Legal
Privacy Policy (GDPR)
Draft last updated: 2026-09-10
Data controller: [COMPANY NAME], [REGISTERED OFFICE], [contact email]. This notice describes how we process the personal data of RIP-CARDS users.
1. Data processed
- Account: email, name, password (encrypted), date of birth, email verification date.
- Orders and Coins: Coins purchases, ledger movements, pack purchases and openings, Binder contents.
- Shipping: shipping address, status, tracking.
- Technical: security and audit logs (relevant actions, timestamps), IP address for security and abuse-prevention purposes.
- If you sign in with Google: the account identifier and email provided by that provider.
2. Purposes and legal bases
- Performance of the contract (sign-up, purchases, shipping, support).
- Legal obligations (accounting, tax).
- Legitimate interest (platform security, fraud prevention, integrity of the draw mechanism).
We do not carry out profiling or marketing without separate consent.
3. Providers (data processors)
- Application hosting: Vercel.
- Database: Neon (EU region).
- Transactional email: Resend.
- Payments: Stripe.
- Google sign-in: Google.
A data processing agreement is (or will be) in place with each of them. Where a provider involves transfers outside the EU, the safeguards required by the GDPR are applied (standard contractual clauses).
4. Retention
Account data: for the duration of the relationship and for as long as needed to meet legal obligations. Accounting data: 10 years. Security logs: a limited and proportionate period.
5. Rights
You can exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to [email]. You may lodge a complaint with the data protection authority.
[TO COMPLETE: record of processing activities, DPO if appointed, detailed retention periods by category, data-subject request procedure.]