Privacy Policy
Last updated: 10 August 2026
1. Who we are
TCG Actana is operated by the person below, who is the controller responsible for data processing under the EU General Data Protection Regulation (GDPR):
Darpin Digital, owner: David Demircian (provider of the TCG Actana service)
Forstgarten 2
37603 Holzminden, Germany
Email: info@tcgactana.com
2. Scope and principles
This Privacy Policy applies to the tcgactana.com website, the TCG Actana desktop app, the TCG Actana browser extension, and the associated account, scan, synchronisation, billing, and installer services. The public beta has registration in the desktop app, 250 test cards once, and optional paid monthly card allowances, but no public social features or standalone iOS app. We do not sell personal data or use advertising or analytics trackers.
3. Data we process
a) Website, server requests, and installers
When you access the website or our API, the servers process technically necessary connection data, particularly your IP address, time of access, requested resource, and response status. This is required to deliver the service, diagnose errors, prevent abuse, and keep operations secure. We count successful installer starts only in aggregate by platform and app version; the counter contains no IP address or user identifier. Your IP address is processed temporarily to limit abusive volumes of download requests. The legal basis is Article 6(1)(f) GDPR (our legitimate interest in secure and stable operation).
b) Account and authentication
With email-and-password registration, we process your email address and password during secure transmission and store only a cryptographic password hash. We store a technical user ID, a randomly generated internal profile identifier, language, account and confirmation timestamps, and the versions of the Terms you accepted and Privacy Policy you acknowledged during registration and before checkout. Where applicable, we also record declarations about starting the service during the withdrawal period, including the version, time, language, context, and associated checkout. Your email address and required delivery data are processed for confirmation, security, and password-reset emails where the selected login method requires them. The legal basis is Article 6(1)(b) GDPR; retaining evidence may also be based on Article 6(1)(c) and (f) GDPR.
c) Collection
The card and collection data you record is stored in connection with your account. This includes, in particular, the game, card name, set, card number, language, variant, condition, quantity, time recorded, collection assignment, and assigned market price information. This processing enables synchronisation, management, statistics, and export of your collection. The legal basis is Article 6(1)(b) GDPR.
For the seller area, we also store an account-linked work history for processed stacks and successfully created exports. Its summary includes the time and duration, card and entry counts, counts per game, and, for exports, the destination, market, file count, and skipped count.
For new history entries, we additionally store an immutable catalogue and export snapshot for each numbered entry. This may include the game, internal catalogue identifier, card name, set and set code, collector number, language, condition, finish, quantity, foil, reverse and first-edition attributes, a catalogue-image URL, and Cardmarket and TCGplayer identifiers. Export snapshots may also include the type and value of the destination identifier, storage location, unit price and currency, and a file label. These snapshots do not contain scan images or crops captured by you, raw CSV contents, local file paths, or free-text comments. The work history is shown across devices, retained for the lifetime of the account, and deleted with the account. The legal basis is likewise Article 6(1)(b) GDPR.
d) Desktop scanning
During a scan in the desktop app, the app reads parts of the card using local optical character recognition (OCR). For card recognition, the app transmits the captured card image together with the recognised text, necessary scan settings, and your account assignment to our backend. The backend calculates a numerical image feature (embedding) from the card image, matches it against the card catalogue, and discards the image immediately afterwards. Card images are processed exclusively in volatile memory and are neither stored nor shared with third parties. Older app versions and the fallback path continue to calculate the image feature locally and transmit only that feature instead of the image. The legal basis is Article 6(1)(b) GDPR.
e) Browser extension for Cardmarket delivery notes
The TCG Actana browser extension reads a Cardmarket order-detail page only after you click the extension in the active tab and request a delivery note. It may copy the order number, buyer name or username, shipping address, order and shipping details, and card name, set, card number, language, variant, and quantity. The extension does not read Cardmarket passwords, cookies, or API credentials and does not crawl Cardmarket in the background. Orders opened in private browsing windows are not imported.
Imported buyer, address, order, and card data is processed only locally in the extension's volatile session storage for the current delivery note. It is not transmitted to TCG Actana, Cardmarket, or other third parties and ends with the browser session or when the extension data is cleared. We synchronise only your seller template with TCG Actana: sender and contact details, layout, accent colour, greeting, issue and optional buyback texts, and an optional logo. This template is stored against your Actana account and loaded again when you sign in.
For sign-in, the extension's background service sends your email address and password over an encrypted connection to our self-hosted Supabase authentication service. Access and refresh tokens are held only in the extension's volatile session storage; you must sign in again after restarting the browser. Only a pseudonymous account marker remains locally during use to keep data from different Actana accounts separate. The legal basis is Article 6(1)(b) GDPR.
Chrome Web Store Limited Use: Our use of information received through the browser extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use this data only for the disclosed delivery-note feature and related account-template synchronisation, not for personalised advertising, resale, or unrelated purposes. We cannot access order data that is processed exclusively locally. Human access to transmitted account data occurs only with your explicit consent for a specific support case or where required for security or legal obligations.
f) Usage and security statistics
To operate the service, debug problems and prevent abuse, we keep per-account daily counters for the scan feature. We record the game, app version, image path used, result category, and a fixed coarse diagnostic reason. We do not record card or catalogue identifiers, names, sets, OCR text, filenames, images, IP addresses, or device identifiers in these counters. Daily counters are deleted after 90 days and removed immediately when the account is deleted. A random scan event ID prevents duplicate counting during retries; this short-lived association also contains no card content and is deleted after eight days. To fend off overload and abuse, we additionally keep a short-lived, volatile record (24 hours, never persisted) of rejected requests per account or per pseudonymised IP address. The legal bases are Article 6(1)(b) and (f) GDPR.
