Effective as of: December 13, 2019
You should also read our Terms of Service which set out the contract between you and Niantic.
1. Who decides how your information is used?
Niantic, Inc. is the data controller responsible for making decisions about how we use your personal information if you are based outside of the European Economic Area (EEA). If you are based in the EEA, your data controller is Niantic International Limited in the United Kingdom.
If you have any questions or comments on this policy, you can:
2. The information we collect about you and how we use it
We need to collect and use certain Personal Data to provide the Services to you and fulfil the promises we make to you in the Terms of Service:
- When you sign up for our Services you give us Personal Data voluntarily by providing it to us, for example when you sign up for an account. We collect and use that information in order to authenticate you when you register an account and use the Services, to make sure you are eligible and able to receive the Services, and so that you receive the correct version of the Services. That information includes the in-game username you choose to use on our Services, and internal account IDs that we assign to your account.
If you choose to link your Google account to the Services, we will collect your Google email address and an authentication token provided by Google.
If you choose to link your Facebook account to the Services, we will collect a unique user ID provided by Facebook and, if permitted by you, your Facebook registered email address.
Some external providers may notify you that they make additional information, such as your public profile, available to us when you use their single sign-on services. We do not collect that information from them.
We collect and use your device location information as you use our Services (and, if you elect to turn on background location tracking for our Services, while you are not directly interacting with the Services), including how you move around and events that occur during gameplay. Our Services include location based games whose core feature is to provide a gameplay experience tied to your real world location, so we need to know where you are to operate these games for you, and to plan the location of in-game resources (for example PokéStops within Pokémon GO). We identify your location using a variety of technologies, including GPS, the WiFi points you are accessing the Service through and mobile/cell tower triangulation.
We also collect and use your in-game actions and achievements, as well as certain information about your mobile device (including device identifiers, device OS, model, configuration, settings and information about third party applications or software installed on your device), to operate the Services for you.
We also use the information above to show in-game sponsored locations that are in your vicinity as part of the gameplay experience.
We further use the information above in order to provide technical and customer support to you.
You also give us Personal Data when you make a purchase through us, subscribe to our publications, register for a live event, enter a competition, promotion, sweepstakes or survey or communicate with us. Depending on which of these Services you use, that may include your name, mailing address, phone number, country of residency, date of birth (as needed to verify eligibility), and email address. We use that information to fulfil those Services to you and to provide related customer support to you.
In addition, we have and rely on a legitimate interest in using your Personal Data as follows:
- Using your IP address, browser type, operating system, the web page you were visiting before accessing our Services, the pages of our Services which you browsed or the features you used, and the time spent on those pages or features, the links on our Services that you click on, device and advertising identifiers, as well as actions you take during gameplay, your in-game user settings and preferences and your in-app purchases to understand who is using our Services and how.
- Using your contact information, namely your email address in order to communicate with you to provide technical and customer support.
- Using your internal account ID in order to attribute to your account any user content (such as local points of interest) that you elect to submit to Niantic through the Services.
- Using your email address and device information in order to share updates and news about the Services with you either within the games or by email. You can unsubscribe from these at any time in your device settings or in-app settings.
- To provide social features within our games so you can interact and play with other players, including storing your communications with those players, find your friends and be found by them, and share your gameplay experience and achievements with your friends.
- To offer new or additional features for our Services.
- To organize and run live events based on or featuring our games. Note that when you participate in live events your in-game actions and achievements, in-game username and your avatar, team, and other components of your in-game profile will be visible to other event participants and to the public (for example on leaderboards displayed at the event and online).
- Using your in-game actions and achievements, as well as certain information about your mobile device (including device identifiers, device OS, model, configuration, settings and information about third party applications or software installed on your device), to carry out anti-fraud and anti-cheating measures against behaviors prohibited under our Terms of Service, to ensure that we provide a fair gaming experience to all players.
- To make legal or regulatory disclosures and to establish, exercise, or defend legal claims.
We will only use your Personal Data to do the following if we have your consent:
If you elect to turn on background activity tracking in our Services (for example Adventure Sync in Pokémon GO) we will collect your Personal Data as you use the Services as well as in the background when you do not have the Services open on your device. This includes your device location and your fitness activity data (such as Step Count, Calories Burned, and Distance Walked). We use background activity tracking to provide you certain functionalities in the Services such as in-game items and rewards tied to your fitness activity level and alerts for nearby gameplay events. You can change your mind and turn off background activity tracking at any time in your device settings or in-app settings.
With your permission we use your device’s health app (Apple HealthKit if you use an Apple device, or Google Fit if you use an Android device) to collect your fitness activity data: we read and/or write your fitness activity data to your device’s health app to operate background activity tracking and to ensure you get “credit” in your device’s health app for all of the walking you do while playing our games. We do not use data collected through Apple Health Kit or through Google Fit for marketing or advertising purposes. Our Services cannot read from or write to your device’s health app without your consent. You can change your mind and disable our access to any type of fitness activity data at any time in your Apple Health or Google Fit app settings on your device.
