BATTLE FREE
PrivacyTermsMonetisationCommunityCookies
Data transparency

Privacy Policy

This Privacy Policy explains how Battle Free collects, uses, and protects your information across our mobile app and website.

🔒 BATTLE FREE PRIVACY POLICY (Final & Complete — Mobile App & Website) Effective Date: 18/07/2026 App Name: Battle Free This Privacy Policy must be read together with the Battle Free Terms & Conditions and Cookies Policy. 1. Introduction Battle Free (“we”, “us”, “our”, “the Company”, “the Platform”) values the privacy of every individual who uses our mobile application and website (together, “the Services”). This Privacy Policy explains, in full detail, what personal and technical information we collect, why we collect it, how we use it, who we may share it with, how long we keep it, and what rights and choices you have regarding your information. This Privacy Policy applies to all Users of Battle Free, including Players participating in esports tournaments (such as Free Fire and BGMI), Creators uploading Reels and Stories, participants in our student part-time Job Program, buyers and sellers using our in-App Shop, and any visitor to our website, www.battlefree.in. By downloading, installing, registering on, or otherwise using the Services, you consent to the collection, use, storage, and disclosure of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, you should not use the Services. 2. Information We Collect We collect several categories of information in order to operate, secure, and improve the Services. This includes information you provide to us directly, information generated through your use of the Services, and information collected automatically through technical means. 2.1 Information You Provide Directly • Full name. • Email address and mobile/phone number. • Date of birth / age confirmation. • Game ID / Player ID for supported titles such as Free Fire and BGMI. • Profile details such as username, profile picture, bio, and follower/following information. • Payment and withdrawal details, including UPI ID, bank account number, IFSC code, or other payment-instrument information. • KYC documents, including government-issued identification, submitted for age/identity verification, withdrawal eligibility, or Job Program participation. • Content you upload, including Reels, Stories, images, videos, audio, captions, and comments. • Screenshots and match-proof uploads submitted for tournament verification or dispute resolution. • Messages and communications sent through in-App chat, voice, or video calling features. • Job Program applications, task submissions, qualifications, and related information. • Shop-related information, including shipping address, order history, and product preferences. • Any information you submit through customer-support tickets, feedback forms, or surveys. 2.2 Information Collected Automatically • Device information, including device model, manufacturer, operating system and version, unique device identifiers, and hardware specifications. • IP address and approximate location derived from it. • Usage logs, including in-App navigation, feature usage, session duration, and click/tap events. • Match results, gameplay statistics, and tournament participation history. • Reels and Stories metadata, including upload timestamp, file format, duration, resolution, device used for recording/upload, hashtags, captions, and engagement metrics (views, likes, comments, shares). • Analytics data collected through in-App analytics tools to understand feature usage and improve the Services. • Crash reports and diagnostic logs generated automatically when the App encounters a technical error, to help us identify and fix bugs. • Advertising Identifier (such as Google Advertising ID / Apple IDFA), used for ad personalization, ad-performance measurement, and fraud prevention, where applicable. • Push-notification tokens, used to deliver notifications about tournaments, messages, monetization updates, and other App activity. 3. Purpose of Data Collection We use the information described in Section 2 for the following purposes: • Operating and running esports tournaments, including registration, match scheduling, result verification, and prize distribution. • Processing payments, Wallet top-ups, withdrawals, subscriptions, Shop orders, and Job Program payouts. • Detecting, investigating, and preventing fraud, cheating, multi-accounting, ad-fraud, and other abuse of the Services. • Improving, maintaining, and developing new features for the Services, based on usage patterns and feedback. • Providing customer support and responding to inquiries, complaints, and appeals. • Verifying the identity, age, and country of residence of Users, particularly for monetization, withdrawals, and the Job Program. • Enabling and moderating social features, including chat, calling, follow/following, Reels, Stories, and content monetization. • Sending important notifications, including tournament updates, security alerts, payment confirmations, and policy changes. • Personalizing content, recommendations, and advertisements shown to you within the App. • Complying with applicable law, regulatory requirements, and lawful requests from government or law-enforcement authorities. 4. Data Storage & Retention • Your information is stored on secure servers, which may be operated directly by Battle Free or by trusted third-party cloud hosting providers, and may be located in India or in other countries where our hosting infrastructure operates. • We retain personal information for as long as necessary to fulfil the purposes described in this Policy, including the duration of your active account, plus any additional period required for legitimate operational, fraud-prevention, tax, accounting, or legal purposes. • Specific retention periods vary by data category: transactional/payment records are typically retained for a minimum period required under applicable financial and tax law (commonly several years); KYC documents are retained for the period required under applicable identity-verification regulations; chat logs and moderation-related data (see Section 8) may be retained for a defined period sufficient to investigate disputes and fraud; Reels, Stories, and related metadata are retained for as long as the content remains active on the Platform, plus a reasonable backup/retention period thereafter. • Even after you delete your account (see Section 15 — Account Deletion Process), certain logs, transaction records, and fraud-prevention data may be retained for a further period as necessary to comply with legal obligations, resolve disputes, enforce our agreements, and prevent fraud or abuse across the Platform, even where the underlying account is no longer active. • Once the applicable retention period expires and retention is no longer required for any legitimate purpose, we will delete, anonymize, or securely destroy the relevant information. 