D20 Dungeon

Privacy

What we hold about you, why, and who else sees it.

Version 2026-09-16, in effect from that date

The short version

We hold the least we can get away with: what you tell us, and what a purchase or a booking needs in order to happen. We do not sell it, we do not share it for advertising, and there is no analytics or tracking of any kind on this site — no Google Analytics, no advertising pixels, no third-party trackers. Nobody is watching what you browse.

Card details never reach us at all. Payment happens inside Stripe, on their systems, even though the page around it is ours.

A few things on these pages load from somebody else’s service rather than ours — the map, a game master’s video, the card form on the payment page, and pictures — and what each of those can see is set out under cookies, below.

What we hold, and why

An account holds your email address, and your first and last name and a phone number if you give them. Email is how you sign in — there is no password to store.

If you have shopped at our counter, your account may have started from the register’s own customer record — your name, email address, phone number, what you had spent there and how many orders, and whether you had agreed to marketing email — so that somebody who shops in both places has one account rather than two. The counter keeps those up to date, so a change made there reaches your account here.

A purchase holds what you bought, what you paid, and where it went. A delivery holds the name, address and phone number needed to get a package to you. A pickup order holds no address at all.

A booking holds the date and time, what it cost, and which room or game master it was for.

A place at an event holds your name and how many places you took.

A seat at a weekly game holds however you asked us to reach you — a phone number, a Discord handle, or nothing. That is shown to the person organizing the table and to shop staff, and to the other players at that table only if you checked the box saying so.

A post or a seat request on the community board holds your first name, which is public on that board, and a contact note, which is not. Your surname and email are never shown there.

Selling us cards holds your name, how to reach you, what you sent us and any photos you uploaded. Where we pay cash, it also holds the TYPE of photo ID you showed and its last four digits — never a scan, never a copy, never the full number.

A bug report holds what you typed, any pictures you attached, the page you were on and the one before it, your window size, and your browser version, because a fault that cannot be reproduced cannot be fixed.

Store credit and the loyalty program hold what you have spent with us, which is summed from those purchases rather than stored as a separate profile.

If you join the achievements program, we record which achievements you have earned and when. Those are worked out from things this policy already describes — what you bought, when you visited, which events you came to — and the achievement itself is what we keep, not a separate profile of your habits. Your points are added up from that list rather than held as a score against your name.

It is opt in. Nothing is recorded until you press Join, and leaving stops it. If we ever show a leaderboard in the shop or online, it shows first names only, and you can ask us to keep you off it.

Who else sees it

Stripe processes payments and holds your card details. We never see a card number. It receives your email address with a payment and, when an order is shipped, the delivery address. Stripe also calculates tax and handles subscriptions for weekly seats.

Resend delivers our email. Everything we send passes through them — what we send you, including the sign-in link, and the notices staff get about your order, booking or request.

Google Workspace holds the shop’s own mailboxes. Those staff notices — with your name and what you bought or asked for — are kept there, and so is anything you write back to one of our emails.

EasyPost buys shipping labels and checks that a delivery address exists. It receives the name and address on a package.

Sortswift is our stock system for card singles. When you buy a card single it is told the sale so the card comes off the shelf everywhere else it is listed, and it receives your name, email address, phone number and — if the order is being shipped — the delivery address, so the order can be picked and handed to the right person.

Shopify runs the register at our counter and keeps our stock of everything that is not a card single. It holds the customer list the counter uses, and that list is kept the same as the accounts on this site: if you have an account here, Shopify holds your name, email address and phone number even if you have never shopped at the counter, and if you gave an email address at the counter, you have an account here with your name and phone number too. It also holds your store credit balance, so the same credit can be spent at the counter and here. Nothing we send it signs you up for marketing email. When you buy dice, games or anything else from the Shop on this site, Shopify is told what sold so the shelf count stays right — not who bought it.

Cloudflare stores files for us, including the photos and files you send us with cards to sell, a print request or a bug report, and the card pictures shown on this site. The nightly backup copy of the database is kept with Cloudflare too, in a store of its own. Cloudflare also sits in front of the whole site, so every page you open and everything you type into a form passes through it on the way to Vercel.

GitHub runs our scheduled jobs. One of them makes that nightly backup, so a copy of the database passes through one of their machines on its way to Cloudflare, and that machine is thrown away when the job ends. GitHub also keeps the code for this site, and our working notes there can name a customer — usually while tracing a problem with an order or a balance.

