Privacy Policy

Last updated 13 June 2026

This Privacy Policy explains what World Fan Wall (“we”, “us”, “the Wall”) collects when you use the site, why we collect it, how we keep it, and the choices and rights you have. We keep data collection to the minimum needed to run the service. By using the Wall you agree to this policy.

1. Who we are

World Fan Wall is an independent fan project that lets people place a personalised trading card on a shared digital wall. We are the data controller for the information described below. For any privacy question or request, contact hello@worldfanwall.com.

2. Information we collect

  • Account email — used to sign you in (via a one-time email code) and to email you when your card is live or about your orders.
  • Your card content — the name, country, position, photo you upload, chosen style/pose, and any social link you add.
  • Payment records — the amount, time, type and status of a purchase. Card numbers are handled entirely by Stripe; we never see or store your card number.
  • Affiliate data — if you join the affiliate program: your referral code, click counts, the purchases attributed to you, and your PayPal email for payouts.
  • Messages — anything you send us through the contact form or about an order.
  • Technical data — standard server logs (IP address, browser type, timestamps) used for security, fraud-prevention and rate-limiting, and a referral cookie if you arrive via an affiliate link.

3. How we use your information

  • To create your card and display it publicly on the wall.
  • To take payment and provide receipts and order support.
  • To sign you in and secure your account.
  • To operate the affiliate program (attributing referrals and calculating commissions).
  • To prevent abuse, fraud and spam, and to comply with our legal obligations.

4. Your photo and public content

The photo you upload is used to generate your trading card. For paid AI cards it is sent to our image provider (OpenAI) to create the artwork. Your finished card, the name and details on it, and any link you add are shown publicly on the wall — that is the point of the service. Do not upload anything you are not happy to show publicly, and only upload photos of people who have agreed to appear.

5. Who we share data with

We use a small number of processors to run the service, and share only what each needs:

  • Stripe — payment processing.
  • Supabase — database, authentication and file storage.
  • OpenAI — AI card image generation (paid cards only).
  • Resend — sending transactional and account emails.
  • Railway — hosting.

We do not sell your personal data. We may disclose information if required by law.

6. Cookies

We use essential cookies to keep you signed in. If you arrive through an affiliate link we store a referral cookie for up to 30 days so any purchase can be credited to that affiliate. We do not use third-party advertising cookies.

7. How long we keep it

We keep your account and card data for as long as your card is on the wall or your account is active. Payment and commission records are kept as long as needed for accounting and legal reasons. You can ask us to delete your account and cards at any time.

8. Your rights

  • Hide or remove a card from the wall at any time from your account.
  • Edit or remove the social link on a card.
  • Request a copy of your data, or its correction or deletion, by emailing us.

9. Security

The site is served over HTTPS. Payments run through Stripe’s secure checkout, so your card details never reach our servers. Access to administrative tools is restricted.

10. Children

The service is not directed at children under 13, and we do not knowingly collect their data.

11. Changes

We may update this policy; we will revise the “last updated” date above when we do.

12. Contact

Questions or a deletion request? Email hello@worldfanwall.com.