Privacy Policy

Last updated: July 13, 2026

Introduction

Will of Deck is operated by Los Necios LLC, a South Dakota limited liability company. In this Privacy Policy, "Will of Deck," "Los Necios," "we," "us," and "our" refer to Los Necios LLC.

Contact Information:

We are committed to protecting your privacy and ensuring you have a positive experience while using our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

Information We Collect

Personal information & account authentication

When you sign up using email/password with Supabase Auth, we (via our infrastructure providers) collect and maintain:

  • Email address used for authentication and account-related notices
  • Username or display profile fields you choose
  • Optional profile avatar URL or image preferences you configure
  • Password credentials (stored by Supabase using industry-standard hashing; we cannot read your plaintext password)
  • Records of acceptance (with timestamps) showing which version of these policies you agreed to

Technical & usage telemetry

We intentionally collect only what is needed to operate the Site. Today that includes data from:

  • Vercel Analytics: aggregate page-view and performance metrics (route visited, referrer, coarse device/browser class, and anonymized telemetry Vercel provides). This helps us gauge traffic—not individual click-by-click workflows.
  • Supabase Authentication & database: session tokens issued to stay signed in securely, timestamps for account lifecycle events, alongside the deck/collection/bindings data described below.
  • Supabase Postgres: rate-limit or quota counters tied to authenticated users where required by product features.

We do not run additional first-party behavioural analytics dashboards beyond the items above unless we update this Privacy Policy accordingly.

Saved content inside your account

We persist the playable content you expressly save inside the cloud database, currently including:

  • Deck lists, leaders, ratios, autosave checkpoints, deck metadata, tags, limits, decks you share with downstream features
  • Collection quantities, binder layouts, binder slot assignments, chase-card tags/notes/preferences
  • Custom tags you associate with catalogue cards while signed in
  • Optional periodic snapshots of your estimated collection value (totals over time) when that feature is enabled, derived from your saved quantities and catalogue pricing—not payment or brokerage data you provide to us
  • UI preferences you configure while signed in—theme (light/dark), site background style, and optional play style—stored in your profile as ui_preferences so they carry across sessions and devices
  • Tournament hosting records: tournament names, participants, match results, standings, and bracket pairings you create (Pro feature)
  • Match statistics: win/loss records, opponent information, deck performance metrics, and competitive tracking data you log (Pro feature)
  • Tournament participation: your registrations, deck selections for events, and match results in tournaments you join
  • Trade listings: cards you mark for trade, quantities available, trade preferences, and public storefront information you choose to share
  • Trade interaction preferences: auto-listing settings, default keep counts, and storefront visibility controls

Market pricing & collection estimates

To show estimated card and collection values, we maintain catalogue-wide market price records in our database (for example, latest market or mid prices keyed to cards in our catalogue). These rows are not sold to third parties and are not a list of what you personally own; they are reference data used to multiply against your saved collection quantities.

When you use collection value features while signed in, we compute display totals on our servers from your saved collection plus those reference prices. If we enable historical charts, we may store per-account snapshots (such as a weekly total) so you can see trends. We do not collect bank accounts, credit cards, or investment profiles for this feature.

Market figures originate from third-party market data feeds (see Third-Party Services). Coverage may be incomplete; unpriced cards are excluded from totals where no reference price exists.

Locally stored drafts & preferences

Portions of your experience use browser storage (typically localStorage or sessionStorage) for draft recovery (for example unfinished decks), presentation preferences (theme and background style), optional play-style selection, optional proxy-creator payloads, or short-lived UX flags.

When you are not signed in, those preferences stay on your device only. When you are signed in, theme, background style, and play style additionally sync to your profile in Supabase (see Saved content above). Other local-only artefacts—such as unfinished deck drafts or proxy-creator payloads—still do not sync unless you explicitly save the corresponding data inside your logged-in workspace. Clearing site data from your browser will remove local copies; signed-in UI preferences remain in your profile until you change or delete your account.

