TCGHeart
Privacybeleid
Versie 2.2, laatst bijgewerkt 21 juli 2026.
Van toepassing op de TCGHeart-app (Android com.tcgheart.app, iOS) en op tcgheart.com.
1. Verwerkingsverantwoordelijke
TCGHeart is verantwoordelijk voor de verwerking van jouw persoonsgegevens zoals beschreven in dit privacybeleid.
2. Welke gegevens we verzamelen
We verzamelen de volgende categorieën persoonsgegevens:
a. Accountgegevens
- Bij registratie met e-mail: e-mailadres, gebruikersnaam en een versleuteld wachtwoord (bcrypt);
- Bij registratie via Apple, Discord of Google: e-mailadres, gebruikersnaam, profielfoto en de bijbehorende OAuth-ID.
b. Abonnements- en aankoopgegevens
- Abonnementsstatus (Free, Pro of Vendor), productidentificatie en vervaldatum van je in-app abonnement;
- Abonnementen worden verwerkt via de Apple App Store of Google Play Store; TCGHeart ontvangt geen betaalkaartgegevens of bankgegevens, alleen bevestigingen van aankoop, verlenging of opzegging via RevenueCat.
c. Collectie- en portfoliogegevens
- Kaarten die je toevoegt aan je collectie, inclusief staat, taal, hoeveelheid, aankoopprijs, aankoopdatum en notities;
- Portfolio-indelingen en dagelijkse portfoliowaarden (snapshots);
- Verlanglijst (wishlist) met optionele prijsdoelen;
- Ruilgeschiedenis (Trade Calculator, Pro-functie): namen van ruilpartners, kaarten, bedragen en datums.
d. Scangegevens
- Bij het scannen van kaarten wordt een afbeelding naar onze server gestuurd voor herkenning via DeckLedger. Deze afbeelding wordt niet opgeslagen en direct na verwerking verwijderd.
e. Evenementgegevens
- RSVP-status voor evenementen (aanwezig/geïnteresseerd);
- Kaartaanbiedingen die je plaatst bij evenementen, inclusief vraagprijs, staat, taal en type (ruil/verkoop).
f. Vendor-organisatiegegevens
- Organisatienaam, ledenlijst en gedeelde inventaris wanneer je deel uitmaakt van een vendor-organisatie;
- Verkoopregistratie binnen een organisatie (bedrag, betaalmethode, verkoopkanaal, datum) voor de eigen administratie van die organisatie;
- Vendor-organisaties krijgen automatisch een deellink (storefront) waarmee de inventaris publiek toegankelijk kan worden gemaakt. De zichtbaarheid van prijzen, kostprijzen en notities is instelbaar.
g. Profieldeelgegevens
- Bij registratie wordt automatisch een deellink voor je profiel aangemaakt. Wanneer iemand deze link opent, zijn je gebruikersnaam en profielfoto altijd zichtbaar;
- Je bepaalt zelf of prijzen, notities, kostprijzen en waardegeschiedenis zichtbaar zijn via de zichtbaarheidsinstellingen;
- De deellink blijft bestaan zolang je account bestaat en kan niet worden ingetrokken (wel kun je de zichtbaarheid beperken of de link vernieuwen).
h. Meldingen
- In-app meldingen (zoals uitnodigingen voor vendor-organisaties en prijsalerts) worden opgeslagen met type, inhoud en leesstatus;
- Meldingen worden bewaard zolang je account bestaat.
i. Technische gegevens
- Push-notificatietoken (Expo Push Token) voor het bezorgen van meldingen op je mobiele apparaat. Expo levert notificaties via Apple Push Notification Service (APNs) en Firebase Cloud Messaging (FCM) als subverwerkers;
- IP-adressen in serverlogbestanden (30 dagen bewaard);
- Een apparaat-ID dat lokaal wordt gegenereerd, uitsluitend om het aantal gelijktijdig actieve apparaten binnen een vendor-organisatie te handhaven;
- Lokale voorkeuren (thema, taal, land, conditie) opgeslagen in localStorage/AsyncStorage op je apparaat. Deze worden niet naar onze servers verstuurd, maar worden als queryparameters meegestuurd bij prijsverzoeken;
- Scantellingen per gebruiker en per organisatie, gebruikt voor het handhaven van de scanlimieten per abonnementsniveau;
- Kaart- en productafbeeldingen worden tijdelijk op de server gecachet (maximaal 7 dagen) om laadtijden te verbeteren. Dit betreft geen persoonsgegevens.
