1. The short version
The website offers wallet-approved collectible purchases through Collector Crypt. Browsing and pack purchases use your wallet; optional private binder features use a verified wallet session. We do not ask for your private keys or seed phrase, and we do not sell personal information.
2. Website purchases and public records
When purchases are activated, your public wallet address, pack selection, signed transaction, and purchase reference pass through our server to Collector Crypt to prepare payment, submit it, and deliver your collectible. Before approval, Gacha may query the configured Solana RPC for the transaction fee, simulation result, and public USDC token-account details. Blockchain addresses and transactions are public and can remain accessible permanently. Collector Crypt, the RPC provider, and your wallet provider handle information under their own policies.
Your browser stores purchase references, wallet addresses, selected packs, prices, dates, accepted pack terms, and the verified payment amount, recipient, network fee, and validation time so you can recover an interrupted opening. The Trust Center stores any cooling-off end time and maximum pack-price control in this browser. Clearing site data or using another device can remove those local controls. The server stores the matching purchase reference, a one-way transaction-message hash, and the same validation snapshot to prevent a different transaction from being submitted. This list is not a Gacha account or a current ownership ledger. Our hosting provider may process IP addresses, request times, and browser or device information for operation and security. Loading collectible images may send standard request information to the image host.
3. Information used by the app
The Gacha iPhone app stores collection and gameplay progress locally on your device. Gacha does not operate an account system or receive that gameplay data. If you choose to use Game Center, Apple may process your Game Center identity, achievements, and leaderboard activity under Apple’s terms and privacy policy.
4. Location
If you use a location-based “Field” feature, the app may request device location permission to provide that experience. Based on the current app design, location is used on the device and is not collected by Gacha servers. You can deny or revoke location permission in your device settings.
5. Messages you send us
If you use the online support form, Gacha stores your name, email address, topic, message, optional receipt reference, request identifier, and support status in our Supabase database. The form asks for your agreement before submission and confirms a reference only after saving. Authorized team members use these records to answer your request. Emailing us separately sends your message to our email service. Do not include private keys, seed phrases, passwords, or verification codes. We keep correspondence only as long as reasonably needed for support and applicable obligations.
6. Your binder, launch updates, and session cookies
When collection sync is activated and you verify your wallet, Gacha stores your wallet address, favorites, wishlist, collection folders, set goals, and purchase references in shared storage. Wallet verification uses a one-time signed message, not a spending approval. An essential, HTTP-only session cookie keeps your binder signed in for up to seven days. A Solana asset-index provider receives wallet or collectible addresses to check public ownership; it does not receive your private keys. If you request a balance check, our configured Solana RPC provider receives your public wallet address to read SOL and USDC balances. Gacha does not store balance snapshots from that tool.
Folders start private. Publishing a showcase makes that folder’s name, wallet address and selected current holdings visible to anyone with its link. Other folders, favorites, wishlists, set goals and private purchase history are not included. Turning off publishing prevents future access through Gacha, but cannot recall copies already saved by viewers or erase public blockchain data.
The redemption preview does not collect a recipient name, street address, identity document or shipping payment. Its planned tracking record contains a public wallet and collectible address, provider reference, destination country code, status and cost snapshot only. If redemption is activated later, sensitive delivery and identity information should be collected through the approved fulfiller’s protected process and its privacy terms.
If you opt into the app-launch list, we store your email address, consent, and signup date to send Gacha launch news. If signup or collection storage is not active, the page says so rather than treating an unsaved request as complete. Contact us to leave the list or request deletion of stored binder information. The website does not intentionally set advertising cookies or use third-party behavioral advertising. For abuse prevention, limited request counters use a daily keyed hash of a platform-provided IP address or email address rather than storing that identifier directly in the counters. Support records still contain the email you submit. Order-status checks store provider-reported states, observation times, check counts, and generic error codes. The private dashboard summarizes these operational records; it does not track your browsing clicks or infer that an unconfirmed order was abandoned.
7. Your choices and deletion
Use “Sign out of binder” to end your verified binder session, and disconnect your wallet to end its website connection. Clearing Gacha site storage removes the local purchase list, so save important receipt links first; it does not delete synced folders or the server’s purchase index. You can unpublish or remove folders in your binder, or contact us to request deletion of server-stored binder information or launch signup details. These actions do not erase blockchain transactions, transfer collectibles, or delete records held by Collector Crypt. In the app, use Settings → Delete All My Data to remove locally stored progress. For privacy questions or help, email info@trygacha.app.
8. Children and families
Website purchases involve real funds and third-party eligibility requirements. They are separate from the iPhone app’s gameplay. Do not submit children’s personal information through the support form. Parents and guardians should supervise device permissions and app use.
9. Security and changes
We use reasonable safeguards appropriate to the information we handle, but no technology is completely secure. We may update this policy as Gacha evolves. Material changes will be reflected by a new “Last updated” date and, where appropriate, an additional notice.
10. Contact
For privacy questions or requests, contact us at info@trygacha.app.