Privacy Policy
Your private studio stays private. Sharing is a choice.
Updated October 7, 2026 · Draft pending operator details
The service’s legal operator, jurisdiction and final retention and refund terms still need confirmation. This draft describes the current product and does not replace mandatory rights.
1. Who and what this covers
This policy describes the LARPay website, community gallery and desktop app. The operator determines how these services process personal data. The operator’s full legal identity, address and jurisdiction have not yet been supplied; they must be added to this policy. Meanwhile, send privacy requests to hello@larppay.com or through the form below.
2. Private previews and your device
Website preview images are processed locally and stay in memory until you reset the preview, leave or close the page. Desktop saved designs use local IndexedDB. These private designs are not uploaded merely because you preview or save them. Community publication is a separate, explicit action.
The desktop app uses USB to identify a trusted iPhone, detect Wallet card identifiers and apply artwork. Raw device logs are filtered locally. Card identifiers are not sent to the community. License verification sends the license proof and installation binding to the server; license secrets are protected using operating-system encryption when available.
3. What the community stores
When you publish, the service stores your image, public creator name, title, description, category, upload time, agreed policy version and a pseudonymous browser ownership identifier. It validates and re-encodes accepted images into WebP, removing original embedded metadata. Information visibly shown in an image is not removed.
The image and its public details are visible worldwide. Likes are linked to a pseudonymous browser identifier; the public gallery shows aggregate like counts, not the private identifier. Creator names are not verified. Clearing cookies does not remove already published work. Delete uploads first, or submit an ownership request through the form.
A report or support request stores the name, email, supplied URL, message, request type, submission time and review status. These details are private to operators and service providers that process the request. Relevant complaint details may be shared with the affected uploader, a rights holder or authorities where necessary to handle a dispute or meet legal requirements. Do not include unrelated sensitive information.
Designs credited to creators on cardart.cc show the creator’s public handle and a link to the original page, as already published there. We do not collect other information about these creators. A creator can ask us to correct or remove these details through the form.
4. Purchases and service providers
Stripe processes payments on its hosted checkout. LARPay uses order identifiers, payment status, purchase email, license records and installation bindings to deliver and validate access and resolve purchase issues. LARPay does not store your payment card number or CVC. Email delivery uses a server queue and the configured email provider. If you agreed to receive relevant offers through our website, Stripe or another documented consent process, we may send one email when your checkout expires or payment is canceled without a completed purchase. We may use the checkout or billing email supplied through Stripe, including Apple Pay. The email includes a personal, single-use 10% discount link valid for 24 hours; once the offer is displayed on our site, you have five minutes to continue to checkout. We encrypt the recipient email and store the consent source or its operator confirmation and offer details to prevent duplicates, honor unsubscribe requests and stop reminders after a purchase. This is not a newsletter subscription. Use the unsubscribe link or reply to withdraw consent.
Production website traffic passes through Cloudflare. Firebase/Google Cloud provides the API and database; the configured database is in Frankfurt, Germany. Stripe and email and infrastructure providers may process data in other countries. Their processing is governed by their applicable terms and safeguards. Specific transfer arrangements and the final operator contact details remain to be documented; no EU-only processing promise is made.
Hosting providers may process IP addresses, request information and security logs. The API uses IP-based request limits to reduce abuse. LARPay does not sell personal data. Optional advertising measurement on the website is described in section 5 and runs only with your consent.
5. Cookies and browser storage
Website analytics: Google Analytics 4 loads only after you explicitly select Accept in our cookie banner or Cookie settings, in every country. An older acceptance of advertising pixels alone does not authorize Google Analytics. It measures page views, product views, checkout starts, installer download starts, copies of the installation command, and general checkout or download errors. These events may include the operating system and app version. Confirmed purchases include the verified order amount, currency and a pseudonymous transaction identifier. A download start or command copy does not confirm a completed installation. Google processes browser and device information, approximate location and cookie identifiers such as _ga; data may be processed outside your country. We exclude checkout session IDs and private URL parameters, license keys, payment card details, email addresses, uploaded images and support messages from the events we send to Google Analytics. Google signals and advertising personalization are disabled. Analytics does not run in the desktop app or the private license-delivery site. Select Decline in Cookie settings to stop collection and remove Analytics cookies from this site. Your analytics choice is stored separately in this browser.
The necessary community cookie is HttpOnly and links likes and uploaded artwork to this browser for up to one year. The checkout cookie links payment to license delivery for up to 30 days. The private purchase site uses a separate Secure, HttpOnly cookie, valid for up to 30 days, to let this browser view purchased keys and request another email copy. Temporary access links expire after two minutes and can be used once. The language setting uses browser storage, and desktop saved designs use IndexedDB. You can clear these in your browser or app settings; doing so may remove access to upload management or purchase delivery in that browser.
