Privacy Policy
This page describes how ONE TCG processes your personal data. We comply with the General Data Protection Regulation (GDPR, EU 2016/679) and applicable data protection laws.
1. Data Controller
The data controller is the publisher of ONE TCG, whose full identity and contact details appear on the "Legal notice" page accessible from the footer. For any questions about your data or to exercise your rights (see §9), write to us at privacy@onetcg.app, specifying the email address associated with your account.
2. Data Collected
We only collect what is necessary for the service to function. The categories of data processed are as follows:
- Account identifiers: email, password (hashed with bcrypt on the Supabase Auth side, never readable in plain text);
- Profile: username, biography, avatar, preferred language, social links you choose to add;
- Content: collections, decks, trade lists, wishlists, card photos, custom tags, comments, post-trade reviews;
- Trades: trades proposed or accepted, private messages, friend requests, user blocks;
- Preferences: dashboard layout, visibility settings, interface preferences;
- Technical logs: IP addresses, user-agents (for security and abuse prevention purposes);
- Payment data (if applicable): if you subscribe to a paid plan, payment processing is handled by a specialist provider. We do not store any card payment data on our servers.
- Usage activity: to measure retention and improve the service, we record a minimal activity signal — your account identifier together with the dates of the days you use the app (no IP address or precise timestamp in this record).
- Age data: your date of birth, provided on a self-declared basis at sign-up and stored as a date only (not editable), used solely to enforce the minimum age and to protect minors on connection features.
- Optional geolocation: if you enable it, city, postal code, country, search radius and approximate coordinates (municipality centroid, not precise GPS) to suggest nearby events and wishlist matches; can be disabled at any time from your profile;
- Professional seller data (if applicable): if you enable the Pro area, declared legal identity, SIRET, business name, professional address and contact, VAT number where applicable, sale notes and storefront metadata; the SIRET may be checked for format and existence against the public company directory;
- Parental consent (ages 13–14): when the declared age so requires, a parent/guardian email address (stored as a hash fingerprint, not in clear text), request and confirmation timestamps, and time-limited confirmation tokens;
3. Purposes
- providing the service (authentication, synchronisation, social features);
- enabling AI deck analysis at your explicit request (see §5);
- preventing fraud and abuse (quota limiting, automation signal detection);
- responding to user requests and support;
- complying with our legal obligations (court orders, accounting).
4. Legal Bases
- Performance of a contract (Art. 6.1.b GDPR) for the essential features of the service;
- Legitimate interest (Art. 6.1.f) for security, fraud prevention, and moderation;
- Consent (Art. 6.1.a) when you choose to make certain content public or trigger an AI analysis;
- Legal obligation (Art. 6.1.c) for the retention of technical logs and responding to court orders.
5. Hosting & Processors
ONE TCG relies on the following processors, who act strictly within the framework set by their own terms and by this policy:
- Supabase (PostgreSQL database hosting, object storage, authentication) — instance located in the European Union. Supabase's privacy policies are available on their official website.
- Vercel (web application hosting, CDN distribution). Vercel may process technical logs (IP, user-agent) for security and routing purposes. Data transfers may transit through nodes located outside the EU (see §6).
- privacy.sections.sous-traitants.l3
- Voyage AI (United States) — provider of vector embeddings used for RAG, semantic search and similar decks. Text required for embeddings may include card oracle text, deck card lists, format/TCG and aggregated reference deck content; no personally identifying data is intentionally transmitted. Retention and transfer safeguards depend on the professional terms, DPA, Standard Contractual Clauses and/or Data Privacy Framework applicable to the active supplier contract.
- Scryfall (United States) — public source of Magic card metadata. Requests to Scryfall are made server-side without transmitting any user data.
- Stripe (United States / Ireland) — payment provider for Premium and Pro Seller subscriptions. When you subscribe, Stripe processes your name, email address, billing address, card metadata, and IP address in order to carry out and secure the transaction. No card payment data transits through or is stored on ONE TCG's servers (see transfers outside the EU, §6).
- Resend (United States) — provider for delivering transactional emails (sign-up confirmation, account notifications, subscription). Resend receives your email address and the content of the email sent in order to ensure deliverability (see §6).
