Maplehaze SDK Developer Compliance Guidelines

Effective Date: January 1, 2026

Last Updated: August 18, 2026

SDK Information

Item Details
SDK Name Maplehaze SDK
Developer Maplehaze Group Ltd.
Main Functions Ad delivery, ad performance data monitoring
Android Version 1.0.0
iOS Version 1.1.0
Privacy Policy Maplehaze SDK Privacy Policy
Personal Information Collected Device brand, device model, operating system version, screen resolution, device language, device time zone, network information (network type, connection status), IP address (which may be used to estimate the general location of a device), advertising identifiers (GAID and App Set ID on Android; IDFA and IDFV on iOS, subject to App Tracking Transparency consent), application package name / bundle ID and version number, user product interactions with ads (impressions, clicks, conversions), and diagnostic and performance data (crash data, app launch time, hang rate, energy usage).
Scenarios / Purposes of Use Providing advertising services to users

To help developers and operators using the Maplehaze SDK (hereinafter referred to as "you") conduct third-party SDK business in compliance with applicable laws, regulations, policies and standards, to better implement the requirements of user personal information protection, and to help you clearly understand the compliance of the Maplehaze data business and the security protection technologies we have adopted — in particular the methods and measures for protecting personal information and privacy — Maplehaze Group Ltd. and its affiliates (hereinafter referred to as "we", "us" or "the Company") have formulated these Maplehaze SDK Developer Compliance Guidelines (hereinafter referred to as the "Guidelines"), to help you comply with the corresponding compliance requirements when using the Maplehaze SDK.

1. Compliance Requirements for Developer Protection of Personal Information

The following content mainly explains the key compliance requirements for the collection and use of personal information in the course of your use of the Maplehaze SDK. Our requirements are aligned with the compliance practices of the Google Mobile Ads SDK (AdMob) and applicable international regulations, including the EU General Data Protection Regulation (GDPR), the ePrivacy Directive, the California Consumer Privacy Act (CCPA), Apple's App Tracking Transparency (ATT) framework and the Google Play Data safety requirements.

1. Your app must have an independent privacy policy.
The privacy policy must comply with the national and regional laws, regulations, standards and regulatory requirements related to data security and personal information protection that apply to your app (including the GDPR where you have users in the EEA/UK, and the CCPA where you have users in California), as well as your agreement with Maplehaze, and must fully disclose the relevant information about the Maplehaze SDK to your users.

2. Disclosure of the Maplehaze SDK in your privacy policy.
You should disclose the Maplehaze SDK in the third-party information sharing list of your app privacy policy, including the SDK name, company name (Maplehaze Group Ltd.), categories and purposes of personal information processed, collection methods, and a link to the SDK privacy policy. Your privacy policy must be standalone and prominently presented: when the app is first launched, users must be prompted in an obvious way (such as a pop-up) to read the privacy policy, and you may only initialize the Maplehaze SDK and begin collecting and processing personal information after the user has confirmed consent. You must clearly inform users of the purpose, manner and scope of personal information collection and use. Please note that merely improving service quality, enhancing user experience, targeted information push, or developing new products is not sufficient justification for requiring users to consent to the collection of their personal information. Consent must be freely given by users and must not be obtained through pre-ticked boxes, deception or inducement.

3. Consent management for users in the EEA/UK and other regulated regions.
If your app serves users in the European Economic Area (EEA), the United Kingdom, or other regions requiring user consent for advertising identifiers or cookies, you must implement a consent mechanism (such as a Consent Management Platform, CMP) consistent with Google's EU User Consent Policy and the Transparency & Consent Framework (TCF), and pass the consent status to the Maplehaze SDK through the configuration interfaces described in Sections 4 and 5 before making ad requests. Where consent is not obtained, you must request non-personalized ads.

4. Delayed initialization.
Do not initialize the Maplehaze SDK, and do not send any ad request, before you have obtained the user's consent required by applicable laws (including ATT consent on iOS where applicable).

5. Children's privacy.
If your app is directed to children, or you have actual knowledge that a user is a child, you must comply with applicable children's privacy laws such as the US Children's Online Privacy Protection Act (COPPA) and Article 8 of the GDPR. You must configure the SDK accordingly (see Section 5) so that only non-personalized, contextual advertising is served and advertising identifiers are not used.

6. App store disclosure.
You must accurately complete the data safety / data disclosure forms of the app stores where your app is distributed (including the Google Play Data safety section and Apple App Privacy details), reflecting the data practices of your app together with the Maplehaze SDK and the integrated Google Mobile Ads SDK (AdMob). For the latest data disclosure reference of the Google Mobile Ads SDK, please visit https://developers.google.com/admob/android/privacy/play-data-disclosure.

