Draw Together processes personal data in accordance with Singapore's Personal Data Protection Act 2012 (PDPA) and other applicable data protection laws. This Policy distinguishes between the basic guest game and optional member or paid services.
1. Data Processed for the Basic Guest Game
Basic mini games can be used through an anonymous session without login. For this purpose, the Operator processes only the minimum data needed to provide the game:
- Anonymous activity identifier, participant role, and join or leave time
- Shared game state, drawings, choices, and other play data
- Short game text voluntarily entered in the prompt or topic field
- Minimum technical records needed for AI hints, security, and fault diagnosis
This data is used only to provide the game, synchronise activity participants, restore a connection, provide AI hints, and address security or technical issues.
2. Data Processed for Optional Member and Paid Services
Only when a user elects optional features, purchase restoration, or paid digital services may the Service connect a member account through an external login. In that case, the Operator may process the selected login method, the provider-specific identifier, a linked service user identifier, and the product, payment, delivery, or refund status needed to provide the service.
The Operator does not directly collect or store passwords, payment card numbers, or payment credentials. Payment credentials are handled by the payment service provider.
If a user consents to basic profile sharing by the external login provider, the Operator may process the provider's unique identifier, display name, email address and verification status, and profile-photo URL to confirm the same account and display it in the Service. This information is not combined with contacts or video-meeting participant data and is retained until account unlinking or deletion is requested, or it is no longer needed to provide the Service.
3. Data Not Required or Automatically Collected
The basic game does not require a name, email address, telephone number, physical address, date of birth, precise location, advertising identifier, or payment card information. The Service does not store call video, audio, captions, video-meeting participant email addresses, or contacts, and does not use them to identify an account. The prompt or topic field is only for short game text and must not contain personal data.
4. Third-Party Login and Payment Services
The basic guest game does not require a third-party login or payment. If a user chooses a member or paid service, information required for authentication or payment may be sent directly to and processed by the selected third-party login or payment provider. Users should review the provider's terms and privacy policy before logging in or paying.
The actual providers, processing countries, transfer timing and method, processing scope, and retention period will be confirmed and disclosed in this Policy and the relevant service screen before the feature is activated.
5. Overseas Transfers and Protection
Cloud, AI, login, or payment services used to operate the Service may process information outside Singapore. Where required by the PDPA or applicable law, the Operator will disclose the purpose, processing scope, and country, and will take appropriate safeguards and contractual measures to ensure a standard of protection comparable to that required under the PDPA.
6. Retention and Disposal
- Anonymous activity, drawing, and topic data: deleted within approximately 24 hours after an activity ends
- Optional member account-link data: until disconnection, deletion request, service termination, or when it is no longer needed for a business or legal purpose
- Paid-service transaction records: for the period required by Singapore law, mandatory consumer protection law applicable to the user, and the obligations of the payment channel
When retention is no longer necessary for a business or legal purpose, the Operator securely deletes or anonymises the data.
7. Your Rights
You may request access to, correction of, withdrawal of consent for, or deletion of personal data held or controlled by the Operator. Subject to the PDPA, you may request information about how your personal data was used or disclosed in the preceding year. Send requests to the contact above. The Operator may verify identity or authority and will respond in accordance with applicable law.
8. Security and Data Breach Response
The Operator applies reasonable safeguards, including access separation, transport protection, minimal retention, and separation of server secrets. If a data breach occurs, the Operator will assess it and, where notification is required by the PDPA or applicable law, notify the relevant authority and affected individuals as soon as practicable.
9. Data Controller and Data Protection Contact
Data Controller: Joo Hyung Park (Park Joo Hyung)
Data Protection Contact and Data Protection Officer: dusskapark@gmail.com
10. Changes to This Policy
Changes to this Policy, including their effective date and key changes, will be posted on this page. Material changes to processing purposes, third-party disclosure, or overseas transfer will be additionally communicated where required by applicable law.