Privacy Policy
Last updated: 12 August 2026
1. What this policy covers
This policy explains how we process personal data when you visit tuckbox.cards and when you use the Tuckbox: TCG Card Scanner mobile app. It applies alongside the privacy information shown on the App Store and Google Play listings.
2. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:
Bytes & Pixels GmbH
Gröbenzeller Str. 40, 80997 München, Deutschland
Represented by: Benjamin Robert Bachhuber
E-mail: kontakt@bytes-and-pixels.de
Phone: 089-15002979
For questions about data protection, including requests to exercise your rights, write to kontakt@bytes-and-pixels.de.
3. Hosting and server log files
This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you access the site, the hosting provider automatically processes technical information (IP address, browser type, operating system, referrer URL, time of access) in server log files to deliver the website and ensure its stability and security (Art. 6 (1) (f) GDPR). We have concluded a data processing agreement with Vercel. Log data is deleted or anonymised after a short period.
4. Analytics and marketing on this website
This website currently uses no analytics or marketing tracking tools and sets no cookies beyond those technically required to deliver the pages.
5. Data we process in the Tuckbox app
Tuckbox scans trading cards with your phone camera, identifies them and keeps your collection organised together with an indicative estimate of what it is worth. To do that, the App processes the following data, each for the stated purpose and on the stated legal basis:
- Account data (e-mail address and password, or your Apple or Google sign-in) — to create your account, sign you in and sync your collection between your devices. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
- Collection data (the cards you add, quantities, conditions, wishlists and notes) — to store and display your collection and its estimated value. Legal basis: Art. 6 (1) (b) GDPR.
- Card photos taken with the camera — to identify the card you scanned and, where you save it, to show the picture in your collection. Legal basis: Art. 6 (1) (b) GDPR.
- Subscription status (purchase receipt and store identifier) — to unlock paid features and to prevent misuse of free trials. Legal basis: Art. 6 (1) (b) GDPR.
- Device and diagnostic data (device model, operating system and app version, crash reports) — to find and fix errors and keep the app stable. Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in a working app).
- Usage data (which screens and features you use, pseudonymous) — to understand how the app is used and improve it. Legal basis: Art. 6 (1) (a) GDPR (consent — you can decline without losing any feature).
- Support correspondence (your message and contact details) — to answer your request. Legal basis: Art. 6 (1) (b) and (f) GDPR.
Where processing is based on your consent, you may withdraw it at any time with effect for the future; withdrawal does not affect the lawfulness of processing carried out beforehand. Where data is needed to provide a feature, not providing it means that feature cannot work.
6. Camera and photos
The camera is used only while you are scanning a card, and the app asks for that permission the first time you use it. You can withdraw the permission at any time in your device settings — scanning then stops working, the rest of the app does not.
A photo is sent to our card data provider to identify the card. If you do not save the card to your collection, the photo is deleted after processing. We do not access the rest of your photo library unless you pick a picture yourself.
7. Advertising
The app shows no third-party advertising, uses no advertising identifier and does not sell personal data.
8. Service providers
We use the following providers to operate the App. They process data on our behalf as processors under Art. 28 GDPR, on the basis of a data processing agreement, and only on our instructions:
- Apple App Store and Google Play (Apple Distribution International Ltd., Ireland and Google Ireland Ltd., Ireland) — distribution of the app and processing of in-app purchases.
- RevenueCat (RevenueCat, Inc., USA) — management and validation of subscriptions.
- Google Firebase (Google Ireland Ltd., Ireland) — account sign-in and storage of your collection.
- Card data provider (TODO(APP-418): name the card recognition and market-price vendor and its registered seat) — identifying scanned cards and supplying the market data behind the price estimates.
- Sentry (Functional Software, Inc., USA) — crash reports and error diagnostics.
- PostHog (PostHog, Inc., EU Cloud) — pseudonymous product analytics, only if you consent.
Apple and Google additionally act as independent controllers for the store and payment data they collect when you download the App or make a purchase; their own privacy policies apply to that processing.
9. Transfers outside the EU
Some of the providers named above are based outside the European Economic Area, or process data there. In those cases the transfer is safeguarded by the European Commission’s standard contractual clauses, by the provider’s certification under the EU-US Data Privacy Framework, or by your explicit consent (Art. 44 ff. GDPR). Despite these safeguards, we cannot rule out that authorities in those countries access data.
10. How long we keep data
Your collection stays in the app until you delete it or delete your account; we then remove it from our live systems within 30 days and from encrypted backups within a further 30 days. A photo of a card you do not save to your collection is deleted once the scan has been processed, at the latest after 24 hours. Crash reports are kept for 90 days and pseudonymous usage data for 12 months.
Website server log data is kept only briefly for security purposes. Beyond that we keep personal data only as long as it is needed for the purpose it was collected for, or as long as statutory retention periods require — invoices and accounting records, for instance, must be kept for up to ten years under German tax and commercial law.
11. Deleting your data
You can delete your data at any time: open Settings → Account → Delete account in the app, which permanently removes your collection together with your account. You can also ask us to do it by writing to ben@bytes-and-pixels.de — we confirm deletion within 30 days.
Deletion removes your data from our live systems. Encrypted backups are overwritten on their normal rotation, and data we must keep for legal reasons — invoices, for instance — is blocked from further use instead of deleted until the retention period ends.
12. Children
The App is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it. Where we rely on consent, users under 16 in the EU need the consent of a parent or guardian (Art. 8 GDPR).
13. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future. To exercise your rights, contact kontakt@bytes-and-pixels.de.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany. You may also contact the authority where you live.
14. Changes to this policy
We may update this privacy policy to reflect legal or technical changes. The current version is always available at https://tuckbox.cards/privacy.