How We Use Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our services
  • To authenticate users and manage accounts
  • To personalize your experience and content
  • To enforce account caps (such as decks or binders) that protect platform stability through Supabase-hosted counters
  • To communicate with you about your account or support requests sent to us
  • To analyze usage patterns and improve platform functionality
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our terms

Lawful Basis for Processing (UK/EU)

If you are located in the United Kingdom or European Economic Area, we process your personal information based on the following lawful bases under GDPR and UK GDPR:

PurposeLawful Basis
Create and maintain your accountPerformance of contract
Authenticate and log you inPerformance of contract; Legitimate interests
Save decks, collections, binders, and preferencesPerformance of contract
Process subscriptions and paymentsPerformance of contract
Maintain invoices and tax recordsLegal obligation
Prevent fraud and abuseLegitimate interests; Legal obligation
Secure the service and protect accountsLegitimate interests
Respond to support requestsContract; Legitimate interests
Send required account noticesContract; Legitimate interests
Send promotional communicationsConsent (where required)
Operate analytics (essential)Legitimate interests
Operate analytics (non-essential)Consent (where required)
Establish or defend legal claimsLegitimate interests

Where we rely on legitimate interests, we have conducted balancing assessments to ensure our interests do not override your rights and freedoms. Where we rely on consent, you have the right to withdraw consent at any time.

Third-Party Services

Supabase

Supabase powers authentication, PostgreSQL-backed application data for features you sync to your account (with Row Level Security), automated backups handled by Supabase, and HTTPS transport encryption for API calls routed through Supabase-hosted endpoints. Operational detail is described in Supabase's own privacy policies and Trust Center publications.

Vercel

The public Will Of D. Eck frontend is deployed on Vercel, which terminates TLS, serves static bundles, emits edge logs (including originating IP/port metadata Vercel needs to mitigate abuse), and powers the Web Analytics instrumentation identified elsewhere in this policy.

Stripe Payment Processing

Stripe, Inc. processes all subscription payments and billing for Pro memberships. When you subscribe to Pro, Stripe may collect and process:

  • Name and email address
  • Billing address
  • Payment method information (credit/debit card details)
  • Transaction amount and currency
  • Subscription status and billing cycle
  • Invoice information
  • Payment success or failure status
  • Refund and dispute information
  • Fraud prevention and risk signals
  • Device, network, and authentication information

What Los Necios LLC receives from Stripe:

  • Stripe customer ID (to link your subscription to your account)
  • Subscription status (active, canceled, past due, etc.)
  • Subscription plan and billing interval
  • Invoice ID and transaction status
  • Payment method type (e.g., "card")
  • Card brand (e.g., "Visa," "Mastercard") and last 4 digits
  • Billing country
  • Refund or dispute status

Important: We do NOT store full credit card numbers, CVV/CVC security codes, or complete payment credentials. Stripe handles all sensitive payment data on PCI DSS compliant infrastructure. We have configured our integration to ensure payment credentials never touch our servers.

Stripe's Role

Stripe's role depends on the activity. Stripe processes information:

  • As a service provider / processor for payment processing functions we direct
  • As an independent controller for fraud prevention, identity verification, legal compliance, network security, and operation of certain Stripe services

Los Necios LLC remains responsible for lawful processing bases, vendor due diligence, checkout disclosures, data minimization, access controls, retention policies, responding to your rights requests, and secure technical integration.

Stripe's infrastructure is US-based with international compliance certifications. Data transfers are protected by Stripe's Data Processing Agreement and Standard Contractual Clauses. For details on how Stripe processes and protects payment data, review Stripe's Privacy Policy.

Market data providers

Estimated card and collection values rely on third-party trading-card market catalogues and price feeds (for example, data aggregated via TCGCSV-style product and price APIs). We ingest reference prices into our database; we do not send your account email, password, or full collection export to those providers as part of routine price display. Their own terms and privacy policies govern how they collect and license source market data.