5. Data Sharing & Disclosure We do NOT sell your personal data to any third party. We do not rent, trade, or otherwise provide your personal data to third parties for their own independent marketing purposes without your consent. We may, however, share your information in the following limited circumstances, strictly as necessary to operate the Services: • Payment Partners — payment gateways, UPI providers, and banking partners, to process Wallet top-ups, withdrawals, subscription payments, and Shop transactions. • Government & Regulatory Authorities — where legally required by a valid court order, government directive, or applicable law, including tax authorities and law-enforcement agencies. • Fraud Prevention Agencies & Partners — to detect and prevent fraud, cheating, chargebacks, and other abuse across the Platform. • Technical Service Providers — cloud hosting, content-delivery, analytics, crash-reporting, customer-support, and communication (SMS/email/push-notification) providers who process data strictly on our behalf and under confidentiality obligations. • Game Publishers — only where necessary to verify tournament results or investigate suspected cheating, and only to the minimum extent required. • Advertising & Analytics Partners — limited technical and usage data (such as Advertising ID and aggregated analytics) shared for ad-serving, ad-measurement, and Platform-improvement purposes, as described in Sections 2, 9, and 10. • Business Transfers — in connection with a merger, acquisition, restructuring, or sale of all or part of Battle Free's business or assets, in which case your information may be transferred as part of that transaction, subject to confidentiality protections. • With Your Consent — in any other circumstance where you have given explicit consent for us to share your information with a specific third party. 6. Data Security • We implement industry-standard technical and organizational security measures, including encryption (in transit and, where appropriate, at rest), access controls, firewalls, and regular security reviews, to protect your information from unauthorized access, alteration, disclosure, or destruction. • Payment and KYC information is handled through secure, access-restricted systems and, where applicable, through PCI-DSS-compliant payment partners. • Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security of your information. • You are responsible for maintaining the confidentiality of your account credentials, password, and OTPs, and for taking reasonable steps to secure your own device, including using a secure lock screen, updated operating system, and trusted networks when accessing the Services. • If you become aware of any unauthorized access to your account or any security vulnerability affecting the Services, please notify us immediately using the contact details in Section 52. 7. Your Rights Regarding Your Data Subject to applicable law and the retention/legal exceptions described in this Policy, you may exercise the following rights regarding your personal information: • Right to Access — request a copy of the personal information we hold about you. • Right to Correction — request correction of inaccurate, incomplete, or outdated information in your account. • Right to Deletion — request deletion of your account and associated personal information, subject to the legal and operational retention requirements described in Section 4 and the Account Deletion Process in Section 15. • Right to Withdraw Consent — where processing is based on your consent (such as certain Cookies, permissions, or marketing communications), you may withdraw such consent at any time, without affecting the lawfulness of processing carried out before withdrawal. • Right to Restrict or Object — request that we restrict or stop certain types of processing, such as marketing communications, subject to our legitimate interests and legal obligations. • Right to Data Portability — request your data in a structured, commonly used, machine-readable format, where technically feasible and legally applicable. • Right to Lodge a Complaint — you may lodge a complaint with your local data-protection authority if you believe your rights have been violated. To exercise any of these rights, please contact us using the details in Section 52. We may need to verify your identity before processing certain requests, and we will respond within a reasonable timeframe as required by applicable law. 8. Chat, Calling & Communication Data Handling • As disclosed in the main Terms & Conditions, private chat and voice/video calls on Battle Free are NOT end-to-end encrypted. This means that, unlike some messaging services, Battle Free retains the technical ability to access chat content and call metadata under the circumstances described below. • Chat messages, images, and files shared through in-App messaging are stored on our servers to enable message delivery, message history/sync across devices, and moderation. • Call metadata (such as the time, duration, and participants of a voice/video call) is logged for security, billing (where applicable), and dispute-resolution purposes. Call content itself is not routinely recorded, unless required for a specific fraud/safety investigation or unless a User reports a call for review. • We may review chat and call-related data where necessary to investigate reports of fraud, harassment, abuse, threats, scam activity, or violations of the Community Guidelines, or where required by a valid legal request. • Chat and call logs are retained for a defined period sufficient to support fraud-prevention and dispute-resolution purposes, as described in Section 4, after which they are deleted or anonymized unless retention is separately required for an ongoing investigation or legal obligation. • Automated systems, including keyword/pattern-detection and AI-based moderation tools, may scan chat content to detect spam, scam links, hate speech, and other Community Guidelines violations, consistent with the AI Moderation provisions of the main Terms & Conditions. • Users should not share sensitive personal information (such as full payment-card numbers, passwords, or government ID numbers) through in-App chat, given that chats are not end-to-end encrypted. 9. Reels, Stories & Content Metadata • When you upload a Reel or Story, we collect not only the content itself (video, image, audio, caption) but also associated metadata, including the upload date and time, file size and format, video duration and resolution, the device and app-version used to create/upload the content, geotag information (if you choose to enable location tagging), hashtags, mentions, and audio-track information used in the content. • We also collect and analyze engagement metadata associated with your Reels and Stories, including view counts, watch-time, likes, comments, shares, saves, and follower-growth attributable to specific content, which is used for the ranking, recommendation, monetization-eligibility, and analytics purposes described in the Terms & Conditions and Monetization Policy. • Content metadata may also be used by our copyright-detection and content-moderation systems (described in Sections 10 of the Monetization Policy and Terms & Conditions) to identify duplicate, reposted, or infringing content. • Stories are automatically stored for the display duration configured within the App (for example, 24 hours) and may thereafter be archived, deleted, or retained in accordance with your own Story-archive settings and our general retention practices described in Section 4. 10. Analytics, Crash Reporting & Diagnostic Data • We use in-App analytics tools, which may include services such as Firebase Analytics, to understand how Users interact with the App — including which features are used most, session length, screen views, and in-App navigation flow — in order to improve the design, performance, and usability of the Services. • We use crash-reporting and diagnostic tools, which may include services such as Firebase Crashlytics, to automatically detect and report technical crashes, errors, and performance issues encountered while using the App. Crash reports may include device model, operating-system version, app version, and the technical state of the App at the time of the crash, and help us identify and fix bugs quickly. • Analytics and crash-reporting data is generally used in aggregated or pseudonymized form for product-improvement purposes and is shared with our analytics/crash-reporting service providers strictly for that purpose, under their own respective data-processing terms. • You may, where supported by your device's operating system, be able to limit certain analytics or diagnostic data collection through your device settings, though this may affect our ability to diagnose issues affecting your specific device. 