Last Updated: May 1, 2025
This Privacy Policy explains how Sekai (formerly Yonko SAS), the operator of Naruto Ninja Cards (“we,” “us,” or “our”), collects, uses, shares, and protects your personal information. We are committed to safeguarding your privacy and complying with applicable privacy laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), Canada’s PIPEDA, and other relevant regulations. We strive to be transparent about our data practices and give you control over your personal information. By using Naruto Ninja Cards (our website or mobile app), you agree to the collection and use of information as outlined in this policy.
1. Information We Collect
We collect both personal information (data that can identify you) and non-personal information. The types of information we collect depend on how you interact with our platform (web or mobile):
- Information You Provide:
- Account Information: When you create an account, we collect information such as your email address, username, and display name (if applicable). If you choose to sign up or log in via a third-party account we receive basic profile details from that provider (such as your name and email).
- Profile and Content: If the platform allows, you may provide additional profile details or content (for example, avatar, preferences, or feedback). Providing this information is optional.
- Customer Support Communications: If you contact us for support or give feedback, we collect the information you choose to provide in those communications (such as your contact details and a description of the issue).
- Information Collected Automatically:
When you use our website or app, certain data is collected automatically to help us understand usage and ensure the service works properly. This may include:- Device and Usage Data: We collect data about your device and how you use the platform. This includes your IP address, browser type, device type (e.g. model, operating system, unique device identifiers or advertising ID), language, and timestamps of access. We also log your interactions such as pages or screens viewed, features used, links clicked, and other usage metrics (e.g. time spent in the app, errors or crashes).
- Web Cookies & Similar Technologies: On our website, we use cookies and similar tracking technologies (such as web beacons or local storage) to remember your preferences and gather analytics about how you navigate our site. These cookies may collect information about your browsing behavior on our site over time. You can learn more in the Cookies section of this policy.
- Mobile App Analytics: In our mobile app, we embed analytics SDKs that function similarly to cookies. For example, we may use a device’s advertising identifier (IDFA on iOS, GAID on Android) with your permission for analytics or marketing attribution. (On iOS, we will prompt for your consent via Apple’s App Tracking Transparency framework before accessing IDFA or any data that could track you across apps.) If you decline, we will disable third-party tracking on that device.
- Information from Third-Party Services:
We work with third parties to enhance our platform and marketing, which may result in us receiving additional data about you or your device. For instance:- Analytics Providers: We use third-party services to gain insights into how you use Naruto Ninja Cards. These tools automatically collect technical and usage information and provide us with aggregated reports. (It may record in-app user interface interactions for usability analysis, but it is configured not to capture sensitive fields.)
- Advertising and Attribution Partners: We partner with marketing and ad platforms to understand how new users find us and how our ads perform. These partners might provide us with information like what ad or campaign led you to install the app or visit our site. For example, we may receive an anonymous advertising ID or campaign identifier and an install event. We do not receive your personal details from these ad platforms; we only get data used for measuring the effectiveness of our marketing.
- Social Login: If we offer sign-in with third-party services, those services will ask your permission to share certain information with us. We only use that information for authentication and to set up your account/profile.
We do not knowingly collect any sensitive personal data such as government ID numbers, financial information, or biometric data through the Naruto Ninja Cards platform. If in the future we need to collect new types of data, we will update this Policy and, if required, request your consent.
2. How We Use Your Information
We use the collected information for the following purposes:
- Provide and Maintain the Service: We process data to create your account, allow you to log in, and enable core features of Naruto Ninja Cards (such as your card collection, opening virtual scrolls, saving preferences, and interacting with other features). This also includes using data to troubleshoot and fix issues, ensure security (for example, to detect fraud or abuse), and to provide customer support when you contact us.
- Improve and Personalize the Platform: Usage and analytics data help us understand how users interact with our app and website. We use this insight to improve existing features, develop new features, and personalize your experience. For example, we might use your activity data to recommend content or tailor in-game experiences to your interests. We also analyze aggregated usage patterns to make the app more user-friendly and performant.
