Privacy Policy
Last updated: August 14, 2026
Short version. You can play the whole game without telling us anything about yourself. There are no analytics, no ad SDKs and no trackers of any kind. Three things do leave your device automatically: the cards you pull go to a public live-pulls feed, technical error reports go to us when the app breaks, and both carry a random device id that isn't linked to your identity. Everything else — your email, your account, your shipping address — happens only because you typed it in. We don't sell data and we've never had an advertising partner.
Where this app is right now
Waffles.cards takes real payments. Card details are entered on Stripe's own hosted checkout and never touch this app: we never see or store your card number. What comes back to us from Stripe is the payment's status, amount, currency and identifiers, which we keep against your account as the record of what you bought. Signing in is required before a pack can be bought or opened, so a signed-out visitor can browse the shop, the odds and the public pull feed without ever reaching a payment form. This policy labels which sections apply to which.
What we collect, surface by surface
Playing signed out
Your practice balance, cards, purchases, points, streak, achievements, notifications and preferences are written to your browser's local storage and stay there. They are never uploaded. We hold no copy and cannot see them.
The random device id
The first time the app runs it generates a random id — something like
wfl_mshpwlqe_jp5p6doy — and keeps it in local storage. It is what makes the
server-side rate limits work and what ties your pack-opening to your own pulls in the
feed.
What it is not: it is not derived from your hardware, your IP address, your browser configuration, an advertising identifier, or anything about you. It is not a fingerprint — we do no fingerprinting at all. It is a random string; on its own it identifies a browser profile, not a person. Clearing your browser's site data destroys it and the app mints a new one.
The live pulls feed — this one is public
When you open a pack, the four cards' names, values, rarities and category are published to the app's live pulls feed, along with the random device id and a timestamp. That is the point of the feed: everyone sees what everyone is pulling.
The feed is genuinely public, but what it publishes is only the card facts above. The random device id is stored privately alongside each row so our server can rate-limit submissions — it is not part of the public feed and cannot be read by other visitors, so nobody but us can group pulls together by device. Nothing about your account, your email or your balance is ever attached to a feed row. There is no way to opt a pack out of the feed today, short of not opening it.
Error reports
If the app throws an error, it sends us: the error message, the stack trace, the page
path it happened on (for example /app/packs), your browser's user-agent
string, and the random device id. This is our own self-hosted error log — we deliberately
use no third-party crash-reporting SDK. It contains no account data, no email, no
browsing history from outside this app, and no game state.
Accounts
Accounts are optional — the app is fully playable without one. If you create one, we store the email address you sign up with and, if you set a password, a secure hash of it (we never see or store the password itself). This is handled by our authentication provider, Supabase. Alongside it we keep a small profile row: your username, your email, a link to your device id, an internal account role, a cached balance figure and the created/updated timestamps. Your email is used to operate the account — sign-in links, email confirmation, password resets — and for nothing else. We do not send marketing to account emails, and we do not sell or share them.
The email-list popup
That popup no longer appears — it existed to collect an address before packs went on sale. For everyone who used it we hold the email address, which popup it came from, the random device id, and the referring URL their browser reported. It is a real list in our own database, it gets at most one message, and it is never sold or shared. To be removed, email us — see Your choices.
Creator program applications
If you apply to the creator program at /creators, we store exactly what the form asked for: the name you gave, your email address, which platform you post on, the handle or link you gave, the audience size you typed in yourself (we do not check it against anything), what you said you would make, and what you said you were asking for. Alongside it we keep the random device id, the referring URL your browser reported, and — only if you happened to be signed in at the time — a link to your account.
It is used to answer you and for nothing else. It is not a mailing list, it is never sold or shared, and submitting it does not sign you up to anything. Nothing emails you to confirm it. Nobody but us can read it: the applications are not visible to other visitors and cannot be looked up by anyone, including you — if you want your own copy, use the "send it by email instead" option on the page. To have an application deleted, email us; see Your choices.
Shipping addresses
If you request that a card be shipped, the form asks for the name, street address, unit, city, province/state, postal code, country and (optionally) phone number the package should go to.
When you are signed in, that address is sent to our server and stored on the shipment record, because that is what a shipping label is. It is used to address, label and track your package, and for nothing else — never for marketing. A copy is also kept in your browser so the next request is one tap. If you delete your account while a parcel is still in flight, the stored address is erased automatically the moment that shipment closes.
Canada Post receives it, because they are the ones delivering. Two separate things happen: to quote you a shipping price we send Canada Post the destination postal code and country and nothing else — not your name, not your street address — and when the parcel actually goes out it carries the name, address and any phone number you gave, the same as any package you have ever been sent. We do not give your address to anyone else.
Payments
Packs are paid for with a real payment method. Card details are entered on Stripe's own hosted checkout page — they never pass through our servers and we never see or store a card number. What we store on our side is a payment record: the amount, currency, status, purpose, Stripe's session and payment-intent identifiers, and a link to your account. Those records are kept even if you delete your account, de-identified; see "How long we keep it" below.
The "online now" counter
The live tab shows how many people currently have the app open. It works by joining a realtime channel keyed by the random device id and publishing a timestamp while your tab is open. Nothing is written to a database and the entry disappears when you close the tab. Chat is deliberately not built — anonymous unmoderated chat is a trust liability, and the drawer says so.
