封
WOOPRSealed Japanese TCG · Sydney
← Back to shop
Legal

Privacy

What we collect, why, who else sees it, and how to make us delete it. No dark patterns, no selling your data, ever.

Last updated 2 October 2026
On this page

What we collect

When you buy something

When you join the members programme

There is no password. Signing in sends a six-digit code to your email.

Automatically

We do not sell your data

Not to advertisers, not to data brokers, not to anyone. There is no scenario in which your details are a product we trade.

Why we collect it

We only send marketing email if you have asked for it, and every one has a one-click unsubscribe. Transactional email about an order you actually placed is not marketing and is not optional.

Who else sees it

Only these, only for the stated job:

WhoWhat they getWhat for
ShopifyOrder, account and payment detailsStore platform, checkout and payment processing
NetlifyRequest logs, session cookieHosting this site and the members backend
ResendYour email address and message contentSending members emails and reward codes
Australia PostName, delivery address, phoneDelivering the parcel
MetaA one-way hashed form of your email, phone and name, plus the order value and what you boughtMeasuring which of our ads led to a sale
Google FontsYour IP addressServing the site's typefaces

Some of these store data outside Australia: Shopify, Netlify, Resend and Google all operate overseas infrastructure, principally in the United States. By ordering, you consent to that transfer. Each is a substantial provider with its own published privacy commitments.

We will also disclose information if the law compels it: a court order, a regulator, or a legitimate law-enforcement request.

Advertising measurement

We advertise on Facebook and Instagram. To know whether that money is doing anything, we have to be able to connect an ad you saw to a box you bought. That is the only reason any of the following happens.

What is sent. When you browse the shop, the Meta pixel reports the page, the sets you look at, what you add to the cart and when you start checkout. When an order is paid, our server sends Meta the order total, the items, and your email, phone and name hashed first, which means converted to an irreversible string of characters. Meta compares that string against the one it already holds for your account. We never send your email address, phone number or name to Meta in readable form.

What we get back. Counts and totals. Which ad produced how many sales. We cannot see your Facebook or Instagram profile, your friends, or anything you do off this site.

How to stop it. Any of these works, and none of them affects your ability to order:

This is measurement, not a mailing list

Nothing here puts you on a marketing list, and nothing here is sold. It answers one question for us: did the ad work.

Cookies and local storage

Three of the entries below are advertising cookies, described in full above. Everything else here exists to keep you signed in or to remember a preference. We do not run a consent banner, because Australian law does not require one and we would rather tell you plainly on this page than train you to click Accept.

NameTypePurposeLife
hikari_sessionCookieKeeps you signed in. Holds a signed customer ID, nothing else.90 days
hikari_loginCookieGuards the sign-in handshake against forgery. Deleted the moment login finishes.10 minutes
hikari-themeLocal storageRemembers light or dark modeUntil cleared
hikari-viewLocal storageRemembers your grid density choiceUntil cleared
hikari-introSession storageStops the intro animation replaying on every page viewUntil tab closed
hikari-goldlockSession storageRemembers you have opened the vaultUntil tab closed
_fbpCookieSet by the Meta pixel. A random ID for this browser, so a sale can be matched to an ad. Holds nothing about you personally.90 days
_fbcCookieSet only if you arrived by clicking one of our ads. Stores that click's ID.90 days
wpr-fbcLocal storageOur copy of the above, because Safari deletes the cookie after 7 days and a pre-order can outlive that.Until cleared

The two cookies are HttpOnly, Secure and SameSite=Lax — unreadable to JavaScript, sent only over HTTPS. Shopify sets its own cookies during checkout; those are covered by Shopify's privacy policy.

Our own storage entries never leave your browser and are not sent to us. The _fbp, _fbc and wpr-fbc entries are the exception: they are the advertising IDs described above, and they are the one thing here you may want to clear.

How long we keep it

Your rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles you may:

Email contact@wooprtcg.com.au. We respond within 30 days, and usually within one day. There is no charge.

If our answer does not satisfy you, complain to the Office of the Australian Information Commissioner.

Security

No system is perfectly secure. If a breach ever occurs that is likely to cause you serious harm, we will notify you and the OAIC as the Notifiable Data Breaches scheme requires.

Who to contact

WOOPR, a trading name of ABN 40 319 255 624 · Sydney, NSW
contact@wooprtcg.com.au