- Communicate with You: We use your contact information (like email) to send you important notifications about the service. This includes confirmations (e.g. account creation or purchase receipts), critical updates (such as changes to this Policy or Terms of Service), or security alerts (like suspicious login attempts). We may also send marketing communications such as newsletters, promotions, or news about upcoming features and events if you have agreed to receive them. You can opt-out of marketing emails at any time by clicking the unsubscribe link in the email or contacting us directly. (Transactional or service-critical emails, which are not promotional, may still be sent as needed.)
- Advertising and User Acquisition: With your consent where required, we may use and share certain data for advertising purposes. For example, we might use cookies or mobile IDs to enable our partners (like TikTok or Meta) to show you relevant ads for Naruto Ninja Cards on their platforms or to measure if our ads are effective. If you have given the appropriate consent (such as accepting advertising cookies on the web or allowing tracking on iOS), we might use your interactions (e.g. that you visited our site or achieved a milestone in-game) to tailor advertisements you see for our products on other platforms. Note: We do not serve third-party ads within the Naruto Ninja Cards app itself at this time; any advertising use of data is primarily for promoting our own platform externally.
- Legal Compliance and Protection: We may use your information to comply with legal obligations (for example, keeping transaction records for tax and accounting regulations, or responding to lawful requests by authorities). Additionally, we will process and possibly share data as needed to enforce our Terms of Service, investigate or prevent fraud, security issues, or other harmful behavior, and to protect the rights, property, and safety of our users, our company, or others. This can include analyzing logs for security breaches or using information to block abusive users.
Legal Bases for Processing (GDPR)
If you are located in the EU/EEA or another jurisdiction that requires a legal justification for data processing, we rely on the following legal bases:
- Consent: We will ask for your consent before processing certain data when required by law. For instance, we obtain your consent to send marketing emails, to use non-essential cookies, or to collect device identifiers for advertising analytics (e.g., the iOS tracking prompt). You have the right to withdraw your consent at any time (for example, by turning off certain app permissions or contacting us to opt out), but this will not affect the lawfulness of any processing already performed.
- Contract: When you create an account and accept our Terms of Service, a contract is formed between you and Sekai to provide the Naruto Ninja Cards service. We need to process certain personal data to fulfill this contract – for example, using your email to register your account or processing your data to maintain your in-app collection. Without this data, we wouldn’t be able to provide the service you expect.
- Legitimate Interests: In some cases, we process data to pursue our legitimate business interests in a manner that does not outweigh your privacy rights. For example, improving and securing our platform, or sending you product updates and offers if you are an existing customer, may be considered our legitimate interests. When we rely on this basis, we carefully consider and balance any potential impact on your rights. You have the right to object to processing based on legitimate interests (see Your Rights below).
- Legal Obligation: Finally, certain processing may be necessary to comply with a legal obligation, such as retaining records required by law or responding to valid legal process (subpoenas, court orders, etc.).
3. How We Share Your Information
We value your privacy and do not sell your personal information to third parties. However, we do share information in certain circumstances to operate our services effectively, as described below:
- Service Providers and Partners: We employ trusted third-party companies and individuals to perform functions and provide services on our behalf (collectively “Service Providers”). This includes, for example:
- Analytics & Performance: We share usage data with analytics providers so they can generate usage reports and help us troubleshoot issues. These partners act on our behalf and are bound by privacy obligations.
- Advertising & User Acquisition: We work with partners for advertising and user acquisition tracking. We may send them certain identifiers or event data (like that an install happened) to credit the source of a new user or to create lookalike audiences. These partners also have strict requirements under app store policies to only use that data for measurement and not misuse it.
- Infrastructure & Storage: We may use cloud hosting providers to store and process data securely. Similarly, we might use services for database management, content delivery, and other IT support.
- Communication Tools: If we send emails or newsletters, we might use a third-party email service to manage mailing lists and dispatch messages. Your name and email could be stored with such a provider for the purpose of sending you communication on our behalf.
