Last updated: September 4, 2026
1. Controller
The controller is:
Jonas Feldmann
c/o Online-Impressum 10756
Europaring 90
53757 Sankt Augustin
Germany
Email: [email protected]
2. Scope and principles
This Privacy Policy applies to industrygo.de, the Industry GO app for Android and iOS, the related game servers, support and communication features, and the external API. We process personal data only as needed to provide the game and API, process purchases, communicate, keep the service secure or comply with legal obligations.
Industry GO does not sell personal data. We do not use data to track users across apps or websites owned by other companies. On iOS, we do not use the advertising identifier for cross-app tracking. Ads are delivered under the limited advertising policy described below.
3. Website and server logs
When the website or app API is accessed, our systems process data such as IP address, date and time, requested page or API function, HTTP status, transferred data volume, referrer, browser, operating system, device, app and version information. This is necessary to deliver the website and game, investigate errors, defend against attacks and prevent abuse (Art. 6(1)(b) and (f) GDPR).
4. Account, sign-in and gameplay
Depending on the sign-in method and use, we process:
- email address, username, password hash, internal user ID and verification status;
- for Sign in with Google, the provider ID and profile data released by Google, such as email address and name;
- for Sign in with Apple, the provider ID and the email address or Apple private relay address you release, and your name where provided;
- game progress, level, experience, inventory, virtual currency, buildings, production, market and trade activity, rankings and events;
- session, device, IP and security data, such as access tokens, app version, operating system and request times and results.
Google and Apple receive technically necessary request data when their sign-in services are used and process it under their own privacy policies. Account and gameplay processing is based on Art. 6(1)(b) GDPR; security and abuse prevention are additionally based on Art. 6(1)(f) GDPR.
Depending on the feature you use, your username, leaderboard values, alliance membership and profile or community details that you choose to publish are visible to other players. This does not make private messages, individual alliance contributions, your email address or precise location public.
5. External API
If you activate or use the external API, we process the API key assigned to your account, activation status, available API credit balance, and usage and security data. This may include the time, requested endpoint, requested topic, result status, credits used, IP address, user agent, and technical error data. The API key is a personal access credential and must not be shared with third parties.
The full API key is displayed only when it is activated or rotated. Afterwards, for verification we primarily store a cryptographic key hash together with its prefix, suffix, permission scope and the times of creation, rotation and last use.
This processing is necessary to provide, meter and protect the API under Art. 6(1)(b) GDPR. Detecting abuse, repeated use and attacks is additionally based on our legitimate interest in secure and fair operation under Art. 6(1)(f) GDPR. Key and credit data is generally kept until the API is disabled or the account is deleted; billing and security evidence may be kept longer under the criteria below.
6. Precise location and OpenStreetMap
Industry GO is location-based. If you grant location permission, the app processes your precise device location to display your map position, check distance and location-based actions, determine resource fields and detect manipulation such as GPS spoofing. You can withdraw location permission in your device settings; location-based features will then be unavailable or limited.
For server-side location proofs we may store coordinates, accuracy, GPS and device time, speed, location provider, mock-location indicator, action, target coordinate and distance, as well as app version, Android version, device manufacturer/model and a random installation identifier. The installation identifier is generated locally for the app installation and, together with the other information, is used to detect manipulation and abuse.
The map uses data from OpenStreetMap. When map tiles are requested, the map servers in use may receive technically necessary data such as IP address, time, requested map area and device information. Map tiles and sections may be cached temporarily on the device.
The legal basis is Art. 6(1)(b) GDPR and, where device permission or consent is required, Art. 6(1)(a) GDPR. Precise location is not used for advertising or cross-app tracking.
7. Push notifications and Firebase Cloud Messaging
If you allow push notifications, we use Firebase Cloud Messaging (FCM), a Google service, to send gameplay, account, chat or service notices to your device. A push token, app and device information and delivery data are processed. On Apple devices, Apple Push Notification Service (APNs) is also technically involved. You can disable notifications at any time in device settings.
