ManaMatesManaMates

Your data, clearly explained

Privacy Policy

ManaMates is built around collections and friendships. This policy explains which personal data is needed to run that service, what other Mates can see, and the choices you have.

Last updated 2 August 2026Version 1.0

1. Who is responsible

ManaMates (beta), based at The Netherlands, is the controller for personal data processed through ManaMates. Questions and privacy requests can be sent through the contact route on our Legal page.

This policy applies to the ManaMates website, account, collection, wants, deck, Mate, notification and chat features. It does not govern independent third-party websites.

2. Data we process

CategoryExamplesHow we receive it
Account dataEmail address, username, password hash, account status and timestampsYou provide it when registering or managing your account.
Card and social contentCollections, printings, quantities, wants, decks, availability, Mate relationships, chat messages and notificationsYou add it or create it through the service.
Import dataUploaded CSV/TXT contents, import results and validation errorsYou provide it when importing card lists.
Security and technical dataIP address and user-agent associated with sessions, token metadata, errors and limited server logsGenerated when you use or secure the service.
Card-service requestsCard names, printing identifiers and image requests sent to ScryfallGenerated when card information or artwork is loaded.

What other Mates see

Accepted Mates can view the collections and wants lists exposed by the current sharing features, and non-private completed decks. Spare collection cards are open to matches and proposals by default; you can opt your full collection out under Account, and cards reserved in decks or active trades are excluded automatically. Chat messages are visible to their sender and recipient. Do not add personal or confidential information to card-list names, deck notes or chat that you do not want the intended audience to see.

ManaMates does not use solely automated decision-making that produces legal or similarly significant effects. Card matching is a deterministic convenience feature based on wants and available cards.

3. Why we use it

PurposeLegal basis
Create accounts; store collections, wants and decks; connect Mates; deliver chat and notificationsPerformance of our agreement to provide ManaMates.
Authenticate sessions, prevent abuse, secure the service, diagnose faults and protect usersOur legitimate interests in operating a safe and reliable service.
Send password-reset and essential service messagesPerformance of the service and our legitimate security interests.
Meet legal requests, preserve evidence and comply with applicable lawLegal obligation or legitimate interests, depending on the request.
Use optional analytics or tracking technology in the futureConsent, requested before any non-essential technology is activated.

4. Sharing, processors and transfers

We disclose data only where needed to run ManaMates, when you intentionally share it with Mates, or where law requires it. Service providers may include hosting and database infrastructure, an outbound-email provider and error/security tooling selected for production. A current provider list and applicable processing agreements must be maintained by the operator.

Scryfall supplies card metadata, prices and images. Loading these resources can disclose technical request data such as your IP address to Scryfall. Scryfall is an independent service with its own privacy information.

If a provider processes data outside the European Economic Area, the operator will use an applicable transfer mechanism such as an adequacy decision or approved contractual safeguards, where required. ManaMates does not sell personal data.

5. How long we keep data

  • Account and user content: while the account is active and afterwards only as needed to complete deletion, resolve disputes or meet legal obligations.
  • Chat and social history: while available through the account, unless removed or required for safety and dispute handling.
  • Password-reset links: valid for 30 minutes and unusable after successful reset.
  • Session and security records: for their validity period and a proportionate period afterwards for security, fraud prevention and incident investigation.
  • Backups: until overwritten under the production backup schedule.

Before public launch, the operator must adopt documented deletion and backup schedules matching these criteria.

6. Your privacy rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or object to processing. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. We may need to verify your identity before acting.

Send a request to the Legal page contact. You may also complain to the Dutch Data Protection Authority or the authority in your country.

7. Security and children

ManaMates uses password hashing, verified email addresses, rate-limited authentication, short-lived HttpOnly access cookies, rotating refresh sessions, single-use password-reset links and access controls. No internet service can promise absolute security; report suspected account misuse immediately.

The beta is not directed to children under 16. If we learn that a child’s data was collected without a valid basis or required permission, we will take appropriate steps to remove it.

8. Changes and contact

We may update this policy when the service, providers or law changes. Material changes will be communicated in the service where appropriate, and the date at the top will change.

Privacy contact: complete the operator email before launch.