Legal
Privacy Policy for Pizza Boss
Effective date: August 25, 2026
1. Scope and who we are
This Privacy Policy explains how information is handled when you use Pizza Boss, contact us about the game, or visit the Global Vacuum Games pages used for legal and support information.
Global Vacuum GamesStudio/publisher brand responsible for Pizza Boss
Country: Kazakhstan
Correspondence and privacy address: Brusilovskogo 56, Almaty 050005, Kazakhstan
Email: [email protected]
Website: https://globalvacuumgames.com/
Pizza Boss does not provide a Global Vacuum Games player account, social login, first-party cloud save, or first-party game backend. Information can still leave the device through the Google, Firebase, Unity, advertising, store, website, and email services described below.
2. Information you choose to provide
Support, privacy, purchase, and refund messages
The mailbox [email protected] accepts general support, privacy, access, deletion, correction or objection requests where applicable, and purchase or refund questions.
When you use the in-game support or refund option, Pizza Boss opens a draft in your external email application. The game does not silently send the message. You can review and edit the draft, remove any prefilled information, add an attachment, or close it without sending.
If you send a message, we and the involved email providers may receive:
- your sender email address and any sender display name added by your mail application;
- the incident date, problem description, and other text you write;
- the request type, device operating-system family, device model, app version, game name, and a random per-run support reference added to the editable draft;
- for a purchase or refund request, the product and approximate purchase date you enter; and
- if it is genuinely needed to locate a transaction, a Google Play order number or receipt screenshot you choose to attach.
The per-run support reference is also placed in Crashlytics so one support message can be matched to one app run. It changes whenever the game restarts, is not stored by Pizza Boss as a persistent device identifier, and cannot be used by the game to link separate sessions.
The current template does not automatically include a stable device identifier, the email address of the Google Play purchase account, a purchase token, a raw receipt, an order number, or a full transaction identifier. We do not ask for your full payment-card number, bank credentials, password, or authentication code. Please do not send information that is not needed for your request.
3. Information handled automatically in the game
Firebase Analytics
Pizza Boss uses Google Analytics for Firebase to understand use of the game and improve progression, balance, reliability, and user experience.
Depending on the applicable consent state and service configuration, Firebase Analytics may process:
- an app-instance identifier, Firebase installation identifier, and Android advertising identifier when it is available and permitted;
- a masked IP address from which Google derives approximate location;
- device, operating-system, app-version, app-lifecycle, session, and screen information;
- automatic in-app purchase and subscription information such as product ID, product name, and price; and
- gameplay events and parameters sent by Pizza Boss.
The gameplay events include game launch, screen views, level and zone progress, tutorials, objectives, missions, unlocks, restaurant and employee activity, virtual-currency earnings and spending, rewards, settings changes, rewarded-ad activity, and purchase-funnel results. Parameters may include game-feature identifiers, player level, balances and amounts of virtual currency, product identifiers and displayed price, ad placement and response/error information, and app version.
Pizza Boss may set Analytics properties for language, maximum level reached, current zone, tutorial-completion state, ads-removal state, and subscription state. The audited code does not set a Firebase Analytics user ID and does not send a support email address or name to Analytics.
The Android configuration starts Analytics collection disabled. Pizza Boss uses Google UMP/TCF state to derive and pass the four Google Consent Mode signals analytics_storage, ad_storage, ad_user_data, and ad_personalization, and separately enables or disables Analytics collection based on analytics_storage. Before a choice is resolved, game events can be held temporarily in memory; after denial they are discarded rather than sent. If Analytics permission is withdrawn, the app disables collection and asks Firebase to reset the local Analytics instance data. Outside regions where Google reports that consent is required, collection may be enabled without displaying the European consent message.
Google Signals is currently off, user-provided-data collection is not configured, and no Google Ads, AdMob, BigQuery, or Google Play product link is currently configured for the Analytics property. These settings can change; material changes must be reflected in this Policy.
