Skip to main content
360 Degrees Interactive

Privacy policy

Privacy policy

What our games collect, why, how long we keep it, and how to make us delete it. Written to the Privacy Act 1988 (Cth).

Effective 10 August 2026Version 1.0Privacy Act 1988 (Cth)

1Who we are and what this covers

This policy explains how 360 DEGREES INTERACTIVE PTY LTD (ACN 697 527 834, ABN 27 697 527 834) handles personal information. In this document "we", "us" and "our" mean that company, and "you" means a person whose personal information we handle.

We are an Australian proprietary company registered in New South Wales. We build mobile games for Android and iOS and publish this website at threesixtyinteractive.cc.

What this policy covers

  • This website.
  • Every mobile game published under this company name, on any store.
  • Correspondence you send us by email.

What it does not cover

  • The app stores themselves. Apple and Google collect their own information when you download or pay for something, under their own policies, and we have no access to and no control over that.
  • Advertising networks acting as independent controllers of the data they collect, which is dealt with in its own section below and where the network's own policy governs.
  • Any site you reach by following a link from ours.

The short version. Our games are playable with no account and no email address. What we collect is mostly a device identifier, a crash report and enough gameplay telemetry to tell whether a level is broken. We do not sell personal information. Personalised advertising is off unless you turn it on. You can ask us for what we hold, and to delete it, at hello@threesixtyinteractive.cc, and we answer within 30 days.

2The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. 360 DEGREES INTERACTIVE PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

3What we collect

The tables below are the authoritative list. If a category is not in a table, we do not collect it.

From the games

Personal information collected by our mobile games
CategoryExample fieldsWhyOptionalKept for
Device and appDevice model, operating system version, app version, screen size, language, country from store region, free storageRendering the game correctly and reproducing bugs on the device that hit themNo, collected on launch13 months
Advertising identifierGoogle Advertising ID on Android, Identifier for Advertisers on iOSFrequency capping, measuring whether an install came from an ad, and personalised advertising only if you enable itYes. Resettable and disableable in operating system settings13 months
Install attributionGoogle Play Install Referrer string, campaign identifier, install and first open timestampsKnowing which advertisement led to an install so we do not pay for the same install twiceSupplied by the store, not by us13 months
Gameplay telemetryLevel started, level completed, duration, score, failure point, settings toggledFinding the level where everyone stops playing, which is usually a bug rather than a difficulty spikeNo, but it is pseudonymous and not linked to a name25 months, then aggregated
Crash and diagnosticsStack trace, memory state at crash, thread state, breadcrumb log of the last actionsFixing crashesCan be turned off in the title's settings screen90 days
Purchase recordsStore transaction identifier, product identifier, amount, currency, date, refund statusRestoring purchases and meeting tax and accounting obligationsOnly if you buy something7 years
Optional accountEmail address or a store sign in token, display name you choose, progress dataCarrying progress between your devicesYes. Entirely optional and never required to playUntil deleted, then 30 days

We do not collect: your real name unless you type it into an email to us, your contact list, your photos, your precise location, your microphone or camera, your browsing history outside our apps, your health data, your financial account numbers, or any government related identifier.

From this website

Personal information collected by threesixtyinteractive.cc
CategoryExample fieldsWhyKept for
Request logsIP address, timestamp, path requested, user agent, response codeServing the page, and defending against denial of service and scraping. Held by our hosting provider, not by usProvider default, currently under 30 days
Security cookieA strictly necessary cookie our hosting provider may set to distinguish automated trafficBlocking abusive traffic. See the cookie noticeUp to 30 days

This website runs no analytics, no advertising, no tracking pixel and no session recording. There is no consent banner because there is nothing here that needs consent. The reasoning is in the cookie notice.

From correspondence

When you email us we hold your email address, whatever you chose to put in the message, and the message metadata your mail provider attached. We keep support threads for 24 months and complaint threads for 7 years, because a complaint may need to be evidenced later.

4Device and advertising identifiers

Almost everything we hold about a player is tied to a device identifier rather than to a person. It is worth being precise about what these are, because "we do not collect personal information, only device identifiers" is a claim other companies make and it is not true.