Card images & display proxies

Card artwork may be loaded from our catalogue storage or, in some cases, retrieved through our application servers from third-party image URLs solely to render the interface. That processing is for display convenience; we do not use it to build a separate commercial image library.

Future integrations

Features such as ticketing, storefronts, or marketing automation may introduce additional subprocessors later. Whenever we materially expand processing, we will update this Privacy Policy and, when required by law or contract, notify you beforehand.

Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Secure authentication and authorization systems
  • Regular security assessments and updates
  • Access controls and monitoring
  • Secure hosting environments provided by Supabase (data plane) and Vercel (application delivery plane)

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

User Rights

You have the following rights regarding your personal information:

  • Access: Request access to your personal data
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your personal data
  • Restriction: Request restriction of processing
  • Billing History: Access your payment and subscription history via the Stripe Customer Portal (available through Profile → Manage Subscription)

To exercise these rights, please contact us using the information provided in the Contact Us section below.

Data Retention

We retain your personal information according to the following schedule:

Data TypeRetention Period
Active account data (profile, decks, collections)Duration of active account
Deleted account data30-90 days, then deleted or anonymized
Backups containing deleted dataOverwritten within 90 days
Security and access logs90-365 days
Support correspondence2 years after case closure
Subscription and invoice records7 years (tax/accounting requirements)
Payment dispute and chargeback recordsDuration of dispute plus 6 years
Fraud prevention recordsDuration of applicable limitation period
Policy acceptance recordsAccount lifetime plus legal defense period
Tournament, match, and trade recordsAccount lifetime plus 90 days post-deletion
Analytics data12-24 months maximum
Browser local storage (offline drafts, preferences)Until you clear browser data or app expiration

When You Delete Your Account

When you delete your account, we will delete or anonymize your personal information within 30-90 days, except where we are legally required to retain it for:

  • Tax and accounting compliance (subscription/invoice records)
  • Fraud prevention and security
  • Legal defense and dispute resolution
  • Regulatory compliance

Some information in automated backups may persist for up to 90 days until backups are overwritten in the normal course of operations.

Children's Privacy and Age Requirements

Age Requirements

To use Will of Deck:

  • You must be at least 13 years old to create a free account
  • Users under the age of majority in their jurisdiction (typically 18) must have parental or guardian permission to use the Service
  • You must be at least 18 years old (or the age of majority where you live) to purchase a Pro subscription, unless a parent or guardian completes the purchase on your behalf

Children's Information

We do not knowingly collect personal information from children under 13 without parental authorization. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at privacy@willofdeck.com. If we discover that we have collected information from a child under 13 without verified parental consent, we will delete that information promptly.

Parental Controls

If a parent or guardian purchases a Pro subscription for a minor, the parent/guardian is responsible for:

  • Managing the account and subscription
  • Monitoring the minor's use of the Service
  • Ensuring compliance with our Terms of Service
  • Managing payment methods and billing

Future Social Features

If we introduce community features such as messaging, public chat, enhanced public profiles, or user-generated content areas beyond our current tournament and trade features, we will conduct a separate child-safety assessment and may implement additional age restrictions, parental controls, and content moderation.

Given that trading card games attract minors, we may assess compliance with the UK Age Appropriate Design Code before materially expanding features accessible to children.

International Data Transfers

Los Necios LLC operates from the United States (South Dakota). Your information may be processed by us and our service providers in the United States and other countries where our vendors operate.

Where Your Data is Processed

  • Los Necios LLC: United States (South Dakota)
  • Supabase: West US (Oregon) for database hosting
  • Stripe: United States and global infrastructure for payment processing
  • Vercel: Global edge network for application delivery

How We Protect International Transfers

When your information is transferred outside your country, we protect it through:

  • Adequacy Decisions: Where applicable, we rely on adequacy arrangements recognized by UK and EU authorities
  • Standard Contractual Clauses: We use Standard Contractual Clauses (SCCs) approved by the European Commission and UK International Data Transfer Addenda where applicable
  • Data Processing Agreements: We maintain signed Data Processing Agreements with our vendors (Supabase, Stripe, Vercel)
  • Technical Safeguards: Encryption in transit and at rest, access controls, secure authentication, Row Level Security (Supabase), PCI DSS compliance (Stripe)
  • Organizational Measures: Vendor due diligence, security assessments, access restrictions, incident response procedures

These transfers are necessary to provide the Service and fulfill our contract with you. You may request more information about the safeguards we use for international transfers by contacting us at privacy@willofdeck.com.