Firebase Crashlytics
Pizza Boss uses Firebase Crashlytics to detect and diagnose crashes and application-not-responding events. Crashlytics may process stack traces, fatal or non-fatal status, relevant app state, device model and operating-system information, processor/memory/storage diagnostics, Crashlytics and Firebase installation identifiers, and session information.
The game adds a release/development build-type key and the random per-run support reference described above. It does not set a Crashlytics user ID. Production logging is designed to replace or remove purchase tokens, raw receipts, Google Play order numbers, full transaction identifiers, and email-like strings before Unity logs can be attached to a Crashlytics report. If Firebase Analytics is allowed, Analytics breadcrumbs may also show app interactions immediately before a crash.
Crashlytics operates independently of the advertising choice shown by UMP and has no in-game on/off switch in the current version.
Firebase Remote Config
Pizza Boss uses Firebase Remote Config to download balance and progression configuration for build pads, customers, the economy, employees, the player, production, progression, and rewards. The current production configuration uses a one-hour minimum fetch interval; the game keeps local defaults if the service is unavailable.
Remote Config automatically handles information such as country code, language, time zone, platform and operating-system version, Firebase App ID, app package, SDK version, and Firebase installation ID. It is not controlled by the advertising choice. The current Firebase configuration has no Remote Config conditions, personalizations, A/B tests, or rollouts.
Google Mobile Ads and rewarded advertising
Pizza Boss uses Google Mobile Ads (AdMob) for Rewarded ads. The current ad inventory contains a Rewarded unit and does not implement ordinary banner, interstitial, app-open, or rewarded-interstitial ads. The game includes voluntary Rewarded placements and a periodic Rewarded offer after the relevant game feature is unlocked. The separate noads_forever purchase removes that periodic offer but does not remove voluntary Rewarded placements.
Google's current Mobile Ads disclosure says its Android SDK automatically collects and shares the following types with Google and advertising partners for advertising, analytics, and fraud-prevention purposes:
- IP address, which may be used to estimate approximate location;
- app and ad interactions, including app launches, taps, and video views;
- app and SDK diagnostics, including launch time, hang rate, and energy use; and
- device or account identifiers, including the Android advertising ID, App Set ID, and other applicable device/account or provider-issued identifiers.
The Android Advertising ID permission is present in the current uploaded app bundle. Whether an Advertising ID or another identifier is available in a particular request depends on Android settings, consent, Limited Ads behavior, and Google's configuration. Limited or non-personalized ads can still require IP address, device, delivery, security, and fraud-prevention information.
The current AdMob account uses a maximum ad content rating of G/all ages. First-party ID and Limited Ads are enabled, passing the full IP address to bidders is disabled, impression-level ad-revenue reporting is disabled, and no separate third-party mediation adapter is configured. Google can still use authorized buyers and advertising partners within its advertising services, so the absence of a mediation adapter does not mean that no advertising partner receives data.
Pizza Boss does not request Android precise-location permission and does not send GPS coordinates to the advertising SDK through game code.
Google User Messaging Platform and privacy choices
Pizza Boss uses Google's User Messaging Platform (UMP) to obtain current privacy-message requirements and determine whether the game may request an ad. The published European-regulations message applies to the EEA, United Kingdom, and Switzerland and provides Consent, Reject, and Manage options. When Google reports that privacy options are required, the game provides an entry in Settings to reopen them.
UMP and related IAB TCF state may store and transmit consent status, purpose/vendor choices, whether a form or privacy-options entry is required, and whether ads may be requested. Pizza Boss does not explicitly initialize or load a Rewarded ad until UMP reports that ads may be requested. When privacy choices change, the game updates Consent Mode and destroys a preloaded Rewarded ad whose consent state no longer matches before loading a replacement.
Rejecting personalized advertising does not necessarily stop Limited Ads or information needed to deliver, secure, and measure an ad. The list of advertising partners and their purposes is maintained through Google's message and can change.
Google Play purchases and subscriptions
Pizza Boss offers optional Stardust consumables, the noads_forever non-consumable, and the vip_monthly subscription through Google Play Billing and Unity In-App Purchasing (Unity IAP).
