Boomit Privacy Policy

Last updated: June 11, 2026

1. Who we are

Boomit is operated by SmartID Technologies B.V. ("SmartID," "we," "us"), a company incorporated in the Netherlands with its registered office at Leliegracht 32, 1015 DG Amsterdam, the Netherlands (Chamber of Commerce / KvK no. 74371908, VAT no. NL859870911B01).

SmartID is the controller of the personal data described in this Privacy Policy. This policy explains what data we process when you use the Boomit mobile app or visit www.boomitparty.com, why we process it, and what rights you have under the EU General Data Protection Regulation (GDPR). Your use of Boomit is also governed by our Terms of Service, available at https://www.boomitparty.com/legal/terms.

Boomit is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.

Contact: hello@smartidtechnologies.com | Leliegracht 32, 1015 DG Amsterdam, The Netherlands

2. The short version

You can play Boomit without creating an account, and we never ask for your name to use the app. We do not show ads in the app and we do not sell your data. The data we process is limited to: technical and usage data so the app works and we can improve it, crash reports so we can fix bugs, purchase status so your premium content stays unlocked, and your email if you contact our support. Payments are handled entirely by Apple and Google — we never see your payment details.

3. What data we process

When you use the Boomit app:

  • Device and usage data — device model, operating system and version, language, country (derived from coarse, IP-based location), app version, and in-app events (such as which game modes are played and which screens are used). This is collected through Google Firebase Analytics and is linked to pseudonymous identifiers (an app instance ID and your device's advertising or vendor identifier), not to your name.
  • Crash and diagnostic data — crash logs, device state at the time of a crash, and performance data, collected through Firebase Crashlytics so we can identify and fix bugs.
  • Purchase and entitlement data — if you buy a subscription or lifetime unlock, we receive confirmation of the transaction (product, price, currency, timestamp, and a pseudonymous user ID) through RevenueCat and the Apple App Store or Google Play. This lets us unlock and restore your purchases. We do not receive or store your payment card details, billing address, or Apple/Google account credentials — payment is processed entirely by Apple or Google under their own privacy policies.

When you visit our website:

  • Technical and analytics data — browser type, device, pages visited, and similar data, collected via cookies and similar technologies (see Section 7). Analytics and marketing cookies are only placed with your consent.

When you contact us:

  • Contact and correspondence data — your email address and the content of your message when you reach out to our support.

We do not process special categories of personal data (such as health or religious data), and we do not use your data for automated decision-making with legal or similarly significant effects.

4. Why we process your data (lawful bases)

Purposes, data, and lawful bases for processing
Purpose Data Lawful basis
Providing the app and delivering purchased content (including restoring purchases) Device data, purchase/entitlement data Performance of a contract (Art. 6(1)(b) GDPR)
Fixing crashes and bugs, keeping the app secure Crash and diagnostic data, device data Legitimate interest (Art. 6(1)(f)): providing a stable, secure product
Understanding how the app is used so we can improve it Usage/analytics data (pseudonymous) Legitimate interest (Art. 6(1)(f)): improving our product
Website analytics Cookie and technical data Consent (Art. 6(1)(a))
Responding to support requests Contact and correspondence data Legitimate interest (Art. 6(1)(f)): helping our users; or performance of a contract where your request relates to a purchase
Complying with legal obligations (e.g. tax and accounting rules) Transaction records Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, in particular because the data involved is limited, pseudonymous where possible, and not used for advertising. You have the right to object — see Section 9.

5. Who we share data with

We share personal data only with service providers (processors) that help us run Boomit, under data processing agreements, and only for the purposes above:

  • Google Ireland Ltd / Google LLC — Firebase Analytics, Crashlytics, and app infrastructure; Google Play for Android purchases.
  • Apple — App Store purchases and app distribution.
  • RevenueCat, Inc. (US) — in-app purchase and subscription management.
  • Website and email providers — hosting of www.boomitparty.com and handling of support email.
  • Professional advisers (lawyers, accountants, auditors) where necessary.

We may also disclose data if required by law, or to a successor entity in the event of a merger, acquisition, or sale of assets — in which case this Privacy Policy will continue to apply to your data.

We do not sell personal data, and we do not allow our processors to use your data for their own purposes.

6. International transfers

Some of our providers (such as Google and RevenueCat) process data in the United States or other countries outside the European Economic Area. Where that happens, we ensure an adequate level of protection through one or more of the following: an adequacy decision of the European Commission — including the EU-U.S. Data Privacy Framework for certified U.S. providers — and/or the European Commission's Standard Contractual Clauses, supplemented where appropriate by additional safeguards. You can contact us for more information about the safeguards applied to a specific transfer.

7. Cookies

Our website uses cookies and similar technologies. Functional cookies that are necessary for the website to work are placed without consent. Analytics and marketing cookies are only placed after you give consent via our cookie banner, and you can withdraw that consent at any time via the cookie settings on our website. You can also configure your browser to refuse or delete cookies, although some parts of the website may then not function properly.

The Boomit app itself does not use cookies; the app-related data described in Section 3 is collected through software development kits (SDKs) embedded in the app.

8. How long we keep your data

We keep personal data no longer than necessary for the purposes described above:

  • Analytics data (Firebase) is retained for a limited period set in our analytics configuration, after which it is deleted or aggregated.
  • Crash data is retained for as long as needed to diagnose and fix the relevant issues, typically no more than 90 days in identifiable form.
  • Purchase records are retained for as long as needed to provide your entitlements, and transaction records are kept for 7 years to comply with Dutch tax and accounting obligations.
  • Support correspondence is retained for up to 2 years after your request is resolved.

We may retain data longer where necessary to establish, exercise, or defend legal claims, and we may anonymize data (so it can no longer be linked to you) for statistical purposes.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict processing in certain circumstances;
  • Object to processing based on our legitimate interests;
  • Data portability — receive your data in a structured, machine-readable format;
  • Withdraw consent at any time where processing is based on consent (this does not affect processing before withdrawal).

To exercise any of these rights, email us at hello@smartidtechnologies.com. We may ask you to verify your identity before responding. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive. We respond within one month; for complex requests this may be extended by two further months, in which case we will let you know.

Note: because most app data is linked only to pseudonymous identifiers and not to your name, we may need information from you (such as a device identifier) to locate data relating to you, and in some cases we may not be able to identify which data is yours (Art. 11 GDPR).

10. Complaints

If you have a concern about how we handle your personal data, please contact us first — we would genuinely like the chance to resolve it. You also have the right to lodge a complaint at any time with the Dutch supervisory authority:

Autoriteit Persoonsgegevens (AP), Postbus 93374, 2509 AJ Den Haag, The Netherlands — autoriteitpersoonsgegevens.nl. If you live in another EU/EEA country, you may also complain to your local supervisory authority.

11. Security

We take appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS), access controls limiting data access to those who need it, and reliance on established infrastructure providers. No method of transmission or storage is 100% secure, but we have procedures in place to deal with suspected data breaches and will notify you and the AP where legally required.

12. Third-party links

Our website and app may contain links to third-party websites and services (for example, social media or the app stores). Their handling of your data is governed by their own privacy policies, which we encourage you to read.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example when our data practices or the law change. The "Last updated" date at the top shows the current version. For material changes, we will provide a more prominent notice in the app or on the website.