The legal basis is your consent under Art. 6(1)(a) GDPR or, for notices you explicitly request and that are needed for the service, Art. 6(1)(b) GDPR.
8. Optional usage analytics with Firebase Analytics
Usage analytics through Firebase Analytics is disabled by default. Only after you expressly enable it in Settings does Google Analytics for Firebase process technical app and device identifiers, app version, operating system, session and usage data, and events defined by Industry GO. These events include sign-up method, tutorial completion, first mine built, first production started and verified purchase category; currency and value may also be sent for a verified purchase.
We do not send your email address, username, internal player ID, precise coordinates, chat content, API key or purchase receipt for this purpose. Processing is based solely on your consent under Art. 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG. You can withdraw consent at any time in the app Settings. Further collection will then be disabled; prior processing remains lawful. Non-aggregated user and event data is kept for no longer than the period configured for the Analytics property and no longer than 14 months.
9. Advertising and Google Mobile Ads
The app offers voluntarily started rewarded ads through Google Mobile Ads. Approximate region, device and app information, IP address, ad interactions and technical diagnostic data may be processed.
On iOS, Google User Messaging Platform (UMP) is used to request required consent and privacy choices. If Google requires a new choice, the privacy options can be opened in the app. On Android, a rewarded ad is loaded only after you actively select the feature. Selecting an ad does not, however, replace any consent legally required for optional storage, device access or personalised advertising.
We do not use precise location for advertising. Industry GO does not combine ad data for its own purposes with data from other companies' apps or websites and does not permit cross-app tracking. On iOS, the advertising identifier is not used to track you across other companies' apps and websites. Consent-based advertising relies on Art. 6(1)(a) GDPR; technically necessary delivery, fraud prevention and billing rely on Art. 6(1)(b) or (f) GDPR.
10. In-app purchases and subscriptions
Purchases and subscriptions are processed through Google Play on Android and Apple's in-app purchase system on iOS. Google or Apple processes payment details under its own responsibility. Industry GO does not receive full card or bank details. We receive information such as product ID, transaction or receipt, purchase status, time, store, country/region and data needed to verify, grant, restore and protect purchases against abuse. Purchase and entitlement data is kept as needed to perform the contract, provide customer support and meet statutory record-keeping duties.
11. Chat, user-generated content and support
If you use chat, profile, reporting or support features, we process the messages, names, content, attachments, report reasons and related metadata you submit. This allows us to deliver and display content, handle support, moderate the service and protect other users. Do not send passwords or unnecessary sensitive data.
The legal basis is Art. 6(1)(b) GDPR and, for moderation, preservation of evidence and abuse prevention, Art. 6(1)(f) GDPR.
12. Local storage on the device
The app stores technically necessary data locally, such as login and session information, user ID, app settings, map view and cache, filters, synchronisation and notification settings and recently displayed game and chat information. Depending on the operating system, this data remains until sign-out, deletion in the app or uninstalling the app.
Website: fonts and saved choice (September 28, 2026)
Only after you decide, your external-font choice is stored as igo_privacy_choice in this browser’s localStorage (version, permission or refusal, and timestamps). It is valid for 180 days from your choice; we then ask again. This local entry only remembers your choice and does not set a cookie. If browser storage is blocked, the choice applies only to the current page. You can change your choice through “Cookie settings” in the footer and withdraw permission with “Necessary only”. We then return to system fonts and stop loading further Google fonts; requests already made cannot be undone. The font choice does not activate website analytics or advertising trackers.
13. Hosting, recipients and international transfers
The website runs on a web server in Germany and is delivered and protected through Cloudflare. Cloudflare may process technically necessary connection, request and security data such as IP address, headers, time and requested URL. The app API and database run on servers operated by Hetzner Online GmbH.
