Privacy Policy
Last updated: April 23, 2026
Table of Contents
1. Introduction
WordlyPlay ("we", "our", or "us") is operated by Ecom Solutions. We operate the website wordlyplay.com (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website and use our word puzzle game platform.
By using WordlyPlay, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Username — your chosen unique identifier (publicly visible)
- Email address — used for account recovery and important notifications
- Password — securely hashed using industry-standard algorithms; never stored in plain text
- Display name — an optional name shown on your profile
- Avatar — a profile image URL if you upload or select one
2.2 Game Data
We collect gameplay data to provide our service, including:
- Game scores, win/loss records, and guess patterns
- Number of guesses used and time taken per game
- Daily challenge attempts and results
- Streak counts and best times
- Gem balances and powerup usage
- Leaderboard rankings (daily, weekly, monthly snapshots)
- Battle history (opponents, outcomes, durations)
2.3 Chat & Messaging Data
We store messages sent through our messaging features:
- Battle chat — Messages sent during multiplayer battles. These are associated with the battle session and include your username and timestamp.
- Support chat — Messages sent through our in-game support system. These are stored as support tickets and include your user ID, message content, and timestamps to help us assist you.
Chat messages may be reviewed by our team for safety moderation, support quality, and enforcement of our Terms of Service.
2.4 Automatically Collected Data
When you visit our website, we automatically collect:
- IP address — used for rate limiting, abuse prevention, and general security
- Browser type and version — collected via Google Analytics for service optimisation
- Device type and screen resolution — collected via Google Analytics
- Pages visited and time spent — collected via Google Analytics
- Referring website — how you found us
2.5 Guest User Data
If you play without creating an account, we assign a random guest token (stored as a cookie) to track your game session. No personally identifiable information is collected from guest users beyond their IP address for rate limiting.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the game service
- To track your game progress, statistics, and leaderboard rankings
- To enable multiplayer features including battles, chat, and player profiles
- To provide customer support through our support chat system
- To prevent abuse, cheating, and enforce our Terms of Service
- To analyse usage patterns and improve our game (via Google Analytics)
- To maintain the security and integrity of our platform
- To communicate important service updates (to your registered email)
4. Google Analytics
We use Google Analytics 4 (GA4) to understand how visitors interact with our website. GA4 collects data such as pages visited, session duration, device information, and general geographic location.
Google Analytics uses cookies (specifically _ga and _ga_*) to distinguish users and track sessions. This data is processed by Google LLC in accordance with their Privacy Policy.
Opt out: You can opt out of Google Analytics tracking by:
- Installing the Google Analytics Opt-out Browser Add-on
- Disabling cookies in your browser settings
6. Data Sharing & Disclosure
We do not sell your personal data to third parties.
We may share data in the following limited circumstances:
- Public profile information — Your username, display name, game statistics, and league rankings are visible to other players on profiles and leaderboards.
- Google Analytics — Anonymised usage data is shared with Google LLC for analytics purposes.
- Legal requirements — We may disclose information if required by law, court order, or governmental regulation.
- Safety — To protect the rights, safety, or property of our users or the public.
7. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account information | Until you request deletion |
| Game data & statistics | Retained for the lifetime of your account |
| Battle chat messages | 90 days after the battle ends |
| Support chat messages | 1 year after ticket is closed |
| Rate limit logs (IP addresses) | 30 days |
| Google Analytics data | 14 months (Google's default retention) |
When you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate security purposes.
8. Data Security
We implement industry-standard security measures to protect your data, including:
- HTTPS encryption for all data in transit
- Secure password hashing (bcrypt)
- CSRF (Cross-Site Request Forgery) token protection
- Server-side rate limiting to prevent brute-force attacks
- HTTP-only, secure session cookies
While we take reasonable precautions, no method of transmission over the Internet is 100% secure. We cannot guarantee the absolute security of your data.
9. Your Rights
9.1 All Users
Regardless of your location, you have the right to:
- Access your personal data
- Correct inaccurate data (e.g., update your email or display name)
- Delete your account and associated data
- Opt out of Google Analytics tracking
9.2 European Economic Area (EEA) & UK Residents — GDPR
If you reside in the EEA or UK, you also have the right to:
- Data portability — receive a copy of your data in a structured, machine-readable format
- Restrict processing — ask us to limit how we use your data
- Object to processing — object to data processing based on legitimate interests
- Withdraw consent — where processing is based on consent, you may withdraw it at any time
- Lodge a complaint — with your local data protection authority
Our legal basis for processing your data includes: performance of a contract (providing the game service), legitimate interests (analytics, security), and consent (where applicable).
9.3 California Residents — CCPA
California residents have the right to:
- Know what personal information we collect, use, and disclose
- Delete your personal information
- Opt out of the sale of personal information — we do not sell your data
- Non-discrimination — we will not discriminate against you for exercising your rights
Exercising Your Rights
To exercise any of these rights, contact us at support@wordlyplay.com. We will respond within 30 days.
10. Children's Privacy
WordlyPlay is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. Account registration requires users to be at least 13 years old.
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at support@wordlyplay.com and we will promptly delete that information.
Guests of any age may play without creating an account, in which case no personal information beyond a randomly-generated session token is collected.
11. International Users
WordlyPlay is operated from the United States. If you access the Service from outside the US, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
By using the Service, you consent to the transfer of your information to the United States. We take appropriate measures to ensure your data is protected in accordance with this Privacy Policy and applicable data protection laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@wordlyplay.com
Operator: Ecom Solutions