11. Device Permissions We May Request Depending on the features you choose to use, the Battle Free App may request the following device permissions. You may grant or deny these permissions through your device's operating-system settings, and you may change your choice at any time, though doing so may limit or disable certain features. 11.1 Camera & Microphone Permission Requested to allow you to record and upload Reels and Stories, participate in in-App voice/video calls, and submit photo/video match-proof for tournament verification. If denied, you will not be able to use these specific features, but can continue using other parts of the App. 11.2 Storage Permission Requested to allow you to select and upload existing photos, videos, or documents from your device (such as pre-recorded gameplay clips, screenshots for match proof, or KYC documents), and to allow the App to save downloaded or cached content to your device. 11.3 Location Permission Where the App requests location permission, it is used to help verify your country/region of residence for eligibility, monetization, and regional-content purposes, to support fraud-prevention systems, and, if you choose to enable it, to add a location tag to your Reels/Stories. Location permission is optional in most cases and can be denied without preventing use of core Platform features, other than location-tagging. 11.4 Notification Permission Requested to send you push notifications regarding tournament updates, chat messages, monetization and payout updates, security alerts, and promotional communications. You may disable notifications at any time through your device settings or in-App notification preferences. 11.5 Contacts Permission (if applicable) Where offered, this permission may be requested to help you find friends already using Battle Free or to support the Referral Program; this permission is optional, and denying it will not prevent you from manually entering a referral code or searching for other Users by username. 12. Advertising Identifier & Ad Personalization • We and our advertising partners may collect and use your device's Advertising Identifier (such as the Google Advertising ID on Android or the Identifier for Advertisers/IDFA on iOS) to serve relevant advertisements within the App, measure advertising performance, and prevent ad-fraud. • Advertising Identifiers are device-level, resettable identifiers that do not, by themselves, directly reveal your name or contact details, but may be combined with other usage data to build an interest profile for ad-targeting purposes. • You can typically reset or limit ad tracking associated with your Advertising Identifier through your device's operating-system privacy settings (for example, “Opt out of Ads Personalization” on Android, or “Limit Ad Tracking” / App Tracking Transparency settings on iOS). • As described in the Terms & Conditions, whether you see standard or reduced/ad-free advertising also depends on your subscription plan, independent of your Advertising Identifier settings. 13. Firebase & Other Third-Party SDKs • The App may integrate third-party Software Development Kits (SDKs), including but not limited to Google Firebase (for Analytics, Crashlytics, Cloud Messaging/push notifications, and authentication support), payment-gateway SDKs, and advertising-network SDKs. • Each such SDK operates under its own respective provider's privacy policy and terms, and may independently collect certain technical data (such as device identifiers, IP address, and usage events) strictly to provide its designated function within the App. • We select and configure these third-party SDKs to align with our own data-protection commitments, and we do not permit these providers to use data collected through our App for their own independent advertising purposes beyond what is necessary to provide their service to us, except where you have separately consented to such use (for example, through an ad-network SDK's own consent flow). 14. Payment Partners & Financial Data • Wallet top-ups, withdrawals, subscription payments, and Shop purchases are processed through third-party payment gateways, UPI service providers, and banking partners (“Payment Partners”). • We share only the information necessary with our Payment Partners to process a given transaction, such as your name, contact details, and payment-instrument information (UPI ID/bank details), and we do not store full card numbers or banking credentials beyond what is necessary and permitted under applicable payment-security standards. • Our Payment Partners maintain their own privacy and security policies, and process payment data in accordance with applicable financial-regulatory and data-security standards (such as PCI-DSS, where applicable to card transactions). • We are not responsible for the independent privacy or security practices of our Payment Partners beyond our own due diligence and contractual requirements imposed on them, as further described in Section 17 (Third-Party Services). 15. Account Deletion Process • You may request deletion of your Battle Free account at any time by using the “Delete Account” option within the App's settings (where available) or by submitting a deletion request to our support team using the contact details in Section 52. • Upon receiving a valid deletion request, we will verify your identity (to prevent malicious or unauthorized deletion requests) and process the deletion of your account and associated personal information within a reasonable period, generally not exceeding the timeframe specified in-App or required under applicable law. • Certain information may be retained even after account deletion, including: transaction and payment records required for tax/accounting/legal compliance; records necessary for resolving any ongoing dispute, complaint, or investigation; fraud-prevention data (such as device identifiers or flags associated with confirmed fraud/cheating) retained to prevent the same individual from creating new accounts to evade a ban; and any information we are legally required to retain under applicable law. • Once the applicable legal/operational retention period for any residual data expires, such data will be deleted or irreversibly anonymized. • If your account is suspended or terminated by Battle Free due to a policy violation (rather than voluntarily deleted by you), certain data may be retained for a longer period as necessary to enforce the ban, investigate related accounts, and support any legal proceeding, consistent with Section 4. • Deleting your account does not automatically entitle you to a refund of any non-refundable Wallet balance, subscription fees, or other amounts, as described in the main Terms & Conditions. 16. Children's Privacy Policy Battle Free is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children under this age. If we discover that an account has been created by, or contains information belonging to, a person under 16 years of age, such account will be terminated immediately, and the associated personal information will be deleted, subject to any legal retention requirement. If you believe a child under 16 has provided us with personal information, please contact us immediately using the details in Section 52 so that we can take appropriate action. 