If you elect to enable the Facebook User Friends permission available in some of our games, we will import from your linked Facebook account the list of your friends who also play the game and enabled Facebook User Friends. If you enable that permission, your Facebook profile picture and the name on your Facebook account will be visible to your friends in-game. You can change your mind and unfriend other players at any time from your in-app Friends settings. You can also revoke Facebook permissions for our games directly from your Facebook account settings.
- If you elect to add information about Niantic live events to your mobile calendar, we will, with your permission, access your device’s calendar and write in these events. We do not access or collect any other information from your calendar. You can change your mind and disable access to your calendar at any time in your device settings.
- If you elect to help Niantic in its efforts to develop new Augmented Reality (AR) mapping technology, you have the option, in participating games, to opt in to film public spaces around points of interest and send us your video recordings, along with associated device geospatial information. We do not collect audio on these recordings. We will anonymize this information through various means, including blurring, and use it to build a 3D understanding of real-world places, with the goal of offering new types of AR experiences to our users. You can change your mind at any time by disabling this feature in your in-app settings.
- If you elect to connect your game account with an authorized external device, such as the Pokémon Go Plus or Poké Ball Plus, we request Bluetooth permissions from your mobile device in order to connect it with the external device and enable associated game features. You may change your mind at any time by disabling our access to Bluetooth in your device settings or by disconnecting the external device from the game.
- Send you marketing materials by email or via in-app notifications. You can unsubscribe from these at any time in your device settings or in-app settings.
While you may disable the usage of cookies through your browser settings, Niantic currently does not respond to a “Do Not Track” signal in the HTTP header from your browser or mobile application due to the lack of industry standard on how to interpret that signal.
3. Who we share information with
We will not share any Personal Data that we have collected from or regarding you except as described below:
- run, operate and maintain our mobile games through third party platform and software tools;
- perform content moderation and crash analytics;
- run email and mobile messaging campaigns;
- perform game and marketing analytics;
- administer live events, competitions, sweepstakes and promotions, including registering players, managing check-in and attendance, verifying eligibility and prize fulfilment;
- provide technical and customer support; and
- process payments for live events ticketing or other purchases.
Information Shared with Third Parties. We share Anonymous Data with third parties for industry and market analysis. We may share Personal Data with our third-party publishing partners for their direct marketing purposes only if we have your express permission. We do not share Personal Data with any other third parties for their direct marketing purposes.
Information Disclosed for Our Protection and the Protection of Others. We cooperate with government and law enforcement officials or private parties to enforce and comply with the law. We only share information about you to government or law enforcement officials or private parties when we reasonably believe necessary or appropriate: (a) to respond to claims, legal process (including subpoenas and warrants); (b) to protect our property, rights, and safety and the property, rights, and safety of a third party or the public in general; and (c) to investigate and stop any activity that we consider illegal, unethical, or legally actionable.
Information Disclosed in Connection with Business Transactions. Information that we collect from our users, including Personal Data, is a business asset. If we are acquired by a third party as a result of a transaction such as a merger, acquisition, or asset sale or if our assets are acquired by a third party in the event we go out of business or enter bankruptcy, some or all of our assets, including your Personal Data, will be disclosed or transferred to a third party acquirer in connection with the transaction.
4. How your Personal Data is transferred
If we transfer your Personal Data from the EEA to other countries, including the USA, we ensure that a similar degree of protection is provided to your Personal Data as within the EEA by ensuring that at least one of the following safeguards is implemented:
- The country that your Personal Data is transferred to is a country that the European Commission has deemed to provide an adequate level of protection for Personal Data as the EEA.
- We use specific contracts approved by the European Commission which give Personal Data the same protection as it has in Europe when we engage with service providers.
- Where we engage with service providers in the USA, they are part of the EU-US Privacy Shield, which requires them to provide the same protection of your Personal Data as it has in the EEA.
5. How we keep your Personal Data safe
We have appropriate security measures in place to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorized way, improperly altered or disclosed. We also limit access to your Personal Data to employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
6. How long we will keep your Personal Data
When we no longer need to use your Personal Data and there is no need for us to keep it to comply with our legal or regulatory obligations, we will either remove it from our systems or anonymize it so that it can no longer be associated with you. When removing Personal Data, we will take commercially reasonable and technically feasible measures to make said Personal Data irrecoverable or irreproducible.
7. Your rights and choices
You have certain rights in relation to your Personal Data. In order to exercise these rights, please contact us at:
- For Pokémon GO here.
- For Ingress here.
- For Harry Potter: Wizards Unite here.
- For all other Services at email@example.com.
- Request access to the Personal Data we hold on you by emailing firstname.lastname@example.org.
- Delete or correct your Personal Data. The easiest way to update your account information is via your in-app settings. You can also submit a customer support request through our support website here for Pokémon GO, here for Ingress, or here for Harry Potter: Wizards Unite.
