⚠️ This is a draft. Have this document reviewed by a lawyer before publishing.
Privacy Policy
Last updated: June 2026 · Version 1.0 (draft)
1. Who we are
TCGPriceHub is an online Pokémon TCG portfolio tracker operated by:
TODO: Company name, Chamber of Commerce number, address, and email address.
2. What data we collect
2.1 Account data
- Email address (required at registration)
- Username
- Hashed password (bcrypt — never stored in readable form)
2.2 Usage data
- Cards and products you add to your collection or wishlist
- Purchase prices you enter yourself
- Settings and preferences within the app
2.3 Technical data
- IP address (for security and fraud prevention)
- Session cookies (required to stay logged in)
- Error logs (no personal data)
2.4 Payment data (paid subscription)
TODO: Activate when Mollie integration goes live. See section 6.2.
Payment details (such as card details or bank account numbers) are not stored by TCGPriceHub. These are processed directly by our payment provider Mollie B.V.
3. How we use your data
- Providing and improving the TCGPriceHub service
- Authentication and account management
- Displaying your portfolio, collection and wishlist
- Processing subscription payments
- Account-related communication (e.g. password reset)
- Securing the service against abuse
We never sell or rent your data to third parties.
4. Legal basis for processing
We process personal data on the following grounds (GDPR Art. 6):
- Performance of a contract — to deliver the service
- Legitimate interest — for security and abuse prevention
- Legal obligation — where applicable
- Consent — for non-essential cookies (if applicable)
5. Retention periods
- Account data: as long as your account is active, plus up to 30 days after deletion
- Price history: maximum 90 days (technical maximum in the app)
- Error logs: maximum 30 days
- Invoice data: 7 years (statutory retention obligation)
6. Third parties (processors)
6.1 Cardmarket
TCGPriceHub retrieves price information from Cardmarket (cardmarket.com). No personal data of users is shared with Cardmarket. The data retrieved (prices, product names) is publicly available.
6.2 Mollie — payment processor
TODO: Activate when Mollie integration is implemented.
For payment processing we use Mollie B.V. (Chamber of Commerce: 30204462), based in Amsterdam. Mollie processes payment data as an independent data controller. See Mollie's privacy policy for more information.
6.3 Cloudflare CDN
TCGPriceHub loads the Chart.js library from Cloudflare's CDN (cdnjs.cloudflare.com). Cloudflare may set technical cookies for network performance optimisation. These are not tracking or advertising cookies. See Cloudflare's privacy policy.
6.4 Hosting provider
TODO: Name and country of hosting provider (e.g. TransIP, Netherlands).
7. International transfers
TCGPriceHub stores data within the European Economic Area (EEA). No personal data is transferred to countries outside the EEA unless explicitly stated.
8. Your rights (GDPR)
As a data subject you have the following rights:
- Access — you can request which data we hold about you
- Rectification — you can have inaccurate data corrected
- Erasure — you can request deletion of your data
- Restriction — you can request restriction of processing
- Objection — you can object to processing
- Portability — you can request your data in a machine-readable format
To exercise your rights, please contact us at:
TODO: Email address for privacy requests (e.g. privacy@tcgpricehub.com).
You also have the right to lodge a complaint with your national data protection authority. In the Netherlands: Autoriteit Persoonsgegevens.
9. Security
TCGPriceHub takes appropriate technical and organisational measures to protect your data, including:
- HTTPS/TLS encryption for all connections
- Hashed password storage (bcrypt)
- Limited access to the production environment
- Regular security updates
10. Cookies
See our Cookie Policy for a full overview of the cookies we use.
11. Changes
We may update this privacy policy from time to time. For material changes, registered users will be notified by email or upon logging in. The latest version is always available at tcgpricehub.com/privacy.
12. Contact
TODO: Contact details (email, address, Chamber of Commerce number).