Waffles.cards Trust & Transparency

Privacy Policy

Last updated: August 14, 2026

Short version. You can play the whole game without telling us anything about yourself. There are no analytics, no ad SDKs and no trackers of any kind. Three things do leave your device automatically: the cards you pull go to a public live-pulls feed, technical error reports go to us when the app breaks, and both carry a random device id that isn't linked to your identity. Everything else — your email, your account, your shipping address — happens only because you typed it in. We don't sell data and we've never had an advertising partner.

Where this app is right now

Waffles.cards takes real payments. Card details are entered on Stripe's own hosted checkout and never touch this app: we never see or store your card number. What comes back to us from Stripe is the payment's status, amount, currency and identifiers, which we keep against your account as the record of what you bought. Signing in is required before a pack can be bought or opened, so a signed-out visitor can browse the shop, the odds and the public pull feed without ever reaching a payment form. This policy labels which sections apply to which.

What we collect, surface by surface

Playing signed out

Your practice balance, cards, purchases, points, streak, achievements, notifications and preferences are written to your browser's local storage and stay there. They are never uploaded. We hold no copy and cannot see them.

The random device id

The first time the app runs it generates a random id — something like wfl_mshpwlqe_jp5p6doy — and keeps it in local storage. It is what makes the server-side rate limits work and what ties your pack-opening to your own pulls in the feed.

What it is not: it is not derived from your hardware, your IP address, your browser configuration, an advertising identifier, or anything about you. It is not a fingerprint — we do no fingerprinting at all. It is a random string; on its own it identifies a browser profile, not a person. Clearing your browser's site data destroys it and the app mints a new one.

The live pulls feed — this one is public

When you open a pack, the four cards' names, values, rarities and category are published to the app's live pulls feed, along with the random device id and a timestamp. That is the point of the feed: everyone sees what everyone is pulling.

The feed is genuinely public, but what it publishes is only the card facts above. The random device id is stored privately alongside each row so our server can rate-limit submissions — it is not part of the public feed and cannot be read by other visitors, so nobody but us can group pulls together by device. Nothing about your account, your email or your balance is ever attached to a feed row. There is no way to opt a pack out of the feed today, short of not opening it.

Error reports

If the app throws an error, it sends us: the error message, the stack trace, the page path it happened on (for example /app/packs), your browser's user-agent string, and the random device id. This is our own self-hosted error log — we deliberately use no third-party crash-reporting SDK. It contains no account data, no email, no browsing history from outside this app, and no game state.

Accounts

Accounts are optional — the app is fully playable without one. If you create one, we store the email address you sign up with and, if you set a password, a secure hash of it (we never see or store the password itself). This is handled by our authentication provider, Supabase. Alongside it we keep a small profile row: your username, your email, a link to your device id, an internal account role, a cached balance figure and the created/updated timestamps. Your email is used to operate the account — sign-in links, email confirmation, password resets — and for nothing else. We do not send marketing to account emails, and we do not sell or share them.

The email-list popup

That popup no longer appears — it existed to collect an address before packs went on sale. For everyone who used it we hold the email address, which popup it came from, the random device id, and the referring URL their browser reported. It is a real list in our own database, it gets at most one message, and it is never sold or shared. To be removed, email us — see Your choices.

Creator program applications

If you apply to the creator program at /creators, we store exactly what the form asked for: the name you gave, your email address, which platform you post on, the handle or link you gave, the audience size you typed in yourself (we do not check it against anything), what you said you would make, and what you said you were asking for. Alongside it we keep the random device id, the referring URL your browser reported, and — only if you happened to be signed in at the time — a link to your account.

It is used to answer you and for nothing else. It is not a mailing list, it is never sold or shared, and submitting it does not sign you up to anything. Nothing emails you to confirm it. Nobody but us can read it: the applications are not visible to other visitors and cannot be looked up by anyone, including you — if you want your own copy, use the "send it by email instead" option on the page. To have an application deleted, email us; see Your choices.

Shipping addresses

If you request that a card be shipped, the form asks for the name, street address, unit, city, province/state, postal code, country and (optionally) phone number the package should go to.

When you are signed in, that address is sent to our server and stored on the shipment record, because that is what a shipping label is. It is used to address, label and track your package, and for nothing else — never for marketing. A copy is also kept in your browser so the next request is one tap. If you delete your account while a parcel is still in flight, the stored address is erased automatically the moment that shipment closes.

Canada Post receives it, because they are the ones delivering. Two separate things happen: to quote you a shipping price we send Canada Post the destination postal code and country and nothing else — not your name, not your street address — and when the parcel actually goes out it carries the name, address and any phone number you gave, the same as any package you have ever been sent. We do not give your address to anyone else.

Payments

Packs are paid for with a real payment method. Card details are entered on Stripe's own hosted checkout page — they never pass through our servers and we never see or store a card number. What we store on our side is a payment record: the amount, currency, status, purpose, Stripe's session and payment-intent identifiers, and a link to your account. Those records are kept even if you delete your account, de-identified; see "How long we keep it" below.

The "online now" counter

The live tab shows how many people currently have the app open. It works by joining a realtime channel keyed by the random device id and publishing a timestamp while your tab is open. Nothing is written to a database and the entry disappears when you close the tab. Chat is deliberately not built — anonymous unmoderated chat is a trust liability, and the drawer says so.

Where your data lives

That is the complete vendor list. There is no analytics provider, no advertising network, no tag manager, no session-replay tool and no third-party crash reporter anywhere in this app.

Who can see it

How long we keep it

Honestly: we have not built automatic expiry yet. Feed rows, error logs and launch-list emails currently stay in the database until we delete them by hand. We would rather tell you that than publish a retention period we don't actually enforce. Account data is kept until the account is deleted — and you can delete it yourself, at any time, from inside the app. Local data on your device lasts until you clear it. If you want your data removed sooner, ask — see below.

The one exception, stated plainly: financial records. If you have ever paid us real money, deleting your account does not erase the payment record, the ledger entries or the purchase record behind them. Tax and anti-fraud law requires a business to keep records of money it has taken — in Canada, six years from the end of the tax year — and we are not going to claim otherwise. What we do instead is destroy everything that connects those records to you: your email, username, device id and the link to your login are all erased in the same operation, so what remains is a line in a ledger that identifies nobody. If you never spent money here, nothing is kept.

Your choices and how to use them

What we don't do

Cookies and local storage

The app sets no cookies of its own. It uses your browser's local storage, and these are the exact keys:

Two more live in session storage and vanish when you close the tab: waffles_checkout_intent (what you were buying when you left for checkout) and waffles_chase_seen_… (so a big-pull celebration plays once).

Children

Waffles.cards is intended for adults. We do not ask for or store a date of birth, and we no longer record an age confirmation against your account.

We don't knowingly collect data from anyone under 18 — if you believe a minor has given us an email address, write to us and we'll delete it.

Changes to this policy

When the app changes what it collects, this page gets updated and dated. Real payments and server-side shipping addresses are both running now, and the sections above describe them as they actually behave rather than as they were planned.

Contact

Privacy questions, data requests, deletions and unsubscribes all go to one place: [email protected]. A person reads it.