- Object to us processing your Personal Data. Some of the Personal Data we hold is necessary for us to provide the Services to you and fulfill the promises we make to you in the Terms of Service.
- Ask us to stop using your Personal Data, including for marketing and promotional purposes (but be aware that sometimes we need to use your Personal Data in order for you to use the Services).
- Have your Personal Data transferred to another organization (where it is technically feasible).
- Complain to a regulator. We'd appreciate the chance to deal with your concerns directly so we'd prefer you to contact us first. However, if you're based in the EEA and believe that we have not complied with data protection laws, you can complain to our regulator, the UK Information Commissioner’s Office, or with your local supervisory authority.
The law provides exceptions to these rights in certain circumstances. Where you cannot exercise one of these rights due to such an exception, we will explain to you why.
We offer you choices regarding the collection, use, and sharing of your Personal Data and we’ll respect the choices you make. Please note that if you decide not to provide us with the Personal Data that we request, you may not be able to access all of the features of the Services.
After you contact us, you may receive an email in order to verify your request. We aim to provide the information or complete the outcome you request within 30 days.
Unless stated otherwise for a particular Service, children are not allowed to use the Services, and we do not collect Personal Data from them. We define “children” as follows:
- Residents of the EEA: anyone under 16 years old, or the age needed to consent to the processing of personal data in your country of residence.
- Residents of the Republic of Korea, anyone under 14 years old.
- Residents of other regions: anyone under 13 years old
Niantic Game Resources contains information on the age requirement for each of our Apps.
For Services that permit Child participation, parents or legal guardians ("Parents") must provide verified consent. Parents can provide and verify their consent through the Niantic Kids Parent Portal, or through another authorized third-party provider made available through the Service. Where Parental consent is required, Niantic recommends that Parents monitor the Child’s online activity and use of the Service.
The Niantic Kids Parent Portal is operated on Niantic’s behalf by Kids Web Services (KWS), a product of SuperAwesome Trading Ltd of 40 Long Acre, London WC2E 9LG, United Kingdom, www.superawesome.tv. You may contact SuperAwesome directly at email@example.com or +44 203 668 6677 for any questions related to their handling of user information, especially parent information. KWS is certified by the kidSAFE Seal Program, an FTC-Approved COPPA Safe Harbor Program. SuperAwesome is also a valid licensee, and participating member, of the Entertainment Software Rating Board’s Privacy Certified Program (“ESRB Privacy Certified”).
Verifiable parental consent is required for the collection, use, or disclosure of a child's Personal Data. Niantic will not collect, use, or disclose any Personal Data from a child if their parent or guardian does not provide such consent. We may ask a Child to provide a Parent’s email address in order to request this consent, and the Parent’s email address will be deleted if consent is not provided within a reasonable time.
If we learn that we have collected Personal Data of a Child, and we do not have parental consent, we will take steps to delete such information from our files as soon as possible.
If you have questions about our privacy practices for Children, please contact us at firstname.lastname@example.org or Niantic Inc., 1 Ferry Building, Suite 200, San Francisco, CA 94111.
10. Third Parties
11. Disclosures Specific to California Residents
California law requires that we make certain disclosures about your data. We do not sell your Personal Data. The information listed in Section 2 falls under the following California Consumer Privacy Act (CCPA) categories: identifiers, commercial information, Internet or other electronic network activity information, geolocation data, and visual information.
12. Game Specific Disclosures
Additional Privacy Information for Pokémon GO
Pokémon Trainer Club Accounts. You can sign up for Pokémon GO using your external Pokémon Trainer Club (“PTC”) account administered by The Pokémon Company International (“TPCI”). If you choose to do so, we will collect from TPCI your PTC registered email address, your PTC username and a unique PTC user ID. If you are registering your PTC account on behalf of your authorized child we will also collect some Personal Data about your child. See the “Accounts with Children” paragraph below for more information.
For U.S. residents, after a Parent has registered a PTC account, TPCI will verify the Parent’s identity by asking for the sum of the first and last digits of the Parent’s social security number and the Parent’s name, date of birth, and street address. TPCI will not share that information with us. After TPCI verifies the Parent’s identity, it will ask the Parent to consent to the Child accessing Pokémon GO. If a Parent does not consent to a Child’s access to and use of Pokémon GO or does not verify their identity through the consent process, Niantic will bar that Child’s registration on Pokémon GO and prevent the Child’s access to and use of the game.
Information shared with other players. When you take certain actions in Pokémon GO and capture a Gym, your (or your authorized Child’s) username will be shared publicly through the game, including with other players, in connection with that Gym location.
Additional Privacy Information for Ingress
Information shared publicly. When you play Ingress, as part of the gameplay the following information about you will be shared through the game (including with other players directly within the app, in game notifications emailed to other players as part of the gameplay, and online on the Ingress Intel Map website), and will therefore become publicly available: your in-game username, messages sent to other users in COMMS, and in-game portals that you interact with, as well as your device location whenever you take an in-game action.