Google Play processes payment credentials. Pizza Boss and Global Vacuum Games do not receive your full card number or bank-account credentials through this flow. The game and purchase SDKs handle purchase history and transaction information needed to offer, confirm with the store, grant, restore, acknowledge, consume, expire, or revoke a purchase. This can include product ID, title and description, localized price and currency, purchase/transaction state, purchase token or transaction identifier, receipt and signature, subscription entitlement, expiry/renewal information, and confirmation results.
Pizza Boss stores local entitlement and transaction-deduplication state. The current app has no Global Vacuum Games receipt-validation backend. Google Play and Unity can still process purchase data directly through their services, and selected purchase-funnel information may be sent to Firebase Analytics when Analytics collection is allowed.
Unity IAP Insights
Unity IAP 5.4.1 includes a separate Unity IAP Insights/diagnostic data path. It is not Firebase Analytics and is not disabled merely because ordinary Unity Gaming Services Analytics is not in use.
During purchase activity, Unity's current disclosure and the installed package indicate that Unity may process:
- country or approximate location;
- Unity installation, player, session, device, and related identifiers;
- device model, operating system, locale, app/Unity/SDK version, diagnostics, crash logs, and other app-performance information; and
- product and purchase information, including product ID/type/title/description, price, currency, quantity, purchase status, transaction identifier, and receipt data.
Unity's current generic IAP 5.4+ Google Play disclosure also lists an end-user email address as collected, required, and processed ephemerally. Pizza Boss does not ask Unity for a purchase-account email, does not include Unity Webshop or direct-to-consumer checkout, and does not expose an email field in its native Google Play purchase flow. We disclose Unity's published category conservatively because Unity has not provided narrower guidance for this configuration.
Unity states that its covered IAP data is encrypted in transit. Unity IAP does not provide its own consent service or SDK self-service deletion feature.
4. Information stored locally and Android backup
Pizza Boss stores game and app state in Unity PlayerPrefs. This includes currencies and progress, levels and zones, unlocks and upgrades, restaurant and staff state, tutorials and objectives, reward and mission timers, language and audio/haptic settings, local Analytics bookkeeping, ad-break/reward ledgers, and purchase-entitlement and transaction-deduplication state. Some restaurant state is stored as JSON inside PlayerPrefs. PlayerPrefs are not encrypted by the game.
Raw local save data is not sent to a Global Vacuum Games backend because no such backend exists. Selected actions, settings, progress values, purchase events, and advertising events may be sent separately through the SDKs described above.
The Android build explicitly allows the Pizza Boss PlayerPrefs save file to participate in Android cloud backup and device-to-device transfer. This can place game progress and local ledgers in the user's Google-managed backup and restore them after reinstall or on a new device. When Pizza Boss detects a restored installation, it is designed to delete its mirrored consent choices and cached paid-entitlement state before use so UMP can determine the current privacy state and Google Play can restore current purchases. Other gameplay and deduplication state may remain restored.
You can clear the active local copy using Android's Clear storage control. Uninstalling normally removes active app-private storage, but a later installation may receive an eligible Google backup. Google Play can separately restore non-consumable and subscription entitlements.
5. Website and support infrastructure
The Global Vacuum Games website is hosted on Cloudflare Pages and delivered through Cloudflare's proxy. The site does not require a user account and does not contain a first-party support form; support links open an email application.
Cloudflare Web Analytics is configured for automatic real-user measurement outside a configured European Union exclusion. For eligible website visits, Cloudflare may process the page URL, browser, operating system, country, and performance measurements. Cloudflare also processes source IP address, hostname, path/URL, request, cache, and security metadata to deliver, protect, and investigate the site. Sampled request/security records were visible in Cloudflare Security Analytics. No separate Logpush destination was found during the current review. Cloudflare's exact sampling and retention are governed by its service and configuration.
Email sent to [email protected] is routed through Cloudflare Email Routing to a Google Gmail mailbox. The reviewed Gmail settings showed no mailbox delegates or user-level forwarding and POP was off. Those observations do not establish every administrator-level route, IMAP setting, backup, log, technical-retention, deletion, or recovery behavior. Access to correspondence is limited by Global Vacuum Games policy to authorized members of its team.
