PacksPrivacy Policy
Privacy Policy
Last updated: July 23, 2026
This Privacy Policy explains what Pokécha (“we,” “us”) collects when you use the site, why, and the choices you have. It should be read alongside our Terms of Service.
1. Information we collect
Account information
When you sign in with Google, we receive your name, email address, and Google account identifier. We do not receive or store your Google password.
Age attestation
Before you can purchase or open a pack, we collect a self-attested date of birth to confirm you are 18 or older. This is compliance-critical data we retain as long as your account exists, and after, to the extent needed to show we enforced the age gate.
Transaction & opening history
Every purchase, pack opening, referral-code redemption, shipment request, and sell-back request is recorded — the amount, the pack, the outcome, and, for openings, the seed hash and revealed seed used to prove fairness (§5 of our Terms). This is a financial and fairness audit trail; we do not delete it on request the way we would an optional profile field.
Device & location signal
We read a coarse location signal (typically your IP-derived or platform-reported country) to enforce jurisdiction restrictions on purchasing and opening. We do not use this for advertising and do not currently run third-party analytics or ad trackers on the site.
Cookies
We use cookies strictly to keep you signed in (Supabase session cookies, refreshed automatically). We do not use third-party advertising cookies.
2. How we use it
- Operate the service: authenticate you, remember your session, process an opening.
- Enforce account eligibility and jurisdiction restrictions.
- Administer the referral program: match a redemption to the code and the redeemer, and enforce one-redemption-ever and no-self-referral.
- Detect and prevent fraud and abuse (e.g., multiple accounts, chargeback abuse).
- Send transactional email (welcome, sign-in fallback, receipts) via our email provider once that path is live.
- Comply with legal obligations, including financial recordkeeping.
We do not sell your personal information.
3. Who we share it with
We share information only with the providers that operate the platform on our behalf, and only what each needs to do its job:
- Supabase — our database, authentication, and storage provider. Your account row, session, and transaction records live in Supabase's infrastructure, access-controlled by row-level security.
- Google — provides OAuth sign-in; we receive the profile fields described in §1.
- Resend — will deliver our transactional email once wired up.
- A payment processor — will process purchases once live payments are enabled; card details are handled directly by the processor and never touch our servers.
- Shipping carriers — if you request a slab shipped, we share the shipping address you provide with the carrier fulfilling that request.
- Law enforcement or regulators — when required by valid legal process.
4. Data retention
We keep account and profile data for as long as your account is active. Financial and fairness-audit records (ledger entries, pack openings, referral redemptions) are retained after account closure for as long as needed to meet accounting, fraud-prevention, and legal obligations — these records exist specifically so a past draw or transaction can be verified or audited later, so we do not delete them on a simple request the way we would, say, a display name.
5. Your rights & choices
You can review the account information tied to your session at any time on your account page. You may ask us to correct inaccurate profile information, or to close your account and delete data we are not otherwise required to retain (see §4 for what that excludes). Where local law grants additional rights — access, portability, deletion, or objection to processing — we honor them to the extent they apply. To exercise a request, use the contact method in §8.
6. Children's privacy
Pokécha is restricted to people 18 and older and we do not knowingly collect personal information from anyone under 18. If we learn an account belongs to someone under 18, we will disable purchasing on it and take appropriate action on the account.
7. Security
Account and transaction data is protected by database-level row-level security (a user can only read their own rows; admin access is separately controlled) and transport encryption. No method of storage or transmission is 100% secure, but we scope access tightly and never expose privileged database credentials to the browser.
8. Changes to this policy & contact
We may update this policy as the product changes; material changes will be reflected by updating the date above. Questions about this policy or a data request can be sent to the contact address posted on the site once support channels are live.