Other recipients, only where required for a feature, include Google (Firebase Cloud Messaging, Firebase Analytics, Google sign-in, Google Mobile Ads/UMP, Google Play and Google Fonts), Apple (Apple sign-in, APNs and in-app purchases), map/OpenStreetMap services and technical processors acting on our instructions. The website loads Google Fonts only after your explicit permission; Google receives technically necessary request data such as your IP address. Without permission, we use system fonts.
We use Online-Impressum, a service of Clear-Media UG (haftungsbeschränkt), to receive and forward business mail. For incoming business correspondence, we may process sender and contact details, addresses, mailing and forwarding data, and the contents of the correspondence. The legal basis depends on the matter and is Art. 6(1)(b), (c) or (f) GDPR; our legitimate interest is reliable and documented business availability.
Some providers may process data outside the European Economic Area, particularly in the United States. For certified US providers, we rely on the EU-US adequacy decision; otherwise we use safeguards including EU Standard Contractual Clauses and assess any necessary supplementary measures. You can request a copy of the applicable safeguards or information on where they are available by emailing [email protected]. Delivering and protecting the website are based on our legitimate interests under Art. 6(1)(f) GDPR.
14. Retention and deletion
- Account and game data is generally kept for the life of the account.
- Push tokens are deleted or made unusable when push is disabled, you sign out, the token becomes invalid or the account is deleted, subject to a short technical transition period. Notifications shown in the app are generally purged after 14 days, and no more than 80 current entries are retained per account.
- Support and moderation data is kept as long as needed to handle the case, defend legal claims or prevent abuse.
- Purchase and billing records may be kept longer to comply with statutory retention duties and, after account deletion, may be retained without a link to the deleted player for accounting, fraud prevention and legal claims.
- API key and credit data is generally kept until the API is disabled or the account is deleted; usage and security logs are deleted or anonymised when the operational or security purpose ends.
- Firebase Analytics data collected with consent is retained as described above; the local consent setting remains stored until you change it or delete the app data.
- Business correspondence is kept as long as needed to handle the matter, perform a contract, defend legal claims or meet statutory retention duties.
- Server and security logs are deleted or anonymised regularly unless a security incident or legal duty requires longer retention.
You can delete your account in the app or follow the instructions on Delete account. Once a request is clearly identified and confirmed, we generally process it within three days and no later than 30 days. Data subject to legal retention duties or needed to address specific abuse is restricted until the purpose ends and then deleted or anonymised.
15. Your rights
Subject to the GDPR, you have rights of access, rectification, deletion, restriction, data portability and objection. You may withdraw consent at any time for the future. To exercise your rights, email [email protected]. You also have the right to lodge a complaint with a data protection authority.
Specific right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the affected data unless compelling legitimate grounds or the establishment, exercise or defence of legal claims prevail.
16. Required information
Data marked as required for registration, sign-in, purchase verification or API access is needed for the relevant contract or requested feature. Without it, we cannot provide the account, purchase credit or API access. Location, push, analytics and advertising consent is voluntary; without location permission, location-based features will be unavailable or limited.
17. Security
We use technical and organisational safeguards, including encrypted HTTPS transmission, access controls, receipt validation, security logging and anti-manipulation measures. On Android, Google Play Integrity may be used for this purpose. A short-lived integrity token and details and verdicts relating to app authenticity, package, licence, device integrity, device model and Android version are transmitted to Google and our server. The results are linked to the account to detect modified apps, automated abuse and unauthorised purchases (Art. 6(1)(f) GDPR).
Operational player logs are generally retained for 30 days in the regular cleanup cycle. Integrity and security events are retained for as long as needed to detect, investigate and prevent abuse, apply restrictions or defend legal claims, and are then deleted or anonymised. No system can guarantee absolute security. If you suspect a security issue, contact [email protected].
18. Changes
We update this Privacy Policy when features, providers or legal requirements change. The current version is available on this page.