- Payments and Purchases: If you make purchases (e.g. buying a digital “scroll” or other in-app content), those transactions are handled by Apple App Store or Google Play Store on mobile and Stripe on web. We do not receive your credit card number or financial details; we may get confirmation of your purchase and details of the item purchased to fulfill it in your account. (On the web, if we enable purchases, we would use a secure payment processor and similarly would not store full payment details ourselves.)
These Service Providers are given access only to the information necessary for them to perform their functions, and they are contractually obligated to protect it and use it only for the purposes we specify. - Affiliates: We may share your information with our corporate affiliates (e.g. parent company, subsidiaries, or other companies under common ownership with Sekai) if any, for purposes consistent with this Privacy Policy. Any affiliate who receives your information will also be bound to protect it under this Policy.
- Business Transfers: If Sekai (Yonko SAS) is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of that transaction. We would ensure that the new owner continues to honor the commitments we've made in this Privacy Policy regarding your personal data (unless you consent to changes). You would be notified via the website or email of any change in ownership or control of your personal information.
- Legal Compliance and Protection: We may disclose your information when we believe in good faith that such disclosure is necessary to:
- Comply with the law or legal process (for example, responding to a subpoena, court order, or regulatory request).
- Enforce our Terms of Service and other agreements or policies.
- Protect the rights, property, or safety of Sekai, our users, or the public. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction, or in the context of investigating security incidents.
- With Your Consent: In cases where we want to share your information for purposes not covered by the above, we will ask for your explicit consent. For example, if in the future we run a cross-promotion with another app or a contest together with a partner, we would only share your contact info with that third party if you opt-in to that specific program. You are in control and will decide if any additional sharing should occur.
Important: We do not sell your personal information to third parties for their own marketing use, and we do not share data with third-party advertisers for their independent purposes without your consent. In CCPA terms, we do not “sell” personal data (and we haven’t in the past 12 months). If that ever changes, we will update this policy and provide a mechanism for you to opt-out of such sale.
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website, and analogous identifiers in our mobile app, to provide and improve our services. Here’s a summary of how we use them:
- Types of Cookies/Trackers We Use:
- Essential Cookies: These are necessary for the website or app to function. For example, they help authenticate your login session and remember your preferences or items in your cart. Without these, certain basic features would not work.
- Analytics/Performance Cookies: These cookies (or mobile trackers) collect information about how users interact with our platform, which pages are visited, and any errors encountered. We use this data to improve the performance and design of our service. For instance, analytics cookies may track that a certain feature is frequently used or that a certain page load time is slow, informing us where to focus improvements.
- Advertising and Marketing Cookies: If you consent, we and our advertising partners use cookies or mobile IDs to collect information about your browsing or app usage over time across our site/app and other sites/apps. This information is used to personalize marketing – for example, to show you ads for Naruto Ninja Cards on other platforms that might be more relevant to you. They can also be used to limit how many times you see our ad or measure the effectiveness of ad campaigns. These cookies/trackers typically record information like when you visited our site, what content you viewed, whether you downloaded our app, etc., and they may combine it with other demographic information to target ads. We only deploy advertising cookies or similar tracking with your permission (e.g., via a cookie consent banner on the web, or via the mobile OS settings as described earlier).
- Your Choices:
When you first visit our website, you will be presented with a cookies consent banner (where required by law) giving you the option to allow or refuse non-essential cookies. You can always manage or delete cookies through your browser settings. Each browser is different, but most have options to remove or block cookies. Please note that if you disable cookies entirely, our website may not function properly – for example, you might not be able to stay logged in. - For the mobile app, you can control certain tracking via your device settings. For example, you can reset or limit the use of the advertising identifier, or decline to give permission for tracking when prompted on iOS. Additionally, you can typically opt out of personalized ads on your device (for instance, by enabling “Limit Ad Tracking” on iOS or “Opt out of Ads Personalization” on Android), which informs all apps not to use your ID for building ad profiles.
- Do Not Track: Our website does not respond to “Do Not Track” signals from browsers, because there is no agreed-upon standard for what those signals entail. However, we treat all users’ data with the same high level of security and privacy controls, and you still have the options described above to manage cookies and trackers.
