Privacy Policy
Career Tycoon: Road To Success
Version 1.0 · Prepared 7 October 2026 · Effective date: 7 October 2026
1. Who we are
Gherghina Codrut, trading as Carpathian Wolf Interactive, operates Career Tycoon: Road To Success (the “Game”). The Game may appear under its earlier name, Career Clicker Road To Success, in Google services. The Game is offered worldwide. We are the controller of the personal information we process to operate the Game.
Our business/service address is Strada Ana Ipătescu 12, Timișoara, Timiș County, 300463, Romania. Contact us about privacy, support or deletion at contact@carpathianwolfinteractive.com.
This policy covers the Game, the website at carpathianwolfinteractive.com and communications you send us about them. The website does not use analytics or advertising; the Game separately uses Firebase Analytics/Crashlytics and AdMob as described below. Third-party stores, advertisements and external websites also have their own privacy notices. The website host may still process technical request and security logs under its own terms; its log-retention period has not been confirmed.
2. Information used by the Game
Local career and preferences. The device stores your player name and profile, career progress, game currency, inventory, cosmetics, achievements, skills, generated offers, fictional inbox, tutorial progress, timestamps, purchase fulfillment markers and recovery saves. Profile/CV text you enter may form part of your career save. Preferences and consent records are also stored on the device. Fictional game earnings and attributes are gameplay information, not verified information about your real income or health. Avoid entering sensitive personal information in names, CVs or reports.
Accounts and cloud saves. Firebase Authentication handles the game account identifier and authentication credentials. An account may initially be anonymous and may be linked to Google Play Games. Linking can provide a Google Play Games player identifier and display name. We receive authentication tokens, not your Google password. Firestore and Cloud Functions receive the career save, account and installation identifiers, app version, platform, authentication provider, save revision, hashes and timestamps. Support records summarize your career and account, including an employee number. Recovery copies, validation results, device progression anchors and support actions are associated with the account.
Cloud processing is part of the current Game service: the first-launch agreement is required to proceed into gameplay. It is separate from optional Firebase analytics and crash reporting. Local saving can continue during temporary connection failures; this does not turn cloud processing off.
Purchases. Google Play processes payment and purchase history. Unity In-App Purchasing connects the Game to the store. Verification sends the product identifier and purchase token to our Firebase backend, which checks the transaction through the Google Play Developer API. Our records include the product, order identifier where supplied, token hash, hashed account identifier, grant/entitlement status and verification time. We do not store raw purchase tokens in the backend purchase ledger. Hashes can still be personal information. We do not receive your full payment-card or bank-account details through the game's billing integration.
Unity IAP 5.4 and later has its own service data practices, including installation/player and session identifiers, device information, country, transaction information and diagnostics. These practices are separate from the optional Firebase telemetry choice. The Game does not offer Unity web checkout or Coda/Stripe payments. Details are available in Unity's IAP privacy information and Unity's player privacy policy. Unity IAP is used to connect Google Play billing. Unity may separately process device, installation/session, transaction and diagnostic data under its own service terms; we do not receive those provider-side records in our Firebase purchase ledger.
Optional Firebase analytics and crash reports. When you allow them, Firebase Analytics and Crashlytics handle app/device and installation information, gameplay and purchase events, diagnostic context, error codes, stack traces and crash information. The Game's Firebase analytics events do not intentionally send complete career saves or free-form CV/inbox text. The Analytics & crash reports choice applies to these Firebase services; it does not govern necessary cloud requests, store processing, or advertising services.
Reports and correspondence. Sending a bug report shares the summary, description and severity you enter, app/Unity version, operating system, device model, processor/graphics and memory details, screen dimensions, language, scene and limited gameplay context such as level, balance, job, company, game date, tutorial step and active event. Email support also receives your email address, message and any attachments you choose to send. Do not send passwords, card details, authentication tokens or sensitive personal information.
Notifications. Local reminders are scheduled on your device. Firebase Cloud Messaging uses installation/messaging identifiers and topic subscriptions for game update announcements. The current Game does not upload its messaging token into its own player-account collection. Denying Android notification permission prevents notification display but does not necessarily stop Firebase from creating a messaging identifier.