They are personal information

Under the Privacy Act, personal information is information about an identified individual, or an individual who is reasonably identifiable. An advertising identifier that persists across sessions and can be combined with other data to single you out is capable of making you reasonably identifiable. We treat these identifiers as personal information and give you the same rights over them as over your email address.

The identifiers we handle

Device identifiers and how to control them
IdentifierPlatformResettable by youHow
Google Advertising ID (GAID)AndroidYes, and it can be deleted entirelySettings, then Google, then Ads. Deleting it makes apps receive a string of zeros
Identifier for Advertisers (IDFA)iOSYes, and it is unavailable unless you allow trackingSettings, then Privacy and Security, then Tracking
Install identifierBothYes, by uninstalling and reinstallingGenerated by us at first launch, random, not derived from any hardware value
Support identifierBothYes, regenerate it in settingsShown in the title's settings screen so you can quote it in a privacy request

What we do not use

We do not collect hardware serial numbers, IMEI, MAC addresses, or the Android ID. We do not use device fingerprinting to reconstruct an identifier you have reset, which is a practice both stores prohibit and which would defeat the point of giving you the reset control.

5How we collect it, and notification at collection

Australian Privacy Principle 5 requires that we tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards.

We meet that obligation in three places, and deliberately not only here:

  • In the store listing. Apple's privacy nutrition labels and Google Play's Data Safety section state what a title collects before you install it. Those declarations are kept consistent with this policy, and if they ever diverge, treat the divergence as a bug and tell us.
  • At the point of collection in the app. A permission prompt explains what the permission is for before the operating system dialog appears, not after.
  • Here. This document is linked from every screen of the website and from the settings screen of each title.

APP 5 also requires us to tell you the consequences of not providing information. Those consequences are set out against each item in the collection tables, and for the app permissions in the permissions table.

6Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

In our case this is not a grudging concession. Our games are playable without an account, without an email address and without a name. If you never sign in, we never learn who you are, and the identifiers described later in this policy are device identifiers rather than identity documents.

Where you write to us, you may use a pseudonymous email address. The one place the option genuinely falls away is a request to access or correct personal information: to answer it we have to be satisfied you are the person the information is about, which is dealt with under access and correction below.

7Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

This happens most often when somebody sends us a bug report and includes a full screen recording, a diagnostic export, or a message thread containing other people's details. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.

8How we use it and who we disclose it to

Australian Privacy Principle 6 governs what we may do with personal information once we hold it. The rule is that information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where one of the specific exceptions in the Act applies.

What we use it for

  • Delivering the games and the features you have asked for.
  • Diagnosing crashes and defects, and measuring whether a fix worked.
  • Preventing fraud, cheating and abuse, including detecting automated play and duplicated installs.
  • Serving advertising, which is what makes a free title free, in the manner described in the advertising section.
  • Answering your correspondence and complying with a legal obligation.

What we do not do

  • We do not sell personal information. Not to data brokers, not to advertisers, not as part of an "audience" product.
  • We do not build a profile of you across the products of unrelated companies.
  • We do not use your correspondence with us to target advertising.

Disclosure to law enforcement and courts

We may disclose personal information where the Act permits it: where required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists (including a serious threat to life, health or safety, or suspected unlawful activity), or to an enforcement body where reasonably necessary for an enforcement related activity.

Where we make such a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you that a request was made, we will.

9Advertising in our games

Our games are free and carry advertising. This section says exactly what that means, because it is the part of a game studio's data practice that most affects you and the part usually described in one vague sentence.

Personalised advertising is off by default

On first launch, and on every launch until you change it, advertising requests are marked as non-personalised. A non-personalised advertisement is chosen from context, such as the fact that you are playing a puzzle game, rather than from a profile of you. You can turn personalisation on in the title's settings screen if you prefer more relevant advertising, and you can turn it off again at any time without losing any feature.

App Tracking Transparency on iOS

On iOS, access to the Identifier for Advertisers requires your permission through Apple's App Tracking Transparency prompt. We only present that prompt if you have first turned personalised advertising on in our own settings screen, so you are never asked cold. If you decline, or if you never turn personalisation on, the prompt does not appear and the identifier is not available to us or to the network.

