
- Sensitive Data: We do NOT process sensitive biometric, racial, ethnic, sexual, or religious personal information.
- Third-Party Selling: We do NOT sell or rent your personal data to data brokers or third parties. Zero commercial monetization of player identities.
- Security & Safety: Protected by cryptographic token authentication, Google Cloud infrastructure, and strict operational access controls.
- Your Global Rights: Support for GDPR (EU/UK), CCPA/CPRA (California), US State privacy statutes, and global data export/deletion requests.
- No Offshore Loopholes: CrimsonFlame is a legitimate United States entity committed to legal transparency and accountability under US law; we do not operate through offshore havens or third-world legal loopholes.
1. What Information Do We Collect?
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You:
- Usernames and public player handles (e.g.,
@username) - Contact or authentication credentials (email address and encrypted credentials)
- Profile customization assets (avatar URL, custom bio, profile banner)
- Full names (if voluntarily submitted for support or verification)
Sensitive Information: We do not process sensitive personal information.
Application Data: If you use our application(s), we may request access or permissions to certain features from your mobile or VR hardware, including device storage and microphone for voice chat functionality. You can manage or revoke these permissions at any time within your device's native operating system settings.
2. How Do We Process Your Information?
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- Account Administration: Facilitate account creation, single sign-on authentication via CrimX, and manage active player sessions.
- Service Delivery: Synchronize VR avatars, multiplayer lobbies, friends lists, and cloud game saves.
- Security & Abuse Prevention: Keep our platform safe through fraud monitoring, automated bot defense, and zero-tolerance policy enforcement against illicit activities.
- User Communications: Send transaction receipts, security alerts on new sign-ins, and respond to support inquiries.
3. What Legal Bases Do We Rely On?
- Consent: Where you have granted explicit permission for a specific purpose (which you may withdraw at any time).
- Contractual Performance: Necessary to fulfill our obligations under our Terms of Service.
- Legitimate Interests: Protecting platform integrity, diagnosing system failures, and improving game experience.
- Legal Obligations: Compliance with lawful court orders, subpoenas, and statutory preservation requirements.
4. When and With Whom Do We Share Your Information?
We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. We may also share information with authorized law enforcement agencies under lawful judicial process pursuant to our zero-tolerance policy on illegal conduct.
5. How Do We Handle Social Logins?
Our Services offer you the ability to register and log in using third-party social media providers (such as Google or Discord). Where you choose to do this, we receive identity tokens, your verified email address, public profile name, and avatar image. We do not store or have access to your third-party account passwords.
6. How Long Do We Keep Your Information?
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. In no event will personal information be retained longer than thirty-six (36) months past the termination of the user's account. Upon permanent account termination, active profiles are scrubbed, and residual archival logs are isolated from active production.
7. How Do We Keep Your Information Safe?
We have implemented comprehensive technical and organizational security measures, including HTTPS encryption in transit, cryptographic token verification, firewalls, and least-privilege administrative access. However, no internet transmission is 100% impenetrable. While we continually update our safeguards, you access the Services within your personal discretion and should maintain strong credential hygiene.
8. What Are Your Privacy Rights?
Depending on your location (such as the EEA, UK, Switzerland, and various US states), you may have the right to request access to your data, request rectification of inaccuracies, demand deletion, restrict processing, or request data portability. You can exercise these rights directly within your CrimX Dashboard settings or by emailing our corporate compliance team at allaboutwaterdiamond@gmail.com.
9. Controls for Do-Not-Track Features
Most web browsers include a Do-Not-Track ("DNT") signal. Because no uniform technology standard for recognizing DNT signals has been formally finalized by international consortiums, our systems do not currently alter behavior upon receiving DNT browser headers.
10. Do United States Residents Have Specific Rights?
Residents of California (CCPA/CPRA), Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia are entitled to specific statutory disclosures:
| Category | Description / Examples | Collected |
|---|---|---|
| A. Identifiers | Account username, email address, IP address, device fingerprints, unique player UID | YES |
| B. Personal Info (Cal. Civ. Code ยง 1798.80) | Name, financial details, credit card numbers, educational history | NO |
| C. Protected Classifications | Race, ethnicity, sexual orientation, religious affiliations, gender identity | NO |
| D. Commercial Records | Commercial purchases, transaction history outside of game licenses | NO |
| E. Biometric Data | Fingerprints, facial geometry, retina scans | NO |
| F. Internet / Network Activity | Telemetry, game session duration, connection stability, client logs | YES |
| G. Geolocation Data | Precise GPS coordinates | NO |
| H. Sensitive Personal Info | Social security numbers, driver's licenses, biometric identifiers | NO |
No Sale of Data: CrimsonFlame has not sold, rented, or shared consumer personal information for commercial consideration in the preceding twelve (12) months, nor will we do so in the future.
11. Do Other Regions Have Specific Privacy Rights?
Australia & New Zealand: We process data in full compliance with the Australian Privacy Act 1988 and New Zealand Privacy Act 2020. Inquiries may be escalated to the Office of the Australian Information Commissioner (OAIC).
Republic of South Africa: Processed in accordance with the Protection of Personal Information Act (POPIA). Formal complaints may be directed to the South African Information Regulator.
12. Do We Make Updates to This Notice?
Yes, we update this Privacy Notice periodically to reflect modifications in our software, platform features, and legal requirements. The updated iteration will be denoted by an amended "Last Updated" timestamp at the top of this document.
13. How Can You Contact Us About This Notice?
Corporate Domicile: Georgia, United States
Direct Inquiries: allaboutwaterdiamond@gmail.com
14. How Can You Review, Update, or Delete Data?
Based on the applicable laws of your jurisdiction, you may request access to, correction of, or permanent deletion of your personal information. To submit a verifiable data subject access request, simply log into your CrimX Dashboard or email us at allaboutwaterdiamond@gmail.com.