Privacy notice
This draft describes the current preview and the production arrangements still to be confirmed. The controller identity and working contact details still need completion in the operator notice.
What the preview stores
- Account name, email, password authentication data, age declaration and timestamp, sessions and security-related request information.
- Owned cards, pack openings, balances, transactions, auction bids, collections, albums, favorites, tags, votes and achievement progress.
- Profile and appearance choices, sensitive-image preferences, image reports and notification state.
Chosen names and published creations may appear to other players. Auction activity exposes the information needed to display and settle listings. Email addresses are not intended for public display. Avoid putting personal or sensitive information in public descriptions.
Why data is used
The purposes are account access, game delivery, ownership and balance integrity, abuse prevention, support and product improvement. Contract is the proposed basis for requested gameplay. Proportionate security and analytics, replay and diagnostics require a documented lawful-basis assessment where personal data is involved. Mandatory billing records would rely on applicable legal obligations once payments begin. These assessments must be finalized before publication.
Product analytics and session replay
PostHog measures approved page visits and game actions to understand how people discover cards, open packs, create collections and use the marketplace. It uses cookies and local storage, anonymous browser identifiers and a stable pseudonymous account identifier when signed in. That account identifier is generated from the internal account ID using a keyed transformation; names and email addresses are not sent as identity traits. Pseudonymous data is still personal data.
Events can include card rarity, article identifiers and relevant game-object identifiers. Event properties are restricted; free-form descriptions, search text, form contents and URL query strings are excluded. Routes are generalized. Requests go through the same-origin /ph endpoint to PostHog EU; this proxy does not mean the data stays solely on our server.
Session replay is enabled on eligible pages to diagnose usability problems. Text and inputs are masked; forms, dialogs, payment/private elements, editable content and embedded frames are blocked. Authentication, settings, billing, checkout and password-recovery pages are excluded, as are pages with a query string or fragment. Canvas recording and network headers/bodies are disabled. Masking reduces exposure but requires ongoing verification and is not an absolute guarantee that no personal information can appear.
Acquisition measurement
Google Analytics 4 integration is prepared but inactive until a dedicated property and stream are configured. When enabled, it is intended to measure production pageviews using analytics cookies, generalized page paths, a fixed page title and only the referrer origin. It does not send the game account ID, email or form text. Advertising storage, advertising user data, ad personalization and Google signals are disabled. Test and simulated accounts are excluded.
Error diagnostics
Sentry EU receives technical errors from the browser and server: error types, sanitized messages, stack traces, source context, release/environment and selected runtime, browser, operating-system and React context. Up to 30 technical network/navigation breadcrumbs can include sanitized URLs, methods, response status and duration. Request bodies, headers, cookies, DOM text and console breadcrumbs are excluded; user identity is removed. Messages are filtered for recognizable secrets and identifiers, but filtering is not a guarantee of complete anonymization.
Error collection is configured without sampling out SDK errors. It is separate from product analytics and does not follow the analytics opt-out. It does not enable Sentry replay, tracing or session tracking. SDK coverage, network failures and browser blocking mean that delivery of every error or event cannot be guaranteed. Network recipients may receive connection information even when IP addresses are not added to event properties.
Measurement choices
No analytics opt-in banner is displayed in this private preview. PostHog and the prepared GA4 integration respect an existing wc_analytics=no preference, browser Do Not Track and Global Privacy Control. There is not yet a self-service preference editor on this page. Contact [email protected] for privacy requests. Stopping future collection does not automatically erase data already received by a provider.
Applicable privacy framework
The operator is being configured as a Polish business. GDPR Article 3 covers processing in the context of an EU establishment regardless of server location. Terminal storage and access must also be assessed under applicable electronic-communications rules, including Article 399 of the Polish PKE. Persistent analytics storage and replay require their own consent and lawful-basis analysis. The current no-banner configuration is not a claim of a legal exemption or a public-release compliance decision. No French authority or French analytics exemption is assumed to govern this deployment.
Providers and external content
The preview uses PostgreSQL for game and account records. Optional Redis is a cache. Wikipedia and Wikimedia image requests can disclose technical connection information, such as the requesting IP address, to the image host; external source links open third-party services.
MXroute hosts the contact mailbox. Google project and OAuth client configuration exist for the local preview; a successful end-to-end Google sign-in is not yet confirmed. SES transactional sending remains pending AWS access, and a WikiCollector Stripe account awaits completion. Cloudflare and production hosting remain proposed arrangements. Provider entities, regions, contracts and international-transfer safeguards must be verified against the final deployment.
Retention and your choices
The configured sign-in session lifetime is seven days with rolling renewal. A legacy analytics-decline cookie can remain for up to 180 days. There is currently no completed automated account-erasure, log-expiry or backup-erasure schedule. Retention periods for accounts, transactions, security logs, support mail, analytics, replay, error diagnostics and backups must be verified and documented before release. PostHog replay retention was reported as 30 days in the provider setup; this must be rechecked before publication. Other analytics and diagnostic provider retention settings have not been verified.
Depending on the processing and applicable law, rights include access, correction, erasure, restriction, objection and portability. Consent may be withdrawn. Individuals may also complain to the competent data-protection authority. Contact [email protected] for privacy requests. Identity checks and the full response workflow must be verified before public registration.
Changes
The final notice will identify its effective date and explain material changes. It must reflect the actual deployment rather than the infrastructure proposal.