Privacy Policy
Last updated: 12 August 2026
This policy explains what Road Rush (the “App”) does with data, and what it does not. It applies to the Road Rush mobile app published by New Horizon Software Ltd. Plain summary: the App has no accounts and never asks for your name, email or phone number. It shows ads and records anonymous gameplay statistics, both through Google. Your best time stays on your phone.
1. Who we are
New Horizon Software Ltd (“we”, “us”, “our”) is the data controller for the personal data described in this policy. You can reach us about anything in it at hello@horizonsoftware.co.uk.
Where our advertising and analytics partners determine their own purposes for the data they receive, they act as independent controllers of that data. Their policies are linked in section 5.
2. What the App does not do
- It does not require an account, login or registration of any kind.
- It does not collect your name, email address, phone number or postal address.
- It does not access your location services, contacts, photos, camera or microphone.
- It contains no in-app purchases and does not process payments.
- It does not knowingly collect data from children under 13.
3. Data processed in the App
The App processes the following, and nothing else.
a. Advertising — Google AdMob
The App is free and funded by advertising served through Google AdMob. You will see full-screen interstitial ads between runs, and you may choose to watch a rewarded video ad to continue a run. Rewarded ads are always optional and are only shown when you tap to watch one.
To serve, cap, measure and protect those ads against fraud, Google processes data such as your device advertising identifier, IP address (from which an approximate, city- or country-level location can be inferred), device and operating system information, and interactions with the ads shown.
b. App Tracking Transparency and the advertising identifier
On iOS, the App shows Apple’s App Tracking Transparency (ATT) prompt. If you allow tracking, the device advertising identifier (IDFA) may be used to show you personalised ads. If you decline, the IDFA is not used and the ads you see are non-personalised. Declining does not remove ads, and it does not affect gameplay in any way.
c. Ad consent — Google UMP
Where the law requires it — for example under the GDPR in the UK and the EEA — the App uses the Google User Messaging Platform (UMP) to present a consent message before personalised advertising is enabled, and to record your choice. Your consent choice is stored on the device and passed to the ad SDK.
d. Analytics — Google Firebase Analytics
We use Google Firebase Analytics to understand how the game is played in aggregate, so we can balance the difficulty and fix what is broken. The events we record are:
- when a run starts and when a run ends;
- the score for that run;
- whether the run beat your previous best;
- whether an ad was shown, and whether a continue was used;
- coarse buckets of how many runs have been played in total on the device.
None of these events contain anything that identifies you as a person. Firebase additionally collects standard technical information such as an app instance identifier, device model, operating system version, app version and country.
e. Data stored only on your device
Your best time, your lifetime number of runs and your lifetime number of crashes are saved locally on your device. This never leaves the device, is never sent to us, and is deleted when you delete the App.
4. Why we process it, and our legal basis
For users in the UK and the European Economic Area, our legal bases under the UK GDPR and the EU GDPR are:
- Consent (Art. 6(1)(a)) — for personalised advertising and, where consent is required in your jurisdiction, for analytics. You give or refuse this in the consent message and in the ATT prompt, and you can change your mind at any time (section 6).
- Legitimate interests (Art. 6(1)(f)) — for non-personalised advertising, ad fraud prevention, security, and understanding aggregate gameplay so we can improve the game. We have balanced these interests against your rights, and the data involved is limited and not used to build a profile of you as an individual by us.
- Performance of a contract (Art. 6(1)(b)) — to provide the game itself under our Terms of Use.
We do not sell personal data for money, and we do not use any of this data for credit, employment or insurance decisions.
5. Third parties we share data with
We use the following providers. Each processes data under its own privacy policy, which we recommend you read:
- Google AdMob (advertising) — How Google uses advertising data and Google Privacy Policy.
- Google Firebase Analytics (analytics) — Firebase privacy and security.
- Google User Messaging Platform (consent management) — About privacy and messaging.
- Apple — distributes the App and provides the ATT framework. Apple may also give us anonymous, aggregated App Store analytics.
See also how Google uses information from apps that use its services. We may additionally disclose data where we are legally required to, or to establish or defend legal claims.
6. Your choices and how to opt out
- Turn off tracking (iOS).Open Settings → Privacy & Security → Tracking and switch off the permission for Road Rush, or switch off “Allow Apps to Request to Track” for every app. The IDFA will not be used and your ads will be non-personalised.
- Limit ad personalisation.On iOS, Settings → Privacy & Security → Apple Advertising → turn off Personalised Ads. On Android, Settings → Google → Ads → delete or reset your advertising ID and opt out of ads personalisation.
- Change your ad consent. Where the consent message applies to you, you can change your choice from the privacy option in the App if one is shown. Otherwise, deleting and reinstalling the App clears the stored consent and the message will be presented again.
- Clear the on-device data. Deleting the App removes your best time, run count and crash count from your device permanently.
7. Your rights (UK and EEA)
If you are in the UK or the EEA you have the right to request access to your personal data, and to request its correction, deletion or restriction; to object to processing based on legitimate interests; to portability; and to withdraw consent at any time, without affecting processing carried out before you withdrew it.
Because the App holds no account and no directly identifying information, we usually cannot connect a request to a specific person on our own. To help us act on a request about advertising or analytics data, please contact us and, where you can, include your device advertising identifier. You also have the right to lodge a complaint with your data protection authority — in the UK, the Information Commissioner’s Office.
8. California privacy rights (CCPA / CPRA)
In the past 12 months the App has enabled the collection of the following categories of personal information: identifiers (device advertising identifier, app instance identifier, IP address); internet or other network activity (ad interactions, in-app events); coarse geolocation inferred from IP address; and device information. These are used for the advertising, measurement, security and product purposes described above.
We do not sell personal information for money. However, allowing personalised advertising means identifiers are shared with advertising partners for cross-context behavioural advertising, which counts as a “sale” or “share” under the CPRA. You can opt out at any time by declining the ATT prompt, refusing consent in the ad-consent message, or emailing us at hello@horizonsoftware.co.uk.
California residents also have the right to know, to delete and to correct personal information, the right to limit the use of sensitive personal information (we do not collect any), and the right not to be discriminated against for exercising these rights. We do not knowingly sell or share the personal information of anyone under 16.
9. Children’s privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided personal information through the App, contact us at hello@horizonsoftware.co.uk and we will take steps to delete it and to remove the associated identifiers from our partners where we are able to.
10. Data retention
On-device data (best time, lifetime runs, lifetime crashes) is kept until you delete the App. Analytics events are retained by Google Firebase for the retention period we configure in the Firebase console, after which they are deleted or kept only in aggregate form that cannot be linked to a device. Advertising data is retained by Google under its own policies and retention schedules. Correspondence you send us is kept for as long as we need it to deal with your query, and then deleted.
11. International transfers
Our providers are Google and Apple, and data may be processed on servers outside the UK and the EEA, including in the United States. Where data is transferred out of the UK or the EEA, it is protected by appropriate safeguards — typically the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, as set out in the providers’ own terms.
12. Security
The App holds no account credentials and no personal profile, which removes most of the risk in the first place. Data in transit between the App and our providers is encrypted using industry-standard transport security. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Changes to this policy
If we change how the App handles data we will update this page and change the “Last updated” date at the top. If a change is significant — for example a new category of data, or a new purpose — we will present it in the App before it takes effect where the law requires that. Continuing to use the App after a change means you accept the updated policy.
14. Contact us
Questions about this policy, or about your data — New Horizon Software Ltd, hello@horizonsoftware.co.uk.
We aim to reply within two business days, and to substantive data protection requests within one month, as the GDPR requires.