PacksPrivacy Policy
Privacy Policy
Last updated: September 2, 2026
This Privacy Policy explains what Pokécha (“we,” “us”) collects when you use the site, why, and the choices you have. It should be read alongside our Terms of Service.
1. Information we collect
Account information
Privy is our primary authentication provider. When you sign in with email or X, Privy provides the verified identity details needed to create your Pokecha account. Supabase stores a linked application profile and session so database row-level security can protect your records. We never receive your provider password.
Wallet sign-in
You can sign in with an Ethereum wallet instead. Privy verifies wallet control and provides the wallet address to Pokecha. If the wallet identity has no email, we ask you to add one for receipts and shipment updates. A self-entered contact address is stored separately from a provider-verified address.
Transaction & opening history
Every purchase, pack opening, referral-code redemption, shipment request, and sell-back request is recorded — the amount, the pack, the outcome, and, for openings, the seed hash and revealed seed used to prove fairness (§5 of our Terms). This is a financial and fairness audit trail; we do not delete it on request the way we would an optional profile field.
Device & location signal
We read a coarse location signal (typically your IP-derived or platform-reported country) to enforce jurisdiction restrictions on purchasing and opening. We do not use this for advertising and do not run analytics or ad trackers on the site. The authentication and wallet component that loads in your browser is Privy's (§3).
Cookies & browser storage
We use cookies and browser storage to keep your Privy and linked Supabase sessions active. That state remains until you sign out of Pokécha or clear it yourself. We do not use third-party advertising cookies.
2. How we use it
- Operate the service: authenticate you, remember your session, process an opening.
- Enforce the account and jurisdiction restrictions in our Terms.
- Administer the referral program: match a redemption to the code and the redeemer, and enforce one-redemption-ever and no-self-referral.
- Detect and prevent fraud and abuse (e.g., multiple accounts, chargeback abuse).
- Send transactional email (welcome, sign-in fallback, receipts) via our email provider once that path is live.
- Comply with legal obligations, including financial recordkeeping.
We do not sell your personal information.
3. Who we share it with
We share information only with the providers that operate the platform on our behalf, and only what each needs to do its job:
- Supabase — our database, authentication, and storage provider. Your account row, session, and transaction records live in Supabase's infrastructure, access-controlled by row-level security.
- X — provides social sign-in through Privy when you choose that method.
- Privy — provides primary authentication, embedded wallets, external-wallet connection, and supported wallet funding/onramp options. Privy receives the identifiers needed for the method you select.
- Resend — will deliver our transactional email once wired up.
- A payment processor — will process purchases once live payments are enabled; card details are handled directly by the processor and never touch our servers.
- Shipping carriers — if you request a slab shipped, we share the shipping address you provide with the carrier fulfilling that request.
- Law enforcement or regulators — when required by valid legal process.
4. Data retention
We keep account and profile data for as long as your account is active. Financial and fairness-audit records (ledger entries, pack openings, referral redemptions) are retained after account closure for as long as needed to meet accounting, fraud-prevention, and legal obligations — these records exist specifically so a past draw or transaction can be verified or audited later, so we do not delete them on a simple request the way we would, say, a display name.
5. Your rights & choices
You can review the account information tied to your session at any time on your account page. You may ask us to correct inaccurate profile information, or to close your account and delete data we are not otherwise required to retain (see §4 for what that excludes). Where local law grants additional rights — access, portability, deletion, or objection to processing — we honor them to the extent they apply. To exercise a request, use the contact method in §8.
6. Children's privacy
Pokécha is restricted to people 18 and older and we do not knowingly collect personal information from anyone under 18. We do not collect date of birth. If we learn an account belongs to someone under 18, we will disable paid features and take appropriate action on the account.
7. Security
Account and transaction data is protected by database-level row-level security (a user can only read their own rows; admin access is separately controlled) and transport encryption. No method of storage or transmission is 100% secure, but we scope access tightly and never expose privileged database credentials to the browser.
8. Changes to this policy & contact
We may update this policy as the product changes; material changes will be reflected by updating the date above. Questions about this policy or a data request can be sent by email to store.pokecha@gmail.com. We will get back to you as soon as possible.