17. Cookies & Tracking Technologies Our website, www.battlefree.in, uses cookies and similar tracking technologies to improve website performance, remember preferences, and measure marketing effectiveness, as described in detail in our separate Cookies Policy. Within the App itself, we use analogous technologies — including local storage, device identifiers, and SDK-based tracking as described in Sections 10 through 13 of this Privacy Policy — to achieve similar purposes of improving user experience, security, and platform performance. Please refer to our Cookies Policy for full details relevant to the website. 18. Legal Requests & Law Enforcement Cooperation We may access, preserve, and disclose your personal information, including chat and call metadata, transaction records, and content-related data, where we have a good-faith belief that such action is necessary to: • Comply with a valid legal process, such as a court order, subpoena, or search warrant. • Respond to a lawful request from a law-enforcement or government authority. • Enforce our Terms & Conditions, including investigating potential violations. • Detect, prevent, or address fraud, security, or technical issues. • Protect the rights, property, or safety of Battle Free, our Users, or the public, as required or permitted by law. 19. Ownership of Uploaded Content & Use of Verification Data • By uploading screenshots, videos, or other proof of match results, you grant Battle Free the right to store, verify, and use such content for the purpose of tournament dispute resolution, fraud investigation, and platform integrity. • By uploading Reels, Stories, or other public content, you grant Battle Free a non-exclusive, worldwide, royalty-free licence to host, display, distribute, and use such content within the Platform, and, where reasonably related to promoting the Platform, in Battle Free's own marketing and platform-review materials, consistent with the Promotional Rights provisions of the main Terms & Conditions. • This licence does not transfer ownership of your content; you retain ownership of your original content, subject to the rights granted to Battle Free described above and in the Terms & Conditions. 20. Third-Party Services The Services may contain links to, integrations with, or reliance upon third-party services, including but not limited to: • Payment gateways and banking partners. • Game publishers (such as the publishers of Free Fire and BGMI), for the limited purpose of match verification. • Cloud hosting and content-delivery network providers. • Analytics and crash-reporting platforms (such as Firebase). • Advertising networks and ad-serving platforms. We are not responsible for the independent privacy practices, policies, security standards, or service failures of these third parties, each of which operates under its own separate privacy policy and terms of service. We encourage you to review the privacy policies of any third-party service you interact with in connection with the Services. 21. International Data Transfers Your information may be processed and stored on servers located outside your country of residence, including where our cloud hosting, analytics, or payment-processing partners operate internationally. Where such cross-border transfers occur, we require our service providers to implement appropriate contractual and technical safeguards consistent with applicable data-protection law to protect your information during and after transfer. 22. Marketing Communications & Promotional Messages • We may send you promotional messages, tournament announcements, offers, and other marketing communications via email, SMS, WhatsApp, or push notification, based on your account preferences and applicable consent requirements. • You may opt out of non-essential marketing communications at any time by following the unsubscribe instructions included in such communications, adjusting your in-App notification settings, or contacting our support team. Please note that you cannot opt out of essential service-related communications, such as security alerts, payment confirmations, and policy-update notices, which are necessary for the operation of your account. 23. Grievance Officer / Data Protection Contact In accordance with applicable data-protection and information-technology law, Battle Free may designate a Grievance Officer or Data Protection Contact responsible for addressing privacy-related complaints and requests. Details of the designated Grievance Officer, where applicable, will be published within the App and/or on our website, and Users may also route any privacy-related grievance through the general contact details provided in Section 52. 24. Changes to This Privacy Policy We may revise, update, or amend this Privacy Policy at any time, at our sole discretion, to reflect changes in our data practices, the introduction of new features, or changes in applicable law. Any material changes will be communicated by updating the “Effective Date” at the top of this document and, where required by law or where the change is significant, by additional notice within the App. Continued use of the Services after such changes constitutes your acceptance of the revised Privacy Policy. 26. Special Categories of Data & Sensitive Information • Government-Issued ID / KYC Data: We collect copies of government-issued identification documents (such as an Aadhaar card, PAN card, passport, or driving licence) strictly for age verification, identity verification, and compliance with withdrawal/payment regulations. This data is stored in encrypted form with restricted access limited to authorized compliance and support personnel. • Financial/Payment Data: Bank account numbers, UPI IDs, and related payment-instrument details are collected strictly for processing Wallet transactions and are handled in accordance with applicable payment-security standards, as further described in Section 14. • We do not intentionally collect biometric data (such as fingerprints or facial-recognition templates) unless a specific feature explicitly requiring such data is introduced in the future, in which case this Policy will be updated and separate, explicit consent will be obtained before such collection begins. • We do not knowingly collect information revealing racial or ethnic origin, religious beliefs, health information, sexual orientation, or political opinions, and we ask that Users refrain from voluntarily submitting such sensitive information through chat, Reels, Stories, or support tickets unless directly relevant to resolving a specific issue (for example, a request for reasonable accommodation). 27. Automated Decision-Making & Profiling • We use automated systems, including AI-based moderation and fraud-detection tools, to make certain decisions that may affect your account, such as flagging suspicious transactions, detecting cheating or ad-fraud, classifying content for monetization eligibility, and identifying potential copyright infringement, as described in the Terms & Conditions and Monetization Policy. • Where an automated decision results in a significant action against your account (such as suspension, demonetization, or a strike), you have the right to request human review of that decision through the appeal process described in the Terms & Conditions and Monetization Policy, and through the general contact channel in Section 52. • We also use algorithmic recommendation systems to personalize the Reels, content, and advertisements shown to you, based on your engagement history, interests, and similar Users' behaviour. You may, where such controls are available in-App, adjust certain personalization settings or reset your Advertising Identifier as described in Section 12. 