3. Grondslagen voor verwerking (Art. 6 AVG)
Wij verwerken jouw gegevens op basis van de volgende grondslagen:
- Uitvoering van de overeenkomst (Art. 6 lid 1 sub b): het aanmaken en beheren van je account, het opslaan van je collectie en het leveren van de dienst;
- Toestemming (Art. 6 lid 1 sub a): het versturen van push-notificaties (je kunt deze te allen tijde uitschakelen);
- Gerechtvaardigd belang (Art. 6 lid 1 sub f): het beveiligen van de dienst, het voorkomen van misbruik en het bijhouden van serverlogbestanden;
- Wettelijke verplichting (Art. 6 lid 1 sub c): het bewaren van administratieve gegevens voor vendor-organisaties waar de wet dit vereist.
4. Derden en verwerkers
TCGHeart deelt geen persoonsgegevens met derden voor commerciële doeleinden en verkoopt geen gegevens. We maken gebruik van de volgende verwerkers en dienstverleners:
- RevenueCat wordt gebruikt voor het verwerken en beheren van in-app abonnementen. RevenueCat ontvangt je gebruikers-ID (intern nummer), productidentificatie en abonnementsstatus via de Apple App Store en Google Play Store. RevenueCat slaat geen betaalkaartgegevens op. Die worden uitsluitend door Apple/Google verwerkt;
- Apple App Store en Google Play Store worden gebruikt voor het verwerken van betalingen voor Pro- en Vendor-abonnementen. TCGHeart ontvangt alleen bevestigingen van transacties, geen betaalgegevens;
- DeckLedger levert kaartprijzen en scanherkenning. Hierbij worden geen persoonsgegevens gedeeld (alleen anonieme kaartdata en scan-afbeeldingen);
- Mailgun wordt gebruikt voor het versturen van wachtwoord-reset e-mails en uitnodigingen. Alleen je e-mailadres wordt gedeeld;
- Expo wordt gebruikt voor het bezorgen van push-notificaties. Alleen je push-token wordt gedeeld. Expo levert notificaties via Apple Push Notification Service (APNs) en Firebase Cloud Messaging (FCM);
- Apple, Discord en Google verzorgen OAuth-inlog; je gegevens worden verwerkt conform het privacybeleid van die partijen. TCGHeart slaat alleen de gegevens op die nodig zijn voor je account;
- Pokeradar CMS wordt gebruikt voor het ophalen van evenementinformatie. Hierbij worden geen persoonsgegevens gedeeld;
- SumUp wordt uitsluitend door vendor-organisaties gebruikt voor betalingen aan de eigen kraam. TCGHeart geeft alleen het te betalen bedrag door aan de SumUp-app op het apparaat van de verkoper en ontvangt hooguit een transactiecode terug. Er worden geen betaalgegevens van klanten verwerkt.
5. Internationale doorgifte
Sommige van onze verwerkers zijn gevestigd buiten de Europese Economische Ruimte (EER), met name in de Verenigde Staten (RevenueCat, Mailgun, Expo, Discord, Google, Apple). Voor deze doorgiftes zijn passende waarborgen getroffen, waaronder EU-standaardcontractbepalingen (Standard Contractual Clauses) of een adequaatheidsbesluit.
6. Bewaartermijnen
Wij hanteren de volgende bewaartermijnen:
- Accountgegevens: tot je je account verwijdert;
- Collectie- en portfoliogegevens: tot je je account verwijdert;
- Scan-afbeeldingen: worden niet opgeslagen (direct verwijderd na verwerking);
- Push-tokens: tot je uitlogt of de app verwijdert;
- Serverlogbestanden: maximaal 30 dagen;
- Wachtwoord-reset tokens: 1 uur na aanvraag;
- Abonnementsgegevens: tot je je account verwijdert (RevenueCat bewaart een eigen kopie conform hun bewaarbeleid);
- Meldingen: tot je je account verwijdert.
7. Verwijdering van je account en gegevens
Je kunt je account en de bijbehorende gegevens op elk moment permanent verwijderen, in de app via Profiel → Account → Account verwijderen of op het web via Instellingen → Account verwijderen. De verwijdering wordt direct uitgevoerd, zonder wachttijd.
