Skip to content
Home

Legal

Privacy policy

This policy sets out exactly what data TrackMyDex collects, why, who it is shared with, how long it is kept, and how you can retrieve or erase it. It applies to trackmydex.com and to nothing else.

1. Who is responsible

TrackMyDex is published and operated by trackmydex.com. For any question about your personal data, or to exercise one of the rights described in section 7, write to: contact@trackmydex.com We answer within one month at the latest, as required by article 12 of the GDPR.

2. What we collect

We collect only what the service needs to work. There is no hidden collection: the list below is exhaustive. • Account data. Your email address and display name. If you register by email we also store a hash of your password (scrypt) — never the password itself. If you sign in with Google, Google passes us your email address, name, Google account identifier and profile picture URL; we receive neither your Google password, nor your contacts, nor anything from your other Google services. • Collection data. The cards and sealed products you record: the card's identifier in our catalogue, quantity, condition, printed language, whether it is graded, the purchase price and date if you enter them, and any notes you write. Your wishlist works the same way. • Preferences. Interface language, default card language, display currency, theme, and your choice about the weekly email summary. • Session data. A session cookie once you sign in, and the date you last signed in. • Server logs. IP address, timestamp, the page requested, the response code and the browser identifier. These are produced automatically by the web server, as on any website. We collect no location data, no contacts, no advertising identifiers, no payment details, and no special-category data within the meaning of article 9 of the GDPR. The service is free and involves no payment.

3. Why we use it

Each purpose below maps to a specific legal basis. We do not use your data for anything else. • Account data — to authenticate you, secure your session, and send you the email strictly tied to the account: address verification and password reset. Legal basis: performance of the contract (art. 6.1.b). • Collection data — to display your collection, value it from public market data, compute your progress per set, and build its value history. Legal basis: performance of the contract (art. 6.1.b). • Weekly summary — to email you a summary of how your collection has moved, only if you ticked that box. Legal basis: consent (art. 6.1.a), withdrawable at any time in your preferences or through the unsubscribe link. • Server logs — to diagnose faults, detect abuse and rate-limit automated requests. Legal basis: legitimate interest in keeping the service available and secure (art. 6.1.f). We carry out no profiling, no automated decision-making with legal effect, and no targeted advertising, and we neither sell nor rent any data.

4. Who it is shared with

We sell no data and we share your collection with nobody. Only three third parties are involved, each for a precise technical reason: • Hosting — Oracle Cloud Infrastructure. The application server and the database run in a data centre located in the European Union. Oracle acts as a processor within the meaning of article 28 of the GDPR and does not exploit the content. • Google — only if you choose Google sign-in. The exchange is limited to the OAuth 2.0 protocol: Google passes us the data listed in section 2, and we pass it nothing beyond the authentication request itself. Your collection is never sent to Google. Google's policy: https://policies.google.com/privacy • Card data providers — TCGdex and TCGCSV. Our server queries them nightly to build the catalogue, the artwork and the prices. Those requests are about cards, never about you: no personal data is sent to them, and they are made by our server rather than by your browser. Those providers therefore cannot track you. Beyond these three cases, your data is disclosed to a third party only where the law compels us, at the request of a judicial authority. No personal data leaves the European Union because of our service, with the single exception of Google authentication if you use it.

5. How long we keep it

• Account and collection data — for as long as your account exists. It is permanently erased, not merely deactivated, when you delete your account. • Dormant accounts — no automatic deletion: an account left unused for years keeps its collection intact. • Server logs — 30 days, then deleted automatically by rotation. • Database backups — a rolling 14 days. A deleted account therefore also disappears from backups within 14 days at the latest. • Session cookie — 30 days, or immediately if you sign out.

6. Security

Traffic between your browser and the server is encrypted with TLS, without exception: any plaintext request is redirected. Passwords are hashed with scrypt and never stored in the clear; we are therefore technically unable to tell you your password, and a reset is the only route. The database is not exposed to the internet: it is reachable only from the application. Administrative access to the server uses an SSH key, with no password. The session cookie is marked HttpOnly, Secure and SameSite, which makes it unreadable by third-party JavaScript. In the event of a breach likely to create a risk to your rights, we will notify the supervisory authority within 72 hours and tell you directly if the risk is high.

7. Your rights

The GDPR gives you the rights of access, rectification, erasure, restriction, objection and portability. Two of them can be exercised immediately in the app, with no need to write to us and nothing to wait for: • Portability — My account → Export my collection. The CSV produced contains all of your collection data, in an open format, readable by any spreadsheet and importable elsewhere. • Erasure — Profile → Delete my account. Deletion is immediate and permanent: account, collection, wishlist, preferences and sessions are removed from the database in the same transaction. • Rectification — your name, email and preferences can be changed at any time from your profile. For access, restriction and objection, or for any question, write to contact@trackmydex.com. We answer within one month, free of charge. If our answer does not satisfy you, you may lodge a complaint with the data protection authority of the country you live in.

8. Cookies and local storage

One cookie is set: the one that keeps you signed in. It is strictly necessary for the service to work and therefore requires no prior consent. It is not set unless you sign in: browsing the site without an account writes no cookie at all. No advertising cookies, no third-party trackers, no pixels, no analytics — neither Google Analytics nor any equivalent. That is why you will never see a cookie banner here: there is nothing to accept. The app does use your browser's local storage for two things that never leave your device and are never sent to the server: the theme you chose, and any cards you added before creating an account. Those cards are moved onto your account, then cleared from the browser, at the moment you sign up.

9. Children

The service is aimed at a family audience and may be used by minors. We do not knowingly collect data from a child under 15 without the consent of the holder of parental authority. No data we collect is used for advertising or profiling, whatever the user's age. If you are a parent and find that an account was created by your child, write to contact@trackmydex.com: the account and its data will be deleted.

10. Changes to this policy

This policy may change if the service does. Any substantial change — a new purpose, a new recipient, a longer retention period — will be announced in the app before it takes effect, and the date below will be updated. Earlier versions remain readable in the project's public source history.

Last updated: 2026-09-20