Privacy and personal data
Updated: October 2, 2026
This notice describes the data processing currently involved in creating and securing a MainTable.app account. It will be updated as new features are introduced.
Data controller
WIZCARD EI, the business of Sébastien MANGIN, 1 rue du Château, 02250 Marle, France. Contact for questions and privacy requests: [email protected].
Data collected and purposes
Registration collects a username, email address, password, language and dated acceptance of the terms of use. Passwords are stored as non-reversible hashes. A six-digit code, also stored as a hash, confirms the email address. If a password is forgotten, a single-use link is sent and only its hash is stored temporarily. A unique URL identifier derived from the lowercase username without accents provides access to the public profile; the email address is not shown there. The last account activity date is used to determine inactivity. Session data and attempt counters help protect accounts from abuse. Likes are linked to the account, can be removed at any time and are erased with the account; only the total is displayed. Aggregate counters show views, deck copies and cards played. The deck composition used and its actions form part of the game history.
Legal basis and required data
Form data is needed to create the account and provide the requested service. Technical protection and rate limiting serve the legitimate interest of securing the service. An account cannot be created without a username, email address, password or successful anti-bot check. Acceptance of the terms of use is also required.
Recipients and providers
Wizcard manages accounts. OVHcloud hosts the service and database. Cloudflare delivers and protects site traffic and provides Turnstile: it may process IP addresses, technical data and request contents. Gmail receives the recipient’s email address, username and activation code or reset link needed to send the message. A private managed-services company makes daily backups. Cloudflare and Google may process some data outside the European Union. Their public documents describe transfer safeguards, including standard contractual clauses for Cloudflare and the EU–US framework for Google; their precise application to Wizcard’s accounts remains to be checked.
Security
Public connections to the site use HTTPS. Passwords and activation codes are hashed, sessions expire after inactivity, and authentication attempts are rate-limited. These measures do not mean that the entire database is encrypted at rest.
Retention
In the live database, unactivated accounts are deleted after 30 days and active accounts after two years without activity, except where temporary retention is required by a legal obligation or dispute. Deletion includes the user’s decks and games played at tables they joined; this can also remove other players’ game history at those tables. Activation codes expire after fifteen minutes and their hashes are erased on activation or with the pending account. Password reset links expire after thirty minutes; their hashes are erased when used or with the account. A private managed-services company makes daily backups and rotates older copies. Data erased from the live database may remain in those copies until they are replaced; Wizcard has not yet received the exact rotation period. The retention period for technical logs is also being checked.
Your rights
You can request access to, correction or deletion of your data, restriction of processing, and exercise other applicable rights by writing to the address above. You may also lodge a complaint with the French data protection authority, the CNIL. Account deletion can be requested by email; Wizcard will review which data can be erased and which must still be retained due to legal obligations or a dispute.
Wizcard will update this notice once its providers confirm the outstanding retention periods and processing terms. Privacy requests can be sent to the contact above.
Back to registration