Documentation

​
​

Development

User Acquisition

Monetization

Industry

In-App Purchasing

IAP Client API

IAP SDK API

Webshop Admin API

Webshop Client API

In-App Purchasing

LiveOps
​
​
Get started
  • Overview
  • Introduction to IAP
  • What's new in IAP v5.4
  • Upgrade from IAP v4 to v5
  • AI skill for In-App Purchasing
Direct to Consumer (D2C) payments
  • Direct to Consumer (D2C) payment providers
Webshop
  • Overview
  • Get started with webshops
  • Webshop setup
  • Catalog and payments
  • Game integration for webshops
  • Troubleshooting webshops
Platform-native stores
  • Set up IAP for platform-native stores
  • Codeless IAP
Catalogs and store management
  • Create product catalogs
  • Supported stores
Purchases
  • Purchase management and fulfillment
Monitor IAP performance
  • Overview
  • IAP revenue performance
  • D2C performance
Privacy
  • Privacy and consent
    • IAP 5.4 and later
    • IAP versions earlier than 5.4
      • Privacy overview
      • Apple privacy manifest
      • Google Play data safety
  1. Unity In-App Purchasing
  2. Privacy and consent

Privacy overview

Learn about privacy and data handling considerations when implementing Unity In-App Purchasing in your game.
Read time 3 minutes
Last updated 2 months ago

In-App Purchasing SDK - Expand your revenue opportunities across multiple stores and platforms with one SDK. Unity IAP supports industry-leading app stores, including Google Play, the App Store, and more.
This documentation is intended to assist products to display their privacy compliance to Developers. It is not intended to be used as legal guidance or as a replacement to reading Unity’s Privacy Policy. If you have questions about a term used, please see the Glossary below.
If you have further questions about the privacy implications of your product, please email DPO@unity3d.com with your question. For expediency, please list the product about which you are inquiring.
Note
This page applies to Unity IAP versions earlier than 5.4. If you use IAP 5.4 or later, refer to Privacy overview for IAP 5.4 and later.

Personal Data Collected about App Users/Game Players

Default Personal Data Collected (always collected in order for the product to work)
  • This product does not collect any personal data about app users.
Optional Personal Data Collected (personal data which may be collected at choice/action of the end user/Developer)
  • This product does not collect any personal data about app users.

Relationship under Privacy Laws

Not Applicable

Legal Basis for Processing

Not Applicable

Consent (Opt in) vs Opt out

Not Applicable

Data Subject Requests

Not Applicable

Dependencies

Not Applicable

Data Retention

Not Applicable

Child Privacy

If required to do so under applicable laws, you (the developer) must obtain Verified Parental Consent prior to submitting child-user data, as outlined in the Unity Terms of Service.

Privacy Policy Requirements

It is never appropriate to use Unity’s privacy policy for your application. You will need to ensure that the personal data practices are reflected in your Privacy Policy, as required in the Unity Terms of Service.

Data Processing Agreement (DPA)

The Unity DPA applies to the transfer of data for this product.

Glossary & Notable Laws

  • GDPR - The General Data Protection Regulation (GDPR) took effect in the European Economic Area (EEA). References to GDPR also encompass UK GDPR which is the UK’s version of GDPR which applies post-Brexit.
  • CCPA - The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (“CPRA”).
  • PIPL - In November of 2021, Personal Information Protection Law (PIPL) took effect in China.
  • LGPD - The Brazilian General Data Protection Law
  • VCDPA - The Virginia Consumer Data Protection Act
  • CPA - The Colorado Privacy Act
  • CTDPA - The Connecticut Data Protection Act
  • UCPA - The Utah Consumer Privacy Act
  • PIPEDA - The Canadian Personal Information Protection and Electronic Documents Act
  • COPPA - The Children’s Online Privacy Protection Act (COPPA) imposes restrictions on how data can be collected and used from children under the age of 13.
  • CARU - A self-regulatory organization for the promotion of responsible privacy practices to children under the age of 13
  • DPA - A Data Processing Addendum (or Data Processing Agreement) forms part of a contract and governs the rights and obligations of each party concerning the processing of personal data.
  • ATT - iOS 14 and later requires publishers to obtain permission to track the user's device across applications. This device setting is called App Tracking Transparency, or ATT.

Copyright © 2026 Unity Technologies
LegalPrivacy PolicyCookiesDocumentation Terms of UseDo Not Sell or Share My Personal InformationYour Privacy Choices (Cookie Settings)

"Unity", Unity logos, and other Unity trademarks are trademarks or registered trademarks of Unity Technologies or its affiliates in the U.S and elsewhere (more info here). Other names or brands are trademarks of their respective owners.

Some pages are machine-translated for convenience, and may contain inaccuracies. In the event of conflicting information, the English version is authoritative.

  • On this page
    • Personal Data Collected about App Users/Game Players

    • Relationship under Privacy Laws

    • Legal Basis for Processing

    • Consent (Opt in) vs Opt out

    • Data Subject Requests

    • Dependencies

    • Data Retention

    • Child Privacy

    • Privacy Policy Requirements

    • Data Processing Agreement (DPA)

    • Glossary & Notable Laws


Report a problem with this page