Privacy Policy
Last Updated: August 1, 2026
Draft notice. This document describes what the Ripchest codebase actually collects, stores, and shares, verified against the schema and the code paths that call third parties. It is not legal advice, and it does not yet name a controlling entity, a jurisdiction, or a data protection contact. Have counsel review before publishing, and see the open items listed in section 12.
1. Scope
This Policy explains how Ripchest ("we," "us," "our") handles personal data when you use the Ripchest service (the "Service"). It forms part of the Agreement described in our Terms of Service.
This Policy covers the Service only. It does not cover the separate privacy practices of the payment, identity, shipping, or sign-in providers described in section 5, each of which handles your data under its own policy.
2. What we collect
You give us:
- Email address. Required to create an account, whether you register with a password or through Google. It is how we contact you and how you sign in.
- Username. Chosen by you. It is public — see section 6.
- Password. Stored only as an Argon2id hash. We never store or log the password itself, and we cannot recover it; a forgotten password is replaced, not retrieved. Accounts created through Google have no password at all.
- Age self-attestation. A timestamp recording when you confirmed you are 18 or older.
- Shipping address. Recipient name, street lines, city, region, postal code, and country, collected only when you request a physical shipment.
- Avatar image. Optional. Stored as a WebP file served from a public URL.
- Deposit references. For manual transfers, the reference code you are given and any note an operator records while reviewing your payment. For USDC deposits, the on-chain transaction signature you submit. We do not store your wallet address.
We generate as you use the Service:
- Pull history. Every pack you open, the card drawn, and its recorded value at that moment.
- Balance ledger. Every movement of USD balance into and out of your account, with the reason for it.
- Vault contents. Which physical card instances are assigned to you.
- Fairness records. Your commit–reveal seeds, kept so any past pull remains independently verifiable.
- Spend totals. Lifetime spend, used for the KYC threshold, and any daily limit you set yourself.
- Session records. For each sign-in: a hash of the session token, its expiry, when it was last used, and the IP address and browser user-agent seen when it was created.
- Support and moderation records. If an account is frozen, the time and the reason.
We receive from others:
- From Google, if you sign in with Google. Your email address, whether Google considers it verified, your name, and Google's stable account identifier. We request only the
openid,profile, andemailscopes. - From Stripe. Payment and dispute events for your purchases, stored as received. We keep the full event record.
- From Stripe Identity. The outcome of an identity check — its status, its session identifier, and when it completed. See section 4.
3. What we do not collect
Stated plainly, because their absence is a design decision and not an oversight:
- No third-party analytics. No Google Analytics, no product analytics, no advertising or tracking pixels, no cross-site tracking of any kind. There is nothing to opt out of because nothing is there.
- No advertising, and no sale or sharing of personal data. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- No identity documents. See section 4.
- No wallet addresses. A USDC deposit is matched by the reference code in its memo. We read the transaction you point us at; we do not record who sent it.
- No cookies except the ones the Service needs to work. See section 7.
4. Identity verification
Identity verification is required before your first shipment, before any payout, and once your lifetime spend crosses the published threshold.
We do not collect, receive, or store your identity documents. When verification is required, we create a session with Stripe Identity carrying only your internal account identifier, and you complete the check on Stripe's own hosted flow. Your document images and selfie go to Stripe, not to us.
What we store is the result: a status, Stripe's session identifier, and the time of verification.
5. Third parties who receive your data
We use the following processors. Each receives only what its job requires.
| Provider | What it is for | What it receives |
|---|---|---|
| Stripe | Card payments | Your internal account identifier and the purchase amount. Our servers do not send your email address; Stripe collects payment and contact details directly on its own checkout page. |
| Stripe Identity | Age and identity verification | Your internal account identifier, plus the documents and selfie you provide directly to Stripe. |
| Resend | Sending email | Your email address and the contents of the message, which include your username and any one-time link. |
| Shippo | Shipping labels | Your full shipping address, when and only when you request a shipment. Also our warehouse address and the internal shipment identifier. |
| Sign-in, if you choose it | Whatever Google's sign-in flow involves. We receive the fields listed in section 2. | |
| Solana RPC provider | Confirming USDC deposits | The transaction signature you submit. Solana transactions are public regardless. |
| Sentry | Server-side error monitoring | Technical error data only: stack traces, the route or operation that failed, and — when a session had already been resolved — your internal account identifier. Sent from our servers, never from your browser. Not used for analytics, advertising, or product tracking. |
Two further services are called with catalog data only and never receive anything about you: PriceCharting, for card market prices, and optcgapi, for the card catalogue. Card images may load in your browser directly from optcgapi.