Google Play Data Safety

Each title's Data Safety declaration on Google Play states what is collected and shared. We keep that declaration consistent with this policy. If you find a difference, that is a defect on our side and we want to hear about it at hello@threesixtyinteractive.cc.

The networks act as independent controllers

When an advertisement is requested, the network receives the request and decides what to serve. For its own purposes, such as fraud prevention and measurement across its whole inventory, the network acts on its own account rather than on our instructions. We cannot delete data an advertising network holds about you, and we will not pretend we can. What we can do is stop sending it, which is what turning personalisation off does, and tell you whose policy to read.

Controls that work regardless of us

  • Android: Settings, then Google, then Ads, then delete the advertising ID. Apps then receive zeros.
  • iOS: Settings, then Privacy and Security, then Tracking, and turn off Allow Apps to Request to Track.
  • Both: Uninstalling the title stops all collection from that device immediately.

10Service providers, and where the data is held

We disclose personal information to the service providers below, and to nobody else. This list is the whole list.

Service providers and where the data is held
ProviderWhat it doesWhat it receivesWhere
Google LLC and Google Ireland LimitedFirebase crash reporting and analytics, Google Play billing and the Install Referrer, advertising deliveryDevice data, crash reports, gameplay events, advertising identifier, purchase recordsUnited States, Ireland, and other Google regions
Apple Inc.App Store distribution, in-app purchase billing, crash reporting on iOSPurchase records, crash reports, whatever the store collects independently of usUnited States and Apple regions
Cloudflare, Inc.Serving and protecting this websiteRequest logs including IP addressGlobal edge network, including Australia
Our email providerReceiving and storing correspondence sent to our published addressAnything you put in an email to usAustralia and the United States
Our accountantStatutory accounts, business activity statements and taxAggregated purchase and revenue records, and individual transaction records where a specific query requires itAustralia

Not on this list

No data broker. No marketing platform. No customer data platform. No lead enrichment service. No "audience" or "identity graph" product. If one is ever added, this table changes first and the change is announced under the changes section.

Business transfer

If the company or a title is sold, personal information may transfer to the buyer as part of that sale. If that happens, we will give notice on this website before the transfer completes where we are lawfully able to, and the buyer will be bound by this policy until it publishes its own, which cannot reduce your rights in respect of information collected before the transfer without your consent.

11Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime: consent, accurate sender identification, and a functional unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days.

Our position

We do not run a marketing list. We have never sent a marketing email under this company name. If that changes, it will be opt in, the consent will be recorded with a timestamp and the wording you agreed to, and the first message will say where the address came from.

Writing to our support address does not subscribe you to anything. That is the most common way small companies quietly build a list, and we do not do it.

Advertising inside a game is not direct marketing to you

Advertisements shown inside a title are served by an advertising network, not addressed to you by us. That activity is governed by the advertising section of this policy rather than by APP 7, but you can still control it: personalised advertising is off unless you turn it on, and the operating system level controls described in the advertising section work regardless of anything we do.

12Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

13Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to, our products have no age verification or identity verification step that would need one, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

14Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Most of what we hold is machine generated and therefore accurate in the narrow sense that it faithfully records what a device reported. The category most likely to go stale is anything you told us yourself, such as an email address in a support thread. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

15Security, and what we do not have

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company this size

  • Transport encryption on every connection. The website and every app endpoint are served over HTTPS only.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every administrative account that can reach production data or a store console.
  • Access on a need to know basis. The number of people who can reach production data is small and is reviewed when anyone joins or leaves.
  • Separate credentials for development and production, so a compromised development credential does not reach live data.
  • Collecting less. The most reliable security control available to a small studio is not holding the data, which is why the collection tables are short.

What we do not have, stated plainly

360 DEGREES INTERACTIVE PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

16How long we keep things

Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed, unless it is contained in a Commonwealth record or we are required by law to keep it.

