Privacy Policy
Privacy Policy
Kerala Bus Mod Livery Developer: Kerala App Creators Effective Date: May 8, 2026 - Last Updated: May 8, 2026
1. Introduction
Kerala Bus Mod Livery ("App," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
This policy applies to all users of the Kerala Bus Mod Livery mobile application, available on Google Play. By using the App, you consent to the data practices described in this Privacy Policy. If you do not agree, please do not use the App.
This Privacy Policy should be read alongside our Terms & Conditions.
2. Information We Collect
We collect only the minimum data necessary to provide our services, process purchases, prevent abuse, and deliver advertisements. Below is a complete breakdown of every data type we collect.
2.1 Information You Provide (Account Data)
When you sign in using Google Sign-In, we receive the following from your Google account:
2.2 Information Collected Automatically
a) Device Information
b) Ad Interaction Data
c) Purchase Data
d) Local Storage (On-Device Only)
2.3 Information We Do NOT Collect
We want to be transparent about what we do not collect:
- ❌ GPS location or precise/approximate location data
- ❌ Contacts, call logs, or SMS messages
- ❌ Camera, microphone, or biometric data
- ❌ Files or photos from your device storage (beyond downloaded mod files)
- ❌ Browsing history or data from other apps
- ❌ Payment card numbers, bank account details, or financial information (all billing is handled by Google Play)
- ❌ Advertising ID for personalised tracking (we use contextual ads only)
- ❌ Health, fitness, or sensitive personal data
3. How We Use Your Information
We use collected data strictly for the following purposes:
4. Data Sharing & Third-Party Services
We do not sell, rent, or trade your personal data to any third party for marketing or advertising purposes. We share data only with the following service providers, strictly for operational purposes:
4.1 Google Firebase
- Services Used: Firebase Authentication, Cloud Firestore, Cloud Functions, Remote Config, Cloud Messaging
- Data Shared: Account information, purchase records, ad statistics, notification tokens
- Purpose: Backend infrastructure, authentication, database, serverless functions, push notifications
- Privacy Policy: firebase.google.com/support/privacy
4.2 Google Play Billing
- Data Shared: Purchase tokens and product IDs (for server-side verification via the Android Publisher API)
- Purpose: Processing in-app purchases, verifying payment authenticity, preventing replay attacks
- Note: All payment processing (credit card, UPI, etc.) is handled entirely by Google Play. We never receive or store your payment method details.
- Privacy Policy: policies.google.com/privacy
4.3 AppLovin MAX (Ad Mediation)
- Services Used: Rewarded Ads, Interstitial Ads, App Open Ads
- Mediated Networks: Meta Audience Network, Unity Ads, InMobi
- Data Shared: AppLovin SDK and its mediated networks may collect device identifiers, IP address, and ad interaction data as described in their respective privacy policies
- Purpose: Serving advertisements to support the free app model
- Consent: User consent preferences are passed to AppLovin via setHasUserConsent() and setDoNotSell().
- Privacy Policies:AppLovin: applovin.com/privacy Meta: facebook.com/privacy/policy Unity Ads: unity.com/legal/privacy-policy InMobi: inmobi.com/privacy-policy
Meta: facebook.com/privacy/policy
Unity Ads: unity.com/legal/privacy-policy
InMobi: inmobi.com/privacy-policy
4.4 Google Sign-In
- Data Shared: OAuth authentication tokens (handled by Google's SDK)
- Purpose: User authentication
- Privacy Policy: policies.google.com/privacy
5. Data Retention
We retain your data for the following periods:
6. Data Security
We implement the following measures to protect your data:
- Encryption in Transit: All data transmitted between the App and our servers uses TLS/SSL encryption (HTTPS).
- Server-Side Security: Firebase Firestore Security Rules enforce strict access controls - users can only read and modify their own data. Premium Pass balances can only be modified by authenticated Cloud Functions, never by the client app directly.
- Purchase Verification: All in-app purchases are verified server-side using Google Play's Android Publisher API with cryptographic token validation.
- Replay Attack Prevention: Each purchase token is recorded in a server-side database and checked for uniqueness before granting passes, preventing duplicate redemptions.
- Device Verification: Server-side device ID validation prevents unauthorised access from unregistered devices.
- Anti-Fraud: Invalid Traffic (IVT) protection detects emulators, VPN usage, and suspicious click patterns to prevent ad fraud.
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
7. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
7.1 Access & Portability
You can view your account information (name, email, pass balance, transaction history) within the App through the My Premium Passes dashboard.
7.2 Data Deletion
You can permanently delete all your data using any of the following methods:
- In-App (Instant): Navigate to the App drawer → Delete Account. This immediately and permanently deletes your user data, transaction history, ad statistics, and authentication record from our servers.
- Web: Visit our Account Deletion Page and follow the instructions to submit a deletion request. Processed within 30 days.
- Email: Send a deletion request to [email protected] with the subject line "Data Deletion Request" and your registered email address. Processed within 30 days.
7.3 Ad Consent & Tracking
You can opt out of personalised ads through your device Settings → Google → Ads → "Opt out of Ads Personalisation."
7.4 Push Notifications
You can enable or disable push notifications at any time through your device's notification settings for the Kerala Bus Mod Livery app.
7.5 GDPR Rights (European Economic Area)
If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR), including:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
To exercise any of these rights, please contact us at [email protected].
7.6 CCPA Rights (California, USA)
If you are a California resident, you have the right to:
- Know what personal information is collected about you
- Request deletion of your personal information
- Opt out of the sale of your personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
8. Children's Privacy
The App is rated "Everyone" on Google Play and is suitable for all age groups. We take children's privacy seriously and comply with the Children's Online Privacy Protection Act (COPPA) and applicable international regulations.
- We do not knowingly collect personal information from children under 13 beyond what is strictly necessary for account authentication (Google Sign-In) and app functionality.
- We do not serve interest-based or personalised advertisements. All ads displayed are contextual.
- We do not use behavioural targeting, remarketing, or user profiling of any kind.
- In-app purchases require authentication through Google Play, which supports parental controls and purchase approval workflows.
9. International Data Transfers
Our backend services are hosted on Google Cloud Platform / Firebase, which may process data in data centres located outside your country of residence. By using the App, you consent to the transfer of your data to these facilities.
Google Cloud complies with internationally recognised data protection frameworks, including the EU-US Data Privacy Framework, to ensure adequate protection of transferred data. For more details, see Google Cloud's GDPR commitments.
10. Cookies & Tracking Technologies
The App itself does not use browser cookies. However, the following local storage mechanisms are used on your device:
- SharedPreferences: Stores lightweight key-value pairs (ad cooldown timestamps, cached pass count) locally on your device. This data never leaves your device.
- Hive Database: Stores cached content listings locally for offline access. This data never leaves your device.
Third-party SDKs (AppLovin MAX) may use their own tracking technologies as described in their respective privacy policies.
11. App Permissions
The App requests the following Android permissions:
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
- The "Last Updated" date at the top of this page will be revised.
- For material changes that significantly affect how we handle your data, we will make reasonable efforts to notify you through the App or via the email associated with your account.
- Your continued use of the App after any changes constitutes acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- General Support: [email protected]
- Payment & Purchase Issues: [email protected]
- Website: marveloustravelvibes.in
For data deletion requests, please contact us at [email protected] with the subject line "Data Deletion Request" and your registered email address. We aim to respond to all enquiries within 48 hours and process data deletion requests within 30 days.