Privacy Policy
This Privacy Policy explains how XB Console Store (“we”, “our”, or “us”) collects, uses, shares, retains, and protects information when you use the XB Console Store Android app, website, and related services. Some information is processed only when you use the corresponding feature, such as signing in, syncing favorites, enabling notifications, creating a shared link, or viewing ads.
Information We Collect
- Account and authentication data: if you register or sign in, Firebase Authentication processes your email address, Firebase user ID, authentication provider and provider identifier. Supported sign-in methods are email/password and Google. Firebase handles passwords; XB Console Store does not store your password.
- Synced account data: favorites and legacy wishes, custom collection names, product identifiers, collection cover image URLs, library product identifiers, update timestamps, wishlist capacity, and the related policy version. If you participate in beta testing, we may also store beta status or a Firebase Cloud Messaging token associated with an email-derived account key.
- Advertising and consent data: Google Mobile Ads may process device and advertising identifiers, IP-derived approximate location, ad requests, ads shown, interactions, reward completion, diagnostic and fraud-prevention signals, and your applicable advertising-consent choices. The app can display interstitial ads when you open eligible collections and optional rewarded ads that you choose to view for an in-app benefit.
- Notification data: when notifications are enabled, Firebase Cloud Messaging processes a Firebase installation identifier and push token. The app also manages topic subscriptions based on your selected store language, notification preferences, and rounded UTC offset so it can deliver announcements and deal updates. We do not use precise device location for notification topics.
- Diagnostics: Firebase Crashlytics may receive crash and non-fatal error reports, crash traces, installation identifiers, timestamps, app version and state, device model, Android version, memory and storage information, and related technical data. A signed-in Firebase user ID may be attached to diagnostics.
- Shared-link and website data: shared links can contain an app route, game or collection identifiers, collection name, preview title, description and image, a generated link code, and creation time. Firebase Hosting and Cloud Functions also receive ordinary web request data such as IP address, user agent, requested URL, request time, and abuse-prevention signals.
- Information stored on your device: app settings, selected store region, cached account ID and email, favorites and library state, search history, notification preferences, ad-related state, and the date of birth entered for local content-rating decisions. The date of birth is stored locally and is used to decide whether age-restricted media can be shown.
- Catalog request data: when the app requests public game and store information from Microsoft Store or Xbox services, those services receive ordinary network request information such as IP address, request headers, requested products, and request time under their own terms and privacy practices.
How We Use Information
- To create and authenticate accounts.
- To sync favorites, collections, library entries, and account limits.
- To provide game catalog, price, collection, and shared-link features.
- To deliver notifications according to your language and preference choices.
- To deliver, measure, and control advertising, including optional rewarded ads.
- To diagnose crashes, improve reliability, and protect the service from abuse.
- To respond to support, privacy, and legal requests.
Service Providers and Sharing
We disclose information as needed to operate the service:
- Google and Firebase: Firebase Authentication, Realtime Database, Cloud Functions, Crashlytics, Cloud Messaging, and Hosting; Google Sign-In, Google Mobile Ads (AdMob), and Google Play distribution services.
- Microsoft: Microsoft Store and Xbox services used to retrieve public catalog, product, availability, and pricing information.
- Legal and safety reasons: when reasonably necessary to comply with law, respond to lawful requests, protect users or the public, investigate abuse, or enforce our rights.
- Business changes: as part of a merger, acquisition, financing, reorganization, or transfer of the service, subject to appropriate safeguards.
We do not sell personal information for money. Advertising providers may process identifiers and activity information for ad delivery, measurement, personalization where permitted, and fraud prevention. Some privacy laws may describe certain advertising-related disclosures as “sharing”.
Learn more in Firebase Privacy and Security, Google’s Privacy Policy, and How Google uses data from partners’ apps.
Data Retention
- Synced account data is generally retained while the account exists. When an account is deleted, an automated cleanup removes its primary cloud record and identified tester records. Provider logs, backups, security records, and information required by law may remain for their applicable retention periods.
- Firebase Authentication retains logged IP addresses for a few weeks. After account deletion is initiated, Firebase states that other authentication information is removed from live and backup systems within 180 days.
- Firebase Crashlytics retains crash traces and associated installation identifiers for 90 days before beginning removal from live and backup systems.
- Firebase Hosting retains IP data for a few months. Firebase Cloud Messaging retains a Firebase installation identifier until deletion is requested through its API, then removes it from live and backup systems within 180 days.
- Shared-link records are retained until we remove them. Information stored locally on your device remains until it is overwritten, app data is cleared, or the app is uninstalled.
Account Deletion
You can permanently delete a registered account inside the app or through our account-deletion page using email/password or Google authentication. Deletion removes the Firebase Authentication account and triggers removal of the primary cloud account record containing synced favorites, collections, library data, limits, and identified tester records.
Account deletion does not automatically clear information stored on an Android device. Clear the app’s data or uninstall the app to remove local information. Provider logs, backups, Crashlytics records, and installation identifiers may remain for the retention periods described above. If you cannot sign in, email xb.store.dna@gmail.com from the account address.
Your Choices and Rights
- You can change store region, notification, and other app preferences in the app.
- You can change Android notification permission in system settings.
- You can review applicable advertising privacy choices through the in-app consent flow and device settings.
- You can reset the password for an email/password account from the app sign-in flow.
- You can delete a registered account in the app or on the account-deletion page.
- Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning personal information. Contact us to exercise an applicable right.
Security and International Processing
We use reasonable technical and organizational measures intended to protect information, including HTTPS in transit and Firebase access controls. No system is completely secure. Google, Firebase, Microsoft, and their service providers may process information in countries other than your own, subject to their terms and applicable safeguards.
Changes to This Policy
We may update this policy when the app, providers, or legal requirements change. The effective date at the top identifies the current version. Material changes may also be communicated in the app where appropriate.
Contact
Developer: Store DNA Apps
Email:
xb.store.dna@gmail.com