Privacy Policy
Updated July 2026Effective date: July 15, 2026 · Last updated: July 15, 2026
Introduction and scope
This Privacy Policy explains how Clockwise Cards LLC ("ClockwiseCards," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the ClockwiseCards mobile application and our related web pages at clockwisecards.com (including the invite, public-game join, pool-invite, and check-in pages) (together, the "Service").
ClockwiseCards is a scheduling and social-coordination tool for private poker games. It helps a host organize who is coming to a game and helps players say whether they will attend. It is not a gambling service and does not handle wagers, stakes, or money (see our Terms of Service).
This policy applies both to people who use the ClockwiseCards app and to people who interact only with our web pages (for example, someone who submits a request to join a game or a host's player pool through a web form). By using the Service, you acknowledge the practices described here. If you do not agree, please do not use the Service.
A note on our identity model. ClockwiseCards has no traditional user account — there is no username, password, or email login. When you first open the app, your device generates a random identifier that acts as your credential. A phone number becomes associated with your player identity only when a host sends you an invite link and you complete the invite ceremony (see Section 3). Understanding this model helps explain what we do and do not collect.
Quick summary
Phone number, name, a random device identifier, coarse (city-level) location for the optional "Looking For Game" feature, host-entered venue name, contacts you choose to import to send invites, game-participation and reliability activity, IP address (security), push-notification token, a one-way hash of your Apple/Google sign-in identifier (only if you link an Apple/Google account — a feature not currently available in the app), reports you submit about other players or games and your block list (safety tools), and crash and error reports (technical diagnostics with device/OS and app-version information and recent in-app events — never your name or phone number; only in builds where crash reporting is enabled).
Email address, precise/GPS location, street/physical addresses, camera, photos, videos, microphone, calendar, financial or payment data, or health data.
Sell your data. Share your data with third parties for their own advertising or marketing. Use advertising, analytics, or tracking SDKs. Track you across other apps or websites.
We use a small set of service providers (processors) — Supabase, Railway, the Expo Push Service, Cloudflare, Sentry (crash reporting), and, for the optional "Looking For Game" city lookup only, your device's Apple/Google operating-system geocoder (Section 6 lists them all) — solely to operate the Service on our behalf. We do not "sell" or "share" your personal information for cross-context behavioral advertising as those terms are defined under California law.
Information we collect
We collect only what the Service needs to function. Every category below reflects the Service's actual data practices.
3.1 Phone number
We collect your phone number in two distinct situations:
- Identity binding (in-app invite ceremony). A phone number becomes associated with your player identity only when a host sends you an invite link and you enter your own number to claim it. This is the sole way a phone number is bound to an in-app identity. A plain device sign-up collects no phone number.
- Join requests via web forms. Separately, if you use our public game-join or pool-invite web pages, you may enter your own phone number (and optionally your name) to request a seat or to join a host's player pool. This creates a pending request for the host to review; it does not, by itself, bind a phone number to an app identity.
Phone numbers are stored in the E.164 international format. We do not operate a "look up who's playing by phone number" feature; a person's invites and game details are visible only to the verified device that owns that number.
3.2 Name
We collect the display name you set for yourself. Hosts may also assign names to the contacts they manage (for example, to label a player in their pool). When you request to join through a web form, any name you type is stored with that request.
3.3 Contacts (name and phone number of other people)
If you are a host and choose to invite people, you can import contacts from your device's address book. When you do:
- We read only each contact's name and phone number(s). We do not read email addresses, postal addresses, or any other contact fields.
- The full address book is never uploaded. Only the specific contacts you select and add are sent to us (as a name plus phone number).
- A separate "request an invite" feature lets you pick a single contact to pre-fill a text message on your own device. That selection stays on your device and is not sent to us.
If you provide us with another person's contact information, you represent that you are permitted to share it with us for the purpose of inviting them (see our Terms of Service).
3.4 Location
There are two unrelated kinds of location data, and we treat them separately:
- Coarse device location (optional "Looking For Game" feature only). If you opt into the "Looking For Game" feature and grant permission, the app requests your device's approximate location to determine your city and state. We do not request or collect precise/GPS location. Your raw coordinates are used only to resolve a city/state and are not stored by us — we keep only the resulting city (and optionally state/country). Note: the step that converts coordinates into a city/state is performed by your device's operating system, which may transmit your coordinates to Apple or Google to resolve them; this is outside our control and governed by their privacy policies. You can skip this permission and simply type your city and state instead.
- Host-entered venue name. When a host creates or edits a game, they type a venue name (required). This is text the host authors — it is not sensed from a device. We store the venue name; we do not collect a street address.
