When you use our services, youโ€™re trusting us with your information. We understand that this is a big responsibility, and we work hard to protect your data while giving you control over your privacy. This Privacy Policy explains what information we collect, why we collect it, and how you can update, manage, export, or delete your information.

Our Services

At TortoisePath, we build a range of services that help you explore, discover, and interact with the world in innovative ways. Our network of services includes, but is not limited to:

  • TortoisePath.com โ€“ Our lifestyle portal
  • schoolfinder.tortoisepath.com
  • abacus.tortoisepath.com
  • celebrations.tortoisepath.com
  • blocksandbricks.tortoisepath.com
  • askannie.tortoisepath.com

Managing Your Privacy Settings

You have choices regarding the information we collect and how itโ€™s used. When you sign up for a TortoisePath account, you can manage your privacy settings, control the data you share, and personalise your experience. Many of our services can also be used without an account, though signing in provides additional benefits and a more tailored experience.

Information We Collect

Information You Provide

When you create a TortoisePath account or interact with our services, you may provide us with personal information such as your name, email address, phone number, and other details you choose to share. You might also upload content like reviews, photos, and other media.

Information from Your Device and Activity

We automatically collect certain information when you use our services, including:

  • Device & Browser Data: Details about the device, operating system, browser type, and unique identifiers.
  • Usage Data: Information about your interactions with our servicesโ€”such as pages viewed, search queries, clicks, and other actionsโ€”as well as crash reports and system activity.
  • IP Address: To help us understand usage patterns and for security purposes.

Location Information

We may collect location data through GPS, IP addresses, or other sensor data from your device. This enables us to provide location-based services, such as local recommendations and search results tailored to your area.

Information from Public Sources

Occasionally, we gather information from publicly accessible sources or trusted partners to enhance our services and offer better recommendations.

How We Use Your Information

We use the information we collect for a variety of purposes, including to:

  • Provide Our Services: Deliver and personalize your experience on our platforms.
  • Maintain & Improve: Ensure our services run smoothly, fix issues, and make continual improvements.
  • Develop New Services: Innovate and launch new features based on how you use our platforms.
  • Personalise Content & Recommendations: Tailor content and recommendations to your interests and location.
  • Measure Performance: Analyze usage patterns to help us optimize our services and design.
  • Communicate with You: Send you updates, notifications, and support messages.
  • Protect Our Community: Detect and prevent fraud, abuse, or any other security risks.

Your Privacy Controls

You can review, update, and manage your personal information by signing into your TortoisePath account. If you have any questions or need assistance with your settings, please contact us using the details below.

Security

We take reasonable measures to safeguard your information from unauthorised access, disclosure, alteration, or destruction. Although no security system is completely foolproof, we continuously review and improve our practices to maintain high standards of data protection.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or to comply with new legal requirements. If we make material changes, we will provide notice where appropriate.

Contact Us

If you have any questions about this Privacy Policy or how we handle your information, please contact us at: team@tortoisepath.com

Optional TortoiseWorld analytics

TortoiseWorld V5 works without analytics. If you switch on Share anonymous play metrics, we count consented, identifier-free telemetry segments and coarse events such as ten-second engagement, game start, broad interaction and progression categories, foreground active time, and best-effort exit or abandonment. A segment is usually one page visit, but changing the optional account connection starts a new segment. Segment counts are not unique people, visits, or page loads.

The identifier-free analytics store does not contain names, account identifiers, email addresses, IP addresses, user agents, URLs, referrers, chat, voice, coordinates, device fingerprints, multiplayer identity, inventory, property contents, or financial state. A random per-segment token is HMACed immediately. Short-lived segment state is removed 48 hours after its last accepted event, and daily aggregate rows are retained for 90 days. A scheduled retention job enforces those limits even when no new game events arrive.

To protect this public endpoint from automated abuse, a separate security rate limiter converts the connection address into a secret, minute-specific HMAC bucket. It stores no raw address, cannot join buckets across windows, is not used for analytics, and deletes expired buckets during requests and scheduled maintenance.

Your TortoiseWorld choice expires after no more than 180 days. You can switch it off in the game at any time. Global Privacy Control, Do Not Track, and a site-wide analytics rejection keep collection off. Withdrawal stops future collection and ends the current telemetry segment. Identifier-free counts already aggregated cannot be traced back to an individual and therefore cannot be removed for one person.

Optional Tortoise Profile and Tortoise Fam connection

If you are signed in, you may make a second, separate choice to connect future play analytics to your Tortoise account. This is off by default and is never inferred from membership, login, Passport activity, or the anonymous analytics choice. The server derives a private HMAC account key from the cross-portal account UUID; the raw UUID, local user ID, name, and email are never written to the game analytics store or sent to the game client. This optional connection lets us report linked-account engagement in aggregate. Linked figures overlap the identifier-free totals and are not added to them. An account with two or more segments in a reporting window is not, by itself, proof of a return visit or retention.

The link choice remains on your account until you withdraw it. Linked segment summaries are removed 90 days after their last accepted event. Unlinking or choosing Delete linked play data immediately stops attribution and attempts to remove the linked analytics rows associated with your account. Successfully queued erasures retry until removal is confirmed; if the privacy service or queue is unavailable, deletion is reported incomplete and must be retried after restoration. The same export and erasure controls are connected to WordPress privacy tools and account-deletion hooks. Identifier-free aggregate counts remain because they are not connected to the account.

Hosting, security, and access logs are separate operational systems and may process information such as IP addresses under the other sections of this policy; this TortoiseWorld analytics feature does not copy those logs into its analytics stores. Contact team@tortoisepath.com for privacy, access, withdrawal, or deletion requests.