Please, rotate your device

Mobile apps and games

ARTICLE 1. PURPOSE

1.1. Objective

This Security Policy establishes the principles for responsibly reporting potential security vulnerabilities affecting the Website.

Its purpose is to encourage coordinated vulnerability disclosure while protecting Users, researchers, and the Website from unnecessary risk.


1.2. Scope

This Policy applies to security issues relating to publicly accessible components of the Website, including where applicable:

  • web pages;

  • APIs;

  • authentication systems;

  • user interfaces;

  • infrastructure components;

  • publicly accessible services;

  • and other online resources operated by PlayMarket.


1.3. Good Faith Reporting

PlayMarket welcomes vulnerability reports submitted in good faith.

Security researchers acting responsibly and in accordance with this Policy help improve the security of the Website.


1.4. Coordinated Disclosure

PlayMarket encourages researchers to privately report vulnerabilities before publicly disclosing them.

Responsible coordination allows issues to be investigated and, where appropriate, remediated before details become widely available.


1.5. Relationship with Other Policies

This Policy should be read together with the:

  • Terms of Use;

  • Privacy Policy;

  • Acceptable Use Policy;

  • Editorial Policy;

  • Notice & Takedown Policy;

  • and other applicable legal documents published on the Website.


ARTICLE 2. RESPONSIBLE DISCLOSURE PRINCIPLES

2.1. Good Faith Security Research

Researchers are encouraged to act in good faith and avoid actions that could reasonably result in harm to:

  • Users;

  • the Website;

  • third parties;

  • or PlayMarket's infrastructure.


2.2. No Unauthorized Access

Researchers should not intentionally:

  • access accounts belonging to other Users;

  • obtain personal information;

  • modify data;

  • delete information;

  • upload malicious content;

  • interrupt services;

  • or interfere with normal Website operations.


2.3. Privacy

Any personal information encountered during security testing should be treated as confidential.

Researchers should discontinue testing if personal or confidential information is unintentionally exposed and promptly report the issue.


2.4. Minimal Impact Testing

Security testing should be designed to minimize disruption to the Website and its Users.

Testing that intentionally degrades service availability or performance should be avoided.


2.5. No Social Engineering

This Policy does not authorize social engineering, phishing, physical attacks, credential theft, or attacks against employees, contractors, partners, hosting providers, or third parties.


2.6. Compliance with Law

Nothing in this Policy authorizes conduct prohibited by Applicable Law.

Researchers remain responsible for ensuring that their activities comply with all applicable legal requirements.


ARTICLE 3. REPORTING A VULNERABILITY

3.1. Contact Method

Security vulnerabilities should be reported privately using the contact information published by PlayMarket.

Security reports should not be disclosed publicly before the review process has been completed unless otherwise agreed.


3.2. Information to Include

To facilitate investigation, reports should include, where reasonably practicable:

  • a description of the vulnerability;

  • affected URLs or systems;

  • steps to reproduce the issue;

  • proof-of-concept information where appropriate;

  • potential impact;

  • browser or operating system information;

  • screenshots or logs where relevant;

  • and the reporter's contact information.


3.3. Supporting Materials

Where available, researchers are encouraged to include sufficient technical information to allow the issue to be reproduced and verified.


3.4. Confidentiality

PlayMarket will make reasonable efforts to treat vulnerability reports as confidential during the investigation process, subject to Applicable Law.


3.5. Duplicate Reports

Where multiple reports describe the same vulnerability, PlayMarket may treat them as a single issue for investigation purposes.


3.6. Good Faith Cooperation

PlayMarket appreciates constructive communication with researchers throughout the investigation and remediation process.

ARTICLE 4. SECURITY RESPONSE PROCESS

4.1. Initial Review

Upon receiving a vulnerability report, PlayMarket will make reasonable efforts to review the submission and determine whether sufficient information has been provided to begin an investigation.

Where additional details are necessary, the reporter may be contacted for clarification.


4.2. Investigation

PlayMarket may investigate reported vulnerabilities by:

  • reproducing the reported issue;

  • reviewing relevant systems;

  • assessing potential impact;

  • evaluating exploitability;

  • determining affected components;

  • and identifying appropriate remediation measures.