3.5 Device identifier
When you first launch the app, it generates a random identifier (a UUID). This is not a hardware identifier, advertising identifier (IDFA/IDFV), or any cross-app tracking ID — it is an app-generated value that functions as your account credential. It is stored securely on your device and sent with your requests so we can recognize your player identity. We treat it as a credential and keep it out of our plaintext logs.
3.6 Push-notification token
If you enable notifications on a physical device, we collect a push-notification token so we can deliver notifications to you (for example, "someone joined your list"). Delivery is handled through the Expo Push Service (see Section 6). You can turn notifications off at any time in your device settings, and you can clear your token by disabling notifications in the app.
3.7 IP address (security and abuse prevention)
Our backend records the IP address of requests in security/audit logs, and stores a hashed (one-way) IP for requests submitted through our public web join/pool-invite forms. We use this for security, fraud prevention, rate-limiting, and abuse prevention — not to identify or track you for any other purpose.
3.8 Game participation and reliability activity
The Service generates activity data tied to your player identity, including: games you host or create, your join status and timing (for example, whether you said you would attend, saved your spot, or arrived), and the resulting reliability/punctuality history that hosts rely on. Hosts may also add free-text notes about a game. This activity is core to what the Service does — it lets a host see how reliably each player attends.
We also keep a small amount of first-party usage information on our own systems — for example, a record that an invite link for a game was opened, identified only by the game, its host, and a one-way hash of the invite token (never the recipient's phone number, device identifier, or IP address) — so we can tell whether invitations work. This information stays on our systems and never involves any third party (see Section 3.13 — we use no third-party analytics).
3.9 Account preferences & settings
We store preferences you set — available days, auto-join preference, maximum travel distance, and notification preferences — linked to your identity.
3.10 Social sign-in identifier (if you link one)
This capability is not currently available in the app (the sign-in UI is disabled); it is described here for transparency and for a future release. ClockwiseCards supports (as a gated capability) linking your Apple or Google account so your data can follow you across your own devices. If you use this, we store only a one-way cryptographic hash of your provider's subject identifier — we never store the raw identifier, and we do not store your email from the sign-in token. We use this solely for account linking / cross-device restore, never for advertising.
3.11 Crash reports and error diagnostics
The app includes a crash-reporting tool — the Sentry software development kit ("SDK") — so we can detect and fix crashes and errors. It is deliberately configured to be capture-only and to carry as little personal information as possible:
- What a report contains. If the app crashes or encounters an error, the report sent to our crash-reporting provider contains: the technical error details (error type, message, and stack trace); basic device and operating-system information the SDK attaches by default (such as device model, operating-system version, and our app's version); whether the build is a development or production build; a short trail of recent in-app events the SDK records automatically (called "breadcrumbs" — for example, recent screen navigations and taps) showing what led up to the problem; and, for errors in the app's interface code, a technical trace of the interface components involved.
- What a report does not contain. We disable the SDK's default personal-information collection, so it does not attach your IP address or any default user identifier to reports. The app never tells the crash reporter who you are: it does not attach your name, phone number, player identity, or contacts, and it never uses the SDK's user-identification features. Performance tracing, session replay, and profiling are off — the tool captures crash and error reports only.
- When it is active. Crash reporting runs only in app builds where we enable it at build time (by provisioning a crash-reporting key); in builds without that key the tool is fully inert and is never initialized. It applies to the mobile app only, not to our web pages.
Crash and error reports are transmitted to and stored by Sentry (sentry.io, a service of Functional Software, Inc.), which processes them on our behalf (see Section 6). Our backend server can likewise report its own errors to Sentry when we enable it; those server reports are scrubbed of tokens, device identifiers, and personal information before they are sent. We use crash reports solely to keep the Service stable and fix bugs — never for advertising, profiling, or tracking.
3.12 Reports and blocks (safety and moderation)
The app includes safety tools for reporting and blocking other users:
- Reports. You can report a player or a game you believe is abusive or inappropriate. A report records you as the reporter, the person or game you reported, a reason you select from a fixed list (harassment, spam, inappropriate content, impersonation, or other), and a snapshot of the reported name or game title. We use reports solely to review and act on potential abuse. Reports are visible only to us — never to the reported person or to other users.
- Blocks. You can block another player. We store your block list so we can apply it: you and a blocked player no longer see each other's activity in the Service. Blocking can also remove the blocked player from upcoming games you host and, if you choose, remove you from upcoming games you share with them. You can view and unblock blocked players in the app (Profile › Account › Blocked players).
- Retention for safety. Moderation reports are kept even if the reporter's or the reported person's account is later deleted — the report retains the name/title snapshot (de-linked from the deleted account) so that abuse records cannot be erased by deleting and recreating an identity (see Sections 7 and 9). Block entries, by contrast, are deleted when either account is deleted.
3.13 Information we do not collect
To be explicit, ClockwiseCards does not collect:
- Email addresses. (An internal field exists but is never populated.)