28. Data Collected Through the Student Job Program • Users applying for or participating in the Job Program may be asked to submit additional information, such as educational qualifications, skills, work samples, task submissions, and performance history, to assess eligibility and evaluate completed tasks. • This information is used solely to administer the Job Program — including matching Users to suitable tasks, verifying task completion, and processing payouts — and is retained for as long as necessary to administer the program and resolve any related disputes, consistent with Section 4. • Job Program data is not shared with external employers or third parties beyond what is necessary to operate the program, except where a specific task explicitly requires limited data sharing with a task-requesting brand/partner, which will be disclosed to the User at the time of accepting that specific task. 29. Data Collected Through the In-App Shop • When you place an order through the Shop, we collect your shipping address, contact number, order history, and payment confirmation details necessary to fulfil and deliver your order. • Where products are fulfilled by third-party sellers/vendors on the Platform, limited order and shipping information (such as your name, address, and contact number) may be shared with the relevant seller or logistics/courier partner strictly to enable delivery of your order, consistent with Section 5 and the Shop Policy in the Terms & Conditions. • Purchase history and product-preference data may also be used, in aggregated or individual form, to personalize product recommendations shown to you within the Shop. 30. Referral Program & Subscription Data • Referral Program: We collect data necessary to track referral relationships (such as the referring User's code/link and the referred User's registration event) to verify genuine referrals, calculate referral rewards, and detect self-referral or fraudulent referral activity, as described in the Referral Policy of the Terms & Conditions. • Subscription Data: We collect subscription plan selection, billing cycle, renewal status, and payment-method information necessary to manage your subscription, process renewals, and apply the correct ad-experience or feature benefits associated with your plan. 31. Data Minimization & Purpose Limitation Principles We aim to collect only the information reasonably necessary to provide and improve the specific features you choose to use, and to use that information only for the purposes disclosed in this Policy or for other purposes compatible with those original purposes. Where a specific feature is optional (such as location tagging on a Reel, or contacts-based friend suggestions), we will only collect the associated data if you choose to enable that feature, as described in Section 11. 32. Data Breach & Security Incident Notification • In the event of a data breach or security incident that we determine poses a significant risk to your personal information, we will take prompt steps to investigate, contain, and remediate the incident. • Where required by applicable law, we will notify affected Users and/or the relevant data-protection or regulatory authority within the timeframe mandated by such law, providing information about the nature of the incident, the categories of data involved, and the steps being taken in response. • We encourage Users to promptly change their password and enable any available additional security measures if notified of a security incident potentially affecting their account. 33. Additional Disclosures for Specific Regions 33.1 India — Digital Personal Data Protection Act (DPDPA) Where the Digital Personal Data Protection Act, 2023 (or its successor rules) applies to your personal data, we act as a “Data Fiduciary” with respect to such data. You have the rights described in Section 7, and you may contact our designated Grievance Officer/Data Protection Contact (Section 23) to raise any concern. We will process your personal data based on your consent or another legitimate ground recognized under the Act. 33.2 European Union / United Kingdom — GDPR If you are located in the European Union or United Kingdom, you have rights under the General Data Protection Regulation (GDPR)/UK GDPR, including the rights described in Section 7, as well as the right to object to processing based on legitimate interests and the right to lodge a complaint with your local supervisory authority. Our legal basis for processing is generally consent, contractual necessity (to provide the Services you request), or legitimate interest (such as fraud prevention and service improvement), as applicable to each processing activity described in this Policy. 33.3 United States — State Privacy Laws (e.g., CCPA/CPRA) If you are a resident of a U.S. state with an applicable consumer-privacy law (such as California's CCPA/CPRA), you may have additional rights, including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale/sharing of personal information (noting that we do not sell personal information, as stated in Section 5), and the right to non-discrimination for exercising your privacy rights. You may exercise these rights using the contact details in Section 52. This Section provides a general summary only and does not constitute legal advice; applicable regional rights and their exact scope should be confirmed with a qualified lawyer for each jurisdiction in which Battle Free operates or has Users. 34. Summary — Data Categories, Purpose & Retention at a Glance The table below summarizes, in simplified form, the main categories of data described throughout this Policy. It is provided as a quick-reference summary only; the detailed provisions of Sections 2 through 15 govern in the event of any inconsistency. • Account & Identity Data (name, email, phone, DOB, KYC ID) — Purpose: registration, verification, compliance — Retention: duration of account plus legally required period thereafter. • Payment & Financial Data (UPI/bank details, transaction history) — Purpose: Wallet, withdrawals, Shop, subscriptions — Retention: as required under applicable financial/tax law. • Gameplay & Tournament Data (match results, screenshots, Game ID) — Purpose: tournament operation, dispute resolution, fraud prevention — Retention: duration necessary for verification and dispute windows. • Content & Metadata (Reels, Stories, captions, engagement metrics) — Purpose: hosting, monetization, recommendations, copyright enforcement — Retention: while content is active, plus backup/retention period. • Chat & Call Data (messages, call metadata) — Purpose: communication, moderation, fraud/safety investigation — Retention: defined period per Section 4/8, longer if under investigation. • Device & Technical Data (device ID, IP, Advertising ID, crash logs) — Purpose: security, analytics, ad-serving, bug-fixing — Retention: per analytics/crash-tool provider's standard retention, generally rolling periods. • Job Program & Shop Data (task submissions, orders, shipping address) — Purpose: program administration, order fulfilment — Retention: duration of program participation/order lifecycle, plus dispute-resolution period. 35. Frequently Asked Questions (FAQ) Q1. Does Battle Free sell my data to advertisers? No. As stated in Section 5, we do not sell your personal data. We may share limited technical data (such as an Advertising Identifier) with advertising partners strictly to serve and measure advertisements, but this is not a sale of your personal data. Q2. Can I use Battle Free without granting camera or location permission? Yes, for most core features. However, features that inherently require a specific permission — such as recording a Reel (camera/microphone) or location-tagging a post (location) — will not function if the corresponding permission is denied, as explained in Section 11. Q3. Are my chats private? Your chats are private in the sense that they are not visible to other Users, but they are not end-to-end encrypted, meaning Battle Free retains the technical ability to access chat data for the safety, moderation, and legal purposes described in Section 8. Q4. What happens to my data if I delete my account? Most of your personal information will be deleted or anonymized, but certain records may be retained for legal, tax, or fraud-prevention purposes as described in Section 15, even after your account is deleted. Q5. Does Battle Free use Firebase or similar third-party tools? Yes, we may use tools such as Firebase Analytics and Firebase Crashlytics (or similar services) to understand app usage and diagnose technical crashes, as described in Section 10. Q6. Who can I contact if I have a privacy complaint? You can contact our support team or designated Grievance Officer/Data Protection Contact using the details in Sections 23 and 25. 