Privacy Policy

Last updated: 31 August 2026 This Privacy Policy explains how TCGCardBase collects, uses, shares and protects personal data when you visit tcgcardbase.com (the “Website”), place an order, contact us or subscribe to our communications. It also sets out the rights you have under the EU General Data Protection Regulation (GDPR).

1. Controller and contact details

The controller responsible for data processing on this Website is: TCGCardBase Parkstraße 3 34576 Homberg (Efze) Germany Email: [email protected] If you have any question about this policy or wish to exercise your rights, please contact us at the address above. We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR.

2. Scope

This policy applies to all personal data processed through the Website, our online shop and our customer communications. It does not apply to third-party websites we link to, which have their own privacy policies.

3. What personal data we collect

3.1 Data you provide to us

  • Order data: first and last name, billing address, shipping address, email address, telephone number (where provided), order contents, order value and order history.
  • Payment data: the payment method you choose and the confirmation of a successful payment. Full card numbers and comparable payment credentials are entered directly with our payment service providers and are never stored on our servers.
  • Account data: if you create a customer account, your login credentials (password stored in hashed form), saved addresses and stored order history.
  • Communication data: the content of emails, contact-form messages and support requests, including any attachments.
  • Marketing data: your email address and consent status if you subscribe to our newsletter or promotional messages.

3.2 Data collected automatically

  • Server log data: IP address, date and time of the request, the page or file requested, referring URL, browser type and version, operating system and the amount of data transferred.
  • Usage data: pages and products viewed, items added to cart, session duration, clicks and similar interaction data (only to the extent covered by your cookie consent).
  • Device and cookie data: cookie identifiers, device identifiers, screen resolution, approximate location derived from your IP address and language settings.
We do not knowingly collect special categories of personal data (Art. 9 GDPR) and ask you not to send us any.

4. Purposes of processing and legal bases

Purpose Data used Legal basis
Processing, fulfilling and shipping your order; managing returns and refunds; providing customer support Order data, payment data, communication data Art. 6(1)(b) GDPR β€” performance of a contract
Operating and securing the Website, preventing fraud and abuse, ensuring technical stability Server log data, order data Art. 6(1)(f) GDPR β€” legitimate interest in a secure and functional shop
Managing your customer account Account data Art. 6(1)(b) GDPR
Complying with commercial, tax and accounting obligations Order data, invoices, payment records Art. 6(1)(c) GDPR β€” legal obligation (Β§ 147 AO, Β§ 257 HGB)
Analytics, conversion measurement, advertising and remarketing (Google Analytics 4, Google Ads, Meta Pixel) Usage data, device and cookie data, hashed contact data where applicable Art. 6(1)(a) GDPR β€” your consent; Β§ 25(1) TDDDG for storage of and access to information on your device
Sending newsletters and promotional emails Email address, name, consent record Art. 6(1)(a) GDPR β€” your consent (or Β§ 7(3) UWG for emails about similar goods to existing customers)
Establishing, exercising or defending legal claims All relevant data Art. 6(1)(f) GDPR β€” legitimate interest in legal defence

5. Cookies and similar technologies

We use cookies and comparable technologies (local storage, pixels, tags) on the Website. They fall into the following groups:
  • Strictly necessary cookies β€” required to operate the shop: session management, shopping cart contents, checkout, login state, currency selection, load balancing and security. These are set on the basis of Β§ 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR and cannot be switched off.
  • Analytics cookies β€” help us understand how the shop is used so we can improve it. Set only with your consent.
  • Marketing and advertising cookies β€” used to measure the performance of our advertising and to show relevant ads on Google and Meta platforms. Set only with your consent.
You can give, refuse or change your cookie choices at any time via the cookie settings on the Website. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. You can also delete or block cookies through your browser settings; strictly necessary cookies cannot be disabled without affecting the functioning of the shop.

6. Third-party services we use

6.1 Hosting and shop platform

The Website runs on WordPress with WooCommerce and is hosted by our hosting provider on servers within the European Union. The hosting provider processes server log data and all data stored in the shop database strictly on our instructions under a data processing agreement pursuant to Art. 28 GDPR.

6.2 Payment service providers

  • Stripe β€” Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When you pay by card or a supported wallet, your payment data is transmitted directly to Stripe, which acts as an independent controller for payment processing, fraud prevention and its own regulatory obligations. See stripe.com/privacy.
  • Paygate.to / Coinbase Pay β€” used for card-to-crypto checkout. If you select this method, you are redirected to the provider’s payment page, where your payment and, where required, identity verification data is processed by the provider as an independent controller under its own privacy policy. We receive only the payment status and the reference for your order.
Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract) and Art. 6(1)(c) GDPR (legal obligations of the providers).

6.3 Shipping and logistics

To deliver your order we pass your name, delivery address and, where necessary for delivery notifications, your email address and telephone number to the shipping carrier handling your parcel. Legal basis: Art. 6(1)(b) GDPR.