2. Description of Personal Information Obtained by the SDK

The following table describes the personal information and permissions of end users of your app that the Maplehaze SDK obtains. The data fields collected and whether they are optional may vary between SDK versions; the actual collection is subject to the SDK version you integrate. Our data collection scope is aligned with the Google Mobile Ads SDK (AdMob):

Category of Personal Information Data Fields Purpose
Device Information Required information:
[Android + iOS] Device brand, model, operating system version, screen resolution, device language, device time zone and other basic device information
[iOS only] System boot time, total disk space, total system memory space, number of CPU cores and other basic information
Ad delivery, anti-fraud
Identifiers Required information:
[Android] Google Advertising ID (GAID), App Set ID
[iOS] Identifier for Advertisers (IDFA) (subject to App Tracking Transparency consent)
Optional information:
[iOS] Identifier for Vendors (IDFV)
The specific fields may vary depending on software and hardware versions. The collection of the Android advertising ID can be prevented by updating the app's manifest file, and users can reset or delete the advertising ID through their device settings.
Ad delivery, anti-fraud, ad measurement and attribution
Network Information Required information:
[Android + iOS] IP address, network type and connection status (e.g., Wi-Fi or mobile network). The IP address may be used to estimate the general location of a device.
Ad delivery, anti-fraud, ad measurement and attribution
Ensuring the validity and stability of network services
Application Information Required information:
[Android] Application package name, version number
[iOS] Application bundle ID, version number
Ad delivery, anti-fraud
Ad Interaction Information Required information:
[Android + iOS] User product interactions and interaction data with ads, including app launches, ad impressions, taps, clicks, video views and conversions
Ad measurement and attribution, ad delivery statistics and analysis, anti-fraud
Location Information Optional information:
[Android + iOS] Precise location information and approximate location information, only where the developer application has obtained the corresponding location permissions from the end user. A coarse location estimate may also be derived from the IP address.
Targeted ad delivery, anti-fraud
Diagnostic and Performance Data Required information:
[Android + iOS] Information related to the performance of the app and the SDK, including crash data, app launch time, hang rate and energy usage
Reducing app crashes, providing stable and reliable services

To implement the functions of the Maplehaze SDK and to ensure its secure and stable operation, we may integrate software development kits (SDKs), application programming interfaces (APIs), application plugins or other code provided by our partners, or cooperate in other ways, to achieve the relevant purposes. We apply strict security monitoring to the code of partners that obtain information, in order to protect data security. We list the partners whose code we integrate below, and their specific processing is subject to the partner's own privacy policy or service agreement. Please note that a partner's code may change its data processing types due to version upgrades, policy adjustments or other reasons; please refer to the official statements published by that partner. Due to product iteration and upgrades, some historical versions may differ from the current version; the actual situation shall prevail.

Third-Party SDK Name Company Providing the SDK Privacy Notice
Google Mobile Ads SDK (AdMob) Google LLC https://policies.google.com/privacy
https://developers.google.com/admob/android/privacy/play-data-disclosure
https://support.google.com/admob/answer/6128543

3. Description of System Permissions Requested by the SDK

The fields obtained by different SDK versions may vary. In order to protect the safety of end users and the feasibility of the service, Maplehaze continuously updates the SDK versions to improve security. When the SDK version is updated, Maplehaze will notify you by email and other means. Please update the SDK version in a timely manner; any issues caused by untimely updates shall be resolved by you, and you shall bear all corresponding responsibility. The permission requests of the Maplehaze SDK are aligned with those of the Google Mobile Ads SDK (AdMob).

Android operating system permission list:

Permission Function Purpose When Requested
INTERNET
Network access
[Required] Access the network Allow the user's device to access the network and retrieve ads Requested when the developer invokes SDK functions that require this permission, e.g., when connecting to the network to make ad requests.
ACCESS_NETWORK_STATE
Network information access
[Required] Obtain network status Ad delivery and anti-fraud Requested when the developer invokes SDK functions that require this permission, e.g., making precise ad delivery and anti-fraud determinations based on network conditions.
ACCESS_COARSE_LOCATION
Approximate location access
[Optional] Obtain approximate location information Ad delivery and anti-fraud Requested when the developer invokes SDK functions that require this permission, e.g., delivering ads and performing anti-fraud checks based on approximate location information.
ACCESS_FINE_LOCATION
Precise location access
[Optional] Obtain precise location information Ad delivery and anti-fraud Requested when the developer invokes SDK functions that require this permission, e.g., delivering ads and performing anti-fraud checks based on precise location information.
com.google.android.gms.permission.AD_ID
Advertising ID access
[Optional] Read the Google Advertising ID (GAID) Ad delivery, ad measurement and attribution, anti-fraud Requested when the developer invokes SDK functions that require this permission. Developers may prevent the collection of the advertising ID by updating the app's manifest file; users may reset or delete the advertising ID using the ad ID controls in the Android settings menu.

iOS operating system permission list:

Permission Function Purpose When Requested
NSUserTrackingUsageDescription [Optional] Request tracking consent to obtain the device advertising identifier (IDFA) Ad delivery, ad measurement and attribution, anti-fraud Requested when the developer invokes SDK functions that require this permission. In accordance with Apple's App Tracking Transparency framework, the IDFA is accessed only after the end user grants consent through the system tracking prompt.
NSAppTransportSecurity [Optional] Allow HTTP access Enhancing compatibility so that ad creatives delivered over HTTP can still be accessed, avoiding impact on experience and effectiveness Requested when the developer invokes SDK functions that require this permission, e.g., when making ad requests and impressions.
NSLocationWhenInUseUsageDescription [Optional] Obtain precise location information while the app is in use Ad delivery and anti-fraud Requested when the developer invokes SDK functions that require this permission, e.g., delivering ads and performing anti-fraud checks based on precise location information.

