Privacy policy
1. Controller
Silas Nutz
trading as Mandavo Softwareentwicklung
Daimlerstraße 50, 74211 Leingarten, Germany
kontakt@mandavotech.com
We have not appointed a data protection officer because we are currently not legally required to do so (in particular no obligation under § 38 BDSG). For privacy questions, please contact the address above directly.
2. What TCGaze does - and does not do
TCGaze searches public third-party databases and catalogues for product images of trading cards and displays results with a source reference. We store no images on our servers and keep no account-related history of your search terms. Only the number of searches and downloads per day is counted (quotas), not their content.
3. Categories of personal data
- Account data: e-mail address, password in hashed form (scrypt), optionally name and company, timestamps of registration, e-mail confirmation and login, accepted terms version, image-rights confirmation (date and version, required before downloads).
- Usage counters: number of searches, downloads and bulk jobs per day as well as API requests per month, stored per account or - without an account - per pseudonymised IP address (truncated hash with a daily key, cannot be reversed to the IP).
- Security and event logs: logins, failed login attempts, password and plan changes, image-rights confirmations, cancellation and withdrawal notices, API key events - each with timestamp and pseudonymised IP address, without search content.
- Server access logs: IP address, time, requested address, status code, browser type - for security and error analysis.
- Session data: session identifier (hashed), expiry time, browser type, pseudonymised IP address.
- API keys: stored as hashes only; label, creation and last-used timestamps.
- Bulk import (Business): the CSV rows you upload (item numbers, product names) and the matching results, until you delete the job or the account. Do not upload personal data of third parties.
- Billing data for paid plans: Stripe customer and subscription identifiers, plan, status, billing period. Payment details (card number, IBAN) are processed exclusively by Stripe; we do not receive them.
- Communication: the content of your e-mails to us (support, cancellation, withdrawal, takedown).
4. Purposes and legal bases
4.1 Providing the website, security
When you visit, we process technical data (IP address, time, page requested, browser type) to deliver content and protect the service against misuse (rate limiting, bot protection). Legal basis: Art. 6 (1) (f) GDPR (secure operation).
4.2 Account, login, quotas
We process account data, sessions and usage counters to perform the contract (Art. 6 (1) (b) GDPR) and to prevent misuse (Art. 6 (1) (f) GDPR). Without an account, we count searches pseudonymously per IP address to enforce fair quotas (Art. 6 (1) (f) GDPR).
4.3 Searching for and displaying images - retrieval from third-party sources
Your search query is forwarded by our server to the queried sources (see Sources); only our server’s IP address is transmitted, not yours. To display preview images, your browser usually loads the image files directly from the server of the respective source (e.g. Konami, Bandai, The Pokémon Company, Scryfall, TCGdex, tcgplayer). The source operator thereby receives your IP address, browser type and time; we suppress transmission of the referring page (referrer). For individual sources that do not allow direct embedding, we load the image via our server (proxy); the source then receives only our server IP. Downloads and conversions always run through our server. Legal basis: Art. 6 (1) (b) GDPR (performing the search you requested) and (f) GDPR (efficient provision without storing third-party images). The processing by source operators is governed by their privacy notices; some providers are located outside the EU (in particular USA, Japan).
4.4 Transactional e-mails (Postmark)
For e-mail confirmation, password reset, invoice and plan notifications as well as receipts for cancellation and withdrawal we use the service provider Postmark (ActiveCampaign, LLC, USA). Only the recipient address and message content are transmitted; open and click tracking is disabled. Legal basis: Art. 6 (1) (b) and (f) GDPR. We do not send marketing e-mails without your separate consent.
4.5 Billing and payment (Stripe)
Paid plans are processed via Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA). Stripe processes payment, invoice and identification data (including billing address and, where applicable, VAT ID) as an independent controller for payment processing and partly as a processor for us; we receive customer and subscription identifiers, plan, status and invoices. Checkout takes place on Stripe’s pages; we do not load Stripe scripts on our pages. Legal basis: Art. 6 (1) (b) GDPR; for tax retention Art. 6 (1) (c) GDPR. Privacy notice: stripe.com/privacy.