6.4 Google Analytics 4

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use Google Analytics 4 to understand how visitors use the shop. Google Analytics uses cookies and collects usage and device data, including a truncated IP address. We have enabled IP anonymisation and have not enabled Google signals unless separately disclosed. Data may be transferred to Google LLC in the United States. Legal basis: your consent under Art. 6(1)(a) GDPR and Β§ 25(1) TDDDG. You can additionally install Google’s browser opt-out add-on: tools.google.com/dlpage/gaoptout.

6.5 Google Ads and Google Merchant Center

Provider: Google Ireland Limited. We use Google Ads conversion tracking and remarketing to measure the effectiveness of our advertising and to show you our products on Google services and partner sites. Product data from our shop is also submitted to Google Merchant Center; that feed contains product information, not customer data. Cookies and identifiers used for advertising are set only with your consent (Art. 6(1)(a) GDPR, Β§ 25(1) TDDDG). More information: policies.google.com/privacy.

6.6 Meta Pixel

Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. The Meta Pixel allows us to measure the results of our Facebook and Instagram advertising and to reach visitors of our shop with relevant ads. It collects usage and device data and may transmit hashed contact data for matching purposes. With regard to the collection and transmission of this data, we and Meta act as joint controllers pursuant to Art. 26 GDPR; the essential content of that arrangement is available at facebook.com/legal/controller_addendum. The subsequent processing by Meta is Meta’s sole responsibility. Legal basis: your consent under Art. 6(1)(a) GDPR and Β§ 25(1) TDDDG. More information: facebook.com/privacy/policy.

6.7 Email and customer communication

Transactional emails (order confirmations, shipping notifications, support replies) are sent through our email service provider on the basis of Art. 6(1)(b) GDPR. Where we send marketing emails, we do so on the basis of your consent, and every marketing email contains an unsubscribe link.

7. Transfers to third countries

Some of the providers named above are part of groups with entities in the United States, so your data may be transferred outside the European Economic Area. Such transfers take place on the basis of the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework, where the recipient is certified under it, and/or on the basis of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with additional safeguards. We would be happy to provide you with a copy of the relevant safeguards on request.

8. Recipients of your data

We share personal data only where necessary, namely with: our hosting and IT service providers; payment service providers; shipping carriers; the analytics and advertising providers named above; our tax adviser and accounting service providers; and public authorities or courts where we are legally required to do so. Processors act only on our documented instructions under data processing agreements. We do not sell your personal data.

9. Retention periods

  • Order, invoice and accounting data: retained for the statutory retention periods under German commercial and tax law, which run for up to ten years from the end of the relevant calendar year.
  • Customer account data: retained for as long as your account exists; after deletion of the account, only data subject to statutory retention obligations is kept.
  • Support and contact correspondence: retained for up to three years after the matter is closed, in line with the standard limitation period.
  • Server log data: retained for a maximum of 30 days, unless a security incident requires longer storage.
  • Analytics and advertising data: retained according to the retention settings of the respective provider, generally not longer than 14 months.
  • Newsletter data: retained until you withdraw your consent; the record of your consent and its withdrawal is kept as evidence.

10. Your rights

Under the GDPR you have the right to:
  • Access (Art. 15) β€” obtain confirmation of whether we process your data and receive a copy of it;
  • Rectification (Art. 16) β€” have inaccurate data corrected or incomplete data completed;
  • Erasure (Art. 17) β€” have your data deleted where one of the listed grounds applies and no retention obligation stands in the way;
  • Restriction of processing (Art. 18);
  • Data portability (Art. 20) β€” receive the data you provided in a structured, commonly used, machine-readable format;
  • Object (Art. 21) β€” object at any time, on grounds relating to your particular situation, to processing based on legitimate interests; and to object at any time and without giving reasons to processing for direct marketing purposes;
  • Withdraw consent (Art. 7(3)) β€” withdraw any consent you have given with effect for the future.
To exercise these rights, contact us at [email protected]. We respond within one month; where a request is complex, we may extend this period and will inform you accordingly. We may need to verify your identity before acting on a request.

11. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us is: Der Hessische Beauftragte fΓΌr Datenschutz und Informationsfreiheit Gustav-Stresemann-Ring 1 65189 Wiesbaden, Germany datenschutz.hessen.de

12. Obligation to provide data

Providing the data required for an order (name, delivery and billing address, email address, payment details) is necessary to conclude and perform the purchase contract. Without this data we cannot process your order. All other data is provided voluntarily.

13. Automated decision-making

We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Our payment service providers may run automated fraud checks as part of their own processing.

14. Data security

The Website uses TLS encryption (recognisable by the “https://” prefix and the padlock in your browser) to protect data in transit. We apply appropriate technical and organisational measures, including access controls, encryption at rest for sensitive fields, regular updates and backups, to protect your data against loss, misuse and unauthorised access. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.

15. Children

Our shop is not directed at children. We do not knowingly collect personal data from children under 16 years of age without the consent of the holder of parental responsibility. If you believe a child has provided us with personal data, please contact us and we will delete it.

16. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to our services, our providers or legal requirements. The current version is always available on this page, with the date of the last update at the top. Where changes require your consent, we will ask for it separately.