1. Introduction
This Privacy Policy explains what information Splash (“we”, “us”, or “our”) collects, how we use it, and your choices regarding your data. By using Splash software or services, you consent to the minimal data practices detailed here. We believe privacy is an engineering requirement, not an afterthought.
2. Information We Collect
To operate accounts, license verification, and infrastructure defense, we strictly collect only essential technical attributes:
- Account Data: Your chosen account username and a cryptographically salted password hash (Argon2 / SHA-512). We never store or transmit plaintext passwords.
- Device Identifier: A one-way cryptographic SHA-256 hash derived from baseline system properties. Used strictly to prevent concurrent multi-device abuse. We never scan, catalog, or inspect user files or directory structures.
- Authentication Logs: Timestamps and client IP addresses captured during login requests for rate-limiting, DDoS mitigation, and credential-stuffing prevention.
- Transaction Records: Order identifiers and transaction confirmation tokens passed from payment processors (PayPal / Stripe). We never see, process, or store full credit card numbers or banking secrets.
3. Zero Telemetry Architecture
Splash was built with complete privacy isolation:
- No In-Game Logging: We do not log, stream, or inspect in-game activities, server addresses, or player interactions.
- No Keystroke Harvesting: The macro engine operates locally within Ring-3. Your typing, chat messages, and non-bound key inputs are never recorded or transmitted.
- No Ad Trackers: Zero third-party trackers, analytics SDKs, Google Analytics, or marketing beacons exist in our software or web portal.
4. How We Use Your Information
Collected data is used strictly to:
- Authenticate your license credentials and grant runtime access.
- Enforce single-device hardware lock integrity.
- Provision instant digital delivery upon confirmed payment.
- Mitigate server attacks, abuse, and fraudulent refund exploits.
5. Cryptography & Security Controls
All network communications between the Splash client and authentication servers are encrypted over TLS 1.3 with AES-256-GCM payloads and RSA-4096 public key verification. Database instances run behind isolated network security groups with strict role segregation.
6. Data Retention & Deletion Rights
You have the absolute right to request the deletion of your account and associated session telemetry logs. Contact our support team or submit a ticket through the account portal to request an immediate, irreversible database purge.