De volledige procedure, inclusief wat er precies wordt verwijderd, wat bewaard blijft en hoe je verwijdering aanvraagt als je niet meer kunt inloggen, staat op tcgheart.com/delete-account.
Direct en permanent verwijderd: accountgegevens (e-mailadres, gebruikersnaam, wachtwoordhash, OAuth-koppelingen), collectie- en portfoliogegevens, portfoliosnapshots, verlanglijst, ruilgeschiedenis, instellingen, prijsalerts, meldingen, evenement-RSVP's en aanbiedingen, push-token en wachtwoord-reset tokens. Je profieldeellink wordt ongeldig.
Blijft bestaan: gegevens die toebehoren aan een vendor-organisatie waarvan je lid was (inventaris, verkopen en administratie van die organisatie) blijven beschikbaar voor de overige leden, omdat dit gegevens van de organisatie zijn en niet van jou persoonlijk. Ben je zelf eigenaar van een organisatie, dan moet je het eigenaarschap eerst overdragen of de organisatie verwijderen. Serverlogbestanden met IP-adressen verdwijnen binnen 30 dagen door de reguliere bewaartermijn. Een actief in-app abonnement wordt niet automatisch opgezegd; dat doe je via de App Store of Play Store.
8. Jouw rechten
Op grond van de Algemene Verordening Gegevensbescherming (AVG) heb je de volgende rechten:
- Recht op inzage (Art. 15): je kunt je opgeslagen gegevens inzien via je account;
- Recht op rectificatie (Art. 16): je kunt je gebruikersnaam en e-mailadres aanpassen;
- Recht op verwijdering (Art. 17): je kunt je account en alle bijbehorende gegevens permanent verwijderen, zie tcgheart.com/delete-account;
- Recht op beperking (Art. 18): je kunt verzoeken om de verwerking van je gegevens te beperken;
- Recht op overdraagbaarheid (Art. 20): je kunt je collectiegegevens exporteren in JSON- of CSV-formaat via de exportfunctie;
- Recht op bezwaar (Art. 21): je kunt bezwaar maken tegen de verwerking van je gegevens;
- Recht om een klacht in te dienen bij de Autoriteit Persoonsgegevens, de Nederlandse toezichthouder voor gegevensbescherming.
Voor het uitoefenen van deze rechten kun je contact opnemen via info@tcgheart.com. We reageren binnen 30 dagen op je verzoek.
9. Lokale opslag en cookies
TCGHeart gebruikt geen tracking cookies en geen advertentiecookies. We slaan bepaalde gebruikersinstellingen (thema, taal, land, voorkeuren) op in de lokale opslag (localStorage) van je browser of AsyncStorage op je mobiele apparaat. Dit zijn functionele gegevens die niet naar onze servers worden verzonden.
Je inlogtoken wordt eveneens lokaal opgeslagen zodat je ingelogd blijft. Dit token verloopt automatisch na 7 dagen.
Kaart- en prijsdata worden lokaal gecachet voor snellere laadtijden. Deze cache kun je te allen tijde wissen via de instellingen.
10. Beveiliging
Wij nemen passende technische en organisatorische maatregelen om jouw gegevens te beschermen:
- Wachtwoorden worden versleuteld opgeslagen met bcrypt en zijn nooit leesbaar;
- Alle verbindingen verlopen via HTTPS (TLS-encryptie);
- Toegang tot de database is beperkt tot de applicatieserver;
- Push-tokens worden gewist bij uitloggen of wanneer het apparaat niet meer bereikbaar is.
In geval van een datalek dat waarschijnlijk een risico vormt voor jouw rechten en vrijheden, melden wij dit binnen 72 uur bij de Autoriteit Persoonsgegevens en informeren wij je zo spoedig mogelijk.
11. Kinderen
TCGHeart is niet bedoeld voor kinderen jonger dan 16 jaar. Wij verzamelen niet bewust gegevens van personen jonger dan 16 jaar. Als je minderjarig bent, mag je TCGHeart alleen gebruiken met toestemming van een ouder of wettelijke vertegenwoordiger. Als wij ontdekken dat we gegevens hebben verzameld van een kind jonger dan 16 jaar zonder geldige toestemming, verwijderen wij deze gegevens onmiddellijk.
12. Wijzigingen
Dit privacybeleid kan worden aangepast. Substantiële wijzigingen worden via de app bekendgemaakt. De meest actuele versie is altijd beschikbaar op tcgheart.com/privacy.
