1. Scope
This policy applies when you use the UntapGo website, install or use it as a progressive web application (PWA), create or attend an event, manage a profile or deck, use notifications, or contact the service. UntapGo helps local Magic: The Gathering players find one another and organise in-person tabletop events.
The policy covers information handled through the frontend and the UntapGo application programming interface. A third-party site or service linked from UntapGo applies its own privacy terms.
2. Who controls your data
The controller is {{LEGAL_ENTITY_NAME}}, operating the product under the name UntapGo. Its registered address is {{LEGAL_ENTITY_ADDRESS}} and company registration number is {{COMPANY_REGISTRATION_NUMBER}}.
Privacy questions and rights requests may be sent to {{PRIVACY_CONTACT_EMAIL}}. The current implementation does not establish that UntapGo has appointed a Data Protection Officer, so none is named here.
3. Information we process
Account and authentication
When you register with email and password, Supabase Authentication processes your email address, password authentication material, account identifier, confirmation status and session information. UntapGo does not need to read your plain-text password.
If you choose “Continue with Google”, Google authenticates you and Supabase receives the standard identity information made available for the openid, email and profile scopes. This can include a Google account identifier, email address, email-verification state, name and profile image. UntapGo does not receive your Google password and does not request access to Google Drive, Gmail, Calendar or contacts. Google processes the sign-in interaction under its own privacy terms.
Profile information
You can submit a nickname, avatar, biography and MTG Arena username. The service generates counts of events hosted and played. Privacy settings let you control whether your biography, Arena username, statistics and individually public decks appear on your public profile. Nickname and avatar remain visible so players can identify each other.
Events, participation and attendance
Event data can include title, description, date and duration, capacity, format, power level, proxy policy, host notes, venue address or label, Mapbox place identifier and coordinates. The service records hosting, seat requests, request decisions, membership, saved events, deck selections and the visibility chosen for those selections.
For attendance, UntapGo can process expected, checked-in, attended, no-show, excused or disputed status; timestamps; verification method; and the person who verified attendance. QR check-in uses a short-lived event token. Hosts may enable walk-ins and finalise a roster. Feedback about a host or player may include a sentiment and reason such as inaccurate details, poor communication or unsafe behaviour.
Location-related information
You may search for a place through Mapbox or ask your browser for device geolocation. The browser returns latitude and longitude only after permission. The selected coordinates, label and search radius are saved in your browser. Events contain their submitted location and coordinates so they can be listed, mapped and opened in an external map.
Deck and card information
Deck records can contain names, format, imported or exported deck text, card entries, commander choice, public status, event-specific visibility and a cover image or Scryfall identifier. Scryfall card data and artwork URLs are used to support search and deck display.
Safety, preferences and communications
UntapGo processes favourite and blocked-user relationships, profile reports with a reason and optional details, event feedback, profile visibility choices, distance-unit preference, notification settings and saved events. Reports may contain information submitted about another person and are available to authorised moderation personnel.
Notification, device and technical data
If you enable browser push notifications, the service processes a locally generated device identifier, Firebase Cloud Messaging token, web platform label, application version and browser permission state. Supabase session tokens are stored in browser storage for authenticated API requests. Like most online services, hosting and backend systems may generate request, error, security and server logs containing timestamps, IP addresses, request details and device or browser information. The exact backend log fields and retention must be confirmed before publication.
4. Public and private information
Event listings, including the event’s submitted address or location label, may be available to visitors and logged-in users. A listing identifies its host by nickname and can show format, time, capacity and other event details. Publishing an event can therefore reveal a planned real-world activity. Do not use a private home address unless you are comfortable sharing it with the relevant audience.
Nicknames and avatars are public identifiers. Biography, Arena username, statistics and public decks depend on profile settings and deck-level choices. At an event, hosts and participants may see one another’s nickname, avatar, role, participation or attendance status and the deck information deliberately shared for that event. Hosts see seat requests and attendance-management information required to run their event.
Blocked users have interactions restricted by the service, and the backend applies privacy filtering to public profile responses. Blocking cannot guarantee that two people will never see the same public listing, attend the same public venue or encounter information already shared offline. Reports and moderation records are not public, but may be seen by authorised administrators and disclosed where law or safety requires.
5. Purposes and legal bases
| Purpose | Information | GDPR basis |
|---|---|---|
| Accounts, authentication and account deletion | Email, identifiers, authentication and session data | Performance of the user agreement |
| Profiles, decks, events, requests, saved events and attendance | Profile, deck, event, participation and QR records | Performance of the user agreement |
| Location search and nearby results | Selected or device-provided coordinates, labels and radius | Consent for browser geolocation; performance of the agreement for a location you enter or select |
| Optional browser push | Permission, device ID, FCM token and preference | Consent, which you may withdraw by disabling push |
| Safety, blocking, reports and moderation | Relationships, reports, feedback and relevant account/event records | Legitimate interests in keeping the community safe, enforcing rules and preventing misuse; legal claims where necessary |
| Security and abuse prevention | Authentication, request and security log data | Legitimate interests in securing accounts and systems; legal obligation where applicable |
| Support and service operation | Contact content and related account or technical information | Performance of the agreement and legitimate interests in resolving problems |
| Compliance and legal claims | Information relevant to a lawful request, dispute or obligation | Legal obligation or establishment, exercise or defence of legal claims |
The frontend contains no analytics, behavioural advertising or marketing-email integration. UntapGo therefore does not state a legal basis for those activities here.