36. Glossary of Key Terms • “Personal Information/Data” — any information that identifies, relates to, or could reasonably be linked to an identifiable individual. • “KYC” — Know Your Customer; the identity-verification process required for withdrawals, monetization, and certain other features. • “Advertising Identifier” — a resettable, device-level identifier used for ad personalization and measurement, as described in Section 12. • “Metadata” — data that describes other data, such as the upload time, format, or device used to create a Reel, as described in Section 9. • “Data Fiduciary” — a term under India's DPDPA referring to the entity that determines the purpose and means of processing personal data (i.e., Battle Free, with respect to Users' data). • “Grievance Officer” — the designated contact responsible for addressing privacy-related complaints, as described in Section 23. • “Third-Party Service Provider” — an external company (such as a payment gateway, analytics provider, or cloud host) that processes data on Battle Free's behalf under contractual confidentiality obligations. 37. Internal Access Controls & Employee Confidentiality • Access to Users' personal information within Battle Free is restricted on a need-to-know basis. Only employees, contractors, and authorized personnel who require access to specific data to perform their job function (such as customer support, fraud investigation, KYC verification, or technical maintenance) are granted such access. • All personnel with access to personal information are bound by confidentiality obligations and are trained on data-protection practices relevant to their role. • Access to particularly sensitive data categories, such as KYC documents and payment information, is further restricted to a smaller subset of authorized compliance and finance personnel, with additional logging and monitoring of access to such data. • We conduct periodic internal reviews of access permissions to ensure that access remains limited to personnel who currently require it, and access is promptly revoked when an employee's role changes or their employment ends. 38. Vendor & Sub-Processor Due Diligence • Before engaging any third-party service provider that will process User data on our behalf (such as a cloud hosting provider, analytics tool, payment gateway, or SMS/communication provider), we conduct reasonable due diligence to assess that provider's security practices, data-handling standards, and compliance posture. • We enter into data-processing agreements or equivalent contractual commitments with such providers, requiring them to process User data strictly for the purposes we specify, to implement appropriate security measures, to notify us of any security incident affecting our Users' data, and to delete or return data upon termination of the engagement, where applicable. • We periodically review our list of third-party service providers and their data-handling practices as part of our ongoing data-governance efforts, and may add, remove, or replace providers over time as our operational needs evolve; where such a change materially affects how your data is processed, we will update this Privacy Policy accordingly. 39. Illustrative Scenarios — How This Policy Applies in Practice The following hypothetical scenarios are provided to help Users understand, in practical terms, how the provisions of this Policy typically apply. These examples are illustrative only. Scenario 1 — Tournament Dispute A User disputes a match result and submits a screenshot as proof. Battle Free stores this screenshot, reviews it against opponent/match data, and retains it for the duration of the dispute-resolution window described in Section 4, after which it may be deleted or archived along with other closed-dispute records. Scenario 2 — Suspicious Withdrawal Request A User requests a withdrawal to a bank account that does not match their KYC details. Battle Free's fraud-detection systems flag the mismatch, the withdrawal is placed on hold, and the User's account and transaction history are reviewed by authorized compliance personnel, consistent with Sections 6, 14, and 26, before the withdrawal is approved, rejected, or escalated. Scenario 3 — Reported Chat Message A User reports another User for sending an abusive message in chat. Because chats are not end-to-end encrypted (Section 8), Battle Free's moderation team can access the reported conversation to investigate the complaint, take appropriate action against the offending account, and retain relevant logs for the fraud/dispute retention period described in Section 4. Scenario 4 — Account Deletion Request A User submits an account-deletion request through the App. Battle Free verifies the request, deletes the User's profile, Reels, Stories, and chat history within the timeframe described in Section 15, while retaining anonymized transaction records for the statutory period required under tax law, consistent with Section 4. Scenario 5 — Reel Going Viral & Monetization Review A User's Reel goes viral and generates significant ad impressions. Engagement metadata described in Section 9 is used to calculate the User's monetization earnings under the Monetization Policy, while automated copyright-detection systems (Section 9 and Section 10 of the Monetization Policy) simultaneously check the Reel's audio track for potential rights-holder claims. 40. Tips for Protecting Your Own Privacy & Account • Use a strong, unique password for your Battle Free account and avoid reusing passwords from other services. • Never share your OTP, password, or KYC documents with anyone claiming to be a Battle Free representative through chat, call, email, or any other channel; official communications will never ask for your password or OTP. • Avoid sharing sensitive personal information (such as full card numbers or ID numbers) through in-App chat, given that chats are not end-to-end encrypted, as explained in Section 8. • Review and adjust your device's app-permission settings (camera, microphone, location, storage, notifications) periodically to ensure they reflect your current preferences, as described in Section 11. • Enable your device's built-in security features, such as a secure lock screen and automatic software updates, to reduce the risk of unauthorized access to your device and, in turn, your Battle Free account. • Log out of shared or public devices after using the App, and avoid saving your password on devices that other people can access. • Regularly review your account activity and notify us immediately of any activity you do not recognize, using the contact details in Section 41. 41. Version History Battle Free will maintain a record of material changes made to this Privacy Policy over time. The current version supersedes all prior versions as of the Effective Date shown at the top of this document. • Version 1.0 — Initial publication of the Battle Free Privacy Policy, covering data collection across tournaments, Reels/Stories, chat/calling, the Job Program, the Shop, monetization, and related device permissions and third-party integrations. 