13. Contact
Voor vragen of verzoeken met betrekking tot jouw privacy kun je contact opnemen via info@tcgheart.com.
Je hebt ook het recht om een klacht in te dienen bij de Autoriteit Persoonsgegevens.
Privacy Policy
Version 2.2, last updated 21 July 2026.
Applies to the TCGHeart app (Android com.tcgheart.app, iOS) and to tcgheart.com.
1. Data controller
TCGHeart is responsible for the processing of your personal data as described in this privacy policy.
2. What data we collect
We collect the following categories of personal data:
a. Account data
- When registering with email: email address, username and an encrypted password (bcrypt);
- When registering via Apple, Discord or Google: email address, username, profile picture and the associated OAuth ID.
b. Subscription and purchase data
- Subscription status (Free, Pro or Vendor), product identifier and expiry date of your in-app subscription;
- Subscriptions are processed via the Apple App Store or Google Play Store; TCGHeart receives no payment card details or bank details, only confirmations of purchase, renewal or cancellation via RevenueCat.
c. Collection and portfolio data
- Cards you add to your collection, including condition, language, quantity, purchase price, purchase date and notes;
- Portfolio organisation and daily portfolio values (snapshots);
- Wishlist with optional price targets;
- Trade history (Trade Calculator, Pro feature): names of trade partners, cards, amounts and dates.
d. Scan data
- When scanning cards, an image is sent to our server for recognition via DeckLedger. This image is not stored and is deleted immediately after processing.
e. Event data
- RSVP status for events (attending/interested);
- Card listings you post at events, including asking price, condition, language and type (trade/sale).
f. Vendor organisation data
- Organisation name, member list and shared inventory when you are part of a vendor organisation;
- Sales records within an organisation (amount, payment method, sales channel, date) for that organisation's own bookkeeping;
- Vendor organisations automatically get a share link (storefront) that can make the inventory publicly accessible. The visibility of prices, cost prices and notes is configurable.
g. Profile sharing data
- Upon registration, a share link for your profile is automatically created. When someone opens this link, your username and profile picture are always visible;
- You decide for yourself whether prices, notes, cost prices and value history are visible via the visibility settings;
- The share link remains active for as long as your account exists and cannot be revoked (although you can limit its visibility or rotate the link).
h. Notifications
- In-app notifications (such as invitations to vendor organisations and price alerts) are stored with type, content and read status;
- Notifications are kept for as long as your account exists.
i. Technical data
- Push notification token (Expo Push Token) for delivering notifications to your mobile device. Expo delivers notifications via Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM) as sub-processors;
- IP addresses in server logs (kept for 30 days);
- A locally generated device ID, used solely to enforce the number of simultaneously active devices within a vendor organisation;
- Local preferences (theme, language, country, condition) stored in localStorage/AsyncStorage on your device. These are not sent to our servers, but are passed as query parameters with price requests;
- Scan counts per user and per organisation, used to enforce the scan limits per subscription tier;
- Card and product images are temporarily cached on the server (up to 7 days) to improve loading times. This does not concern personal data.
3. Legal bases for processing (Art. 6 GDPR)
We process your data on the following legal bases:
- Performance of the contract (Art. 6(1)(b)): creating and managing your account, storing your collection and providing the service;
- Consent (Art. 6(1)(a)): sending push notifications (you can disable these at any time);
- Legitimate interest (Art. 6(1)(f)): securing the service, preventing abuse and keeping server logs;
- Legal obligation (Art. 6(1)(c)): retaining administrative data for vendor organisations where the law requires this.
4. Third parties and processors
TCGHeart does not share personal data with third parties for commercial purposes and does not sell data. We use the following processors and service providers:
- RevenueCat is used for processing and managing in-app subscriptions. RevenueCat receives your user ID (internal number), product identifier and subscription status via the Apple App Store and Google Play Store. RevenueCat does not store payment card details. Those are processed exclusively by Apple/Google;
- Apple App Store and Google Play Store are used for processing payments for Pro and Vendor subscriptions. TCGHeart receives only transaction confirmations, no payment data;
- DeckLedger provides card prices and scan recognition. No personal data is shared here (only anonymous card data and scan images);
- Mailgun is used for sending password reset emails and invitations. Only your email address is shared;
- Expo is used for delivering push notifications. Only your push token is shared. Expo delivers notifications via Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM);
- Apple, Discord and Google handle OAuth login; your data is processed in accordance with the privacy policies of those parties. TCGHeart stores only the data needed for your account;
- Pokeradar CMS is used for retrieving event information. No personal data is shared here;
- SumUp is used exclusively by vendor organisations for payments taken at their own stand. TCGHeart only passes the amount due to the SumUp app on the seller's device and receives at most a transaction code back. No customer payment data is processed.