- Precise/GPS location. Fine-location permission is disabled; no device coordinates are stored by us.
- Camera, photos, videos, microphone, or calendar data. These permissions are not requested. (Venue-QR check-in is performed by your phone's own camera/QR reader opening a link; the app itself does not access your camera.)
- Financial, payment, or health data.
- Advertising, analytics, or tracking data. We use no third-party advertising, analytics, or tracking SDKs or services (no Amplitude, Mixpanel, Firebase Analytics, Google Analytics, Segment, ad networks, etc.), and our web pages block third-party origins. There is no "Data used to track you." Our crash-reporting tool (Section 3.11) is a diagnostics tool configured to carry no user identity; it is not an advertising or analytics service and is never used to track you. (The limited first-party usage records we keep on our own systems are described in Section 3.8 — they involve no third party.)
How we use your information
We use the information above to:
- Provide and operate the scheduling Service — create and manage games, invites, join lists, player pools, and reliability history.
- Verify a phone-number-to-device binding via the host invite ceremony (identity).
- Deliver notifications you have enabled (for example, invite and join-status notifications).
- Provide the optional "Looking For Game" matching feature (coarse city/state only).
- Detect, diagnose, and fix crashes, errors, and stability problems in the app (crash reports — Section 3.11).
- Operate our safety tools — review reports of abusive players or games and apply the blocks you set (Section 3.12).
- Understand whether core features work, using only first-party records on our own systems (Section 3.8).
- Maintain security, prevent fraud and abuse, enforce our Terms, and keep audit records.
- Comply with legal obligations and respond to lawful requests.
- Communicate with you about the Service (for example, service-related messages).
We do not use your information for advertising, profiling for advertising, or automated decision-making that produces legal or similarly significant effects about you.
Legal bases for processing (EEA / UK — GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you request: the invite ceremony, game participation, join lists, invitations, and reliability tracking that make the Service work.
- Consent (Art. 6(1)(a)) — for device permissions you grant, such as access to your contacts, approximate location (Looking For Game), and push notifications. You may withdraw consent at any time through your device settings, without affecting prior processing.
- Legitimate interests (Art. 6(1)(f)) — for security, fraud and abuse prevention (including IP logging), operating and retaining the report/block safety records (Section 3.12), crash and error diagnostics that keep the app stable (Section 3.11), delivering the Service reliably, and maintaining the reliability/punctuality history that hosts depend on to organize their games. Where we rely on legitimate interests, we balance them against your rights, and you may object (see Section 9).
- Legal obligation (Art. 6(1)(c)) — where we must process data to comply with applicable law or respond to lawful requests.
We do not intentionally collect special categories of personal data (Art. 9).
How we share information
We do not sell your personal information, and we do not share it with third parties for their own marketing or advertising. We share information only with service providers (processors) who act on our behalf and under contract, and where required by law.
Service providers (processors):
Supabase
Primary database host
Receives all personal data we store (phone, names, contacts you import, coarse city/state, host-entered venue name, device identifier, push token, activity, IP, join-request data, app preferences, moderation reports and block lists, and social-identity hash).
Railway
Backend/API host
Request traffic to our API transits it.
Expo Push Service
Notification delivery (relays to Apple APNs / Google FCM)
Receives your push token and the notification content, which may include a name and a game title/venue name.
Cloudflare
Web page hosting (clockwisecards.com funnel)
Serves our public web pages; the invite, check-in, and phone-change links it serves carry one-time security tokens (opaque codes, not your personal details) in their URLs, and a public join form transmits the name/phone you type to our backend. No personal data is pre-filled, and third-party origins are blocked.
Sentry (a service of Functional Software, Inc.)
Crash and error reporting (sentry.io)
Receives crash and error reports from the app, in builds where crash reporting is enabled (Section 3.11): technical error details and stack trace, device/OS and app-version information, and recent in-app breadcrumb events — with the SDK's default personal information disabled (no IP-address enrichment, no user identifiers, and never your name, phone number, or contacts). Also receives our backend's own error reports, scrubbed of tokens, device identifiers, and personal information.
Apple / Google (OS geocoder)
Operating-system reverse-geocoding (Looking For Game only)
Your device OS may transmit your coordinates to resolve a city/state; governed by their privacy policies.
We may also share information: (a) to comply with law, legal process, or lawful government requests; (b) to enforce our Terms or protect the rights, safety, and security of our users, the public, or ClockwiseCards; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this policy or notify you of any material change.
We do not use advertising or analytics providers. Sentry (above) is a crash-reporting (diagnostics) provider only — Section 3.11 describes exactly what a crash report contains and excludes.
Data retention
We keep personal information for as long as needed to provide the Service and for the legitimate and legal purposes described above.