6. How information is used
We and the relevant providers use the information described above to:
- run Pizza Boss, restore eligible progress, and deliver current game configuration;
- understand use of the game and improve progression, balance, features, and user experience;
- find, diagnose, and fix crashes, errors, and performance problems;
- request, deliver, measure, and protect Rewarded advertising and grant earned rewards;
- display and apply advertising privacy choices;
- process, confirm, restore, revoke, and troubleshoot purchases and subscriptions;
- prevent duplicate rewards, duplicate purchase grants, abuse, and fraud;
- respond to support, privacy, purchase, and refund requests; and
- operate, measure, and secure the website and comply with applicable platform, accounting, dispute, and legal obligations.
7. Who receives information
SDK data is often sent directly from the device to a provider. Global Vacuum Games does not necessarily receive or view every field handled by that provider.
- Google/Firebase: Analytics, Crashlytics, Remote Config, Installations, Sessions, and related transport components. See Firebase privacy and security and the Google Privacy Policy.
- Google Mobile Ads and advertising partners: Rewarded-ad delivery, measurement, analytics, security, and fraud prevention. See Google advertising privacy information.
- Google UMP: privacy-message requirements, consent choices, and permitted ad-request state.
- Google Play: store catalog, payment, purchase, subscription, entitlement, and transaction functions. Google Play receives payment details directly under its own terms.
- Unity: Unity IAP functionality, Insights, purchase analytics, diagnostics, and the related data described above. See Unity's Privacy Policy and Unity IAP privacy information.
- Cloudflare: website hosting, proxy/caching, Web Analytics, security/request analysis, and routing of the support alias. See Cloudflare's Privacy Policy.
- Google Gmail and the user's email provider: only when a user sends support, privacy, purchase, or refund correspondence.
- Android/Google backup services: eligible PlayerPrefs cloud backup and device-transfer behavior controlled through the user's platform/account settings.
The current game has no first-party Global Vacuum Games backend, account database, cloud-save service, attribution SDK, social-login provider, external payment SDK, or Unity Ads runtime package.
8. Your choices and controls
- Advertising and consent: Complete the Google privacy message when shown. When Google reports that privacy options are required, reopen them from Pizza Boss Settings to review, change, or withdraw choices.
- Advertising identifier: Supported Android versions let you reset or delete the Android Advertising ID in device settings. Limited Ads or deletion of the ID does not stop all essential ad-delivery, security, or fraud-prevention processing.
- Rewarded ads: You choose whether to start voluntary Rewarded placements.
noads_foreverremoves the periodic offer but does not remove voluntary Rewarded placements. - Analytics: Analytics collection is controlled by the consent state derived by the game as described above. Crashlytics and Remote Config are separate services and are not disabled by an advertising rejection.
- Support: Do not send the prepared email, or edit its text and attachments first. The technical block and refund details can be removed.
- Purchases: Purchases are optional. Use Google Play to review purchase history, manage or cancel a subscription, and control store payment information.
- Local and backup data: Use Android Clear storage to remove the active local save and use Android/Google account backup controls for provider-held backups. Store entitlements may still be restored by Google Play.
9. Retention
Retention differs by system:
- Local PlayerPrefs remain until overwritten or cleared, and eligible save data may remain in Android/Google backup until removed under platform controls or provider policy.
- The current Google Analytics property retains event data for 2 months and user data for 14 months, with reset-on-new-activity enabled. Aggregated reporting and provider-required records may follow different rules.
- Google states that Crashlytics crash data is generally retained for 90 days before removal begins.
- Firebase installation identifiers, Remote Config data, and SDK caches follow Firebase's service-specific rules.
- Unity states generally that IAP service logs are kept for 90 days and that other IAP order/configuration records follow Unity's service policy. The exact retention of Insights-ingest records and the identifiers Unity would require to locate them for a privacy request are not documented for this configuration.