5. International transfers
Some of our processors are located outside the European Economic Area (EEA), in particular in the United States (RevenueCat, Mailgun, Expo, Discord, Google, Apple). Appropriate safeguards have been put in place for these transfers, including EU Standard Contractual Clauses or an adequacy decision.
6. Retention periods
We apply the following retention periods:
- Account data: until you delete your account;
- Collection and portfolio data: until you delete your account;
- Scan images: not stored (deleted immediately after processing);
- Push tokens: until you log out or delete the app;
- Server logs: a maximum of 30 days;
- Password reset tokens: 1 hour after the request;
- Subscription data: until you delete your account (RevenueCat keeps its own copy in accordance with its retention policy);
- Notifications: until you delete your account.
7. Deleting your account and data
You can permanently delete your account and its data at any time, in the app via Profile → Account → Delete Account or on the web via Settings → Delete account. Deletion is carried out immediately, with no waiting period.
The full procedure, including exactly what is deleted, what is retained and how to request deletion if you can no longer sign in, is documented at tcgheart.com/delete-account.
Deleted immediately and permanently: account data (email address, username, password hash, OAuth links), collection and portfolio data, portfolio snapshots, wishlist, trade history, settings, price alerts, notifications, event RSVPs and listings, push token and password reset tokens. Your profile share link becomes invalid.
Retained: data belonging to a vendor organisation you were a member of (that organisation's inventory, sales and bookkeeping) remains available to the other members, because it is the organisation's data rather than your personal data. If you own an organisation yourself, you must first transfer ownership or delete the organisation. Server logs containing IP addresses disappear within 30 days under the regular retention period. An active in-app subscription is not cancelled automatically; you cancel it via the App Store or Play Store.
8. Your rights
Under the General Data Protection Regulation (GDPR) you have the following rights:
- Right of access (Art. 15): you can view your stored data via your account;
- Right to rectification (Art. 16): you can change your username and email address;
- Right to erasure (Art. 17): you can permanently delete your account and all associated data, see tcgheart.com/delete-account;
- Right to restriction (Art. 18): you can request that the processing of your data be restricted;
- Right to data portability (Art. 20): you can export your collection data in JSON or CSV format via the export function;
- Right to object (Art. 21): you can object to the processing of your data;
- Right to lodge a complaint with the Dutch Data Protection Authority, the Dutch supervisory authority for data protection.
To exercise these rights, you can contact us at info@tcgheart.com. We respond to your request within 30 days.
9. Local storage and cookies
TCGHeart uses no tracking cookies and no advertising cookies. We store certain user settings (theme, language, country, preferences) in the local storage (localStorage) of your browser or AsyncStorage on your mobile device. These are functional data that are not sent to our servers.
Your login token is also stored locally so you stay logged in. This token expires automatically after 7 days.
Card and price data are cached locally for faster loading times. You can clear this cache at any time via the settings.
10. Security
We take appropriate technical and organisational measures to protect your data:
- Passwords are stored encrypted with bcrypt and are never readable;
- All connections run over HTTPS (TLS encryption);
- Access to the database is limited to the application server;
- Push tokens are cleared on logout or when the device is no longer reachable.
In the event of a data breach that is likely to pose a risk to your rights and freedoms, we will report this to the Dutch Data Protection Authority within 72 hours and inform you as soon as possible.
11. Children
TCGHeart is not intended for children under the age of 16. We do not knowingly collect data from persons under the age of 16. If you are a minor, you may only use TCGHeart with the consent of a parent or legal guardian. If we discover that we have collected data from a child under the age of 16 without valid consent, we will delete this data immediately.
12. Changes
This privacy policy may be amended. Substantial changes will be announced via the app. The most current version is always available at tcgheart.com/privacy.
13. Contact
For questions or requests regarding your privacy, you can contact us at info@tcgheart.com.
You also have the right to lodge a complaint with the Dutch Data Protection Authority.