4.6 Bot protection (Cloudflare Turnstile, optional)
We currently do not use an external bot protection service. Should we enable Cloudflare Turnstile at registration, technical browser data and the IP address would be transmitted to Cloudflare, Inc. (USA) (Art. 6 (1) (f) GDPR); we will update this policy accordingly.
4.7 Hosting
The service is operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (EU). Database, logs and backups are located there. Legal basis: Art. 6 (1) (b) and (f) GDPR.
4.8 Cancellation and withdrawal
Notices submitted via the “Cancel contracts here” and “Withdraw from contract” buttons are stored with content, date and time, and we confirm receipt by e-mail (§ 312k BGB, Art. 11a Directive 2011/83/EU). Legal basis: Art. 6 (1) (b) and (c) GDPR.
4.9 Obligation to provide data
Without an e-mail address and password we cannot provide an account; without payment details at Stripe, no paid plan. Searching can be used without an account. All other details (name, company) are voluntary.
5. Recipients and processors
| Recipient | Purpose | Location / safeguard |
|---|---|---|
| Hetzner Online GmbH | Hosting, database, backups | EU (Germany/Finland), processing under Art. 28 GDPR |
| Postmark (ActiveCampaign, LLC) | Transactional e-mails | USA - EU-U.S. Data Privacy Framework, additionally standard contractual clauses |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Payments, invoices, subscription management | Ireland / USA - EU-U.S. Data Privacy Framework, additionally standard contractual clauses |
| Cloudflare, Inc. (only if Turnstile is enabled) | Bot protection at registration | USA - EU-U.S. Data Privacy Framework, additionally standard contractual clauses |
| Source operators (see Sources) | Direct retrieval of preview images by your browser (section 4.3) | independent controllers; partly third countries (USA, Japan) - their privacy notices apply |
6. Transfers to third countries
Where Postmark, Stripe, Cloudflare or source operators process data in third countries, we rely - to the extent applicable to us - on the EU-U.S. Data Privacy Framework for certified providers, otherwise or additionally on the EU Commission’s standard contractual clauses (2021) and supplementary measures. The direct retrieval of images from sources (section 4.3) is performed by your browser at your request; we have no influence on the processing there.
7. Cookies and local storage
We use only technically necessary first-party storage (§ 25 (2) no. 2 TDDDG); there are no advertising or tracking cookies and no analytics services are embedded.
tcgaze_session- login session (httpOnly, Secure), up to 30 days.tcgaze_csrf- protection against cross-site request forgery, 30 days.localStorage- your search settings (game, product type, languages) on your device; not transmitted to us.
8. Retention periods
- Account data: until the account is deleted (possible at any time in the account area); residual copies in backups for up to 30 days.
- Usage counters: 90 days.
- Security and event logs: 12 months; cancellation and withdrawal notices until the expiry of statutory limitation periods (3 years).
- Server access logs: 14 days, longer in case of security incidents where necessary.
- Cache for source responses (no personal data): up to 7 days.
- Bulk import data: until you delete the job, at the latest when the account is deleted.
- Billing data and invoices: 10 years pursuant to § 147 AO / § 257 HGB (at Stripe and in our accounting).
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). Please send requests to kontakt@mandavotech.com. You can delete your account yourself in the account area.
You have the right to lodge a complaint with a supervisory authority. The authority responsible for our registered office in Baden-Württemberg is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Königstraße 10a, 70173 Stuttgart, Germany (baden-wuerttemberg.datenschutz.de).
10. No automated decision-making, no AI use of your data
We make no automated decisions with legal effect within the meaning of Art. 22 GDPR. Rate limiting is purely technical, based on counters. We do not use your account data or uploads to train AI models.
11. Changes
We adapt this policy when processing activities, service providers or the legal situation change and publish the current version at tcgaze.com/privacy.