Anthropic makes Claude, the AI assistant the people who build this site use to write and repair it. Fixing a fault can mean it reads records from the database, which can include a customer’s name, orders or balance.

Neon hosts the database and Vercel hosts the site. Both hold the data in the ordinary course of running it.

That is the whole list of who receives what we hold about you. Nobody receives your details for their own marketing, and we have no advertising partners.

Cookies and what is kept in your browser

Signing in uses three cookies: one that keeps you signed in, one that protects the sign-in form from being submitted by another site, and one that remembers which page to send you back to afterwards. All three are needed for signing in, and none of them is used to track anything.

Your browser also remembers the page you were on before this one, and that you closed a notice at the top of the page so it does not reappear. The notice stays in your browser. The previous page stays there too, unless you send us a bug report, which includes it so we can see how you got to the fault.

There is no cookie banner because there is nothing to consent to. We set nothing for advertising or measurement.

The map on our front page comes from Google, which is why it sits behind a button. Nothing is sent to Google until you press "Show map" — at which point Google sees your address and may set its own cookies, as it would on any site. If you never press it, Google never hears from you.

A game master’s page can show an introduction video from YouTube or Vimeo. That one is not behind a button: when it comes into view your browser loads it from them, so they see your address and may set their own cookies, as they would on any site.

On the payment page, Stripe’s own code runs to take your card, and it may set cookies of its own there to spot fraud.

Most pictures on this site are served by Cloudflare, which keeps the card pictures, or by Shopify, which keeps our product photos, and a few are linked from other websites. Whichever one your browser fetches a picture from sees your internet address, as with a picture on any site. None of them tells us anything about you.

Other websites, and Do Not Track

We put no advertising or measurement code on this site, and nothing here follows you onto other websites.

The services that draw part of a page for us can still recognize your browser the way they do on any website that uses them, and so may collect information about your activity over time and across other sites: Google once you press "Show map", YouTube or Vimeo when a game master’s video loads, and Stripe on the payment page. What they do with it is governed by their own privacy policies, not ours.

Some browsers can send a signal asking websites not to track you — Do Not Track, or Global Privacy Control. This site behaves the same whether or not it receives one, because it does no tracking for the signal to switch off. The services named above decide for themselves what to do with it.

How long we keep it

Orders, bookings, tickets and payouts are kept as business records — an order from two years ago has to still read correctly, and tax rules require it.

Where you have transacted with us, we archive rather than delete: your history stays attached to what actually happened. Deleting a customer out from under a paid order would leave the shop unable to answer a question about its own trade.

Photos and files you send us — with cards to sell, a print request or a bug report — are kept with the job they came with and are never published. The site shows them only to shop staff.

Bug reports are kept after the fault is fixed, marked as fixed, because the same fault can come back and the first report is what shows that it has.

What you can ask us to do

Ask us what we hold about you and we’ll tell you. Ask us to correct it and we will. Ask us to delete it and we’ll remove everything we are not required to keep — write to [email protected] and say what you want.

Every email we send carries a way to reply to a person. If there is a kind of email from us you would rather not get, reply to one and say so.

If you live in California

We do not sell what we hold about you, and we do not give it to anybody for their advertising.

California’s "Shine the Light" law (Civil Code section 1798.83) lets a California customer ask which businesses we have given their personal information to for those businesses’ own direct marketing. We give it to nobody for that, so the answer is none. Write to [email protected] if you would like that in writing.

Anything described above under what you can ask us to do — seeing, correcting or deleting what we hold — works the same for California customers as for everybody else.

Children

You need to be at least 13 to have an account here. We do not knowingly hold information about anybody younger, and if we learn that we have, we’ll delete it.

Younger children are welcome in the shop and at events with a parent. Buying is done on the adult’s account.

Anybody who has posted on the community board — including anybody under 18 — can take the post down with the "Take it down" button on it, or write to [email protected] and we will take it down. That removes it from public view on this site. It cannot guarantee every copy is gone: somebody may already have copied it, and shop staff can still see that it was posted.

If something goes wrong

If data of ours is ever exposed, we’ll tell the people affected and say plainly what happened and what to do about it. Write to [email protected] with anything at all — it reaches a person, not a queue.

When this policy changes

The date at the top of this page is the version in force, and it is the date it took effect. When this policy changes in a way that matters, that date changes too.

Signing in asks you to check a box agreeing to the terms and this policy, and your account records which version was in force when you signed in. So the next time you sign in after a change, you are agreeing to the new one.