Beyond these, the Service makes no third-party requests from your browser at all. Our Content Security Policy permits the page to talk only to our own origin, so no other party can be contacted from a page you are looking at.
We may also disclose personal data where we are legally required to, or where it is necessary to investigate fraud, protect the Service, or enforce our Terms.
6. What is public
Some of what you do is visible to others. This is controlled by a single setting, public activity, in your account settings.
While public activity is on:
- Your username and avatar appear on your public profile at
/u/<username>, alongside your best pull, your vault holdings, your rarity breakdown, and your set progress. - Notable pulls — rare and above — appear in the live feed and on the leaderboard, showing your username, the card, and its recorded value.
- Your username appears in the recent-pulls list on a card's page.
Turning public activity off removes you from the leaderboard and the live feed, clears you from the feed's recent history, and makes your public profile return "not found" — indistinguishable from a username that was never registered. Your own profile page still shows you everything.
Never public, under any setting: your email address, your balance, what you paid, your ledger, your spend totals, your address, and your verification status. Public totals are computed from the recorded value of cards you pulled, never from money you spent.
7. Cookies and local storage
We set three cookies. All of them are strictly necessary; none are used for analytics or advertising, so the Service does not ask for cookie consent.
| Cookie | Purpose | Lifetime |
|---|---|---|
tcg_session | Keeps you signed in | 30 days, extended as you keep using the Service |
tcg_google_state | Protects the Google sign-in exchange against forgery | 10 minutes, deleted as soon as sign-in completes |
tcg_google_verifier | Ditto (PKCE) | 10 minutes, deleted as soon as sign-in completes |
All three are HttpOnly, SameSite=Lax, and, in production, Secure. HttpOnly means no script on the page can read them.
Your browser also stores three display preferences locally — reveal speed, volume, and mute. These never leave your device and are not personal data.
8. How long we keep things
- Sessions expire 30 days after last use.
- Email links — verification and password reset — expire after 24 hours and one hour respectively, and are single use.
- Deposit intents expire six hours after they are created.
- Avatars are deleted from storage when you remove or replace them.
Transaction and game history is permanent. Your pull log, your balance ledger, your card history, and our record of payment events are append-only by design and cannot be edited or deleted, including by us. That is what makes the fairness proofs verifiable after the fact and the balance auditable; it is also a genuine limit on erasure, and we would rather say so than imply otherwise.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a supervisory authority. Residents of California, the EEA, and the UK have specific statutory rights.
What you can do today, in the Service:
- See and correct your email, username, and profile from your settings.
- Change your password, which also signs out every other device.
- Stop being public with the public activity toggle.
- Remove your avatar.
What we cannot yet do automatically. The Service has no self-service account deletion or data export. A deletion request today is handled by hand, and it cannot remove the append-only records described in section 8. Ask through the support channels in the Service and we will do what we can and tell you plainly what we could not. We consider the absence of these tools a gap rather than a policy, and section 12 records it as such.
10. Security
- Passwords are hashed with Argon2id and are never stored or logged in the clear.
- Session and email tokens are 256-bit random values; only their SHA-256 hashes are stored, so a copy of the database does not yield a working token.
- Cookies are
HttpOnly,SameSite=Lax, andSecurein production, and requests that change anything are rejected unless they come from our own site. - The Service sends a Content Security Policy that blocks the browser from contacting any origin but ours.
- Access to administrative data is restricted to accounts holding the operator role.
No system is perfectly secure. Where a breach affects your personal data, we will notify you as required by applicable law.
11. Children
The Service is for adults. You must be 18 or older, or the age of majority where you live, whichever is greater. We do not knowingly collect personal data from children. If we learn that we have, we will delete what we can and close the account.
12. Known gaps
Recorded here rather than omitted, because a policy that describes intentions instead of behaviour is worse than none:
- No self-service account deletion or data export. Section 9.
- Expired sessions and used email tokens are not yet physically deleted, only treated as invalid. They still hold an IP address and user-agent string until removed.
- No named controller, jurisdiction, retention schedule, or data protection contact. These depend on decisions counsel has not yet made.
- No cross-border transfer mechanism is documented, though several processors in section 5 operate internationally.
13. Changes
We may update this Policy. Material changes will be communicated by email or through the Service before they take effect. Other changes will be reflected in the "Last Updated" date above.
14. Contact
Reach us through the support channels available in the Service.