g) Subscription, payment, tax, and contract actions
When you select a paid plan, we process the plan, price, currency, billing period, allowance usage, contract and payment status, and pseudonymous Stripe/Link customer, checkout, subscription, invoice, refund, and dispute identifiers. In the Stripe-hosted Managed Payments Checkout, Sold through Link, LLC and participating Stripe entities also process your name, email address, billing address, selected payment method, and, where applicable, VAT identification number or tax status. Sold through Link, LLC acts as merchant of record for checkout, payment processing, invoices and receipts, indirect taxes covered by Managed Payments, and transaction support. Payment methods and subscriptions are managed through the Link account. We receive the status and reference data required to activate and administer the contract, but do not receive or store complete card or bank details. The legal bases for our processing are Article 6(1)(b) GDPR for contract performance and billing, Article 6(1)(c) GDPR for tax and commercial-law obligations, and Article 6(1)(f) GDPR for preventing fraud, abuse, and payment disputes.
If you cancel or withdraw through the website, we process your name, contact address, contract identifier, requested end date, type of declaration, and any reason you voluntarily provide for an extraordinary cancellation. We retain receipt, processing status, and confirmation in order to carry out and evidence the declaration.
h) Support
If you contact us by email, we process your sender address, message content, and technical delivery data to respond to your request. Depending on the request, the legal basis is Article 6(1)(b) or (f) GDPR.
4. Hosting and recipients
The website, API, authentication, database, and Storage are operated on infrastructure from netcup GmbH in Germany. We self-host Supabase there; account and collection data is not hosted by Supabase Inc. Other recipients receive data only where required to operate the service. For paid orders, Sold through Link, LLC is the merchant of record. Sold through Link, LLC, Stripe Payments Europe, Limited and Stripe Technology Europe, Limited in Ireland receive the information required for checkout, recurring payments, invoices and receipts, covered indirect taxes, fraud prevention, refunds, payment disputes, and transaction support. Stripe and Link may use further financial partners and service providers and process data outside the EEA under their applicable privacy and transfer mechanisms. Darpin Digital remains responsible for processing its own account and product data. More information is available inStripe's Privacy Policy. Another recipient is Resend, a service operated by Plus Five Five, Inc. in the United States, which processes email addresses, message content, and technical delivery data on our behalf for transactional emails. Transfers to the United States are based on its EU-US Data Privacy Framework certification and, where required, the Standard Contractual Clauses in its data-processing agreement. Other recipients include public authorities where we are legally required to disclose information.
5. Card, image, and pricing data from third parties
We obtain card-catalogue and market-price data on the server side from specialist data sources and marketplaces, including Cardmarket and TCGplayer. We do not send your email address or personal collection to these providers. Our backend retrieves Magic set symbols from Scryfall and forwards them to the desktop app, so your device does not connect directly to Scryfall for those symbols.
Card images are loaded partly from our own Storage and partly directly from the image provider recorded in the card catalogue. Direct image sources include cards.scryfall.io, errors.scryfall.com, assets.tcgdex.net, limitlesstcg.nyc3.cdn.digitaloceanspaces.com, optcgapi.com, and cmsassets.rgpub.io. For such an image request, the relevant provider receives your IP address and technically necessary request data. Your email address, access token, and collection data are not transmitted. Depending on the provider's location and infrastructure, this request may also be processed outside the EU/EEA.
6. Local fonts, no trackers, and no advertising
The website, desktop app, and browser extension serve fonts locally and do not connect to Google Fonts for this purpose. We do not use analytics or advertising trackers, create advertising profiles, or use tracking cookies on the public website. Technically necessary session data is stored on the device only where authentication or password recovery requires it.
7. Retention and account deletion
Account, collection, and synchronised seller-template data is generally retained while your account exists. Operational checkout and subscription data is retained for the contract and afterwards where required for billing, complaints, or legal claims. Invoices and accounting records are generally retained for eight years from the legally relevant start of the retention period. Where we use the EU One Stop Shop scheme, the records required for that scheme are retained for ten years from the end of the calendar year of the transaction. Evidence of contracts, cancellations, withdrawals, and declarations is retained in accordance with statutory duties and limitation periods. We retain technical logs only for as long as required for operational security, abuse prevention, and error investigation; they are then deleted or anonymised. The registration record stored with your account is deleted when the account is deleted. Data from the former test-request and invitation system is deleted as soon as it is no longer required for handling or abuse prevention: pending requests after no more than 90 days, rejected requests no more than 30 days after the decision, and approved requests no more than 30 days after the related code expires. Separate support correspondence, Stripe/Link transaction data, and legally required documents may be retained for longer where statutory obligations or the establishment, exercise, or defence of legal claims require it.
You can delete your account in the desktop app under Settings → Account → Danger Zone → Delete account. Once confirmed successfully, TCG Actana removes the authentication account, associated collection, work-history, scan, and seller-template data, and files in your avatar and delivery-note-logo folders. The app then removes the local session and account-related caches; device-only preferences such as language and appearance remain. Invoices, accounting records, and evidence of contracts, cancellations, and withdrawals that must legally be retained are restricted and not deleted with the operational account. We cannot automatically remove CSV files or backups you saved outside the app. You may alternatively request deletion by email.
8. Your rights
Under the GDPR, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and the right to object to processing based on legitimate interests (Article 21). To exercise these rights, contact us at the address above. You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is the State Commissioner for Data Protection of Lower Saxony.
9. Required information and automated decisions
An email address is required to create an account. You additionally need a password and confirm your email address. A paid plan additionally requires the billing, payment, and, where applicable, tax information requested at checkout. Without the required information, we cannot provide synchronised or paid access. We do not use solely automated decision-making with legal or similarly significant effects, and we do not carry out profiling.
10. Changes
We update this policy when features or the legal position change. The version published here at the relevant time applies.