- Sentry (United States) — application error and performance monitoring, on the basis of our legitimate interest (security and debugging). Sentry may receive technical data (URL, user-agent, internal account identifier) for diagnostic purposes; it is configured to collect no personal data by default (no email/username, no cookie) and remains inactive as long as no collection endpoint is configured (see §6).
- Nominatim / OpenStreetMap (geocoding service, Germany / OpenStreetMap infrastructure) — used server-side to resolve event addresses into coordinates. Only event addresses (city, postal code, country, venue name) are sent; no account-identifying personal data is attached. Usage follows the Nominatim usage policy (identifiable User-Agent, rate limit).
- INSEE / recherche-entreprises.api.gouv.fr (France) — public company directory used to verify the format and existence of a SIRET declared by a Pro Seller. Only the SIRET number (and possibly the name returned by the API for display) is queried; no email or account identifier is transmitted.
6. Transfers Outside the EU
Some technical processors (Anthropic, Voyage AI, Vercel, Scryfall, Stripe, Resend, Sentry) are based in the United States (Stripe may also operate from Ireland). The GDPR framing of these associated transfers is being formalized; it relies in particular on:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Data Privacy Framework certification where available with the processor;
- strict minimisation of transmitted data (see §5).
AI and embedding features may be disabled; when active, transfers to Anthropic and/or Voyage AI may occur only after an explicit action on your part (deck analysis, photo recognition or similar-deck search). You can opt out by simply not using those features.
7. Retention Period
- Active account: for as long as you use the service;
- After account deletion: maximum 30 days, then erasure (unless a legal retention obligation applies, e.g. for accounting or in response to a court order);
- Technical logs: maximum 12 months. The register of administration actions is not subject to this period: it is kept under a legal obligation and takes precedence over the right to erasure;
- Personal content upon account deletion: your private messages and your collections (with their contents) are erased as part of the deletion; your analytics usage logs are anonymised (dissociated from your identifier);
- Reviews and trade history: to preserve the reputation and history of the other users you interacted with, the reviews you wrote and the trades you took part in are retained but anonymised when your account is deleted (your identity is dissociated: they appear as "deleted account"). This anonymisation is automatic; legal retention obligations (accounting, court orders) take precedence where applicable.
- Optional geolocation: the city, postal code, country, radius, and approximate coordinates (municipality centroid) linked to your home location are kept for as long as you keep this option enabled and are deleted as soon as you disable it or delete your account. Location data attached to events and the associated notifications is subject to bounded retention and is purged by scheduled jobs within a maximum of 90 days. You can edit or delete your location at any time from your profile.
- Notifications and transactional emails: in-app notifications are retained as long as needed for display, then purged or expunged by scheduled jobs; email delivery logs are retained as long as needed for deliverability, support and proof of sending.
- Internal analytics: usage events strictly necessary to operate the product are aggregated or anonymised as soon as they are no longer useful for security, support or internal statistics.
- Reports, moderation decisions and appeals: retained as long as needed for processing, abuse prevention, defending our rights and transparency obligations; they may be aggregated in an annual report without unnecessary personal data.
- AI: deck analyses and AI usage events are retained to return results, track quotas and diagnose errors; scan images are not retained by ONE TCG after processing.
- Date of birth: retained for the entire lifetime of the account (a non-editable profile field), then erased together with the account upon its deletion.
- Decks on account deletion: your decks are removed from the community (set to private) and free-text fields (name, description, cover image) are erased or replaced with a neutral label. The technical card list may be retained without an owner for fork/history integrity, but is no longer publicly listable or readable.
8. Security Measures
We implement reasonable technical and organisational measures to protect your data:
- end-to-end TLS encryption of communications with the service;
- hashed passwords (bcrypt) — we are technically unable to read your password;
- database-level security policies (Postgres RLS) that restrict each user's access to their own data;
- logging of sensitive access for audit purposes;
- quota limiting to prevent abuse and enumeration attacks;
- strict separation between client-side code (which only receives necessary data) and privileged server-side operations.
No system is infallible, so we recommend using a strong, unique password and regularly exporting your sensitive data using the service's export features.