42. Push Notification Categories Where you have granted notification permission (Section 11.4), Battle Free may send you the following categories of push notifications. Some categories are essential to your account and cannot be disabled; others are optional and can be managed through your in-App notification preferences or device settings. 42.1 Essential/Account Notifications (cannot be fully disabled) • Security alerts, such as a new device login or password change. • Payment confirmations, withdrawal status updates, and KYC verification status. • Critical policy-update notices affecting your account or data. 42.2 Optional/Preference-Based Notifications • Tournament reminders, match schedules, and result announcements. • New chat messages, call invitations, and follow/like/comment alerts. • Monetization and payout updates, including strike notices and appeal outcomes. • Promotional offers, new features, referral updates, and marketing announcements. • Job Program task alerts and Shop order/delivery updates. 43. Appendix: Consolidated Data Inventory For ease of reference, the following is a consolidated, plain-language inventory of substantially all categories of data that Battle Free may collect across the App and Website, cross-referencing the Section of this Policy where each category is discussed in detail. • Name, email, phone number, date of birth (Section 2.1) • Game ID / Player ID for Free Fire, BGMI, and other supported titles (Section 2.1) • Username, profile picture, bio, follower/following graph (Section 2.1) • UPI ID, bank account and IFSC details (Sections 2.1, 14) • KYC documents / government ID (Sections 2.1, 26) • Reels, Stories, images, videos, audio, captions, comments (Sections 2.1, 9) • Match-result screenshots and tournament proof (Sections 2.1, 19) • Chat messages and call metadata (Sections 2.1, 8) • Job Program applications, qualifications, and task submissions (Sections 2.1, 28) • Shop orders, shipping address, and purchase history (Sections 2.1, 29) • Customer-support tickets, feedback, and survey responses (Section 2.1) • Device model, OS version, unique device identifiers (Section 2.2) • IP address and approximate location (Section 2.2) • In-App usage logs and navigation/click events (Section 2.2) • Gameplay statistics and tournament participation history (Section 2.2) • Reels/Stories metadata — timestamps, resolution, hashtags, engagement metrics (Sections 2.2, 9) • Analytics data via tools such as Firebase Analytics (Sections 2.2, 10) • Crash reports and diagnostic logs via tools such as Firebase Crashlytics (Sections 2.2, 10) • Advertising Identifier (Google Advertising ID / IDFA) (Sections 2.2, 12) • Push-notification tokens (Sections 2.2, 42) • Camera, microphone, storage, location, notification, and (where applicable) contacts permissions data (Section 11) This Appendix is a summary aid only and does not itself expand or limit the substantive provisions found in the numbered Sections of this Policy referenced above. 44. Consent Management & Preference Center • Where technically feasible, Battle Free will provide an in-App privacy/preference center allowing you to view and manage certain consent-based settings, such as marketing-communication preferences, optional permissions (location, contacts), and ad-personalization settings, in one place. • Where such a centralized preference center is not yet available for a specific setting, you may manage the relevant preference through your device's operating-system settings (for permissions and Advertising Identifier controls, as described in Sections 11 and 12) or by contacting our support team directly using the details in Section 52. • We will honor consent withdrawals and preference changes within a reasonable operational timeframe, though some previously initiated processing (such as an advertisement already served) may not be capable of being reversed retroactively. 45. How Data Flows Between Different Features of the App Because Battle Free combines tournaments, social/content features, monetization, a Job Program, and a Shop within a single account, certain data may be used across features in a manner consistent with the purposes described in this Policy. For transparency, the following illustrates common cross-feature data flows: • Your verified country of residence (established for KYC/withdrawal purposes) is also used to determine your monetization eligibility and applicable tax treatment, as described in Sections 6 and 13 of the Monetization Policy. • Your tournament performance and Reels engagement may both contribute to your overall creator/player reputation score (where such a feature exists), which may influence your visibility in recommendations or eligibility for certain promotions. • A Community Guidelines strike issued in connection with chat/social behaviour may also affect your eligibility for the Job Program and Shop features, since all features are governed by the same underlying account standing. • Wallet balance and transaction history are shared across tournament winnings, monetization payouts, Job Program payments, referral rewards, and Shop purchases, since all of these features settle through the same central Wallet, as described in the Terms & Conditions. This cross-feature use of data is limited strictly to what is necessary to maintain a consistent, fraud-resistant, and functional single-account experience across Battle Free's various features, and does not involve sharing your data with external third parties beyond what is already described in Section 5. 46. Verifying Your Identity for Data Requests To protect your information from being accessed, corrected, or deleted by someone impersonating you, we will verify your identity before processing any access, correction, deletion, or portability request submitted under Section 7. Verification may include confirming details already on file (such as your registered mobile number or email), sending a one-time verification code to your registered contact details, or, for more sensitive requests, asking you to reconfirm KYC information already submitted. We will not process a data request from an unverified source, and we may decline a request that we reasonably believe to be fraudulent, abusive, or not genuinely made by the account holder. 47. Our Broader Commitment to Responsible Data Practices Beyond the specific rules described throughout this Policy, Battle Free is committed to a set of broader data-stewardship principles that guide how we design and operate our Services. We believe that trust is earned, not assumed, and that a platform built around real money, real gameplay, and real social connection carries a heightened responsibility to handle personal information carefully. The following principles apply across every feature of the Platform, including tournaments, Reels, chat and calling, the Job Program, and the Shop. 47.1 Privacy by Design When we build new features, we consider data-protection implications from the earliest design stage, rather than as an afterthought. This means evaluating, for each new feature, what data is genuinely necessary, how long it needs to be kept, who within the organization needs access to it, and what safeguards should be built in before the feature is released to Users. Where a new feature would involve materially different or more sensitive data collection than described in this Policy, we will update this Policy and, where legally required, seek renewed consent before rolling out that feature broadly. 47.2 Privacy by Default Where a setting has a meaningful privacy implication and is not essential to the basic operation of a feature, we aim to default to the more privacy-protective option, and allow you to opt in to broader data sharing or visibility if you choose. For example, optional permissions such as location-tagging or contacts-based friend suggestions are not automatically enabled; you must actively grant them, as described in Section 11. 