For more detailed information about the specific cookies we set and the third-party cookies in use, you can review our Cookie settings or contact us. We may update our cookie usage from time to time, so we recommend reviewing your cookie preferences periodically.
5. Children’s Privacy
Naruto Ninja Cards is not directed to children, and we do not knowingly collect personal information from children without appropriate consent. The minimum age to create an account is 13 years old. If you are under the age of 13, please do not use our platform or submit any personal information. If you are between 13 and the age of legal majority in your jurisdiction, you should only use the platform under the supervision and with consent of a parent or legal guardian.
For residents of the European Economic Area (EEA) or other regions with similar regulations, we comply with the age limitations set by GDPR and local laws. In many EEA countries, the legal age for online consent is 16. If you are under 16 years old in the EEA, a parent or guardian’s consent is required before you can use our services.
Steps we take to protect children:
- Parental Consent: During onboarding, if we suspect a user is below the required age, we will ask for a parent or guardian’s email to verify consent. We reserve the right to request proof of age or consent at any time if we have reason to believe a user is underage.
- Account Restrictions: Users under the age of majority may have certain account features limited (for example, disabling public sharing or chat, if those exist) to provide a safer environment.
- Deletion of Minor’s Data: If we learn that we have inadvertently collected personal information from a child without proper consent, we will take steps to delete that information promptly. For instance, if a parent notifies us that their under-13 child created an account without permission, we will remove the account and any associated data.
- Parental Rights: If you are a parent or guardian and have concerns about your child’s personal information, you can contact us at any time (see Contact Us below). We will honor parental requests to review, edit, or delete a child’s information, or to refuse further collection of the child’s data.
6. Your Rights and Choices
We respect your rights regarding your personal data. Depending on your location and the applicable law, you may have some or all of the following rights:
- Access: You have the right to request a copy of the personal data we hold about you, as well as information about how we use it. This is sometimes called a “Data Subject Access Request.” We will provide this information, except in rare cases where we are legally permitted to refuse (in which case we will explain why).
- Correction (Rectification): If any of your information is inaccurate or incomplete, you have the right to ask us to correct it. You can also update certain information directly (for example, by logging into your account settings to change your email or profile details).
- Deletion: You can request that we delete your personal data. This is sometimes called the “Right to be Forgotten.” For example, you can ask us to delete your account and remove data we have about you. We will honor deletion requests to the extent required by applicable law. Keep in mind there are some situations where we may retain certain data for legal reasons (see Data Retention below). If you simply stop using the app, we may retain your data for a period, but you can contact us to explicitly delete it sooner.
- Data Portability: You have the right to request your personal data in a structured, commonly used, and machine-readable format, and you may ask us to transfer it to another entity where feasible. In practice, this could mean we provide you a file of your basic account information and content that you provided, so that you can move to another service. (This right applies to personal data processed by us by automated means, and where the processing is based on your consent or on a contract with you.)
- Restriction of Processing: You can ask us to restrict (pause) the processing of your data in certain circumstances. For example, if you contest the accuracy of your data, you can request we halt processing until we verify the information’s accuracy. Or if you object to our processing based on legitimate interest, you can request restriction while we consider your request.
- Objection to Processing: You have the right to object to certain types of processing. For instance, you can object to receiving direct marketing (and we will always honor an opt-out for marketing). If we are processing your data based on legitimate interest, you can object and we will evaluate your request and whether our interest in using the data is overridden by your rights and freedoms.
- Withdraw Consent: If we are processing any of your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing done before the withdrawal. For example, you can withdraw your consent for marketing emails by unsubscribing, or withdraw consent for tracking by adjusting your device settings or cookie preferences.
- Non-Discrimination (CCPA): If you exercise any of your rights under privacy laws, we will not discriminate against you. This means we will not deny you our services, provide a different level or quality of service, or charge you a different price just because you exercised your privacy rights. We treat all users equally, regardless of whether they choose to exercise their data rights.
To exercise any of your rights, please contact us at our support email with your request (see Contact Us section below). For your security and to prevent fraud, we will likely need to verify your identity before fulfilling a request (for example, by confirming ownership of the email associated with your account). We will respond to your request as soon as possible, and in any event within the timeframe required by law (30 days under GDPR, which may be extended if necessary with notice to you; 45 days under CCPA, etc.). If we cannot comply with your request, we will explain the reason in our response.
