TCGBindr
Legal · Privacy Policy
Legal

Privacy Policy

Effective Date: [INSERT DATE BEFORE LAUNCH]  ·  Last Updated: [INSERT DATE]

Plain-English summary: TCGBindr collects the minimum data needed to run the service. We never sell your data. We never run ads. Your collection is yours — we use it only to provide and improve the service. EU and UK users have full GDPR rights. California users have CCPA rights. You can request deletion of your data at any time. The scanner does not upload your card images to our servers.
Attorney review required. This policy was drafted as a comprehensive foundation and must be reviewed and approved by a licensed Texas attorney with GDPR/privacy law experience before going live. Do not publish without legal review.
Table of Contents
  1. Who We Are
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Bases for Processing (GDPR)
  5. How We Share Your Information
  6. Our No-Ads Commitment
  7. Data Retention
  8. Security
  9. Your Rights — All Users
  10. Your Rights — EU & UK Users (GDPR)
  11. Your Rights — California Users (CCPA)
  12. Cookies & Tracking
  13. Children's Privacy
  14. International Data Transfers
  15. Changes to This Policy
  16. Contact & Data Requests

Section 1

Who We Are

TCGBindr LLC is a Texas limited liability company operating the TCGBindr platform — a premium TCG collection management service available at tcgbindr.com and via our mobile application.

For the purposes of the General Data Protection Regulation (GDPR) and UK GDPR, TCGBindr LLC is the data controller of personal information we collect from you.

Questions about this Privacy Policy or your data? Contact us at privacy@tcgbindr.com.

Section 2

Information We Collect

2.1 Information You Provide Directly

Data TypeWhen CollectedWhy
Email addressAccount creation, waitlist signupAccount access, transactional emails, service communications
Username / display nameAccount creationAccount identification, public profile display
Password (hashed)Account creationAuthentication — we never store plaintext passwords
Game preferencesOnboardingPersonalizing your experience (MTG, Pokémon, etc.)
Collection dataOngoing useCore service function — tracking your cards, decks, and values
Trade listingsWhen you create a listingTrade matching with other users
Deck listsWhen you build or share a deckDeck management, set completion, card usage tracking
Price alert preferencesWhen you set an alertSending price movement notifications
Communication contentWhen you contact supportResponding to your inquiry

2.2 Payment Information

Payment card details are collected and processed exclusively by Stripe, Inc. TCGBindr does not receive, store, or have access to your full card number, CVV, or bank account information. We receive only a payment token and basic billing metadata (last four digits, card type, expiry) from Stripe to manage your subscription.

2.3 Information Collected Automatically

When you use TCGBindr, we automatically collect:

2.4 Card Scanner Data

Scanner Privacy
The TCGBindr mobile card scanner processes camera images entirely on your device. Images captured during scanning are not uploaded to our servers, stored in our databases, or transmitted to any third party. The only data that leaves your device is the identified card's set code and collector number, used to look up card data.

2.5 Information From Third Parties

If you choose to connect a third-party account (e.g., signing in with Google), we may receive basic profile information from that service. We will only use that information as described in this policy.

When you join the waitlist on our marketing site, complete post-checkout account setup from the link we email you, or create an account in the TCGBindr app, we may ask you to confirm that you have read and agree to our Terms of Service and Privacy Policy. Submitting the form after checking that box is how we record your agreement (together with a timestamp stored on your app account when you register in the app, or agreement flags stored with your waitlist row on the marketing site database as applicable).

Optional marketing. Email about product news, offers, and promotional content is separate from transactional and service email (for example receipts, security notices, subscription status, and messages needed to run your account). We only send marketing-style email if you opt in—using an unchecked-by-default checkbox on the waitlist form, the post-checkout setup page, or the app registration screen. If you leave that box unchecked, we treat that as no consent for promotional email; you may still receive transactional and account-related email where permitted by law.

Unsubscribe. Marketing messages include an unsubscribe link where required, and you may withdraw marketing consent anytime by contacting support@tcgbindr.com or privacy@tcgbindr.com. Opting out of marketing does not delete your account and does not stop all email (for example billing and important service notices may still be sent).

Your counsel should review this subsection alongside your actual email practices and templates.

Section 3

How We Use Your Information

PurposeData Used
Providing and operating the ServiceAccount info, collection data, deck lists, trade listings
Processing subscriptions and billingEmail, Stripe payment tokens, subscription tier
Sending transactional emailsEmail address — confirmation, receipts, alerts you set up
Sending the weekly collection digestEmail, collection data, price history
Sending new set release notificationsEmail, game preferences, affected collection data
Price alert notificationsEmail, alert preferences, card price data
Trade matchingTrade listings, wishlist data — shown to other users
Customer supportEmail, communication content, account info
Security and fraud preventionLog data, IP address, device info, usage patterns
Product improvement and analyticsAggregated, anonymized usage data
Legal complianceAny data required by applicable law

We do not use your personal collection data to train machine learning models or share it with advertisers. We do not use your data for purposes incompatible with those listed above without your explicit consent.