Service operation and security. Firebase Remote Config retrieves gameplay/service configuration. App Check and Google Play Integrity handle attestation information/tokens to verify requests. Providers receive network information, including IP addresses, and service diagnostics when communicating with their systems. We use server timestamps and gameplay validation to detect invalid saves, duplicate purchases and abuse. The Game does not request access to your contacts, microphone, camera or precise GPS location for its current features.
3. Advertising and device storage
The Game integrates Google AdMob for optional rewarded advertisements. Advertising availability depends on the Game's configuration, your region, applicable privacy choices and network availability. Google's consent interface may communicate with Google to determine and present the appropriate message before an ad is requested. Choosing to watch an advertisement does not by itself authorize personalized advertising.
When advertising services operate, Google and the ad partners identified in the consent interface may process IP address and approximate location, advertising/app-set or other permitted identifiers, device/app details, ad requests, interactions and diagnostic information. They use these to deliver and measure ads and detect fraud, and for personalization where authorized. Non-personalized advertising can still involve data processing or device storage; it is not equivalent to no collection. Test-ad use does not establish that no SDK data is transmitted.
Use the Game's Ad privacy control when available to revisit Google's privacy choices. Android also provides advertising-ID controls. Applicable consent is sought for non-essential device access and advertising personalization. Where supported, regional privacy options can restrict advertising data use. The Game also stores necessary save, authentication and preference information on your device, and SDKs may store their own identifiers or consent records.
We do not sell career saves or support correspondence for money. Advertising disclosures can qualify as “sharing” or a “sale” under some privacy laws even without a monetary payment. Where those laws apply, the corresponding opt-out and other rights remain available. Google's information is available at How Google uses information from apps.
4. Purposes and lawful grounds
Where GDPR or similar laws apply, our purposes and grounds are:
- Account authentication, career saving/restoration and purchase fulfillment: performance of our contract with you, only to the extent processing is objectively necessary to provide those services.
- Save/purchase security, fraud prevention, technical reliability and handling support requests: our legitimate interests in protecting players and operating the Game, balanced against your rights; or contract performance where necessary to resolve your requested service issue.
- Optional Firebase analytics/crash reporting and advertising personalization/non-essential device storage: consent where required. Other advertising processing relies on the ground communicated for that processing and applicable law; consent is obtained whenever required.
- Required transaction, tax, complaint and rights-request records: compliance with applicable legal obligations. Establishing or defending legal claims: legitimate interests or the applicable legal ground.
Accepting the EULA is not blanket privacy consent. Merely describing processing in a contract does not make it necessary. You may withdraw optional consent without affecting the lawfulness of earlier processing. We do not use optional analytics consent as a condition of playing.
5. Recipients and international processing
Authorized publisher personnel and service providers access information as needed for their duties. The current services include Google/Firebase Authentication, Firestore, Cloud Functions, Remote Config, App Check/Play Integrity, Cloud Messaging, Analytics and Crashlytics; Google Play/Play Games; Google AdMob and its disclosed ad partners; Unity IAP; and providers handling support email and hosting. Some services act on our instructions; others, including stores and certain advertising or billing processing, act as independent controllers under their own notices.
We may disclose relevant information to competent authorities when required by law, advisers handling a claim, or a successor in a lawful business transfer, subject to appropriate safeguards and applicable notice. Career files are not intentionally published to other players. External community links open services with their own policies; messages posted there are not private game-support communications.
Information can be processed outside your country, including in the United States and other countries where Google/Firebase, Unity, Google Play and advertising providers operate. Firebase Authentication is a US-only service; many other Firebase services use global infrastructure. Google’s Firebase data-processing terms provide applicable transfer mechanisms, including adequacy frameworks or standard contractual clauses where required. The project’s specific Firestore and Cloud Logging regions have not been confirmed. You can contact us to request information about the safeguards applicable to your data.
6. Retention
- Local career/preferences: until cleared, replaced or deleted on the device. Device/operating-system backups may retain copies under their own settings.
- Account and canonical cloud career: we do not automatically delete accounts for inactivity. We keep the account and its save while the account remains open, until you request deletion or we end the service. A deletion request removes the account and save, subject to the limited records described below and legal retention obligations.
- Recovery revisions/device anchors: a limited rolling set used to validate or recover saves, replaced as the career advances and removed by account deletion. Age alone does not currently expire every recovery copy.