9. Your Rights
Under the GDPR, you have the following rights:
- Right of access and portability: download your personal data in JSON format from your profile; the downloaded file is the authoritative list of included categories. Excluded in particular: audience measurements (aggregated telemetry, dissociated on deletion) and the technical log of analysis-service calls (admin cost/latency log, anonymised on deletion);
- Right to rectification: edit your profile at any time;
- Right to erasure: request account deletion from your profile (processed within 30 days);
- Right to object and to restriction: write to us;
- Right to withdraw your consent at any time for consent-based processing (public visibility of content, AI analysis);
- Right to set post-mortem instructions regarding the retention, erasure, and communication of your data after your death;
- Right to lodge a complaint: you may contact your local data protection authority.
Post-mortem instructions and heirs' procedure. In accordance with Article 85 of the French Data Protection Act, you may set instructions regarding the fate of your data after your death (retention, erasure, communication) by writing to privacy@onetcg.app. In the absence of instructions, an heir may request the closure of the deceased's account, that the death be taken into account, or the communication of information necessary to settle the estate, by sending proof of death and proof of their status as an heir to privacy@onetcg.app; we process such requests within a reasonable time after verification.
10. Cookies
ONE TCG uses only technically necessary cookies required for the service to function. The table below details their classification:
| Name | Purpose | Type | Duration |
|---|---|---|---|
| Supabase Auth (sb-…-auth-token) | Maintaining the authenticated session (JWT and refresh token) | Technical — strictly necessary | Session / refresh token duration (deleted on logout) |
| consent_ok_v4 | Remember acceptance of the legal terms in force and their version | Technical — strictly necessary | 1 hour (revalidated as long as the session stays active) |
| NEXT_LOCALE | Remember your preferred display language | Preference — exempt from consent | 12 months |
| age_gate | Anti-circumvention after an age declaration under 13 | Technical — strictly necessary | 24 hours |
| pwd_recovery | HMAC proof of the forgot-password session | Technical — strictly necessary | 15 minutes |
Interface preferences (display mode, theme) and the dismissal of the notifications prompt are stored locally in your browser (localStorage); this data is not a cookie and is not transmitted to the server.
No advertising, profiling, or third-party analytics cookies are set. In accordance with the ePrivacy Directive, strictly necessary cookies do not require explicit consent.
If ONE TCG later enables a third-party analytics, advertising, profiling or session-replay tool that is not strictly necessary, it will be off by default and subject to your prior consent, in line with the CNIL rules on cookies and trackers.
Push notifications (Web Push) — ONE TCG may send you push notifications in your browser. Purpose: to alert you about the prices you follow, your trade activity (offers, counter-offers, matches), and events near you. Legal basis: your consent (GDPR art. 6(1)(a) and ePrivacy Directive art. 5(3)) — the browser is only accessed after your explicit authorisation, never by default. Data stored: the push subscription address (endpoint) provided by your browser's service, the message-encryption cryptographic keys (p256dh and auth), and the device's user-agent. Retention: for as long as the subscription stays active; it is deleted when you disable notifications, when the browser invalidates the subscription, or when you delete your account. Withdrawal: you can withdraw your consent at any time from your browser's (or system's) notification settings, with no impact on the rest of the service.
11. Minors
The service is open to people aged at least 13. Age is collected through a declarative attestation at sign-up (date of birth + checkbox): the date is not verified with ID documents and is used to enforce the minimum age floor and to restrict some matchmaking features. For accounts whose declared age is 13 or 14, ONE TCG also requires parental consent by email: the user provides a parent/guardian address; a time-limited confirmation link is sent; the parent email is stored as a hash fingerprint, not in clear text. Until the parent confirms, the account remains restricted (private profile / blocked access depending on the flow). This process is not identity verification of the parent or the minor. No advertising profiling or minor-specific commercial processing is applied.
Home geolocation is optional, approximate and can be switched off; it is used only for nearby-event notifications, and only when the user turns it on explicitly. If you are a parent, legal guardian or user and you spot a minor's account without the required authorisation, contact support@onetcg.app: we may ask for further evidence, suspend access, or delete the account concerned.
12. Private messages
Private messages exchanged between Users are stored in the database to allow later consultation. We do not read private conversations as a matter of routine. A team member may only read them in the following cases:
- explicit reporting of an exchange by one of the parties;
- requisition by a competent judicial authority.
Messages are protected by RLS at the database level: only the sender and the recipient can access them via the application.
13. Changes to this policy
This policy may be updated to reflect changes to the service or applicable legislation. Substantial changes are notified by email or via a banner on the service. The date of the last update is shown at the bottom of the page.
Last updated: July 24, 2026.