Retention periods and the reason for each
CategoryPeriodReason
Crash and diagnostic reports90 daysLong enough to fix and verify, short enough that a stale trace is not sitting around
Device and app data13 monthsOne annual cycle, so year on year comparison is possible once
Advertising identifier and attribution13 monthsMatches the attribution window our providers use
Gameplay telemetry25 months, then irreversibly aggregatedTwo annual cycles for balance work, then no individual level record
Optional account and progressUntil you delete it, then 30 daysYours to end
Dormant account with no activity36 months, then deleted after notice to the email on the accountAn account nobody uses is a liability, not an asset
Support correspondence24 monthsLong enough to see a recurring problem
Complaint correspondence7 yearsEvidence of handling, matching the general limitation period in New South Wales
Purchase, tax and accounting records7 yearsSection 262A of the Income Tax Assessment Act 1936 and section 286 of the Corporations Act 2001
Website request logsUnder 30 daysHeld by the hosting provider on its own cycle

Destruction means deletion from live systems and expiry from backups on the ordinary rotation, which completes within 35 days of the live deletion. De-identification means removing every identifier and any field that could reconstruct one, not merely dropping the name column.

17App permissions

Both Apple and Google require that an app requests only the permissions it needs and explains each one. Here is every permission any of our titles requests, what happens if you decline, and how to take it back later.

Device permissions requested by our titles
PermissionWhyRequiredIf you declineHow to revoke
Internet accessLoading advertisements, syncing an optional account, sending crash reportsGranted at install on both platforms and not separately promptableNot applicableTurn off mobile data or wi-fi for the app in system settings
NotificationsTelling you a timed event has finished, if a title has oneNoThe title works normally and sends nothingiOS: Settings, then the app, then Notifications. Android: Settings, then Apps, then the app, then Notifications
App Tracking Transparency (iOS)Access to the advertising identifier for personalised advertisingNoAdvertising is non-personalised. Nothing else changesSettings, then Privacy and Security, then Tracking
Advertising ID (Android 13 and later)Frequency capping and attributionDeclared in the manifest, not promptedDelete the advertising ID in system settings and the app receives zerosSettings, then Google, then Ads
VibrationHaptic feedback on an inputNoNo hapticsTurn haptics off in the title's settings screen

What we never request

Location of any precision, camera, microphone, contacts, calendar, photos, SMS, call log, phone state, body sensors, nearby devices, or accessibility services. If a build of one of our titles asks for any of these, it is either a mistake or not our build, and we would like to be told immediately.

18Deleting your account and your data

Both stores now require that an app offering account creation also offers account deletion, including a route that does not require you to open the app. This section is that route, and it is also the general deletion right.

If a title has an optional account

  1. In the app. Settings, then Account, then Delete account. You confirm once and the request is queued immediately.
  2. By email. Write to hello@threesixtyinteractive.cc with "Delete my account" in the subject line and the email address on the account.

If you never created an account

Uninstalling the title ends all collection from that device. To have the records already collected against your device deleted, send us the support identifier from the title's settings screen, or the advertising identifier, and we will delete the records keyed to it.

What deletion actually does

What is removed and what survives deletion
DataOn deletionWhy
Account record, display name, email address, progressDeleted within 30 daysNo longer needed
Gameplay telemetry keyed to the deviceDeleted or irreversibly aggregated within 30 daysAggregate counts survive, but nothing that can be traced back
Crash reportsDeleted on their own 90 day cycleAlready short lived
Purchase and tax recordsRetained for 7 yearsRequired by the Income Tax Assessment Act and the Corporations Act. We cannot delete these and will say so plainly rather than deleting and hoping
Correspondence about a complaintRetained for 7 yearsEvidence of how a complaint was handled
BackupsOverwritten on the ordinary rotation, within 35 daysSelective deletion inside a backup image is not reliable. We let the rotation clear it and do not restore deleted records from backup

We confirm in writing when deletion is complete. We do not flag records as deleted and keep them.

19Access and correction

Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it.

How to ask

Email hello@threesixtyinteractive.cc with "Privacy request" in the subject line. Tell us what you want and give us enough to find it. For information tied to a device rather than an account, that usually means the advertising identifier or the in-app support identifier shown in the title's settings screen, because without one of those we cannot connect a record to you.