- Ephemeral data is deleted automatically. Certain short-lived records (for example, "Looking For Game" posts and one-time invite/verification tokens that are never claimed) are purged automatically when they expire.
- What we keep, and for how long. As a category-level summary: (a) we retain the following until you delete your account (or ask us to delete it) — your identity (phone number, name, and device identifier), the games and series you host (including any venue name), your reliability and participation activity, your player-pool entries, your account preferences, your social-identity hash, your block list, join requests submitted through our web forms, claimed invite tokens, phone-change request history (which includes both the prior and the new number), and security and audit logs; (b) we automatically purge on expiry — "Looking For Game" posts and unclaimed invite and verification tokens, and pending or expired phone-change requests shortly after they lapse; and (c) we retain moderation reports (Section 3.12) even after a related account is deleted, for safety and abuse prevention. When you delete your account, the account-deletion process removes your phone number from the categories in (a), including join requests, claimed invite tokens, and phone-change history (see Section 9).
- Crash and error reports age out at our provider. Crash and error reports (Section 3.11) are stored by our crash-reporting provider, Sentry — not in our own database — and are deleted automatically at the end of Sentry's event-retention window.
- When we process a verified deletion request, we delete your personal data as described in Section 9. We may retain de-identified or aggregated information that can no longer be linked to you (for example, so that reliability statistics other hosts depend on cannot be manipulated by deleting and recreating an identity), we retain moderation reports de-linked from the deleted account (Section 3.12), and we may retain limited records where we have a legal obligation to do so.
Security
We take reasonable technical and organizational measures to protect your information, including: storing your data with a reputable database provider, transmitting data over encrypted connections, treating your device identifier as a credential and keeping it out of plaintext logs, storing only one-way hashes of social sign-in identifiers and public-form IP addresses, and rate-limiting and auditing sensitive operations. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Your privacy rights
Depending on where you live, you may have some or all of the following rights. To exercise any right, contact us at support@clockwisecards.com or use the in-app controls described below. We will respond within the timeframes required by applicable law and will not discriminate against you for exercising your rights.
- Access — request a copy of the personal information we hold about you.
- Correction — request that we correct inaccurate information. You can edit your display name and profile in the app.
- Deletion / erasure — delete your account and personal data directly in the app at Profile › Delete account. Deletion is immediate and permanent: it removes your account, your personal data, and your phone number everywhere it appears in our systems (including other hosts' contact lists), and deletes games you host. A small set of records survives in de-identified or de-linked form: security audit logs are anonymized (your identifier and IP address are removed), and moderation reports are retained de-linked from your account (Section 3.12). You may also request deletion by contacting us at support@clockwisecards.com; we delete your personal data when we process a verified request. A description of how deletion works is publicly available at https://clockwisecards.com/delete-account.
- Objection / restriction — where we rely on legitimate interests, object to or ask us to restrict certain processing.
- Portability — where applicable, receive your data in a portable format.
- Withdraw consent — turn off contacts, location, or notification permissions at any time in your device settings.
EEA / UK residents (GDPR). You have the rights above and the right to lodge a complaint with your local data protection supervisory authority.
California residents (CCPA/CPRA). In the preceding 12 months we have collected the following categories of personal information: identifiers (name, phone number, device identifier, IP address, push token, social-identity hash); California customer-records information (name and phone number); contact-list information (the contacts you choose to import to send invitations); approximate geolocation (city/state for the optional Looking For Game feature); internet or other network activity (your interactions and game participation, and — in builds where crash reporting is enabled — crash and error diagnostics); user content and messages (host notes and reports you submit through our safety tools); and app settings and preferences (such as your available days, auto-join preference, travel distance, and notification preferences). We collect it for the purposes in Section 4 and disclose it only to the service providers in Section 6.
- We do not "sell" your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. Because we do not sell or share, there is no opt-out to submit — but you may still contact us about your preferences.
- You have the right to know/access, delete, and correct your personal information, and the right to be free from discrimination for exercising these rights.
Other U.S. states / regions. If your jurisdiction grants similar rights, contact us and we will honor them as required by applicable law.
Children's privacy
The Service is a social scheduling tool (comparable to apps that help organize tabletop game nights). You must be at least 13 years old to use the Service. The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13; if we learn we have, we will delete it (contact support@clockwisecards.com).
International data transfers
We operate in Wyoming, United States, and use service providers located in the United States and other countries. If you access the Service from outside those countries, your information may be transferred to, stored in, and processed in a country whose data-protection laws differ from your own. Where required, we use appropriate safeguards for such transfers (for example, standard contractual clauses).
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" above and, where appropriate, provide additional notice (for example, in the app or on our website). Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact us
If you have questions or requests regarding this Privacy Policy or your personal information, contact:
Clockwise Cards LLC
Email: support@clockwisecards.com
Address: 1621 Central Avenue, Cheyenne, WY 82001