California Residents: In addition to the rights above, if you are a California resident, you have the right to request a notice describing the categories of personal information we have shared with third parties for their direct marketing purposes, and to opt-out of such sharing. However, as stated, we do not share personal information with third parties for their own direct marketing without consent. If you have any questions about our compliance with California law, you can contact us.
Canadian Residents: If you are in Canada, you have similar rights to access and correct your personal information under PIPEDA. You also have the right to file a complaint about our personal data practices with the Office of the Privacy Commissioner of Canada. We will happily address any concerns you have if you contact us first.
EEA/UK Residents: You also have the right to lodge a complaint with your local Data Protection Authority or the lead supervisory authority for Sekai’s activities. In France, for example, this would be the CNIL; in the UK, the ICO. We encourage you to contact us first so we can try to resolve your concern directly.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws. The exact duration we keep information can vary based on the type of data and the reasons for processing it:
- Active Account Data: If you have an active account with us, we will retain the information you have provided (and data generated through your use of the service) for as long as your account remains active. This allows us to provide you with ongoing access to your card collection, in-app purchases, and other account features each time you use Naruto Ninja Cards.
- Inactive Accounts: If you stop using Naruto Ninja Cards and do not explicitly delete your account, we may retain your data for a reasonable period in case you return, to make it easier to reactivate your account and recover your past progress/purchases. What constitutes a “reasonable period” may depend on business considerations, but we will not keep data indefinitely. We periodically review user accounts and may anonymize or delete information for accounts that have been inactive for a long time.
- Deletion Requests: If you request deletion of your data (as described in Your Rights above), we will process that request and securely erase or anonymize your personal data (unless a legal exception applies, as discussed below). Backups may not be immediately purged but will be cleared in the normal retention cycle.
- Legal and Operational Retention: We might need to retain certain information even after an account is deleted or you stop using the service, for reasons such as:
- Compliance with Laws: For example, records of financial transactions (purchases) may be kept for a minimum period for tax and accounting purposes. If we banned a user for legal violations, we may retain records of that to comply with legal obligations or law enforcement requests.
- Dispute Resolution: If there’s an ongoing issue, dispute, or legal claim involving your data or account, we will retain relevant information until it is resolved. For instance, if you filed a support claim or if there’s litigation, we’ll keep data through the resolution of that matter.
- Security and Fraud Prevention: We may retain logs and data needed for detecting/preventing security incidents or fraud. For example, we might keep records of IP addresses used to access a known fraudulent account to help investigate that abuse.
- Backup Archiving: Our system may keep encrypted backups for a certain period. When we delete data from our active systems, it might still persist for a time in these backups until they are rotated out. During that period, we maintain administrative and technical controls to prevent restoring or accessing deleted data unless absolutely necessary for security or legal reasons.
Once the retention period expires or the purpose for retention has been fulfilled, we will either delete your personal data or anonymize it so that it can no longer be linked to you. Anonymized data (which is not personally identifiable) may be retained for analytics and improvement purposes indefinitely, since it no longer constitutes personal information.
8. International Data Transfers
Sekai is based in France, but we have users around the world. Data you provide may be transferred to and stored on servers in countries different from your own. Specifically, our primary operations and servers may be located in the European Union and the United States (for example, if we use U.S.-based cloud services). This means your personal information could be processed in a jurisdiction that may not have the same level of data protection laws as your home country.
However, whenever we transfer personal data out of the EU/EEA, UK, or other regions with data transfer restrictions, we take steps to ensure your data remains protected according to applicable standards. These steps include:
- Adequacy Decisions: Where applicable, we may rely on a decision from the European Commission that the destination country’s laws offer an “adequate” level of data protection (for example, transfers from the EU to Canada are permitted because Canada is deemed to have adequate protections for certain data).