Not every reported issue will necessarily be confirmed as a security vulnerability.


4.3. Risk Assessment

Confirmed vulnerabilities may be evaluated based on factors including:

  • potential impact;

  • likelihood of exploitation;

  • affected Users;

  • affected systems;

  • confidentiality risks;

  • integrity risks;

  • availability risks;

  • and overall business impact.

PlayMarket reserves discretion in determining remediation priorities.


4.4. Remediation

Where appropriate, PlayMarket may:

  • correct software defects;

  • update configurations;

  • modify infrastructure;

  • improve monitoring;

  • implement additional safeguards;

  • strengthen internal procedures;

  • or apply other reasonable security measures.


4.5. Public Disclosure

Where appropriate, PlayMarket may publish information regarding resolved vulnerabilities after remediation has been completed.

Such disclosure may include technical information reasonably necessary to improve transparency or promote security awareness, provided it does not create unnecessary security risks.


4.6. Reservation of Rights

PlayMarket reserves the right to determine the appropriate investigation process, remediation approach, disclosure timing, and communication strategy for each reported issue.


ARTICLE 5. OUT-OF-SCOPE ACTIVITIES

5.1. Unauthorized Testing

The following activities are outside the scope of this Policy and are not authorized:

  • denial-of-service (DoS) attacks;

  • distributed denial-of-service (DDoS) attacks;

  • ransomware;

  • malware deployment;

  • destructive testing;

  • credential stuffing;

  • brute-force attacks;

  • phishing;

  • spam campaigns;

  • or other malicious activities.


5.2. Third-Party Services

This Policy does not authorize testing of:

  • hosting providers;

  • payment processors;

  • advertising platforms;

  • analytics services;

  • cloud providers;

  • affiliate systems;

  • external APIs;

  • or other third-party services that are not owned or operated by PlayMarket.

Reports concerning third-party systems should generally be directed to the relevant service provider.


5.3. Physical Security

This Policy does not authorize:

  • physical intrusion;

  • unauthorized access to facilities;

  • theft of equipment;

  • surveillance;

  • hardware tampering;

  • or similar activities.


5.4. Social Engineering

Attempts to deceive employees, contractors, business partners, Users, or service providers into revealing confidential information are strictly outside the scope of this Policy.


5.5. Excessive Testing

Security testing that unreasonably degrades system performance, consumes excessive resources, disrupts Website availability, or negatively affects Users is prohibited.


5.6. Reservation of Rights

Activities outside the scope of this Policy may be investigated and addressed in accordance with Applicable Law and the Website's legal policies.


ARTICLE 6. SAFE HARBOR

6.1. Good Faith Researchers

Where security research is conducted in good faith, in accordance with this Policy, and in compliance with Applicable Law, PlayMarket intends to work cooperatively with the reporting individual to understand and resolve the reported issue.


6.2. Responsible Conduct

To remain within the spirit of this Policy, researchers should:

  • avoid accessing unnecessary data;

  • avoid modifying or deleting information;

  • immediately cease testing if significant risk is identified;

  • maintain confidentiality during the review process;

  • and cooperate with reasonable requests for clarification.


6.3. No Reward Program

Unless expressly announced by PlayMarket, this Policy does not establish a bug bounty or financial reward program.

Submission of a vulnerability report does not create any entitlement to compensation.


6.4. Independent Assessment

PlayMarket reserves the sole discretion to determine:

  • whether reported behavior constitutes a security vulnerability;

  • the severity of any confirmed issue;

  • appropriate remediation measures;

  • and whether any public acknowledgment will be provided.


6.5. No Contractual Relationship

Submission of a vulnerability report does not create an employment relationship, partnership, agency, joint venture, contractual obligation, or other legal relationship between PlayMarket and the reporting individual.


6.6. Good Faith Cooperation

PlayMarket values constructive cooperation with the security community and appreciates responsible disclosures that contribute to improving the security of the Website.

ARTICLE 7. CONFIDENTIALITY AND COMMUNICATION

7.1. Confidential Handling of Reports

PlayMarket recognizes that vulnerability reports often contain sensitive technical information.

Subject to Applicable Law, information submitted through the responsible disclosure process will be handled confidentially and shared only with individuals or service providers who reasonably require access to investigate, validate, remediate, or coordinate the reported issue.


