Legal
Privacy Policy
Social Evergreen is a free social gaming platform for players in Australia. We hold as little information about you as the service allows, and this document explains exactly what that is.
1. Overview
This Privacy Policy describes how Social Evergreen ("we", "us", "our") handles personal information in connection with socialevergreen.com and the Evergreen Bloom game (together, the "Service"). The Service is a free social casino offered for entertainment only: it involves no real-money gambling, no deposits, no withdrawals and no cash prizes, and we therefore never collect payment card details, bank details or financial identifiers of any kind.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs). Where this policy uses the term "personal information", it has the meaning given in that Act.
By creating an account or using the Service you accept the practices described here. If you do not agree with them, please do not use the Service.
2. Information we collect
2.1 Account information
When you register we collect your email address and a password. The password is never stored in readable form — we keep only a one-way cryptographic hash produced with a modern, salted hashing algorithm. We also generate a display name for your grove, which you may change; it does not need to be your real name and we ask you not to use one.
If you sign in with Google, we receive your Google account identifier, email address and, where provided, your given name. We do not receive or store your Google password.
2.2 Gameplay information
We record your virtual coin balance, a short history of recent rounds (spin cost, award and outcome, all denominated in virtual coins), the date of your last free daily top-up, and the play-control preferences you set: quiet mode and any optional daily play limit. This information exists to make the game work across sessions and to honour the limits you choose.
2.3 Technical information
Our servers log the IP address, user agent and timestamp associated with requests, sign-in attempts and password-reset requests. This is used to keep accounts secure, to apply rate limits against automated abuse, and to diagnose faults. Security logs are retained for a limited period and then deleted.
2.4 Communications
If you contact support we retain your name, email address, subject and message so that we can respond and keep a record of the issue.
2.5 What we never collect
We do not collect payment information, government identifiers, precise location, contact lists, biometric data or advertising identifiers. Because nothing in the Service can be purchased, there is no billing relationship to record.
3. How we use information
- To operate the Service — authenticate you, maintain your session, keep your virtual coin balance and progression, and deliver the game itself.
- To keep accounts secure — detect and slow brute-force sign-in attempts, validate password-reset links, and investigate suspected abuse.
- To support you — respond to messages, handle account and data requests, and apply responsible-play controls you ask for.
- To improve the product — understand which parts of the experience are used, in aggregate and without profiling individuals.
- To meet legal obligations — where retention or disclosure is required by applicable law.
We do not sell personal information, we do not share it with data brokers, and we do not use it for behavioural advertising.
4. Why we are allowed to collect this
Under APP 3 we collect only personal information that is reasonably necessary for our functions and activities. In practice that means:
- To provide the account you asked for — an email address and a password hash are the minimum needed to sign you in and keep your grove.
- To keep the Service secure — technical logs and rate-limit records exist to protect accounts against automated abuse.
- With your consent — anything optional, such as future updates, requires you to opt in first, and you can withdraw that consent at any time.
- Where the law requires it — retention or disclosure compelled by Australian law or a court order.
We will not use or disclose your personal information for a secondary purpose unless APP 6 permits it. You may deal with us anonymously or under a pseudonym for general enquiries (APP 2), although we cannot action account-specific requests without verifying the account.
5. Cookies and similar technologies
We use a small number of first-party cookies: a session cookie that keeps you signed in and a token used to protect forms against cross-site request forgery. Cookies set by the Service are marked HttpOnly and SameSite where appropriate, and Secure when served over HTTPS.
Play preferences — quiet mode, an optional daily play limit, the age-gate choice and a guest virtual-coin balance — are stored in your browser's local storage, not in advertising cookies. We do not use advertising cookies or third-party tracking pixels. Full detail is in our Cookie Policy.
6. Analytics
If and where analytics are enabled on the Service, they are configured to measure aggregate usage — page views, broad device categories and error rates — rather than to identify or profile individuals. IP addresses used for analytics are truncated or anonymised before storage where the provider supports it. Any change to this approach will be reflected in this policy and in the Cookie Policy before it takes effect.
7. Service providers
We rely on a small number of processors to run the Service: a hosting provider that operates the servers and database, an email provider that delivers transactional messages such as password resets, and — where you choose to use it — Google, for Google Sign-In. Each processor receives only the information needed for its function, is bound by contractual confidentiality and security obligations, and is not permitted to use your information for its own purposes.
8. How we protect information
- Passwords are stored only as salted one-way hashes; nobody at Social Evergreen can read them.
- All database access uses parameterised, prepared statements.
- Forms are protected by per-form CSRF tokens; output is escaped to prevent cross-site scripting.
- Sessions use HttpOnly, SameSite cookies, marked Secure in production, with periodic identifier regeneration and idle timeouts.
- Sign-in and password-reset endpoints are rate limited per account and per network address.
- Password-reset tokens are single-use, expire within 45 minutes, and are stored only as hashes.
- Security headers, including a Content Security Policy, are applied to every response.
No system is perfectly secure. If we become aware of a data breach likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
9. Data retention
Account information is retained while your account is open. Gameplay history is retained on a rolling basis and older rounds are pruned. Security logs, including sign-in attempts and reset requests, are retained for a limited period and then deleted. Support correspondence is kept for as long as needed to resolve the matter and to maintain a record of it.
When you delete your account, we remove your account record, gameplay history and play-control preferences. Residual copies may persist in encrypted backups for a short period before those backups rotate out.
10. Your rights
Under APP 12 and APP 13 you may request access to the personal information we hold about you and ask us to correct anything inaccurate, out of date or incomplete. You may also ask us to delete your account and everything attached to it, and to withdraw any consent you have given.
To make a request, email support@socialevergreen.com from the address registered to your account. We aim to respond within 30 days, consistent with the Australian Privacy Principles, and we do not charge for access requests.
If you are unhappy with how we have handled your personal information, tell us first so we can put it right. If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
11. Deleting your account
You can request deletion at any time from your account area or by emailing support@socialevergreen.com from your registered address. Deletion is permanent. Virtual coins, badges, themes and progression are erased with the account; because none of these carry monetary value, nothing of value is lost in the process.
12. Children's privacy
The Service is intended for adults aged 18 and over in Australia and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact support@socialevergreen.com and we will close the account and delete the associated information.
13. Overseas disclosure
Social Evergreen is intended for players in Australia and we prefer to keep data onshore. Where a service provider stores or processes personal information outside Australia — a hosting region or an email provider, for example — we take the reasonable steps required by APP 8 to ensure the recipient handles it consistently with the Australian Privacy Principles before any disclosure is made. We will name the countries involved on request.
14. Communications
We send transactional email only: password resets, essential security notices and replies to your support messages. These are necessary to operate the account and cannot be unsubscribed from while the account is open. If we ever introduce optional updates, they will require explicit opt-in and will carry an unsubscribe link in every message.
15. Changes to this policy
We may update this policy as the Service develops or as legal requirements change. The "last updated" date at the top of this page always reflects the current version. Material changes will be announced on the Service before they take effect, and where required we will seek your consent.
16. Contact us
Questions about this policy, or about how your information is handled, should go to support@socialevergreen.com. You can also use our contact form. The APP entity responsible for the personal information described here is Social Evergreen, operating from Australia. Governing law is identified in the Terms of Use.