Privacy Policy
1. Who we are
Wildpack is a mobile app that lets groups of friends create custom "Top Trumps"-style card packs by rating and describing each other. Wildpack is operated by Jack Maclay, trading as Wildpack, a sole trader based in the United Kingdom (not a registered company).
If you have questions about this policy or your data, contact us at [email protected].
2. Scope
This policy applies to anyone who uses the Wildpack app, wherever you're located. Sections 8 and 9 describe the extra rights available to you depending on where you live (the UK, the EU/EEA, or a US state with its own privacy law), on top of the baseline rights we offer everyone.
3. Information we collect
Account information (via Firebase Authentication): email address, password (hashed by Firebase, never visible to us in plain text), display name, profile photo.
Content you create: event and card-pack data, photos you upload (profile photo, card photos, shared album photos), ratings/scores you give or receive, written descriptions, friend connections, trophies earned.
Usage data: basic technical data needed to operate the app (e.g. which screens load, error logs if something breaks). We do not currently use any analytics or advertising SDKs.
We do not currently collect payment information. Stripe, our payment processor, collects and processes payment details directly for card-pack and photo-album purchases; we never see or store your card details ourselves.
4. How we use it
- To operate Wildpack's core features: creating events, inviting friends, submitting and voting on cards, and generating the final reveal.
- To maintain your account and let you log back in.
- To respond to support requests you send us.
- To detect and prevent abuse of the app (e.g. investigating a report about content that violates our Terms of Service).
We do not sell your data to third parties, and we do not use it for advertising.
5. Legal basis for processing (UK/EU users)
If you're in the UK or EU/EEA, we rely on the following legal bases under UK/EU GDPR:
- Contract — processing your account and content data is necessary to provide the Wildpack service you've signed up for.
- Legitimate interests — for basic technical/error logging needed to keep the app working, and for investigating reports of abuse.
- Consent — where we ask for it directly (e.g. if we ever add optional marketing communications; none currently exist).
6. Where it's stored
Your data is stored on Firebase (Google Cloud): Firestore for structured data (event, user, and card data) and Firebase Storage for photos.
- Data region: both our Firestore database and Firebase Storage bucket are located in
europe-west2(London, UK). Your data, including photos, is not transferred outside the UK for storage. Transactional emails (e.g. password reset) are sent via a provider operating in the EU (Ireland) — transfers from the UK to the EEA are permitted without additional safeguards under UK GDPR's adequacy regulations.
7. Sharing
- Event content (photos, ratings, descriptions) is visible only to members of the same event/group, not publicly, and not to other Wildpack users outside that group.
- Your display name and profile photo are visible to your friends and to members of events you share.
- We share data with Google/Firebase as our infrastructure provider (see Section 6). We do not share your data with any other third party, and we don't share it for their own marketing purposes.
- We may disclose data if required by law, or to protect the rights, safety, or property of Wildpack, our users, or the public.
8. Your rights
If you're in the UK or EU/EEA, UK/EU GDPR gives you the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Restrict or object to certain processing
- Data portability (receive your data in a portable format)
- Withdraw consent at any time, where we rely on consent
- Complain to your local data protection authority (in the UK, the ICO — ico.org.uk)
If you're in a US state with its own privacy law (e.g. California, Colorado, Virginia, Connecticut, Utah, and others as they come into effect), you may have similar rights to know what data we hold, request deletion, correct it, and opt out of certain processing. We extend these same rights to all Wildpack users globally, not only where legally required — see Section 9 for how to exercise them.
We do not sell personal data and have not sold personal data in the past 12 months, so there is nothing to opt out of on that front.
9. How to exercise your rights (account deletion, data export, corrections)
Account deletion is self-serve in the app: go to your profile and tap "Delete account." This immediately deletes your profile document and your login. Content you contributed to a shared event (e.g. a rating you gave someone else) may be retained in an anonymised form where removing it entirely would break the event for other members, unless you specifically ask for full removal. Note that friend connections and event membership records elsewhere in the app may still show your account for a period after deletion rather than being cleaned up instantly — contact us if you notice this and want it cleared sooner.
We don't yet have a self-serve data export button, or a self-serve way to request a correction to specific data. For either of those, email [email protected] from the email address on your account with what you'd like, and we'll action it within 30 days. We'll confirm by email once it's done. The same email address also works if you'd rather have us delete your account by hand, or if the in-app deletion doesn't work for you.
10. Reporting content
Reporting content is self-serve in the app during the voting phase: tap the flag icon on any photo or description to report it. Reports go to a queue only we can see and review by hand. Outside of voting, or if you want to report something the in-app flow doesn't cover (e.g. a display name, a whole event, or a pattern of behaviour rather than one piece of content), email [email protected] with the event name/code and a description, and we'll review and act on it (which can include removing content, removing a member from an event, or suspending the account responsible) as quickly as we can.
11. Data retention
We keep your account and content data for as long as your account is active. If you delete your account (see Section 9), we delete your personal data within 30 days, except where we need to retain limited information to comply with a legal obligation or resolve a dispute.
12. Children
Wildpack is not intended for anyone under 13 years old, and we don't knowingly collect data from children under 13. If you're a parent or guardian and believe your child under 13 has created a Wildpack account, contact [email protected] and we'll delete it.
If you're between 13 and 15 and located in a country where local law sets a higher "age of digital consent" for services like this (some EU member states set this as high as 16), you should have a parent or guardian's permission before using Wildpack.
13. Security
We rely on Firebase's built-in security features (authentication, encrypted storage/transport, and Firestore security rules that restrict who can read/write which data) to protect your information. No system is perfectly secure, but we take reasonable steps appropriate to a service of this size.
14. Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above and, for significant changes, notify users in-app or by email before the change takes effect.