← Back to Home
Privacy Policy
Last updated: March 2026
1. Information We Collect
Account information: Email address, username, and password (hashed — we never store plain text passwords).
Activity data: Training history, candy balances, shard balances, faction choice, raid results, raffle entries, referral activity, leaderboard stats, and gallery card collection.
Card lookup data: When you use the Rarity Report or card search features, we log the card searched, timestamp, and an anonymized hash of your IP address for analytics purposes. This data is used to improve search quality and understand which cards are popular.
Card images: When you use the card scanner feature, the photo you take is sent to third-party AI services (Google Gemini) for identification. We do not permanently store your card photos on our servers.
Push notification tokens: If you opt in to push notifications, we store a browser push subscription token to deliver alerts (e.g., candy drip completion reminders).
Location data: GPS coordinates only when you use the QR check-in feature at partner stores. This is used solely to verify you are physically at the store. We do not track your location otherwise.
Technical data: IP address, browser type, and device information for security, rate limiting, and abuse prevention.
Activity data: Training history, candy balances, shard balances, faction choice, raid results, raffle entries, referral activity, leaderboard stats, and gallery card collection.
Card lookup data: When you use the Rarity Report or card search features, we log the card searched, timestamp, and an anonymized hash of your IP address for analytics purposes. This data is used to improve search quality and understand which cards are popular.
Card images: When you use the card scanner feature, the photo you take is sent to third-party AI services (Google Gemini) for identification. We do not permanently store your card photos on our servers.
Push notification tokens: If you opt in to push notifications, we store a browser push subscription token to deliver alerts (e.g., candy drip completion reminders).
Location data: GPS coordinates only when you use the QR check-in feature at partner stores. This is used solely to verify you are physically at the store. We do not track your location otherwise.
Technical data: IP address, browser type, and device information for security, rate limiting, and abuse prevention.
2. How We Use Your Information
- To provide and operate the GCEA platform
- To verify your identity and prevent fraud
- To send account-related emails (verification, password reset, raffle wins)
- To deliver push notification alerts you have opted into
- To enforce our Terms of Service
- To improve the Service based on usage patterns and card lookup analytics
- To deliver prizes to raffle winners
- To process card identification through third-party AI services
- To display card pricing sourced from third-party data providers
3. Information We Do NOT Collect
- We do not sell your personal data to third parties
- We do not use your data for targeted advertising
- We do not track your location outside of explicit QR check-in actions
- We do not store payment information (there are no paid features)
- We do not permanently store photos taken with the card scanner
4. Data Sharing & Third-Party Services
We do not share your personal information with third parties except:
- Email delivery: We use Resend to send transactional emails (verification, password reset)
- Card identification: Card photos are processed by Google Gemini AI for identification. Google's privacy policy applies to their processing.
- Card pricing: We source pricing data from PokePriceTracker, TCGPlayer (via Pokémon TCG API), and Cardmarket. No personal data is shared with these providers.
- Push notifications: Browser push tokens are processed through web push standards (no third-party service stores your data)
- Legal obligations: If required by law or legal process
- Prize fulfillment: Shipping address provided by raffle winners is used solely for delivery
5. Data Security
We take reasonable measures to protect your data:
- Passwords are hashed with bcrypt (12 rounds)
- All connections use HTTPS/TLS encryption
- JWT access tokens expire after 24 hours
- Rate limiting protects against brute-force attacks
- Admin actions are logged for audit purposes
- IP addresses are hashed for analytics (not stored in plain text)
- Database access is restricted with role-based permissions
6. Cookies & Local Storage
We use browser local storage to keep you logged in (JWT tokens) and to store UI preferences (e.g., onboarding tour completion, push notification preferences). We do not use third-party tracking cookies or analytics services.
7. Your Rights
You have the right to:
- Access your personal data through your profile page
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Opt out of push notifications at any time through your browser settings
- Opt out of non-essential emails
8. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect information from children under 13. If you believe a child has created an account, please contact us and we will promptly delete the account.
9. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days. Anonymized, aggregated data (such as card lookup counts) may be retained indefinitely for analytics purposes. Expired authentication tokens are periodically purged.
10. International Users
GCEA is operated from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the United States. By using the Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy at any time. Significant changes will be communicated via email or in-app notification. Continued use of the Service constitutes acceptance of the updated policy. It is your responsibility to review this policy periodically.
12. Contact
For privacy-related questions or requests, email us at support@gcea.app.