Privacy Policy
Table of Contents
- Introduction & Data Controller
- Data We Collect
- Legal Basis for Processing (GDPR Art. 6)
- How We Use Your Data
- Data Sharing & Third-Party Services
- Data Retention
- Cookies, Local Storage & Tracking
- Your Rights (GDPR)
- Data Security
- International Data Transfers
- Children's Privacy
- Changes to This Policy
- Contact & Data Protection Officer
1. Introduction & Data Controller
This Privacy Policy explains how [COMPANY NAME] ("we," "us," "Operator") collects, uses, stores, and protects your personal data when you use TCG Vertex ("Platform"). We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws.
[COMPANY NAME]
[Street Address]
[City, Postal Code, Country]
Email: [CONTACT EMAIL]
2. Data We Collect
2.1 Account Registration Data
| Data | Purpose | Required? |
|---|---|---|
| Username | Public profile identity | Yes |
| Email address | Account recovery, notifications | Yes |
| Password (hashed) | Authentication | Yes |
| Country | Shipping, tax, legal compliance | Yes |
| Account type (private/business) | Compliance, fee structure | Yes |
| Display name | Public profile | Optional |
| Avatar/profile picture | Public profile | Optional |
2.2 Business Account Data
| Data | Purpose |
|---|---|
| Company legal name | Legal compliance, invoicing |
| Company registration number | Business verification |
| VAT identification number | Tax compliance |
| Business address | Legal correspondence, invoicing |
2.3 Seller Verification Data (via Stripe)
When you become a Seller, Stripe collects and processes identity verification data directly. This includes government-issued ID, proof of address, and banking details. We do not store your identity documents — these are processed and held exclusively by Stripe, Inc.
2.4 Shipping Address Data
Billing and shipping addresses provided during registration or at checkout are stored to facilitate order fulfillment. Shipping addresses are shared with Sellers solely for the purpose of shipping purchased items.
2.5 Transaction Data
We record all financial transactions including purchases, sales, balance top-ups, withdrawals, membership payments, commission deductions, and refunds. This data is necessary for accounting, tax compliance, and dispute resolution.
2.6 Automatically Collected Data
| Data | Purpose |
|---|---|
| IP address | Security, fraud prevention |
| Browser type & version | Compatibility, debugging |
| Device information | Responsive design, analytics |
| Access timestamps | Security monitoring |
| Pages visited | Platform improvement |
2.7 User-Generated Content
Content you create on the Platform — including listings, reviews, forum posts, messages, trade binders, and collection data — is stored and may be publicly visible depending on your privacy settings.
3. Legal Basis for Processing (GDPR Art. 6)
| Processing Activity | Legal Basis |
|---|---|
| Account creation & authentication | Art. 6(1)(b) — Contract performance |
| Order processing & payment | Art. 6(1)(b) — Contract performance |
| Identity verification (KYC) | Art. 6(1)(c) — Legal obligation |
| Commission & tax calculations | Art. 6(1)(c) — Legal obligation |
| Transaction records & invoicing | Art. 6(1)(c) — Legal obligation (tax law) |
| Fraud prevention & security | Art. 6(1)(f) — Legitimate interest |
| Platform analytics & improvement | Art. 6(1)(f) — Legitimate interest |
| Notifications & service emails | Art. 6(1)(b) — Contract performance |
| Marketing emails (if any) | Art. 6(1)(a) — Consent |
4. How We Use Your Data
We use your personal data for the following purposes:
- Account Management — Creating, maintaining, and authenticating your account
- Transaction Processing — Processing purchases, sales, payouts, and refunds
- Communication — Sending order updates, notifications, and support responses
- Legal Compliance — Tax reporting, anti-money laundering (AML) obligations, and responding to legal requests
- Security — Detecting and preventing fraud, abuse, and unauthorized access
- Platform Improvement — Analyzing usage patterns to improve features and user experience
- Marketplace Functionality — Sharing necessary data between Buyers and Sellers (e.g., shipping addresses for order fulfillment)
5. Data Sharing & Third-Party Services
5.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
5.2 Third-Party Service Providers
| Service | Provider | Data Shared | Purpose |
|---|---|---|---|
| Payment processing | Stripe, Inc. | Payment details, identity docs | Payments, KYC, payouts |
| Email delivery | [Email Provider] | Email address, username | Transactional emails |
| Hosting | [Hosting Provider] | All Platform data | Infrastructure |
| Shipping tracking | 17track / carriers | Tracking numbers | Delivery status updates |
5.3 Data Shared Between Users
The following data is shared between Buyers and Sellers as part of normal marketplace operations:
- Buyer's shipping address (shared with Seller for order fulfillment)
- Seller's username and public profile information
- For Business Sellers: company name and business information as required by law
5.4 Legal Requests
We may disclose personal data if required by law, court order, or government request, or if necessary to protect the rights, property, or safety of the Operator, Users, or the public.
6. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 30 days | Service provision |
| Transaction records | 10 years after transaction | Tax law (§ 147 AO, § 257 HGB) |
| Invoices | 10 years | Tax law |
| Communication logs | 3 years after last interaction | Dispute resolution |
| Server logs (IP, access) | 90 days | Security |
| Deleted account data | Anonymized within 30 days | N/A |
After the retention period, data is either permanently deleted or irreversibly anonymized.
7. Cookies, Local Storage & Tracking
7.1 What We Use
| Technology | Purpose | Duration |
|---|---|---|
| Local Storage (JWT token) | Authentication / session | Until logout or expiry |
| Local Storage (preferences) | UI preferences (theme, etc.) | Persistent |
| Session Storage | Temporary UI state | Until tab is closed |
7.2 What We Do NOT Use
- We do not use third-party tracking cookies
- We do not use Google Analytics or similar tracking services
- We do not use advertising pixels or retargeting
- We do not share browsing data with advertising networks
8. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of all personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten") |
| Restriction (Art. 18) | Request limitation of processing |
| Data Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interest |
| Withdraw Consent (Art. 7) | Withdraw previously given consent at any time |
To exercise any of these rights, contact us at [CONTACT EMAIL]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national data protection authority.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Password Security — All passwords are hashed using bcrypt with salt. We never store passwords in plaintext.
- Transport Encryption — All data in transit is encrypted using TLS/HTTPS.
- Access Controls — Database access is restricted to authorized personnel and systems.
- Payment Security — Card payment data is processed entirely by Stripe (PCI DSS Level 1 certified). We never see or store your full card number.
- Regular Updates — We maintain up-to-date software and security patches.
10. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), specifically:
- Stripe, Inc. (United States) — For payment processing and KYC. Stripe complies with EU-US data transfer requirements.
Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.
11. Children's Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a child under 18 has provided us with personal data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-platform notification at least 14 days before taking effect. The latest version is always available at /privacy.
13. Contact & Data Protection Officer
[COMPANY NAME]
[Street Address]
[City, Postal Code, Country]
Email: [DATA PROTECTION EMAIL]
Supervisory Authority:
If you believe your data protection rights have been violated, you may lodge a complaint with your local Data Protection Authority (DPA). In Germany, this is the respective state commissioner for data protection (Landesdatenschutzbeauftragter).