Privacy Policy
Last updated: April 2026
This Privacy Policy explains how CardFloor ("we", "us", "our") collects, uses, and protects your personal data when you use the CardFloor platform, available at cardfloor.co. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
- CardFloor (single-founder operator)
- Email: [email protected]
- Website: cardfloor.co
For any privacy-related question, request, or complaint, please contact us at the email address above.
2. Data We Collect
We collect only the data we need to operate the Service:
- Account data: email, hashed password, display name, account creation date
- Profile data: avatar, bio, optional shop information (B2B users)
- Portfolio data: cards/sealed products you own, purchase prices, conditions, languages, quantities
- Tracking data: watchlists, price alerts, decks, trades, wishlists
- Billing data: tier, billing status, Stripe customer ID (no full card numbers stored)
- Technical data: IP address, user agent, request logs, error traces
- Communication data: emails to support, optional Discord webhook URL
We do not collect special categories of personal data and we do not profile users for advertising.
3. Why We Collect It (Legal Basis)
Lawful bases under GDPR Art. 6:
- Account & service features → Performance of contract
- Subscriptions and payments → Performance of contract
- Discord notifications (optional) → Your consent
- Security, abuse prevention, debugging → Legitimate interest
- Service improvement (anonymized) → Legitimate interest
- Legal requests → Legal obligation
4. Third-Party Processors
We share strictly necessary data with carefully selected processors. We do not sell your data.
- Supabase (EU, eu-west-2) — Postgres database + auth identity
- Vercel (Global edge) — frontend hosting + privacy-preserving Web Analytics
- Fly.io (EU, Paris cdg) — backend API + scraper microservice hosting
- Cloudflare (Global edge) — DNS, R2 image CDN, WAF
- Sentry (EU, Frankfurt) — error tracking + session replay (PII masked)
- Stripe (EU/US, SCCs) — payment processing
- Gmail SMTP / Google (EU/US, SCCs) — transactional emails
- eBay API (US) — public marketplace data, no personal data sent
- CardMarket (EU) — public marketplace data, no personal data sent
- Discord webhooks (optional, user-provided URL) — alert delivery
5. Data Retention
- Account data: until you delete your account, then within 30 days
- Portfolio, decks, watchlists: deleted with your account
- Price alerts: up to 1 year of inactivity
- Server/access logs: up to 90 days
- Billing records: as required by accounting/tax law (typically 10 years in France)
- Backups: may persist up to 30 additional days
6. Cookies, analytics, and error tracking
Essential cookie (no consent required, strictly necessary):
tcg_token— JWT authentication cookie, lifetime 7 days. Required for login; without it the Service cannot function.cardfloor_cookie_consent— Stores your consent choice inlocalStorage(not a cookie technically, but covered here for transparency). Lifetime: until you clear browser data.
Privacy-preserving analytics (legitimate interest, no PII):
- Vercel Web Analytics — page views, country, device type, referrer. No cookies, no cross-site tracking, no IP storage, no fingerprinting. Data is aggregated and cannot identify individuals (Vercel documents this here).
Error tracking (legitimate interest, used to fix bugs that affect you):
- Sentry — captures unhandled JavaScript errors and stack traces. May incidentally collect technical metadata (URL, user agent, browser console). When a fatal error happens, a short session replay (60s preceding the error) is recorded with text masked and media blocked. Replays are retained 30 days.
We do not use advertising cookies, Google Analytics, Facebook Pixel, or any third-party trackers for marketing. If we ever introduce non-essential cookies, we will request your explicit consent first.
7. Your GDPR Rights
You have the rights to: access, rectification, erasure, data portability, objection, restriction, withdraw consent, and lodge a complaint with a supervisory authority (in France: the CNIL — cnil.fr).
How to exercise your rights:
- Self-service export: from your settings page (uses
GET /api/auth/me/export) - Self-service deletion: from your settings page ("Delete my account")
- Email: [email protected] — we respond within 30 days
8. Data Security
- Password hashing with bcrypt (no plaintext storage)
- JWT-based authentication, HTTPS only
- Encryption at rest (Supabase)
- Strict access controls to production
- Regular security updates
In the event of a personal data breach, we will notify the relevant authority within 72 hours and inform affected users without undue delay (Art. 33–34 GDPR).
9. International Transfers
Data is primarily stored in the EU (Supabase EU). Some processors may transfer data to the US (Stripe, Google, Vercel edge). Transfers are protected by Standard Contractual Clauses (SCCs).
10. Children
CardFloor is not directed to children under 13. In countries where the digital consent age is higher (e.g., 15 in France), users below that age must obtain parental consent.
11. Changes to This Policy
We may update this Policy. Material changes are notified by email or in-app notice. Continued use after changes constitutes acceptance.
12. Contact
- Email: [email protected]
- Right to lodge a complaint: CNIL (France) — cnil.fr