Verifying who you are

We have to be satisfied you are the person the information is about, or an authorised representative. Where a request relates to an account, we verify through the email address on the account. Where it relates only to a device identifier, possession of that identifier is what we can verify, and we will say so rather than pretend to a higher level of confidence. We will not ask you to send identity documents.

Timing and cost

We respond within 30 days. Access is free. We do not charge for making a request, and we do not charge for correction. If giving access in a particular form imposes a genuine cost, for example producing a bulk export in an unusual format, we will tell you the charge before doing the work and it will not be excessive.

When we can refuse

The Act lists the grounds, and they are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, and where giving access would be unlawful.

If we refuse, in whole or in part, we will give you written reasons, tell you which ground we rely on, and tell you how to complain. Where we can give you part of the information, or give it in another way that meets your need, we will offer that instead of a flat refusal.

Correction

If information is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed the information to someone else and you ask us to notify them of the correction, we will take reasonable steps to do so unless it is impracticable or unlawful.

If we refuse to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we will take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is often overlooked and it is worth knowing about.

20Children and young people

Our games are not directed at children and are not designed to appeal primarily to children. Where a store requires an age rating or a target audience declaration, we declare a general audience.

Australian position

The Privacy Act does not fix an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have capacity unless there is something to suggest otherwise. We apply that presumption.

The Privacy and Other Legislation Amendment Act 2024 provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and applying to services likely to be accessed by children. We will comply with that Code as it applies to us once it is registered and in force, and we will update this policy at that point rather than in advance of knowing its terms.

Practical measures now

  • We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
  • Where a title carries advertising and the store signals that a user is a child, personalised advertising is not requested, and the ad request is marked as child directed so the network serves non-personalised inventory.
  • There is no social feature, no chat, no user generated content and no player to player messaging in anything we build.

If a child's information has reached us

Write to hello@threesixtyinteractive.cc. We will delete it without requiring you to prove a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm when it is done.

21Automated decisions

The Privacy and Other Legislation Amendment Act 2024 inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions made. That requirement commences on 10 December 2026.

Our position, disclosed in advance of the commencement date

We make no automated decision that significantly affects your rights or interests. Nothing we run decides whether you get credit, a job, a service, a benefit, or a legal entitlement.

Automated processing does happen in two places, and neither meets that threshold:

  • Anti-cheat and abuse detection. Automated signals can restrict an account or a device from a leaderboard. Where a restriction is applied to an account rather than a single score, a person reviews it on request. Write to us and say so.
  • Advertising selection. Which advertisement is shown is decided automatically by the advertising network. It does not affect your access to the title or anything you have paid for.

If that ever changes, this section is where it will be described, and it will be described before the processing starts rather than after.

22Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to hello@threesixtyinteractive.cc with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

23The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

24Cookies on this website

This website sets no cookies of its own, runs no analytics and shows no advertising. A strictly necessary security cookie may be set by our hosting provider to distinguish automated traffic from human traffic.

There is no consent banner because there is nothing here requiring consent. The full reasoning, and the one outbound request this site makes, are set out in the cookie notice.

Cookies are a website concept. Our mobile games do not use cookies; they use the device identifiers described above, and those have their own controls.

25Complaints

Step one: tell us

Email hello@threesixtyinteractive.cc with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

26If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to hello@threesixtyinteractive.cc and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. Personalised advertising is off unless you turn it on, which places us outside the sharing definition by default. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

27Changes to this policy

We may change this policy. When we do, we update the effective date and the version number in the header of this page.

Where a change materially reduces your rights or materially expands what we collect, we will give notice before it takes effect: a notice in the app on next launch, and a note at the top of this page for at least 30 days. We will not make a material change effective retrospectively.

Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances.

28How to contact us

All privacy matters reach one address.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of an account and its dataDelete my account30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Anything elseAnything sensible5 business days

Email: hello@threesixtyinteractive.cc

Entity: 360 DEGREES INTERACTIVE PTY LTD, ACN 697 527 834, ABN 27 697 527 834, registered in Australia, New South Wales.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 697 527 834 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.