MITZR by VORDALI

Privacy Policy

How VORDALI Inc. collects, uses, protects, and discloses information when you use the MITZR mobile application.

Effective September 23, 2026

Scope

VORDALI Inc. ("VORDALI," "we," "us," or "our") operates MITZR. This policy applies to the MITZR mobile application and the account, mapping, community, gameplay, and cloud services used by that application. It does not replace the separate privacy terms for other VORDALI products.

Account information

MITZR can be used in guest mode or with an account. If you create or sign in to an account, we process your email address, a Supabase user identifier, authentication credentials, and authentication session information. Authentication is provided through Supabase.

MITZR does not save your password in PlayerPrefs or in MITZR's first-party application tables. Access and refresh tokens are kept in memory for the active session and are not intentionally written to PlayerPrefs.

Location and mapping

MITZR requests precise device location and uses latitude, longitude, accuracy, timestamp, speed, and heading information in memory to place you on the map, show nearby community resources, orient the map, calculate distance, and verify that certain real-world interactions occur near a selected location.

When a signed-in user performs a proximity-gated action such as a discovery, gift deposit or claim, or community condition report, MITZR sends the current coordinates and accuracy to the backend for validation. The currently deployed core box-action backend validates those coordinates without storing them as a continuous GPS history.

If you voluntarily submit a new community location, the submission may include the location name, address or landmark, city, region, postal code, country, notes, exact coordinates, GPS accuracy and source, request identifier, and timestamp. That submission data is designed to be stored privately for moderation before any approved location is added to the public community directory.

MITZR uses Mapbox for mapping. Mapbox telemetry is enabled by default in the current integration and may transmit de-identified location, map usage, and SDK usage information to Mapbox. MITZR includes the Mapbox telemetry control so users can opt out of future Mapbox telemetry collection.

Community activity and user-provided content

Signed-in users may submit condition selections such as stocked, low, empty, or damaged, along with an optional short note. These reports are associated with the account in the private backend for integrity, rate limiting, and abuse prevention, and the resulting condition or note may update the public community location record.

MITZR also records signed-in visits, discoveries, request identifiers, gift deposits and claims, collectible ownership, journey events, and timestamps needed for cooldowns, retry protection, inventory, rewards, and shared collectible gameplay.

Gameplay progress and local data

For signed-in users, MITZR may store account-linked cloud data such as collection and inventory records, collectible ownership and transfers, journey events, visits, request identifiers, virtual coin balances, backpack capacity, reward ledger entries, owned cosmetics, vehicles and avatar items, and server-side entitlement state.

Some appearance and loadout choices are stored only on the device in Unity PlayerPrefs, including avatar presentation and customization choices and selected vehicle or modification choices. These local preferences can be keyed by the signed-in account identifier.

Guest-mode progress is not merged into a cloud account. Guest economy state can be stored locally on the device in PlayerPrefs, while some guest collectible inventory exists only for the current session.

Purchases and SDK data

MITZR uses Google Play Billing through Unity IAP for in-app purchases. MITZR may process product identifiers, purchase or transaction tokens, Unity receipts, store environment information, and purchase-verification results. Purchase verification may involve Supabase backend services and Google Play. MITZR does not receive your payment-card or bank-account numbers.

The Unity IAP SDK also declares collection of technical and transaction-related data needed to operate the store and its SDK, including player or installation identifiers, device information, session identifiers, country or approximate location, purchase history, crash logs, diagnostics, performance data, and other device identifiers. Unity's own processing and retention practices are governed by Unity's applicable privacy terms.

Technical and network information

MITZR and the services it relies on may process ordinary technical information needed to operate a connected mobile application, such as IP address, request timing, app or device platform information, network errors, diagnostics, and service logs. Map requests may also include map coordinates or tile identifiers and related Mapbox usage tokens needed to render and account for map service usage.

First-party Unity runtime logs may contain operational details such as SDK failures, box identifiers, collectible names or rarity, counts, GPS accuracy, and error messages. The current code review did not identify first-party logging of raw coordinates, email addresses, passwords, bearer tokens, or raw purchase receipts.

How we use information

We use information to authenticate accounts; provide maps and nearby resources; validate real-world proximity; review submitted community locations; save collections and account progress; operate community reports and shared-gift features; maintain the virtual economy; verify purchases; prevent duplicate, replayed, or fraudulent actions; troubleshoot and secure the service; respond to support and privacy requests; and comply with applicable law.

Service providers and disclosures

MITZR relies on service providers that process information for us, including Supabase for authentication and cloud application data, Mapbox for mapping and map telemetry, Unity IAP for in-app purchase functionality and SDK telemetry, and Google Play for billing and related Android platform services.

We may disclose information when required by law, to protect users or the service, or in connection with a business transaction. We do not sell MITZR users' personal information, and the current MITZR release does not include an advertising or rewarded-ad SDK.

Data retention

Account-linked gameplay, community, integrity, and purchase records may be retained while reasonably needed to provide MITZR, maintain accurate account and transaction state, prevent fraud or replay, protect the service, and meet legal obligations. MITZR does not currently publish a single fixed retention period for every backend record or for data retained independently by Supabase, Mapbox, Unity, or Google.

When a verified account deletion is completed, MITZR deletes the authentication account and account-linked application records covered by the deletion workflow. Limited transaction evidence may be de-identified rather than deleted when needed to prevent purchase replay, fraud, or abuse, and limited information may be retained where reasonably required for legal compliance, dispute resolution, security, or financial recordkeeping. Data may also remain temporarily in protected backups or provider logs until normal expiration.

Security

MITZR uses authenticated access for account features and HTTPS/TLS when communicating with configured cloud and platform services. Access to application data is restricted through backend authorization controls. Some local preferences are stored in PlayerPrefs and should not be treated as encrypted secure storage. No online service can guarantee absolute security.

Your choices

Android lets you control MITZR's location permission. If precise location is unavailable, features that depend on your current position or verified proximity may not work. You may choose guest mode instead of creating an account, although guest progress is not cloud-saved.

The current Mapbox integration includes a telemetry control that can stop future Mapbox telemetry collection. Clearing app data or uninstalling MITZR removes local PlayerPrefs and locally managed app cache, subject to normal Android behavior. These local actions do not by themselves delete cloud account records or data held by external providers.

Account and data deletion

MITZR provides an in-app path to delete a signed-in account and its associated account-linked data. You can also request deletion outside the app at our dedicated deletion page if you no longer have access to the app. For an external request, we may verify account ownership before processing it. Public community status information that no longer identifies the reporting account may be retained where needed to preserve the integrity of the community directory, and limited de-identified transaction, security, or legal records may be retained where permitted or required.

Request MITZR account deletion →

Data not used by the current release

The current MITZR code review found no runtime collection of photos, videos, microphone audio, user files or documents, and no notification-token implementation. It also found no advertising SDK, rewarded-ad implementation, or Android advertising-ID permission. Planned features such as teams or circles, SOS or emergency data, and cash donations or withdrawals are not implemented in the current release.

Children's privacy

We do not knowingly collect personal information from a child in a manner that violates applicable law. A parent or guardian who believes a child has provided personal information to MITZR may contact us so we can review and take appropriate action.

Changes to this policy

We may update this policy as MITZR features, service providers, or legal requirements change. We will post the revised policy at this URL and update the effective date. Material changes may also be communicated in the app or by another appropriate method.

Contact us

For MITZR privacy questions or requests, email support@vordali.com.