LAST UPDATED: 11 SEPTEMBER 2026
Privacy policy
Adam Janasek operates Two Touch Drift and its leaderboard service. For privacy questions or requests, contact janasek.adam@gmail.com.
Scope
This policy covers this website, the game and the optional leaderboard service. Online features depend on your game version. Playing offline does not require creating an online profile.
Data on your device
The game saves progress, best scores, selected car and route, and sound and haptics settings locally. An online-enabled version also needs to store your guest profile credentials to associate runs with your profile. Do not share those credentials.
Online leaderboard
When you join online ranking, the service stores a randomly generated profile ID, your chosen public name, a hash of your authentication token, creation time and moderation status. Submitted runs include their ID, score, route, car, driving duration, distance, continuation status, game and scoring versions, and server receipt time.
The public leaderboard displays player names, ranks, scores, cars, continuation status and achievement times. It does not expose profile IDs or authentication tokens. The service saves all accepted runs, including runs outside the top 100. Choose a name that does not reveal personal information.
Website, hosting and security
Upsun hosts this service and its PostgreSQL database. Hosting infrastructure processes connection information such as IP addresses, request details and timestamps to deliver the service and diagnose or prevent abuse. Application rate limits store temporary keyed digests instead of raw IP addresses. Expired rate-limit records are cleaned hourly.
These public pages do not use advertising trackers or analytics scripts and do not set visitor cookies. The administrator login uses essential security and session cookies for authorized staff.
Purchases
Optional coffee purchases are processed by Apple or Google through the relevant app store. The game handles purchase status and transaction identifiers; it does not receive payment card details. The leaderboard API does not collect purchase receipts. Store providers process purchases under their own privacy policies: Apple and Google.
Advertising and analytics
Mobile versions with rewarded continuation use Google AdMob. Watching an ad is optional; starting a new run is free. The Google Mobile Ads SDK may process IP addresses, device or advertising identifiers, ad interactions, diagnostics and performance data for ad delivery, measurement and fraud prevention. Available data and personalization depend on consent, device permissions and configuration. Google processes this information under its privacy policy; see its disclosures for Android and iOS.
The game requests consent information through Google's User Messaging Platform and shows applicable choices before requesting ads. When available, AD PRIVACY in Settings lets you revisit these choices. Device tracking permissions can also be managed in operating-system settings. Test builds use test ads. No separate gameplay analytics SDK is integrated.
Reward verification
Google sends signed reward confirmations to our server. We store the ad network and unit, reward transaction ID, reward type and amount, event and receipt times, signing-key ID, a message fingerprint and optional correlation fields. The current game sends a new random identifier for each run; it does not put your nickname, guest authentication token or payment details in these fields. Console verification tests may include test user IDs or custom text.
We use these records to check reward delivery and detect repeated confirmations. They are not public and are removed from the active database after 30 days by scheduled cleanup. Infrastructure request logs and backups follow the hosting retention arrangements described below.
Why we process data
We use profile and run data to provide the online ranking you request. We process limited technical information to operate and secure the service and to investigate abuse, based on our legitimate interests. When you contact support, we use the information you provide to respond and resolve your request. We do not sell your personal data.
Access, storage and retention
Authorized administrators and hosting providers can access data as needed to operate and support the service. Public leaderboard fields are accessible to anyone. Hosting and store providers may process data in other countries under their applicable data-protection arrangements.
Online profiles and runs remain until you request deletion or we remove them for moderation or service operation. Support correspondence is kept for as long as needed to resolve the request and any related obligations. Infrastructure logs and backup copies follow the hosting retention schedules and may outlast deletion from the active database. Contact us for details about data retained in connection with your request.
Your choices and rights
You may play offline without joining the leaderboard. You can request access, correction or deletion of your personal data, and, where applicable, restriction, portability or objection to processing, by contacting us. We may need to verify ownership before acting on a request. You may also raise a concern with your local data-protection authority.
To remove your online profile and all its runs, follow the profile deletion instructions. App-store purchase records and data stored locally on your device are managed separately.
Changes
We update this page when the service or its data practices change. The date above identifies the latest revision.