47.3 Accountability & Internal Governance We maintain internal policies, training, and review processes designed to ensure that our employees, contractors, and business partners handle User data in accordance with this Policy and applicable law. Compliance with these internal policies is periodically reviewed, and material gaps identified through such reviews are addressed through corrective action, including retraining, process changes, or, where necessary, renegotiation or termination of a vendor relationship that fails to meet our data-protection expectations. 47.4 Proportionality in Enforcement Where we must access, review, or act on personal data for fraud-prevention, moderation, or legal-compliance purposes (as described in Sections 5, 8, and 18), we aim to do so in a manner proportionate to the specific concern being addressed — for example, reviewing only the specific conversation or transaction relevant to a reported issue, rather than broadly surveilling an account's entire history, except where a broader review is genuinely necessary to understand a pattern of suspected fraud or abuse. 47.5 Continuous Improvement Data-protection law, industry best practice, and the technology underlying our Services all continue to evolve. We periodically review this Policy and our underlying data practices to identify opportunities to reduce unnecessary data collection, strengthen security controls, and improve the clarity and usefulness of the privacy information we provide to Users, and we will update this Policy as described in Section 24 to reflect meaningful improvements. 48. Additional Frequently Asked Questions Q7. Does Battle Free track me across other apps and websites? We do not track your activity across unrelated third-party apps and websites beyond what is necessary for advertising measurement through your device's Advertising Identifier, as described in Section 12, which you can reset or limit through your device settings. We do not build a general cross-app browsing profile of you outside the advertising-measurement purposes disclosed in this Policy. Q8. What happens to my Reels metadata if I delete a specific Reel (but not my whole account)? When you delete an individual Reel, the content and its publicly visible metadata (captions, hashtags, engagement counts) are removed from public view and, following a reasonable technical processing period, deleted from our active systems, subject to any residual copy retained temporarily in backups or required for an active copyright/fraud investigation involving that specific Reel, consistent with Section 4. Q9. Will my KYC documents be reused if I reapply for the Job Program or a new monetization application? Yes, where your existing KYC verification remains valid and current, we may reuse previously submitted and verified KYC information to streamline a new application, rather than asking you to resubmit the same documents, unless your details have changed or the applicable verification has expired. Q10. Can I ask Battle Free what specific third-party companies my data has been shared with? You may submit a request under Section 7 (Right to Access) asking for a summary of the categories of third parties with whom your data has been shared under Section 5. We will provide this information to the extent reasonably available and consistent with our confidentiality obligations to our service providers, and subject to identity verification as described in Section 46. 49. Additional Glossary Terms • “Processing” — any operation performed on personal data, including collection, storage, use, disclosure, and deletion. • “Anonymization” — the process of removing or altering personal identifiers from data so that the individual can no longer be identified from it. • “Pseudonymization” — the process of replacing identifying information with an artificial identifier, such that the data can only be linked back to an individual with additional, separately held information. • “Data Controller / Data Fiduciary” — the entity that determines the purposes and means of processing personal data (Battle Free, with respect to User data on the Platform). • “Data Processor” — a third party that processes personal data on behalf of, and under the instructions of, the Data Controller/Fiduciary (for example, a cloud hosting or analytics provider). • “Consent” — a freely given, specific, informed, and unambiguous indication of your agreement to the processing of your personal data for a stated purpose. 50. Severability If any provision of this Privacy Policy is found to be invalid, illegal, or unenforceable under applicable law, the remaining provisions shall continue in full force and effect, and the affected provision shall be deemed modified to the minimum extent necessary to make it valid and enforceable while preserving its original intent as closely as possible. This Privacy Policy, together with the Terms & Conditions and Cookies Policy, constitutes the entire agreement between you and Battle Free regarding the collection and use of your personal information, and supersedes any prior privacy-related understanding, whether written or oral, on this subject. 51. Special Note on Real-Money Gaming Data Compliance Because Battle Free facilitates real-money tournament entry fees, winnings, and withdrawals, certain categories of data described in this Policy are collected and retained specifically to satisfy regulatory expectations that commonly apply to real-money gaming platforms, even where not separately called out elsewhere in this document. We describe these here for additional transparency. • Skill-Based Gaming Records: We maintain records demonstrating that tournaments hosted on Battle Free are based on skill (gameplay performance in titles such as Free Fire and BGMI) rather than chance, including match logs, leaderboard data, and scoring methodology, which may be retained for extended periods to support regulatory inquiries regarding the skill-based nature of our tournaments. • Responsible Gaming Indicators: Where we introduce responsible-gaming features (such as deposit limits, cool-off periods, or self-exclusion options), data related to your use of such features will be collected and retained to ensure these protections are correctly applied to your account. • Anti-Money-Laundering (AML) Monitoring: Wallet transactions may be monitored for patterns consistent with money laundering or other financial crime, consistent with applicable law, and suspicious-transaction data may be retained and reported to relevant financial-intelligence authorities where legally required, independent of your own account-deletion request. • State/Regional Restrictions: Because real-money gaming regulation differs by state and country, we may collect and verify your state/region of residence specifically to determine whether real-money tournament features can be legally offered to you in that state/region, and we may restrict access to such features where local law does not permit them, even if other App features remain available to you. This Section supplements, and does not replace, the general data-collection, retention, and sharing provisions described throughout the rest of this Policy, and is intended to give Users a clearer picture of why certain gaming-related records may be retained for longer than typical social or content-related data. 52. Contact Information If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, or if you wish to exercise any of the rights described in Section 7, please contact us at: • Email: support@battlefree.in • Website: www.battlefree.in