Log inSign up

Privacy Policy — tcgcollector.app

Version: 0.1-draft · Effective date: [TBD — on publication] Status: DRAFT — pending legal review (incl. DPO/representative need, retention table, processor list completeness). Not yet in force.

Controller: Zanibytes BV, Otegemstraat 296, 8550 Zwevegem, Belgium, VAT BE 0688.570.534, info@tcgcollector.app.

This Policy explains how we process personal data when you use tcgcollector.app (GDPR Art. 13/14 information).


1. What we process, why, and on what legal basis

DataPurposeLegal basis (GDPR Art. 6)
Account data: email, display name, password hash, country, trader statusAccount operation, login, display on listingsContract (b)
Trader traceability data (traders only): name, address, registration/VAT numbers, contact detailsDSA Art. 30 trader verification and displayLegal obligation (c)
Seller payout details: account-holder name, IBAN; bank-account verification resultsEnabling payouts; fraud reductionContract (b); legitimate interest (f) for verification
OPP onboarding status and identifiersPlatform payment flow (Escrow Hold), payoutsContract (b); OPP acts as independent controller for its KYC
Listing content: photos, descriptions, cert serials, validation photos, watermarked template derivationsMarketplace operation; fraud prevention evidence recordContract (b); legitimate interest (f) for the evidence record
Order, reservation, offer, and chat dataTransacting, buyer–seller communication, dispute resolutionContract (b)
Shipping data: names, addresses, tracking numbersDelivery, returns via Inspection HubContract (b)
Dispute evidence: issue reports, unboxing media, inspection findingsDeciding disposition of held payments; fraud preventionContract (b); legitimate interest (f)
Technical logs: IP, user agent, timestamps, security eventsSecurity, abuse and fraud prevention, rate limitingLegitimate interest (f)
Email notifications (verification, offers, chat nudges, order events)Service messagesContract (b)
Support and complaint correspondenceHandling requests; DSA complaint handlingContract (b); legal obligation (c)
Fraud case recordsProtection against repeat fraud; legal claimsLegitimate interest (f); legal obligation where reporting is required

We do not sell personal data. We do not use it for third-party advertising. No automated decision-making producing legal effects: enforcement and dispute decisions involve human review.

2. Recipients / processors

  • Online Payment Platform (Online Payment Platform B.V.) — payment collection, escrow, and seller payouts (our processor/service provider) and seller onboarding/KYC, fraud screening, and regulatory compliance (independent controller as a licensed payment institution). Payment details entered at checkout go directly to OPP and never touch our servers. OPP processes personal data within the EEA. See OPP's privacy policy: https://onlinepaymentplatform.com/en/privacy
  • Hosting/infrastructure providers (EU-hosted application and storage)
  • Email delivery provider (transactional mail)
  • Carriers and shipping platforms (e.g. Sendcloud and selected carriers) — receive name/address/parcel data to perform delivery
  • Grading companies' public certificate registries — we query serials; we do not send them your identity in normal operation
  • Payment-verification providers (IBAN-name check) where enabled
  • Authorities, courts, and law enforcement where legally required, and grading companies' fraud teams in confirmed counterfeit/tamper cases

Processors are bound by GDPR Art. 28 agreements. Where data leaves the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.

3. Retention

  • Account data: life of the account + 1 year, then deleted or anonymized.
  • Transaction, invoice, and payout records: 7–10 years per applicable Belgian accounting and tax retention rules (the 2022 tax reform extended several periods to 10 years; we retain for the longest applicable period) — wettelijke bewaartermijn / délai légal.
  • Dispute and fraud evidence records: 5 years after case closure, or longer while needed for legal claims.
  • Chat messages: life of the account; parties to a conversation each retain their copy until both accounts are deleted.
  • Technical/security logs: 12 months.
  • Validation photos of sold/withdrawn listings: retained as part of the evidence record per the dispute retention above.

4. Your rights

Access, rectification, erasure, restriction, portability, and objection (GDPR Art. 15–21), exercised via info@tcgcollector.app. We respond within one month. Where processing rests on legitimate interest you may object; fraud-evidence records may be retained despite erasure requests where overriding grounds exist (Art. 17(3)). You may complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, dataprotectionauthority.be) or your local supervisory authority.

5. Cookies and similar technologies

The Service uses strictly necessary cookies only: session authentication and security (rate-limiting state). No analytics or advertising cookies are set without consent; if introduced later, a consent banner and updated policy will precede them.

6. Security

TLS in transit, hashed passwords, scoped access, rate limiting, audit logging of administrative actions, signed validation artifacts (HMAC), encrypted backups. No method is absolute; report vulnerabilities to info@tcgcollector.app.

7. Children

The Service is not directed at persons under 18; we do not knowingly process children's data.

8. Changes

Material changes announced 30 days in advance via the Service or email.