7.2. Confidentiality Expectations

Security researchers are encouraged to maintain the confidentiality of reported vulnerabilities until:

  • the vulnerability has been remediated;

  • PlayMarket confirms that public disclosure is appropriate;

  • or sufficient time has elapsed to allow reasonable remediation efforts.

This coordinated approach helps reduce unnecessary security risks for Users.


7.3. Public Disclosure

Where public disclosure is appropriate, PlayMarket may coordinate with the reporting researcher regarding:

  • disclosure timing;

  • technical accuracy;

  • mitigation status;

  • affected components;

  • and other relevant information.

Nothing in this Policy obligates PlayMarket to publish a security advisory or disclose technical implementation details.


7.4. Communication

PlayMarket will make reasonable efforts to communicate with researchers during the review process where additional clarification is required.

However, due to operational priorities, PlayMarket cannot guarantee individualized updates or ongoing correspondence for every report received.


7.5. Third-Party Coordination

If a reported vulnerability primarily affects infrastructure, software, or services operated by a third party, PlayMarket may coordinate with the relevant provider where appropriate or recommend that the report be submitted directly to the responsible organization.


7.6. Good Faith Dialogue

PlayMarket values respectful, professional, and constructive communication throughout the responsible disclosure process and seeks to maintain cooperative relationships with the security research community.


ARTICLE 8. LIMITATION OF LIABILITY

8.1. No Guarantee of Security

While PlayMarket implements reasonable technical, organizational, and administrative safeguards, no website, network, software application, or online service can guarantee absolute security.

Users acknowledge that cybersecurity risks cannot be entirely eliminated.


8.2. Evolving Threat Landscape

Cybersecurity threats evolve continuously.

Accordingly, PlayMarket may modify its security controls, operational procedures, monitoring capabilities, or technical architecture without prior notice whenever reasonably necessary to maintain or improve security.


8.3. No Warranty

Nothing in this Security Policy constitutes a warranty or representation that:

  • the Website is immune from attack;

  • vulnerabilities will never exist;

  • every vulnerability will be detected;

  • or every reported issue will require remediation.


8.4. Independent User Responsibilities

Users remain responsible for maintaining the security of their own devices, operating systems, browsers, passwords, authentication credentials, and network environments.

PlayMarket cannot protect against vulnerabilities originating outside its own systems.


8.5. Third-Party Components

The Website may rely upon third-party software, libraries, hosting providers, content delivery networks, analytics services, security services, advertising technologies, or other external platforms.

PlayMarket is not responsible for vulnerabilities arising solely from third-party systems outside its operational control.


8.6. Reservation of Rights

Nothing in this Security Policy limits any rights, defenses, remedies, or legal protections available to PlayMarket under Applicable Law.


ARTICLE 9. CONTACT INFORMATION

9.1. Security Contact

Security vulnerabilities should be reported using the official contact information published by PlayMarket.

Security Email:
[email protected]


9.2. Preferred Report Content

To facilitate efficient review, security reports should, where reasonably practicable, include:

  • a clear description of the issue;

  • affected URLs or resources;

  • technical steps required to reproduce the issue;

  • the expected and actual behavior;

  • supporting evidence, such as screenshots or logs;

  • an assessment of potential impact;

  • and the reporter's preferred contact information.

Providing complete information may significantly improve the efficiency of the investigation.


9.3. Encryption

Where appropriate, researchers may request an alternative secure communication method if the submitted information is particularly sensitive.


9.4. Abuse of Reporting Process

The responsible disclosure process must not be used to:

  • submit fraudulent reports;

  • demand payment;

  • threaten disclosure;

  • harass personnel;

  • or otherwise misuse the reporting process.

PlayMarket reserves the right to disregard reports submitted in bad faith and to take appropriate action where permitted by Applicable Law.


9.5. Language

Security reports may be submitted in English.

Where reasonably practicable, PlayMarket may also review reports submitted in other languages; however, English remains the preferred language for technical communications.


9.6. Availability

Although PlayMarket seeks to review security reports within a reasonable timeframe, continuous monitoring or immediate responses cannot be guaranteed.