6. Location data
You can choose an area by searching Mapbox. Search text, a session token used by Mapbox Search, and the resulting place data are sent directly from your browser to Mapbox. You can also press the current-location control. Only then does the browser request high-accuracy geolocation permission. If granted, the coordinates are stored locally and used for nearby results and map positioning.
Creating an event requires a location label and place identifier and can include coordinates. Event pages display the submitted address and offer a Google Maps search link. Location choices can reveal homes, workplaces, routines or travel. Hosts should choose suitable public venues where possible and provide no more detail than participants need.
7. Cookies and similar technologies
UntapGo uses Supabase-managed first-party cookies for authentication, plus browser localStorage for an API access-token copy, selected location and radius, a push device identifier and push-enabled state. A Firebase service worker supports optional push delivery. These are described in the Cookie Policy.
No non-essential analytics or marketing storage was found in the current implementation, so UntapGo does not display a consent banner. Device geolocation and push notifications each use the browser’s separate permission prompt.
9. International transfers
Some providers are international businesses and may process information outside Estonia or the European Economic Area. The configured project regions, processor locations and transfer safeguards are not established by this repository. Before publication, the operator must document them in {{INTERNATIONAL_TRANSFER_INFORMATION}}. We do not claim use of a particular safeguard until that review is complete.
10. Retention and account deletion
UntapGo keeps information while an account is active and as needed to provide the relevant feature. No reliable fixed backend retention periods are present in this frontend. Retention must instead be limited by purpose, account status, safety needs, legal obligations and the time needed to resolve disputes.
- Account, profile, deck, saved-event and preference data are generally needed while the account exists.
- Event, request and attendance records may remain after an event to preserve event administration, safety records and user-facing history.
- Blocks remain until removed or the related data is deleted. Reports and moderation evidence may need to outlast other profile data to prevent repeated abuse or handle claims.
- Push tokens remain useful only while notifications are enabled for that device; the interface asks the backend to delete a device token when push is disabled.
- Support messages and security logs should be retained only while needed for support, security, compliance or claims. Exact criteria require backend review.
The account settings send a permanent deletion request to the backend and then sign the user out. The frontend does not prove which database rows, public content, authentication records, logs or backups are deleted, anonymised or retained, or how quickly. These effects must be confirmed as {{ACCOUNT_DELETION_BEHAVIOUR}}. Limited information may be retained where required for legal obligations, fraud prevention, safety or legal claims, and residual copies may persist temporarily in backups, but the operator must verify that this reflects actual practice.
11. Security
UntapGo uses authenticated API requests, managed authentication, backend-enforced profile visibility and short-lived rotating QR check-in tokens. Access to moderation and service systems should be limited to people who need it. No online system is completely secure, and UntapGo cannot promise that unauthorised access or loss will never occur. If you believe your account is compromised, sign out where possible and contact {{PRIVACY_CONTACT_EMAIL}}.
12. Your data-protection rights
Subject to the GDPR and applicable limits, you may ask for access to your personal data, correction, deletion, restriction, or a portable copy. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Push consent can be withdrawn in notification settings and browser settings; device-location permission can be withdrawn in browser or operating-system settings.
Send a request to {{PRIVACY_CONTACT_EMAIL}}. UntapGo may need to verify identity and clarify the request. You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or another competent supervisory authority, particularly in the EEA country where you live or work or where the issue occurred.
13. Automated decision-making
The inspected frontend contains no legally significant automated decision-making or profiling. Attendance statuses, feedback and moderation tools do not establish an active automated “Trust Score”. If this changes, this policy must be updated before the feature is used in a way that significantly affects people.
14. Children
UntapGo is not intended for anyone below {{MINIMUM_USER_AGE}}. The operator has not yet provided the minimum age or a parental-consent process. Do not create an account below the stated age once it is set. Offline events involving minors must also follow applicable law, venue rules and appropriate adult supervision.
15. Changes to this policy
This policy may change when the service, providers or legal requirements change. Material changes will be communicated through an appropriate in-service notice, email where suitable, or another reasonable method before they take effect when required. The effective and last-updated dates identify the published version.
16. Contact
Controller: {{LEGAL_ENTITY_NAME}}
Address: {{LEGAL_ENTITY_ADDRESS}}
Privacy contact: {{PRIVACY_CONTACT_EMAIL}}
