1) Who we are
Materia Creative Collective (“we”, “us”) operates the Spicy Cards website and web-based game experience (“Service”).
This Privacy Policy explains what personal data we collect, how we use it, how we share it, and the choices and rights available to individuals who visit or purchase Spicy Cards.
2) What we collect
We collect personal data in three main ways: (a) information provided directly, (b) information received from payment and delivery flows, and (c) information collected automatically when the Service is used.
2.1 Information you provide
- Contact information: email address (for receipt-based access delivery, subscription support, and customer support).
- Support communications: any information included when contacting us (for example, issue descriptions, screenshots, and correspondence).
- Optional information: if a name is provided (for example in support messages), it is processed for the purpose it was provided.
2.2 Purchase and access delivery information
Spicy Cards is sold as a subscription product through Gumroad. After successful payment, the purchaser receives a Gumroad receipt email containing a content access link. In connection with the purchase and access flow, we may process:
- Purchase metadata: product purchased, order identifiers, timestamps, payment status, and related transaction references.
- Customer details provided at checkout: typically email address, and where applicable details needed for taxes or receipts (for example billing country or billing address).
- Subscription data: plan selected, renewal status, cancellation status, billing period dates, and similar membership-related records made available to us through Gumroad.
- Delivery and access data: records needed to support receipt-based access, re-send guidance, and troubleshooting (for example order lookup details and access page events).
Important: we do not receive or store full payment card details. Payment information is handled by the checkout provider described in Section 5.
2.3 Automatically collected information (website and app usage)
When someone visits the website or uses the Service, we (and our service providers) may automatically collect:
- Device and network data: IP address, device type, browser type, operating system, language, and similar technical identifiers.
- Usage data: pages viewed, clicks, timestamps, referring URLs, error logs, and performance data.
- Cookies and similar technologies: see Section 6.
2.4 Gameplay inputs
Spicy Cards is an interactive web experience. Gameplay inputs such as player names and in-game selections are used to provide gameplay features such as scoring, progression, and session flow.
As part of normal gameplay, those inputs are stored locally in the browser on the device being used and are not collected by us. Spicy Cards is not intended to collect sensitive personal data during gameplay, and individuals should avoid entering sensitive information into game prompts or player fields.
3) How we use personal data
We use personal data for the following purposes:
3.1 Provide and deliver the Service
- To process subscription purchases and provide receipt-based access to the Service.
- To provide access troubleshooting, help locate purchase receipts, and resolve delivery or access issues.
- To operate core Service features and maintain functionality.
3.2 Customer support
- To respond to questions and support requests.
- To investigate technical problems and provide fixes or workarounds.
3.3 Security, fraud prevention, and service integrity
- To detect and prevent abuse (for example automated abuse, repeated failed access attempts, or suspicious activity).
- To protect the Service, users, and our business.
3.4 Improve the Service
- To understand performance and reliability.
- To improve the website and gameplay experience.
- To diagnose errors and optimize usability.
3.5 Legal and compliance
- To comply with legal obligations, enforce our terms, and handle disputes.
4) Legal bases (EEA, UK, and similar frameworks)
Where applicable, we rely on these legal bases to process personal data:
- Contract: processing needed to deliver the purchased product and provide access and support related to the purchase.
- Legitimate interests: maintaining security, preventing abuse, improving the Service, and responding to basic inquiries. These interests are balanced against individual rights.
- Consent: where required for non-essential cookies or similar technologies, and for optional communications if offered.
- Legal obligation: where certain records must be retained or where lawful requests must be handled.
5) Payments and checkout (Gumroad)
Payments are processed via a Gumroad checkout overlay. Gumroad acts as the merchant of record for subscription purchases and handles checkout, recurring billing, and related payment functions.
In practice:
- Gumroad collects and processes payment and checkout information to complete the transaction.
- We receive limited order details needed to provide access, support customers, and reconcile purchases (for example order identifiers, purchaser email, selected plan, and subscription status).