Investigation and remediation timelines may vary depending on the complexity, severity, and potential impact of the reported issue.

ARTICLE 10. POLICY CHANGES

10.1. Right to Amend

PlayMarket reserves the right to amend, revise, replace, supplement, or otherwise modify this Security Policy at any time.

Changes may be introduced to reflect:

  • evolving cybersecurity threats;

  • technological developments;

  • infrastructure changes;

  • operational improvements;

  • legal or regulatory requirements;

  • industry best practices;

  • or changes to the Website's services.


10.2. Publication of Updates

The current version of this Security Policy will be published on the Website.

Unless otherwise required by Applicable Law, revisions become effective upon publication.


10.3. Material Changes

Where material amendments significantly affect the responsible disclosure process, PlayMarket may publish an updated version of this Policy reflecting those changes.

Nothing in this Article obligates PlayMarket to provide individualized notice to every previous reporter.


10.4. Continuing Improvements

Security practices evolve continuously.

Accordingly, internal security procedures may change without requiring amendments to every operational detail described in this Policy.


10.5. Interpretation

This Security Policy should be interpreted in a manner that promotes responsible vulnerability disclosure, coordinated remediation, and the protection of Users, systems, and third parties.


10.6. Reservation of Rights

PlayMarket reserves all rights to modify its internal security procedures where reasonably necessary to protect the Website, Users, infrastructure, and business operations.


ARTICLE 11. GENERAL PROVISIONS

11.1. No Authorization Beyond This Policy

Nothing in this Security Policy authorizes activities that would otherwise violate:

  • Applicable Law;

  • contractual obligations;

  • intellectual property rights;

  • privacy rights;

  • or the rights of third parties.

Researchers remain solely responsible for ensuring that their activities are lawful.


11.2. No Waiver

Failure by PlayMarket to investigate a report, respond to a communication, or enforce any provision of this Policy shall not constitute a waiver of any legal right or remedy.


11.3. Entire Security Policy

This Security Policy constitutes the complete policy governing the responsible reporting of security vulnerabilities affecting the Website.

It supersedes previous versions addressing the same subject matter from the date the current version becomes effective.


11.4. Relationship with Other Policies

This Security Policy should be read together with the:

  • Terms of Use;

  • Privacy Policy;

  • Acceptable Use Policy;

  • Editorial Policy;

  • Notice & Takedown Policy;

  • Community Guidelines;

  • and all other applicable legal documents published on the Website.

Where another policy specifically governs a particular matter, that policy shall prevail with respect to that matter.


11.5. Language

This Security Policy may be translated into multiple languages for the convenience of Users.

In the event of any inconsistency between translated versions, the English version shall prevail unless mandatory provisions of Applicable Law require otherwise.


11.6. Effective Date

This Security Policy becomes effective upon publication on the Website and remains in force until amended or replaced.


ARTICLE 12. FINAL STATEMENT

12.1. Security Commitment

PlayMarket considers cybersecurity an essential element of maintaining a reliable and trustworthy informational platform.

Reasonable efforts are made to protect the confidentiality, integrity, and availability of the Website through appropriate technical, organizational, and administrative measures.


12.2. Cooperation with the Security Community

PlayMarket appreciates the responsible efforts of independent security researchers, industry professionals, academic researchers, and members of the cybersecurity community who report potential vulnerabilities in good faith.

Constructive cooperation contributes to a safer Internet for all Users.


12.3. Responsible Innovation

As technology evolves, PlayMarket intends to continuously improve its security practices, development processes, infrastructure, monitoring capabilities, and incident response procedures in accordance with recognized industry practices and available resources.


12.4. No Bug Bounty Program

Unless expressly announced on the Website, PlayMarket does not currently operate a bug bounty or vulnerability reward program.

The submission of a vulnerability report does not create any expectation or entitlement to financial compensation, gifts, public recognition, or any other form of reward.


12.5. Good Faith Principle

PlayMarket encourages all participants in the responsible disclosure process to act professionally, ethically, and in good faith, with the shared objective of improving security while minimizing risks to Users and third parties.


12.6. Closing Provision

By establishing this Security Policy, PlayMarket reaffirms its commitment to transparency, responsible security practices, constructive engagement with the security community, and the continuous improvement of the Website's security posture.