AI support: when you send a question, Cloudflare Workers AI processes your message and recent conversation to generate an answer from our support knowledge. LARPay does not save AI conversation transcripts or set chat cookies; the conversation stays in page memory and clears when you reload or choose New conversation. We store temporary usage counters and a daily pseudonymous connection identifier to limit abuse and usage. Do not send full license keys, payment card details, passwords or private purchase links. The assistant cannot access orders or contact staff for you. It is not included on our separate private purchase site or in the desktop app. Contact hello@larppay.com for personal support.
Advertising measurement: the website loads the Meta Pixel (Meta Platforms Ireland Ltd. and Meta Platforms, Inc.) and the TikTok Pixel (TikTok Technology Limited and its affiliates) to measure our ads. Visitors in the European Union, the EEA, the United Kingdom and Switzerland, or whose country cannot be determined, are asked first, and the pixels load only after they select Accept. Elsewhere, the pixels load automatically unless you decline in Cookie settings. They record page views, viewing the product and pricing page, starting checkout and completed purchases, with the price and currency. They set or read cookies and identifiers such as _fbp, _fbc and _ttp, and send them together with your IP address, browser and device details and the page address to Meta and TikTok. Meta and TikTok may link this to your account on their platforms, use it for ad measurement and delivery under their own privacy policies, and process it outside the EEA. If the pixels were allowed when you started checkout and you complete the purchase, our server also reports that purchase directly to Meta and TikTok (through Meta’s Conversions API and TikTok’s Events API), so each platform can match it to an ad and count it once. That report contains the price and currency, a purchase event identifier, the identifiers above or an ad click ID, your IP address and browser details, and a one-way SHA-256 hash of your purchase email, never the email itself. Nothing is reported if you declined or, in the regions above, had not accepted. License keys and payment card details are never sent to them. The pixels are never loaded on the private purchase site or in the desktop app, or, in the regions above, before you accept.
To opt out, select Decline in the cookie banner, or open Cookie settings in the website footer and select Decline. You can change your choice at any time; declining stops the pixels from loading and removes their cookies from this site. Your choice is saved in this browser’s storage. To decide whether to ask first, our hosting provider (Cloudflare) determines your approximate country from your connection; the country is not stored by LARPay. You can also clear site data or block third-party cookies in your browser, and manage ad preferences in your Meta and TikTok account settings.
How Google uses information from sites that use its services
6. Why data is used
Where GDPR or similar rules apply, processing needed to provide the service or fulfill your purchase is based on performance of a contract; fraud prevention, security and proportionate moderation rely on legitimate interests; required accounting and lawful disclosures rely on legal obligations. Consent is used where a specific optional use legally requires it, including the Meta and TikTok advertising pixels, and can be withdrawn at any time. We do not use the upload checkbox as blanket consent for unrelated processing.
7. Retention and deletion
Published artwork and its metadata remain until removed by you or moderation. Deleting an upload removes its active image and gallery record. Private like records and abuse-control records may remain for abuse prevention, and purchase, support and complaint records may be needed for license support, dispute handling and legal obligations. Provider logs and backups follow their configured retention; copies obtained by others cannot be recalled.
Exact retention periods and scheduled cleanup for residual like records, reports, security logs and backups still need operator approval and configuration. We do not promise an automated deletion schedule that is not implemented. The operator must review necessity and remove data when no longer needed.
8. Security
The website and API use HTTPS. Browser identifiers and access tokens are stored as one-way hashes, license keys are stored encrypted, and browsers cannot read the database directly. Uploaded images are decoded and re-encoded on the server before they are shown.
No system is perfectly secure, so never put information you need to keep private into a public upload. If you find a security problem, please tell us through the form instead of testing it on other people’s data.
9. Your choices and rights
Depending on your location and applicable law, you may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent for uses based on consent. You may complain to your local data protection authority. We may need reasonable verification before acting on a request. These rights may be limited by legal obligations or the rights of others.
Use the privacy option below, including the relevant artwork or order reference if available. Do not send full payment details, passwords or license keys. Uploads are intended for adults 18 and over. Report content or information concerning a child for review.
10. Changes to this policy
When this policy changes, we will update the date at the top of this page. For significant changes, or where the law requires it, we will also give notice on the site before the change takes effect.
More about applicable data rights: European Data Protection Board
Contact & requests
Send a private request to the site operator. Include enough information to locate and understand the issue.
