What we collect
To run Dynasty Nexus, we collect what's needed to give you an account and let you play the game:
- Phone number — required for sign-in (one-time codes via SMS). Stored encrypted at rest by our authentication provider.
- Username — chosen by you, public on the leaderboard and your profile.
- Display name — optional, public if set.
- In-game activity — your cards, trades, and score history. Most of this is public (leaderboard, public profile).
- Sleeper integration (optional) — if you link a Sleeper account, we store your Sleeper username and avatar so your profile can show them. That's the extent of it; unlink any time from your profile.
- Anonymous usage analytics — Vercel Web Analytics + Speed Insights. Aggregate page views and performance metrics. No personal identifiers, no third-party cookies.
- Bot-protection signals — when you sign up or log in, Cloudflare Turnstile collects limited browser characteristics (headers, basic fingerprint data) to verify you're a human and not an automated abuse bot. Cloudflare processes this transiently for the verification challenge; we don't store the underlying data.
- Server logs — like every web service, our hosting layer (Vercel) records standard HTTP request metadata including IP address, user-agent, and timestamps. Used for security, debugging, and abuse investigation. Retained on Vercel's standard schedule and not joined to your account identity beyond what's needed to investigate a specific issue.
- Session cookies — we set a small number of first-party cookies to keep you signed in and to bind your verify page to the phone you requested a code for. No third-party advertising cookies; no cross-site tracking.
What we don't collect
- No email address. Phone is the only identifier.
- No payment information for gameplay; the game is free. (Promotional-contest winners provide a payment handle and tax details to receive a prize. See Contest winners below.)
- No tracking pixels or third-party ad cookies.
How we use it
Strictly to run the platform: authenticate you, render the market, compute the leaderboard, send game notifications, and operate the Sleeper integration if you opt in. We don't sell or share your data with third parties for marketing.
Service providers see what they need to do their job:
- Supabase — our database + auth provider. Stores all account and game data.
- Twilio — delivers the SMS one-time codes. Receives your phone number for that purpose.
- Vercel — hosts the application and collects anonymized performance metrics.
- Sleeper — only contacted if you link your Sleeper account, to read your public username and avatar. We don't write to your Sleeper account. Our use of Sleeper's API is subject to their terms.
- Cloudflare — operates the Turnstile captcha that protects the sign-in flow. See the previous section for the data involved.
Contest winners
If you win a promotional contest, we and/or the contest sponsor collect and process the information needed to verify your eligibility and deliver your prize, which may include your name, contact details, a payment-service handle, and tax information (such as an IRS Form W-9). This information is used solely to verify eligibility, pay the prize, and meet tax and legal obligations, and may be shared with payment providers and tax authorities as required by law. With your consent (or where otherwise permitted), your public username may be announced as a winner. We do not sell this information.
SMS and the phone number we store
By signing up, you consent to receive SMS messages from Dynasty Nexus for authentication (one-time codes) and transactional notifications (e.g., weekly honors, game updates). Message frequency varies — typically one message per sign-in plus occasional event-driven alerts. Reply STOP to opt out of non-authentication alerts; reply HELP for help. Standard message and data rates may apply.
We share your phone number with Twilio solely to deliver those messages. We don't share it with anyone else, and we don't use it for marketing.
Where the data lives, how long we keep it
Account and game data lives in Supabase (Postgres) in US data centers. We keep your account data for as long as your account is active. If you ask us to delete your account, we'll process the deletion within 30 days. Some records may persist in aggregated / anonymized form for audit integrity (e.g., weekly trade totals) but won't identify you.
We don't currently auto-purge inactive accounts, but we reserve the right to remove accounts that have been inactive for two or more years with reasonable notice.
Your privacy rights
Depending on where you live, you may have specific rights over your personal data:
- California residents (CCPA / CPRA) — you have the right to know what we collect, request deletion, and opt out of any sale or sharing of your personal information. We do not sell or share your personal information for advertising.
- EU / UK residents (GDPR) — you have rights to access, rectify, delete, port, and restrict processing of your personal data, plus the right to lodge a complaint with your local data-protection authority. The legal basis for processing your account data is performance of our agreement with you; for security log retention, our legitimate interest in preventing abuse.
- All users — you can always email info@dynastynexus.com with any privacy request and we'll respond within 30 days.
Your controls
- Edit / unlink Sleeper — at any time from /profile.
- Sign out — from /profile. Ends the current session.
- Delete your account — email info@dynastynexus.com from the phone or username associated with the account. We process deletions within 30 days; some records (e.g., aggregated audit logs) may persist for integrity reasons but won't identify you.
Children
Dynasty Nexus is not directed at children under 13. If you believe a child has signed up, contact info@dynastynexus.com and we'll remove the account.
Changes
We'll post the "last updated" date above when this policy changes. Material changes are also announced in-app or by SMS. Continued use after a material change means you accept the new policy.
Contact
Questions, requests, or anything you don't see covered above: info@dynastynexus.com.