- Save requests and security audit rows: server code assigns expiry timestamps of 24 hours after request processing and 90 days for audit rows. Those timestamps do not delete documents by themselves. Firestore TTL must be enabled for the relevant collections; its live configuration has not been verified. When active, Google says expired documents are typically deleted within 24 hours (Firestore TTL details).
- Purchase replay records and deletion safeguards: restricted records can outlive account deletion so a purchase cannot be granted repeatedly and queued requests cannot recreate a deleted account. They currently have no automatic expiry. Access is restricted; we review these records at least annually and erase them when they are no longer needed for purchase replay prevention, a pending deletion safeguard or a legal claim. They can include an order identifier, hashed identifiers and a deletion-account identifier; they are not necessarily anonymous.
- Bug reports and support correspondence: game-submitted reports currently have no automatic expiry. We retain a report while investigating it and erase or anonymize it within 12 months after the issue is closed, unless it is needed for an active security investigation or legal claim; in that case, we retain it only until that matter is resolved. This requires a manual review and deletion process. Routine Google Cloud Logging entries in the default log bucket are retained for 30 days by default; required audit logs are retained for 400 days. Project-specific log-bucket settings may change those periods (Cloud Logging retention details). Crashlytics crash traces and associated identifiers are retained by Firebase for 90 days before removal begins (Firebase privacy details).
- Provider-held identifiers, analytics and diagnostics: under the relevant service settings and provider schedules. Deleting a game account does not immediately erase every independent store/provider record. Applicable provider deletion requests and lawful retention exceptions are handled separately.
If a record must be retained for a specific legal obligation or dispute, its use is restricted to that purpose and it is removed when the obligation or need ends.
7. Deletion and your controls
Open Settings → Delete Account to request deletion of the game account and associated career. The Game may ask you to sign in again. Successful in-app deletion removes the Firebase Authentication account, cloud career/recovery files, account support records, queued save/admin requests, employee mapping and time-probe record. It also clears the current device's game saves and preferences. Minimal safeguards described above remain separately. Another device or its backup may still hold a local copy; clear it there as well.
Without the app, follow our account-deletion page or email contact@carpathianwolfinteractive.com with “Career Tycoon account deletion”. Provide the player name and employee number or game-account identifier if available. We may request proportionate ownership verification. Never send your password or purchase/authentication tokens. Include details of any separate bug report or support message you want located. We coordinate applicable service-provider requests for information processed on our behalf.
Uninstalling is not a cloud-deletion request. Deleting the Game account does not delete your Google account or automatically refund purchases. It does not waive lawful refund rights. Changing optional Firebase telemetry consent stops future collection through those services; you can also request deletion of identifiable information already processed, where applicable.
8. Your privacy rights
Subject to the law that applies and its exceptions, you may request access and a copy, correction, erasure, restriction, or portability of information; object to legitimate-interest processing; withdraw consent; and exercise applicable advertising sale/sharing or targeted-advertising opt-outs. You may ask for human review of a disputed save/purchase validation or restriction. These technical checks are not used to make employment, credit or other real-world eligibility decisions.
Contact the address in section 1. We may verify identity using only information reasonably needed for the request. Under GDPR, we respond without undue delay and normally within one month; a permitted extension is explained within that month. Other applicable deadlines and appeal rights are respected. Exercising a right does not require giving up rights or paying a charge except where law expressly permits one.
You may complain to the data-protection or privacy regulator competent where you live, work or believe an infringement occurred. For Romania, see ANSPDCP; for the UK, see the ICO. Elsewhere, contact your local privacy regulator.
9. Young players
The intended minimum player age is 13 years old. The Game is intended for players aged 13 and older, although its content is designed to be suitable for all ages. Players younger than 13 should not create an account or use account-based services. This age/content statement does not replace any legally required safeguards. A store content rating describes suitability and is not, by itself, verification of age or parental consent. Contact us if you believe a child has provided information unlawfully; we will investigate and take appropriate steps. A parent's agreement to the EULA does not replace a legally required child-privacy process.
10. Security and changes
We use encrypted network transport, restricted access, account authorization, protected local saves and server validation to reduce risk. No device or service is completely secure. Please protect your store account and device and report suspected unauthorized access. Where required, we notify the relevant authority and affected people of a personal-data breach.
We publish updates here and provide appropriate notice of material changes. We obtain new consent where required; updating this policy does not automatically authorize new optional data uses.