California Privacy Rights (CCPA)

If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request information about the personal data we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (Note: We do not sell personal information)
  • Right to Non-Discrimination: Receive equal service and pricing even if you exercise your privacy rights

To exercise these rights, please contact us at privacy@willofdeck.com. We will verify your identity before processing your request.

European and UK Privacy Rights (GDPR/UK GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:

Your Rights

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data (subject to legal exceptions)
  • Right to Restriction: Request that we limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format and transfer it to another service
  • Right to Object: Object to processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Rights Related to Automated Decision-Making: Request human review of automated decisions (if applicable)

How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@willofdeck.com with:

  • Your full name and account email address
  • The specific right you wish to exercise
  • Any details needed to locate your information
  • Proof of identity (to protect your privacy)

We will verify your identity before processing your request to ensure we are disclosing or modifying information only to the authorized account holder.

Response Timeframes

We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days and will notify you of any delay and the reasons for it.

Limitations on Rights

In some cases, we may be unable to fully comply with your request where:

  • Disclosure would reveal information about other individuals
  • We must retain information for legal, tax, or regulatory compliance
  • Information is needed to establish, exercise, or defend legal claims
  • Requests are manifestly unfounded, excessive, or repetitive

We will explain any limitations or reasons for denial in our response.

Right to Lodge a Complaint

If you are not satisfied with how we handle your request or our data practices, you have the right to lodge a complaint with your data protection supervisory authority:

UK Residents:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Phone: 0303 123 1113

EEA Residents:

Contact your national data protection supervisory authority

Find your authority: EDPB Member List

We process your data based on: (1) your consent, (2) performance of our contract with you, (3) compliance with legal obligations, or (4) our legitimate interests. See the "Lawful Basis for Processing" section above for details. Data transfers comply with UK adequacy decisions, Standard Contractual Clauses, and UK International Data Transfer Addenda where applicable.

Cookies and Tracking Technologies

We use cookies, browser storage, and similar technologies to provide and improve our Service. This section explains what technologies we use and your choices.

Strictly Necessary Technologies

These are essential for the Service to function and cannot be disabled:

  • Authentication cookies: HTTP-only cookies from Supabase to maintain your login session securely
  • Security tokens: Session tokens to prevent unauthorized access
  • Essential localStorage: Storing critical app state for functionality

Functional and Analytics Technologies

These enhance your experience and help us improve the Service:

  • Preferences storage: localStorage/sessionStorage for theme, background style, play style, deck drafts, and creator tool data
  • Vercel Web Analytics: Anonymized, aggregate traffic metrics (page views, performance, referrers)
  • Performance monitoring: Anonymized telemetry to detect performance issues

Payment and Fraud Prevention

  • Stripe.js: Secures payment forms and tokenizes payment data
  • Stripe fraud detection: Fraud prevention signals processed by Stripe

Your Cookie Choices

UK and EEA Users:

For non-essential cookies and technologies, we will ask for your consent through a cookie banner. You can:

  • Accept all cookies
  • Reject non-essential cookies
  • Choose specific cookie categories
  • Withdraw consent at any time

All Users:

You can also manage cookies through your browser settings. Note that disabling necessary cookies will affect your ability to use certain features of the Service. Browser controls alone do not constitute valid consent for non-essential cookies under UK/EU law.

Detailed Cookie Information: For a complete list of cookies, their purposes, duration, and third-party cookies, see our separate Cookie Policy.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We will respond to your inquiries within a reasonable timeframe, typically within 30 days.