Where your data lives
- Supabase — our database, authentication, edge functions and realtime, hosted in the us-east-2 region (United States). Everything we store server-side lives here.
- Stripe — payment processing. Your card details go to Stripe directly, never through us; see Payments above.
- Canada Post — delivery, and only if you ask for a card to be shipped. They get the destination postal code to price the shipment, and the name and address on the parcel itself. Nobody who does not need to deliver your package receives your address.
- Cloudflare Pages — hosts the website itself. Like any web host, Cloudflare necessarily handles your network request, including your IP address, in order to deliver the page.
That is the complete vendor list. There is no analytics provider, no advertising network, no tag manager, no session-replay tool and no third-party crash reporter anywhere in this app.
Who can see it
- The live pulls feed is public — the card facts only. The device id attached to each row is readable by us alone.
- Everything else is locked down. Error logs, the launch email list, account rows, payment records, purchases and shipments are all deny-by-default at the database level. Only the operator, through a privileged server key, can read them — and for account data, you can read your own rows when signed in.
- Local data is yours alone. Anything in your browser's storage is visible only to you; we have no copy of it.
How long we keep it
Honestly: we have not built automatic expiry yet. Feed rows, error logs and launch-list emails currently stay in the database until we delete them by hand. We would rather tell you that than publish a retention period we don't actually enforce. Account data is kept until the account is deleted — and you can delete it yourself, at any time, from inside the app. Local data on your device lasts until you clear it. If you want your data removed sooner, ask — see below.
The one exception, stated plainly: financial records. If you have ever paid us real money, deleting your account does not erase the payment record, the ledger entries or the purchase record behind them. Tax and anti-fraud law requires a business to keep records of money it has taken — in Canada, six years from the end of the tax year — and we are not going to claim otherwise. What we do instead is destroy everything that connects those records to you: your email, username, device id and the link to your login are all erased in the same operation, so what remains is a line in a ledger that identifies nobody. If you never spent money here, nothing is kept.
Your choices and how to use them
- Play anonymously. Don't create an account. Nothing in the game is gated behind one.
- Skip the email popup. Dismissing it stores nothing on our side.
- Get off the launch list. Email [email protected] and we'll remove or unsubscribe your address.
- Delete your account and its data — yourself, in the app. Account → Settings → Delete account, or read the whole process first at waffles.cards/delete-account. It removes your login (that email is then free to sign up again), your profile, your error reports, your address on the launch list, and everything this browser stored — including the device id. Your card pulls stay in the public feed with the device id erased from them, and financial records are kept de-identified as described above. Deletion asks you to type DELETE, because it cannot be undone. If you've lost access to the account, email [email protected] and a person will do it for you.
- Ask what we hold, or ask us to correct or delete it. Same address.
Tell us the email you used and, if it's about feed or error rows, we'll need the device
id (visible in your browser's storage under
waffles_device_id). - Erase everything on your device. In the app, go to Account → Settings → Clear local data. That wipes the local game state described above. Note that it does not remove the device id — to clear that too, clear the site's data in your browser, use Delete account (which does remove it), or on Android use Settings → Apps → Waffles → Clear storage. And be aware of what clearing does not reach: rows already in the pull feed, entries already in our error log, and your address on the launch email list all live on our server and survive it. Deleting your account does reach all three.
- Forget a saved shipping address. Use "Use a different address" in the ship form, or clear site data.
What we don't do
- No advertising, no ad networks, no ad identifiers.
- No analytics or tracking SDKs — none, from anyone. You can read the page source.
- No device or browser fingerprinting.
- No selling, renting or trading of personal data.
- No profiling you across other websites, and no cross-site tracking.
- No marketing email to account holders. The launch list is separate and opt-in.
Cookies and local storage
The app sets no cookies of its own. It uses your browser's local storage, and these are the exact keys:
waffles_user— your local game state: balance, cards, purchases, points, rewards, notifications, preferences, and any shipping address attached to a card you asked to ship.waffles_device_id— the random device id described above.waffles_auth— your signed-in session, if you have an account.waffles_ship_address— your last shipping address, so the next request is one tap.waffles_lead_prompt_seen— a flag so the launch-email popup only ever appears once.waffles_share_awards— which packs already granted share points, so they can't be claimed twice.waffles_live_reveal_progress— how far through a reveal you got (used only when real-money mode is on).
Two more live in session storage and vanish when you close the tab:
waffles_checkout_intent (what you were buying when you left for checkout) and
waffles_chase_seen_… (so a big-pull celebration plays once).
Children
Waffles.cards is intended for adults. We do not ask for or store a date of birth, and we no longer record an age confirmation against your account.
We don't knowingly collect data from anyone under 18 — if you believe a minor has given us an email address, write to us and we'll delete it.
Changes to this policy
When the app changes what it collects, this page gets updated and dated. Real payments and server-side shipping addresses are both running now, and the sections above describe them as they actually behave rather than as they were planned.
Contact
Privacy questions, data requests, deletions and unsubscribes all go to one place: [email protected]. A person reads it.
Trust & Transparency