- Standard Contractual Clauses (SCCs): We may incorporate the European Commission’s approved Standard Contractual Clauses into our contracts with third-party service providers or within our corporate group, to provide a legal mechanism for data transfer with appropriate safeguards. These SCCs obligate the recipient to protect EU personal data to the high standard required by EU law, even if the data moves to a country with different laws.
- Additional Safeguards: We also evaluate the risk associated with international transfers and may implement additional technical and organizational measures as needed. For instance, we might employ encryption of data in transit and at rest, implement strict access controls, or store certain sensitive data only on servers in the EU when feasible. We also ensure that our U.S. service providers (if any) commit to standards like the EU-U.S. Data Privacy Framework or similar frameworks if they apply, or otherwise commit to GDPR-level protections.
By using Naruto Ninja Cards, you understand that your information may be transferred to our facilities and those third parties with whom we share it as described in this Policy. We will always handle your personal information securely, but if you prefer not to have your data transferred to other jurisdictions, please do not use our services.
If you have questions about our international data transfer practices or need more information about the safeguards in place, you can contact us (see Contact Us section below).
9. Data Security
We take data security seriously and have implemented measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Some of the security practices we employ include:
- Encryption: We use encryption protocols to protect data in transit and at rest. For example, our website and APIs are secured via HTTPS (SSL/TLS) which encrypts data between your device and our servers. Sensitive information (if any) stored on our servers is encrypted or hashed when feasible to add an extra layer of protection.
- Access Controls: We limit access to personal data to authorized employees, contractors, and Service Providers who need to know that information in order to process it for us. These parties are subject to strict contractual confidentiality obligations. Within Sekai, access to databases is restricted via role-based access controls, and employees with access undergo training on data privacy and security.
- Security Testing and Audits: We regularly review our information collection, storage, and processing practices to guard against unauthorized access. This includes periodic security audits and vulnerability assessments. We keep our software and infrastructure updated with the latest security patches. In addition, we may engage third-party specialists to perform penetration testing on our systems.
- Anonymization and Pseudonymization: Where possible, we minimize the use of personal data in our development and testing environments. We use anonymized or pseudonymized data sets for analysis so that actual personal identities are not exposed unnecessarily.
- Physical Security: The data centers where our servers reside are secured with industry-standard physical protections, including controlled access, surveillance, and environmental safeguards.
- Incident Response: We have an incident response plan in place to handle any suspected data breach. In the unlikely event of a security breach that affects your personal data, we will notify you and the relevant authorities as required by law.
Despite all our efforts, it is important to note that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. You can also play a part in keeping your data safe: please use a strong, unique password for your Naruto Ninja Cards account and do not share it with others. If you suspect any unauthorized access to your account or any security vulnerabilities, notify us immediately so we can take action.
10. Updates to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make changes to the policy, we will post the updated version with a new “Last Updated” date at the top. If the changes are significant, we will also provide a more prominent notice, such as via email notification to registered users or a pop-up notice in our app/website.
Your continued use of Naruto Ninja Cards after any such update constitutes acceptance of the changes. However, if we plan to use your personal data in a manner materially different from what was stated at the time of collection, we will seek your consent for those new uses when required by law.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting and using your information. It’s important that you understand our practices and your options.
If you do not agree with any updates to the Privacy Policy, you should stop using our services and you may request that we delete your personal data as described above.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us. We are here to help and will respond as soon as possible.
- Email: support@narutoninjacards.com
- Address: Sekai (Yonko SAS), 7 rue Mariotte, 75017 Paris, France
You can write to us in English or French. If contacting by mail, please mark your letter “Attn: Privacy Officer” or “Data Protection Inquiry” so it gets routed correctly.
Regulatory Contact: If you feel we have not addressed your privacy concern satisfactorily, you have the right to contact your national data protection authority (for EU/EEA users) or other relevant regulatory body. For example, in France you can contact the CNIL; in Canada, the Office of the Privacy Commissioner; in California, the Attorney General’s office. We sincerely hope to resolve any issues directly, but you are free to seek assistance from authorities as your rights entitle you.
Thank you for entrusting us with your information and for being a part of the Naruto Ninja Cards community. Your privacy is important to us, and we will continue working hard to protect it.