Privacy Policy — tcgcollector.app
Version: 0.1-draft · Effective date: [TBD — on publication] Status: DRAFT — pending legal review (incl. DPO/representative need, retention table, processor list completeness). Not yet in force.
Controller: Zanibytes BV, Otegemstraat 296, 8550 Zwevegem, Belgium, VAT BE 0688.570.534, info@tcgcollector.app.
This Policy explains how we process personal data when you use tcgcollector.app (GDPR Art. 13/14 information).
1. What we process, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account data: email, display name, password hash, country, trader status | Account operation, login, display on listings | Contract (b) |
| Trader traceability data (traders only): name, address, registration/VAT numbers, contact details | DSA Art. 30 trader verification and display | Legal obligation (c) |
| Seller payout details: account-holder name, IBAN; bank-account verification results | Enabling payouts; fraud reduction | Contract (b); legitimate interest (f) for verification |
| OPP onboarding status and identifiers | Platform payment flow (Escrow Hold), payouts | Contract (b); OPP acts as independent controller for its KYC |
| Listing content: photos, descriptions, cert serials, validation photos, watermarked template derivations | Marketplace operation; fraud prevention evidence record | Contract (b); legitimate interest (f) for the evidence record |
| Order, reservation, offer, and chat data | Transacting, buyer–seller communication, dispute resolution | Contract (b) |
| Shipping data: names, addresses, tracking numbers | Delivery, returns via Inspection Hub | Contract (b) |
| Dispute evidence: issue reports, unboxing media, inspection findings | Deciding disposition of held payments; fraud prevention | Contract (b); legitimate interest (f) |
| Technical logs: IP, user agent, timestamps, security events | Security, abuse and fraud prevention, rate limiting | Legitimate interest (f) |
| Email notifications (verification, offers, chat nudges, order events) | Service messages | Contract (b) |
| Support and complaint correspondence | Handling requests; DSA complaint handling | Contract (b); legal obligation (c) |
| Fraud case records | Protection against repeat fraud; legal claims | Legitimate interest (f); legal obligation where reporting is required |
We do not sell personal data. We do not use it for third-party advertising. No automated decision-making producing legal effects: enforcement and dispute decisions involve human review.
2. Recipients / processors
- Online Payment Platform (Online Payment Platform B.V.) — payment collection, escrow, and seller payouts (our processor/service provider) and seller onboarding/KYC, fraud screening, and regulatory compliance (independent controller as a licensed payment institution). Payment details entered at checkout go directly to OPP and never touch our servers. OPP processes personal data within the EEA. See OPP's privacy policy: https://onlinepaymentplatform.com/en/privacy
- Hosting/infrastructure providers (EU-hosted application and storage)
- Email delivery provider (transactional mail)
- Carriers and shipping platforms (e.g. Sendcloud and selected carriers) — receive name/address/parcel data to perform delivery
- Grading companies' public certificate registries — we query serials; we do not send them your identity in normal operation
- Payment-verification providers (IBAN-name check) where enabled
- Authorities, courts, and law enforcement where legally required, and grading companies' fraud teams in confirmed counterfeit/tamper cases
Processors are bound by GDPR Art. 28 agreements. Where data leaves the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
3. Retention
- Account data: life of the account + 1 year, then deleted or anonymized.
- Transaction, invoice, and payout records: 7–10 years per applicable Belgian accounting and tax retention rules (the 2022 tax reform extended several periods to 10 years; we retain for the longest applicable period) — wettelijke bewaartermijn / délai légal.
- Dispute and fraud evidence records: 5 years after case closure, or longer while needed for legal claims.
- Chat messages: life of the account; parties to a conversation each retain their copy until both accounts are deleted.
- Technical/security logs: 12 months.
- Validation photos of sold/withdrawn listings: retained as part of the evidence record per the dispute retention above.
4. Your rights
Access, rectification, erasure, restriction, portability, and objection (GDPR Art. 15–21), exercised via info@tcgcollector.app. We respond within one month. Where processing rests on legitimate interest you may object; fraud-evidence records may be retained despite erasure requests where overriding grounds exist (Art. 17(3)). You may complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, dataprotectionauthority.be) or your local supervisory authority.
5. Cookies and similar technologies
The Service uses strictly necessary cookies only: session authentication and security (rate-limiting state). No analytics or advertising cookies are set without consent; if introduced later, a consent banner and updated policy will precede them.
6. Security
TLS in transit, hashed passwords, scoped access, rate limiting, audit logging of administrative actions, signed validation artifacts (HMAC), encrypted backups. No method is absolute; report vulnerabilities to info@tcgcollector.app.
7. Children
The Service is not directed at persons under 18; we do not knowingly process children's data.
8. Changes
Material changes announced 30 days in advance via the Service or email.