LJ3 Cards
PRIVACY POLICY
What we collect, why we collect it, who it goes to, and how to get it removed.
Effective August 21, 2026
1. Scope
This policy covers lj3.cards. It is operated by [LEGAL ENTITY NAME], at [MAILING ADDRESS]. Our Discord server is also governed by Discord’s own privacy policy.
The short version: we collect what we need to run breaks and match cards to the right person. We do not sell your data, and we do not run advertising trackers.
2. What we collect
When you sign in. We use X, Discord, or Google to authenticate you. We never receive your password. From your chosen provider we receive:
- a provider account ID
- your username or handle, and display name
- your avatar image URL
- your email address, where the provider supplies one — X often does not, and we allow sign-in without it
What you give us.
- X and Discord handles you add so your past claims resolve to you
- Venmo and PayPal usernames — so an operator can match a payment to you. These are handles, not credentials. No card numbers, bank details, or payment credentials are ever collected or stored on this site; payment happens on those platforms, not here.
- Collecting preferences — favorite teams, sets you collect, chase cards
- A shipping address when cards are sent to you
- Anything you type into a notes field
What your activity creates.
- The spots you claim, the teams assigned to you, and which breaks you were in
- Notable cards pulled for your team, recorded after a break
- Amounts owed and whether an operator has marked a spot paid
- Shipping counts and bundle status
- Trades you make with other members
- Referrals, if you were referred or referred someone
Guest claims. If you claim a spot without an account, we store the handle you typed and a one-way hash of your IP address — not the address itself. The hash exists only to stop one person from taking the whole board, and it cannot be reversed back into your IP.
Automatically.
- Vercel Analytics — aggregate page-view counts. It is cookieless and does not build a cross-site profile of you.
- Standard server logs kept by our hosting provider (IP, user agent, timestamps), used for security and debugging.
Cookies. We use only what sign-in requires:
- Supabase session cookies, which keep you signed in.
lj3_return_to— a short-lived cookie (ten minutes) remembering which page to return you to after sign-in.
No advertising or cross-site tracking cookies are set.
3. Why we use it
- To run breaks: assign teams, track spots, and get the right cards to the right person
- To show you your own history, loyalty progress, and what you owe
- To match a payment or a claim typed by an operator back to your account
- To ship your cards
- To answer you when you contact us
- To prevent abuse — one-spot limits, duplicate claims, impersonation
We do not use your information for advertising, and we do not sell or rent it.
4. What other people can see
- Public break pages show which spots are taken but deliberately do not show who took them. A stranger with the link learns that a slot is gone, never whose it is.
- Signed-in members can see the roster of a break — the handles of who has which team. That is how a break works and is visible to other participants.
- Operators and admins can see member records, payment usernames, and claim history in order to run breaks and settle up.
- Your shipping address is visible only to us.
5. Who we share it with
Only service providers who run the site on our behalf, under their own privacy terms:
- Supabase — database, authentication, and image storage
- Vercel — hosting and the aggregate analytics above
- Resend — sending email we generate, such as a balance request
- Discord — where our community and break announcements live
- X, Discord, and Google — as sign-in providers, at the moment you choose one
We may also disclose information if the law requires it, or to protect our rights, our members, or the community from harm.
6. How long we keep it
- Account and break history: as long as your account exists, since your loyalty standing and past breaks depend on it.
- Records tied to a transaction or shipment: retained as long as needed for accounting and dispute resolution.
- Guest claim logs, including hashed IPs: kept only as long as useful for abuse prevention.
- On deletion, we remove your profile and preferences. Break records may be retained in de-identified form so historical boards stay intact.
7. Your choices and rights
- See it — most of what we hold about you is on your member dashboard.
- Correct it — edit your handles, payment usernames, and preferences there.
- Delete it — email us and we will close your account and remove your personal information, subject to the retention above.
- Unlink — you can revoke our access from X, Discord, or Google at any time in their own settings.
Depending on where you live, you may have additional rights — for example, California residents may request the categories of personal information collected and ask that it not be sold (we do not sell it). To exercise any of these, email lj3card@gmail.com.
8. Security
Data is stored with Supabase and protected by row-level security, so members can read their own records and not each other’s. Traffic is encrypted in transit. Administrative access is limited to operators. No system is perfectly secure, and we cannot guarantee absolute security — but we do not store payment credentials, so there are none to lose here.
9. Age
LJ3 Cards is for adults 18 and over. We do not knowingly collect information from anyone under 18. If you believe a minor has given us information, email us and we will delete it.
10. Where your data lives
Our providers operate in the United States, and your information is processed there. If you use the site from outside the US, you consent to that transfer.
11. Changes
If this policy changes, the effective date above changes and material changes are announced in Discord.
12. Contact
Questions, corrections, or deletion requests: lj3card@gmail.com.