Privacy Policy

How United Rips collects, uses, shares and protects information about you.

Draft for attorney review
This document is a working draft to be reviewed and finalized by licensed counsel before launch, including state-specific privacy law requirements. Text in square brackets is a placeholder.

Effective date: [DATE]. Last updated: [DATE]. Controller: [ENTITY LEGAL NAME], [ADDRESS].

1. What we collect

Information you give us

  • Account: email address, name, phone number (optional), date of birth or age confirmation, US state of residence, and your sign-in tokens. We sign you in with a one-time link sent to your email; we do not store passwords.
  • Orders and pulls: what you bought, when, the price, the payment method type and a processor reference (never a full card number), the random client seed your browser generated for the purchase, the cards assigned to you, your buyback, vault and shipping decisions, and your store credit ledger.
  • Shipping addresses you save, and the carrier and tracking details for shipments to you.
  • Responsible purchasing settings: spend limits and break periods you set.
  • Support messages you send us.

Identity verification

  • Before we ship a card we verify your identity through Stripe Identity. You provide a government ID and a selfie directly to Stripe. Stripe processes the document and biometric data under its own privacy policy.
  • We do not receive or store your ID document images, document number or selfie. We receive and store only the verification outcome (verified, pending or failed), a Stripe session reference, and, where needed to match the name on a shipping address, the verified name.

Information collected automatically

  • IP address and inferred state: we record the state associated with your IP address at signup and at each purchase to comply with location rules, and we store it on the order.
  • Device and usage data: browser type, pages viewed, approximate timing and referrers, collected through server logs and [ANALYTICS PROVIDER]. We use cookie-free or first-party analytics where possible. [CONFIRM PROVIDER AND COOKIE USE.]
  • Cookies: a session cookie to keep you signed in and a preference cookie for settings such as reduced motion. We do not use advertising cookies.
  • Audit records: security-relevant actions on your account (sign-ins, setting changes, purchases) with timestamps and IP addresses.

2. Why we use it

PurposeExamplesLegal basis
Provide the serviceCreate your account, process orders, assign and store cards, show your vault, ship product, maintain your credit ledgerContract
Legal and complianceAge confirmation, state restrictions, identity verification before shipping, tax reporting, fraud and chargeback prevention, responding to lawful requestsLegal obligation, legitimate interest
Fairness and auditStoring the client seed and proof for every pull so that pulls can be verified after the seed is revealedContract, legitimate interest
CommunicationsSign-in links, order and shipping emails, buyback offer reminders, changes to terms, and, with your consent, product newsContract, consent
Improve the serviceAggregate analytics, performance monitoring, error logsLegitimate interest

We do not sell your personal information and we do not share it for cross-context behavioral advertising.

3. Public and shared information

  • The live feed shows recent pulls with a masked handle (for example the first letters of your name), the card and its tier. You are not identified by full name or email.
  • If you share a pull, the share page at that link shows the card, the reveal replay and the masked handle to anyone with the link.
  • The fairness data for a pack, published after the seed is revealed, includes each sold slot's proof: the purchase number, the client seed your browser generated, and the resulting slot. It does not include your name, email, order id or any account identifier.

4. Who we share it with

RecipientWhatWhy
StripePayment details you enter on Stripe's checkout, email, order amount; identity documents you submit to Stripe IdentityCard payments, Apple Pay and Link, identity verification
PayPalOrder amount and reference; details you enter on PayPalPayPal and Venmo payments
ResendEmail address and message contentSending sign-in links and transactional email
Hosting and database providers ([VERCEL], [RAILWAY])All data stored or processed by the PlatformRunning the service
Shipping carriers and insurerName, address, phone, declared valueDelivering and insuring your cards
Pricing data providersCard identifiers only; no personal dataFair market value estimates
Professional advisers and authoritiesWhat is necessaryLegal, tax and accounting obligations; lawful requests; protecting our rights

Each processor acts under a contract that restricts its use of your data to providing its service to us. If we are acquired or merge, your data may transfer to the successor under this policy.

5. How long we keep it

  • Account data: for as long as your account is open, then deleted or anonymized within [90] days of closure, except as noted below.
  • Orders, pulls, ledger entries and proofs: 7 years after the transaction, for tax, accounting, chargeback and audit purposes.
  • Identity verification outcome: for as long as your account is open plus [5] years. Document data is retained by Stripe under its policy, not by us.
  • IP and state records: on orders, for the order retention period; in server logs, [30] days.
  • Responsible purchasing settings: a self-exclusion is kept for its full duration even if you close your account, so that it cannot be bypassed by re-registering.
  • Audit logs: [2] years.

6. Your rights and choices

  1. Access and portability: you can see your profile, orders, vault and ledger in your account, and you can ask us for a copy of your personal data.
  2. Correction: update your name, phone, state and addresses in your account, or ask us to correct anything else.
  3. Deletion: ask us to close your account and delete your data. We will keep what Section 5 says we must keep and tell you what that is.
  4. Marketing: every marketing email has an unsubscribe link. Transactional emails (sign-in, orders, shipping, offer expiry, terms changes) are sent regardless.
  5. State privacy rights: residents of California, Colorado, Connecticut, Virginia, Texas, Oregon and other states with comprehensive privacy laws may have additional rights, including to opt out of sales or targeted advertising (we do neither) and to appeal a decision. We do not discriminate against you for exercising your rights. [ATTORNEY TO CONFIRM APPLICABLE STATE STATUTES AND THRESHOLDS.]
  6. Do Not Track and opt-out signals: because we do not sell or share data for advertising, these signals do not change how we treat you. [CONFIRM GPC HANDLING.]

To exercise any right, email [PRIVACY EMAIL] from the address on your account. We will respond within 45 days. We may need to verify your identity before acting.

7. Security

We use encryption in transit, encrypted storage with our hosting providers, access controls, audit logging and one-time sign-in links instead of passwords. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.

8. Children

The Platform is for adults only. We do not knowingly collect information from anyone under 18. If you believe a minor has an account, contact us and we will close it and delete the data.

9. Changes

We will post any changes here with a new effective date and, for material changes, notify you by email or on the Platform before they take effect.

10. Contact

[ENTITY LEGAL NAME]
[STREET ADDRESS]
[CITY, STATE ZIP]
Privacy requests: [PRIVACY EMAIL]

See also our Terms of Service.