4. Configuration Switches for Optional Information

Please note that the Maplehaze SDK does not force the acquisition of optional permissions. Even if the optional permissions are not obtained, the basic functions of the SDK will operate normally. You may configure the optional permissions to use other optional functions provided by the SDK. We recommend calling the methods provided by the SDK at an appropriate time before making a request, to obtain the declared permissions only with the end user's consent.

Optional Personal Information and Fields Purpose of Use Usage Scenario Configuration Method and Example
Location information
Developers may choose whether to provide the following information to the SDK:
[Android + iOS] Precise location information
[Android + iOS] Approximate location information
Ad delivery, anti-fraud Used when delivering ads Android: call before making an ad request
agreeReadParams.put("location", false); // whether to allow obtaining location information
Passing true means allowed; passing false means not allowed. If the parameter is not passed or another value is passed, location collection is not allowed by default.

iOS: call before making an ad request
[MHAdConfiguration sharedConfig].allowLocation = YES; // whether to allow obtaining location information
Passing YES means allowed; passing NO means not allowed. If the parameter is not passed or another value is passed, location collection is not allowed by default.
Identifiers
Developers may choose whether to authorize the SDK to collect advertising identifiers:
[Android] Google Advertising ID (GAID)
[iOS] IDFA (subject to ATT consent)
Ad delivery, ad attribution, ad measurement, anti-fraud Used when delivering ads and analyzing ad delivery performance Android: call before making an ad request
agreeReadParams.put("ad_id", true); // whether to allow obtaining the advertising ID (GAID)
Passing true means allowed; passing false means not allowed. If the parameter is not passed or another value is passed, the default behavior follows the device settings; collection is not allowed if the user has opted out of ads personalization.

iOS: the IDFA is accessed only after the end user grants consent through the App Tracking Transparency prompt. Do not call the tracking request before consent is obtained.

Related Code Example

Map<String, Boolean> agreeReadParams = new HashMap<>(); agreeReadParams.put("location", true); // whether to allow obtaining location information agreeReadParams.put("ad_id", true); // whether to allow obtaining the advertising ID (GAID) MaplehazeGlobalSetting.setAgreeReadParams(agreeReadParams); // set privacy configuration

5. Personalized Advertising Configuration

The Maplehaze SDK provides developers with an interface for opting out of personalized advertising. Developers may call the interface to provide end users with the ability to opt out of personalized advertising. After opting out, end users will see fewer and less relevant ads. Developers must comply with applicable laws and regulations and provide end users with an opt-out function within the app, ensuring that the SDK interface is called after the end user clicks the opt-out function. This mechanism is aligned with the personalized / non-personalized advertising controls of the Google Mobile Ads SDK (AdMob), and the consent status is forwarded accordingly to the integrated AdMob SDK.

1. Method description:
Developers can call setPersonalizedState(0) on MaplehazeAdConfig. Report 0 when the user consents, to enable the personalized advertising capability; report 1 when the user refuses, and the SDK will disable personalized advertising in subsequent ad delivery.

Parameter Type Description
1 int Disable personalized advertising (serve non-personalized ads)
0 int Enable personalized advertising

2. Code example:

MaplehazeAdConfig maplehazeAdConfig = new MaplehazeAdConfig(); maplehazeAdConfig.setAppId(Constants.APP_ID); // set app id maplehazeAdConfig.setDebug(true); // log switch: true to enable, false to disable (default) maplehazeAdConfig.setPersonalizedState(0); // 0 enables personalized advertising, 1 disables personalized advertising MaplehazeSDK.getInstance().init(this, maplehazeAdConfig);

3. Consent for users in the EEA/UK and other regulated regions:
For end users in regions where consent is required for personalized advertising (such as the EEA and the UK under the GDPR and the ePrivacy Directive), you must obtain and manage consent in accordance with Google's EU User Consent Policy (see https://www.google.com/about/company/user-consent-policy/) and pass the consent state to the Maplehaze SDK via setPersonalizedState() before any ad request. Where the end user does not consent to personalized advertising, you must set the personalized state to 1 so that only non-personalized ads are served.

4. Apps directed to children:
If your app is directed to children, you must set the personalized state to 1 (non-personalized ads) for all users of the app and ensure that no advertising identifiers are used, in compliance with COPPA and Article 8 of the GDPR.