Privacy Policy

Mahjong Ways (“we,” “our,” or “us”) is committed to protecting any personal data you share with us (“Personal Data”). We follow the EU General Data Protection Regulation (GDPR) (EU 2016/679) and this policy explains—in human terms—what we collect, how we use it, how long we keep it, who we share it with, and the rights you have.

Scope: This policy applies to Mahjong Ways and any wholly owned subsidiaries we directly or indirectly control in the EU/EEA.


1) Quick Intro

  • This policy is issued by Run Good NV (registered address: 9 Abraham de Veerstraat, Willemstad, Curaçao) on behalf of PG Soft.
  • By using our services, you acknowledge you’ve read this policy. If you choose not to provide certain data, some features may not work.
  • This policy is part of our Terms of Service.
  • Unless we define them here, GDPR definitions apply (e.g., controller, processor, data subject, processing, pseudonymization, etc.).
  • Our GDPR principles:
    lawful, fair, transparent · purpose-limited · data-minimized · accurate & up-to-date · stored no longer than necessary · confidential & secure · no third-party sharing without consent or a valid legal basis · full data-subject rights (access, rectification, erasure, restriction, objection, portability).

2) Data We Collect

When you create an account or use our services, we may collect:

  • Identity & contact info (name, email, phone, date of birth), government ID (where required by law).
  • Device and network info (IP address, device identifiers such as MAC where applicable, browser data).
  • Transaction data (payment method details handled via approved processors), gameplay participation, and related logs.

3) How We Use Your Data (Legal Bases under GDPR)

We process Personal Data to:

  • Set up and manage your account and provide personalized services.
  • Respond to support requests and send service updates/notifications.
  • Verify accuracy and prevent fraud or abuse.
  • Meet legal and regulatory obligations (including AML/KYC where applicable).
  • Conduct market research, product/service analytics, and statistics.
  • Send promotions/marketing only with your explicit consent (you can opt out anytime).
  • Fulfill contractual needs and other purposes compatible with the original collection purpose.

Payments: Your payment details may be stored by our PCI-compliant partners to streamline future transactions.
Withdraw consent / stop processing: Contact support@pgsoft.com (note: some requests may require account closure to take effect).
Quality & safety: We may monitor and record communications for training, quality assurance, and security.
If we change how we use your data, we’ll notify you and ask for fresh consent if required.


4) Sharing Your Data (When & With Whom)

We share data only when necessary and with safeguards in place:

  • Within the PG Soft group and with vetted partners (e.g., payment processors).
  • Verification and due-diligence providers.
  • Fraud-prevention bodies and relevant regulators.
  • Auditors and legal advisors.
  • Law enforcement or authorities when legally required.
  • Potential investors or acquirers under strict confidentiality.

Third parties must follow applicable data-protection rules.
Community features/chats: Be mindful—what you share there is at your own risk.
To stop certain processing, email support@pgsoft.com.


5) Your GDPR Rights

You can:

  • Know what we collect and access your data.
  • Correct inaccurate data or delete it where appropriate.
  • Restrict or object to processing in certain cases.
  • Port your data (receive it in a structured, commonly used format).
  • Complain to a supervisory authority and withdraw consent at any time.

How to exercise: email support@pgsoft.com. We’ll acknowledge within 72 hours and aim to complete requests within one month (we may extend for complex cases).
You can update some details in your account settings. We may keep limited backups where required by law.
We can refuse manifestly unfounded/excessive requests and may charge a reasonable fee for complex portability tasks.


6) Contact Us

Questions or requests: support@pgsoft.com


7) Cookies & Tracking

  • We use cookies to improve your experience (not to store sensitive personal identifiers in plain text).
  • You can block cookies in your browser, but some features may break (login, promos, certain services).
  • We use cookies and web beacons for analytics and language preferences.
  • We are not responsible for third-party sites’ privacy practices. See our separate Cookie Policy for details.

8) Minors

Our services are not intended for individuals under 18. We don’t knowingly collect data from minors. If we learn we’ve collected such data, we’ll delete it promptly.


9) Security

We apply technical and organizational measures to prevent loss, misuse, and unauthorized access. Sensitive info is limited to authorized personnel and stored using appropriate encryption and access controls. No system is 100% secure, but we continuously improve our defenses.


10) Data Breaches

If a personal-data breach occurs, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users when the risk is high.


11) Privacy Controls

We offer privacy settings where possible, but no online platform can guarantee absolute protection against unauthorized viewing. Use strong passwords and keep your credentials private.


12) Data Retention

We keep Personal Data only as long as necessary for the purposes stated—generally no longer than eight (8) years unless law requires otherwise. Payment data may be deleted earlier on valid request, subject to legal retention duties.


13) International Transfers

Your data may be processed or stored outside the EU/EEA (for example, in Canada or other jurisdictions). We use appropriate safeguards for cross-border transfers (e.g., Standard Contractual Clauses, adequacy decisions).


14) Data Protection Officer (DPO)

Contact our DPO at data-protection@pgsoft.com. We’ll respond within 30 days and may ask for proof of identity to protect your account.


15) Accountability

We run regular data-protection impact assessments (where required), maintain processing records, and monitor compliance.


16) Governing Law

If this policy conflicts with a local law that applies to you, the law prevails.


17) Changes to This Policy

We’ll notify you by email or on-site notice if we make material updates. The “Last updated” date will change accordingly.