- AdMob, advertising partners, Google Play, Android backup, Cloudflare, Gmail, and the user's mail provider apply their own service, security, transaction, backup, and legal retention rules. No unsupported fixed period is stated for them here.
- Global Vacuum Games keeps support, privacy, purchase, and refund correspondence only for as long as reasonably necessary to handle the request, solve a technical problem, address a refund or purchase dispute, or preserve records needed for payment, dispute, accounting, or legal purposes. When it is no longer needed for those purposes, the operational policy is to delete it through the team's workflow, subject to provider capabilities, backups, technical retention, and records that must still be preserved.
10. Deletion and privacy requests
Pizza Boss has no player account, so there is no account-deletion button. Contact [email protected] to request access, correction, objection, or deletion where applicable, including for support correspondence or provider-held records.
The following limits may apply:
- clearing storage or uninstalling removes the active local copy, not information already sent to a provider or an eligible Google backup;
- Google Play may retain transaction/payment records and restore store entitlements;
- Pizza Boss has no account identifier that automatically links every SDK record to an email address;
- Global Vacuum Games may need an applicable support reference, installation reference, transaction/order reference, or other provider-supported information to locate a record;
- some provider data may not be identifiable from the information you can supply;
- Unity IAP has no SDK self-service deletion tool; a request may need to be validated and routed to Unity; and
- information independently controlled by a provider, or required for security, fraud prevention, transactions, accounting, disputes, or legal obligations, may not be deletable on request.
We will assess a request under applicable law and explain relevant limitations.
11. Privacy rights
Depending on where you live and the laws that apply, you may have rights to request access, correction, deletion, restriction, portability, or information about processing; to object to certain processing; or to withdraw consent without affecting earlier lawful processing. You may also have a right to complain to an applicable privacy regulator.
For users in the EEA, United Kingdom, or Switzerland, Google's published UMP message may present advertising choices. Changing an advertising choice affects the ad and Consent Mode paths described above. It does not disable Crashlytics or Remote Config.
Some US state laws may provide additional rights if their scope and thresholds apply. A Google Play Data Safety label that data is “shared” is a platform classification and is not, by itself, a legal conclusion that data is sold or shared under a particular privacy statute.
Contact us to exercise an applicable right. Providers may process data in different legal roles, and a request may need to be handled by or routed to the provider that controls the relevant record.
12. Children's privacy
Pizza Boss is not specifically directed to children. Availability and age-related access to the game are governed by Google Play settings and applicable law.
The game does not ask users to create a Pizza Boss account or provide their age. If a parent or guardian believes that a child has provided personal information through support or another available communication channel, contact [email protected] so the request can be investigated with the relevant provider.
13. International processing
Google, Firebase, Unity, Cloudflare, email providers, Android backup services, and advertising partners may process information in countries other than the country where you use the game. Their locations, roles, safeguards, and transfer arrangements are governed by their service terms, privacy policies, configuration, and applicable law.
14. Security
The covered Firebase, Google Mobile Ads, and Unity IAP data is encrypted in transit using HTTPS or TLS according to the providers' current disclosures, and the Android application disables cleartext network traffic. No method of transmission or storage is completely secure.
PlayerPrefs are not encrypted by Pizza Boss. Email security depends on the user's provider, Cloudflare Email Routing, and Gmail. Global Vacuum Games limits mailbox access to authorized team members. Access to provider consoles, backups, and exports depends on the security controls of those services.
15. Changes to this Policy
We may update this Policy when Pizza Boss features, SDKs, providers, store configuration, or applicable requirements change. We will change the effective date when a revised version is published. Material technical changes must be reflected consistently in the app, Google Play Data Safety answers, consent configuration, and this Policy.
16. Contact
For support, privacy, access, deletion, correction or objection requests where applicable, and purchase or refund questions about Pizza Boss:
Global Vacuum GamesStudio/publisher brand responsible for Pizza Boss
Country: Kazakhstan
Correspondence and privacy address: Brusilovskogo 56, Almaty 050005, Kazakhstan
[email protected]
https://globalvacuumgames.com/
