Privacy Policy
Last Updated: February 2, 2026
Introduction
CardTrezor ('we', 'us', or 'our') is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application for managing your Pokemon card collection. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.
Information We Collect
We collect information that you provide directly to us when you: • Create an account (email address, username) • Sign in with Google (email, profile information) • Add cards to your portfolio (card information, quantities, conditions, pricing data) • Use premium features (subscription details, payment information via RevenueCat) • Contact us through the app (messages, feedback) We also automatically collect: • Device information (device type, operating system) • Usage data (features used, app performance) • Local storage data (for offline functionality)
Device Access and Permissions
To provide our services, the app may request the following permissions: - Camera Access: To allow you to take pictures of your cards to add to your collection. - Photo Library Access: To allow you to upload existing images of your cards from your device's library.
Log Data / Server Log Files
When you use our app, we automatically collect technical data, including your IP address, access date/time, device identifier, operating system version, and crash logs. This data is processed to ensure the technical stability and security of our services. This data is stored for a period of 7 days before being deleted.
The legal basis for this processing is our legitimate interest (Art. 6(1)(f) GDPR) in providing a functional and secure app.
How We Use Your Information
We use the information we collect to: • Provide, maintain, and improve our services • Manage your account and portfolio • Process subscription payments and manage premium features • Send you technical notices and support messages • Respond to your comments and questions • Analyze usage patterns to improve app functionality • Protect against fraud and unauthorized access • Comply with legal obligations We DO NOT sell your personal information to third parties.
Information Sharing and Disclosure
We may share your information with: • Service Providers: Firebase (authentication, database, storage), RevenueCat (subscription management), TCGdex API (card information) • Legal Requirements: When required by law or to protect our rights • Business Transfers: In connection with any merger, sale, or acquisition We do not share your personal card collection data with other users or third-party marketers.
Google Firebase
We use Google Firebase, a service provided by Google Ireland Limited, for several core functionalities of our app: - Firebase Authentication: To manage user sign-up and login. - Firestore: To store your portfolio data (card information, images, etc.) securely in the cloud. - Firebase Functions: To run backend code in response to events triggered by Firebase features and HTTPS requests. - Firebase Crashlytics: To track and analyze crashes to improve app stability.
RevenueCat
For managing subscriptions, we use RevenueCat, a subscription management service. When you subscribe, payments are processed through your device's app store (Apple App Store or Google Play Store). RevenueCat helps us manage subscription status and entitlements. We do not store your payment details on our servers. The privacy policies of RevenueCat and your app store provider apply to this data processing.
Data Transfer to Third Countries
Services like Google Firebase and RevenueCat are based in the USA. When you use our app, your data may be transferred to, stored, and processed in the United States. The legal basis for this data transfer is the EU-U.S. Data Privacy Framework, under which Google and RevenueCat are certified. This framework ensures an adequate level of data protection.
Data Storage and Security
Your data is stored securely using: • Firebase Cloud Firestore (encrypted database hosting) • Local device storage (AsyncStorage for offline access) • Industry-standard encryption for data transmission • Secure authentication via Firebase Auth and Google Sign-In While we implement reasonable security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
Your Rights (GDPR & Privacy Rights)
You have the right to: • Access: Request copies of your personal data • Rectification: Correct inaccurate or incomplete data • Erasure: Request deletion of your account and data (via Settings > Delete Account) • Data Portability: Request your data in a machine-readable format • Withdraw Consent: Opt out of data collection (may limit functionality) • Object to Processing: Object to certain data uses To exercise these rights, contact us through the app or at the email provided in the Contact section. We will respond within 30 days.
Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access (Art. 15 GDPR): You can request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16 GDPR): You can request that we correct inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten') (Art. 17 GDPR): You can request that we delete your personal data.
- Right to Restriction of Processing (Art. 18 GDPR): You can request that we restrict the processing of your data.
- Right to Data Portability (Art. 20 GDPR): You can request to receive your data in a machine-readable format.
- Right to Object (Art. 21 GDPR): You can object to the processing of your data based on our legitimate interests.
- Right to Withdraw Consent (Art. 7(3) GDPR): You can withdraw your consent at any time for future processing.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority.
Security Measures
We employ various security measures including: • Encrypted connections (HTTPS/TLS) • Firebase Security Rules for database access control • Secure authentication tokens • Regular security updates • Password requirements for account protection You are responsible for maintaining the confidentiality of your account credentials. Notify us immediately of any unauthorized access.
Children's Privacy
Our service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information from our systems.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy in the app and updating the 'Last Updated' date. You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us through: • In-app Contact Form (Settings > Contact Us) • Email: support@cardtrezor.com We will respond to privacy-related inquiries within 30 days.