Individuals should also review Gumroad’s privacy documentation for details on their processing activities.
6) Cookies and similar technologies
We may use cookies, local storage, pixels, and similar technologies for:
- Essential operation: to ensure the website and Service function correctly.
- Preferences: to remember settings such as cookie choices and improve the experience.
- Analytics: to understand how the site is used and improve performance, where enabled.
- Local functionality: to store gameplay session information in the browser during use of the game.
Where legally required (for example in the EEA and UK), non-essential cookies are used only after consent is given through a cookie banner or similar mechanism. Consent choices can be changed at any time using the cookie controls presented on the site (if enabled).
6.1 Google Analytics
We use Google Analytics to understand how visitors use the website and to improve content and performance. Google Analytics may set cookies such as _ga and _ga_* to help measure site usage.
These cookies are used for analytics purposes only. Where required, analytics cookies are only set after consent.
7) Sharing and disclosures
We share personal data only as needed to operate Spicy Cards.
7.1 Service providers (processors)
We currently rely primarily on:
- Gumroad for checkout, payment processing, recurring billing, receipts, and membership-related purchase functions.
- Google Analytics for website analytics, where enabled by consent.
These providers process data under their own terms and privacy documentation, and only to the extent needed to provide the relevant service.
7.2 Legal and safety disclosures
Personal data may be disclosed if disclosure is believed necessary to:
- comply with a legal obligation or lawful request;
- protect the rights, safety, and integrity of the Service, users, or the business; or
- prevent fraud or abuse.
7.3 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
8) International transfers
Service providers may process personal data in countries other than where the individual lives. Where required, appropriate safeguards are used for international transfers (for example contractual protections) and we seek to ensure a level of protection consistent with applicable law.
9) Data retention
Personal data is kept only for as long as necessary for the purposes described in this policy, including:
- delivering access and providing support;
- maintaining security and preventing abuse; and
- meeting legal, accounting, or dispute-resolution requirements.
Retention periods vary depending on the type of data and why it is processed. When personal data is no longer needed, it is deleted or anonymized.
10) Security
Reasonable administrative, technical, and organizational measures are used to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. No online system can be guaranteed to be fully secure, so absolute security cannot be promised.
11) Your choices and rights
11.1 General choices
- Support and access emails: purchasers receive operational emails necessary for receipt-based access, subscription support, and customer support.
- Optional communications: if optional product updates are offered, individuals can opt out using an unsubscribe mechanism or by contacting us.
- Cookies: where applicable, cookie preferences can be adjusted via cookie controls on the website.
11.2 EEA and UK rights (where applicable)
Individuals may have rights to:
- request access to personal data;
- request correction of inaccurate data;
- request deletion in certain circumstances;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability in certain circumstances; and
- withdraw consent where processing is based on consent.
Individuals also have the right to lodge a complaint with a relevant data protection authority.
11.3 California privacy rights (if applicable)
If California privacy law applies to the business, California residents may have rights to:
- know what personal information is collected, used, disclosed, shared, or sold;
- request deletion of personal information, subject to certain exceptions;
- correct inaccurate personal information; and
- opt out of the sale or sharing of personal information where applicable.
Spicy Cards is not designed to “sell” personal information in exchange for money. If “sharing” for cross-context behavioral advertising occurs in the future (for example via certain advertising pixels), appropriate notices and opt-out mechanisms will be provided.
Requests can be made by emailing contact@spicy-cards.com. Identity verification may be required before fulfilling requests.
12) Children
Spicy Cards is not intended for children. Personal data from children is not knowingly collected. If a parent or guardian believes a child provided personal data, they can contact us to request deletion.
13) Changes to this policy
This Privacy Policy may be updated from time to time. The “Last updated” date at the top indicates when this policy was last revised. Material changes will be posted on this page.
14) Contact
For privacy questions or to exercise privacy rights, contact: contact@spicy-cards.com