Section 4

Legal Bases for Processing (GDPR)

For users in the European Union or United Kingdom, we process your personal data on the following legal grounds:

Section 5

How We Share Your Information

5.1 Service Providers

We share data with trusted third-party vendors who help us operate the Service. These vendors are contractually bound to use your data only as directed by us and in accordance with this policy:

VendorPurposeData Shared
Stripe, Inc.Payment processingBilling email, payment method — no full card numbers stored by us
ResendTransactional email deliveryEmail address, email content
CloudflareCDN, DDoS protection, infrastructureIP address, request data (standard CDN operation)
Neon / RailwayDatabase and application hostingAll service data — hosted securely in the US

5.2 Other Users (Trade Matching)

When you create a trade listing or mark your deck list as public, that content is visible to other TCGBindr users. Your username will be associated with your public content. Your private collection data, email address, and subscription details are never shared with other users.

5.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

5.4 Business Transfers

If TCGBindr LLC is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.

5.5 What We Never Do

Our Data Commitments
We never sell your personal data to third parties. We never share your data with advertisers. We never use your collection data to serve you targeted advertising. TCGBindr is funded entirely by subscription revenue — your data is not the product.
Section 6

Our No-Ads Commitment

TCGBindr does not and will never display advertisements. We do not work with advertising networks, do not allow third-party tracking pixels for advertising purposes, and do not monetize your data through advertising.

This commitment is structural, not just a policy — our business model is built entirely on subscription revenue. We have no financial incentive to compromise your privacy for advertising purposes.

This no-ads commitment applies to TCGBindr's own products and properties. If you access TCGBindr content through third-party platforms, those platforms' own advertising practices are governed by their respective policies.

Section 7

Data Retention

We retain your personal data for as long as your account is active, as long as needed to provide the Service, or as required by applicable law. Specifically:

You may request deletion of your account and data at any time. See Section 9 for your rights and how to submit a deletion request.

Section 8

Security

We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include:

No method of transmission or storage is 100% secure. While we work hard to protect your data, we cannot guarantee absolute security. If you suspect a security issue, please contact us immediately at security@tcgbindr.com.

In the event of a data breach that affects your personal data, we will notify you as required by applicable law, including within 72 hours for users covered by GDPR where required.

Section 9

Your Rights — All Users

Regardless of where you live, you have the following rights regarding your personal data:

Access
Request a copy of the personal data we hold about you, including your collection data, account info, and subscription history.
Correction
Request correction of inaccurate or incomplete personal data associated with your account.
Deletion
Request deletion of your account and personal data. We will honor this within 30 days, subject to retention requirements for billing records.
Data Export
Export your collection data in CSV format at any time from your account settings, or by contacting support.
Unsubscribe
Opt out of marketing emails at any time using the unsubscribe link in any email, or by updating your notification preferences in account settings.
Account Closure
Close your account at any time. You can do this in account settings or by emailing support@tcgbindr.com.

To exercise any of these rights, contact us at privacy@tcgbindr.com. We will respond within 30 days.

Section 10

Your Rights — EU & UK Users (GDPR / UK GDPR)

If you are located in the European Union or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:

International Transfers
Your data is stored and processed in the United States. By using TCGBindr, EU and UK users consent to the transfer of their personal data to the US. We implement appropriate safeguards for such transfers in accordance with GDPR requirements, including standard contractual clauses with our processors where applicable.

To exercise your GDPR rights or submit a data subject access request, email privacy@tcgbindr.com with the subject line "GDPR Request." We will respond within 30 days.

Section 11

Your Rights — California Users (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights:

To submit a CCPA request, email privacy@tcgbindr.com with the subject line "CCPA Request" or write to us at our registered address. We will respond within 45 days.

Categories of personal information collected: identifiers (email, username, IP address); commercial information (subscription tier, billing history); internet/network activity (usage logs); inferences drawn from collection data (portfolio value estimates).

Disclosure for business purposes: We share identifiers and usage data with our service providers (Stripe, Resend, Cloudflare) for the purposes described in Section 5. We do not sell or share this information for cross-context behavioral advertising.

Section 12

Cookies & Tracking

TCGBindr uses the following categories of cookies and similar technologies:

We do not use advertising cookies, third-party tracking pixels, or any cookies that track your behavior across other websites for advertising purposes.

You can manage cookie preferences in your browser settings. Note that disabling certain cookies may affect the functionality of the Service.

Section 13

Children's Privacy

TCGBindr is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a user is under 13, we will delete their account and all associated data promptly.

Users between 13 and 18 may use TCGBindr with parental consent. Parents or guardians who believe their child under 13 has created a TCGBindr account should contact us at privacy@tcgbindr.com to request deletion.

Section 14

International Data Transfers

TCGBindr is operated from the United States. If you access the Service from outside the United States — including from the European Union or United Kingdom — your personal data will be transferred to, stored, and processed in the United States.

The United States may not have data protection laws equivalent to those in your country of residence. By using TCGBindr, you consent to this transfer. We take steps to ensure that data transfers are made in compliance with applicable legal requirements, including, where applicable, implementing standard contractual clauses under GDPR.

Section 15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make material changes, we will:

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We will not materially change how we use your data without providing advance notice and, where required by law, obtaining your consent.

Section 16

Contact & Data Requests

For any questions about this Privacy Policy, to exercise your data rights, or to submit a deletion, access, or correction request:

We aim to respond to all privacy inquiries within 30 days. For GDPR data subject access requests, we will respond within 30 days. For CCPA requests, we will respond within 45 days.

If you are unsatisfied with our response to a privacy concern, EU and UK residents have the right to lodge a complaint with their local data protection authority.


TCGBindr LLC · Texas · Effective [INSERT DATE] · This policy requires attorney review before publication.