TCG Portfolio

Privacy Policy

Effective 2026-08-29 · Version 1.0

Who we are. TCG Portfolio ("the App") is operated by Oisin McNally, a sole trader established in Ireland ("we", "us", "our"). We are the data controller for the personal data described in this policy.

Contact / postal address: Oisin McNally, Earlspark, Loughrea, H62 WK79, Co. Galway, Ireland. Email: tcgportfoliodev@gmail.com

Scope. This policy explains what personal data we process when you use the App on iOS or Android, why, on what legal basis, how long we keep it, who we share it with, and your rights. The App is available worldwide; most of our users are in the US, UK, Canada and the EU/EEA.

A quick, honest summary. You need an account to track your portfolio, so we process your email address and login data. The App is free and supported by advertising, so advertising partners may process device and usage data to show you ads. We do not sell your personal data for money. However, showing personalised ads can count as a "sale", "sharing" of personal information, or "targeted advertising" under some US state privacy laws — you can opt out (see section 7). We do not run any social, sharing, messaging or user-content features.

1. What we collect, why, our legal basis, retention and recipients

Data category Purpose GDPR legal basis (Art. 6) Retention Main recipients
Account data (username, email, hashed password, email-verification status) Create and secure your account; sign-in; sending email-verification and password-reset emails Art. 6(1)(b) performance of contract Until you delete your account; deleted data is purged from backups within 30 days AWS (hosting, including Amazon SES for transactional email), Neon (database)
Portfolio data (cards you add, quantities, purchase prices/notes you enter) Provide the core portfolio-tracking service Art. 6(1)(b) contract Until you delete the item or your account (30-day backup purge as above) AWS, Neon
Server logs (IP address, request metadata, timestamps, device/OS identifiers in requests) Operate, secure and debug our servers; prevent abuse and fraud Art. 6(1)(f) legitimate interest in service security and integrity Up to 12 months AWS
Card price lookups Show current estimated values from third-party price sources Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest in accurate estimates Transient; cached only within each source's permitted limits eBay, TCGplayer (and other price APIs)
Device & usage analytics (device model/type, OS and version, app version and build, screen dimensions, timezone, screens/actions in the App, your email address and account identifier where you are signed in, and approximate city-level location — GeoIP coordinates estimated from your IP address) Understand and improve the App Art. 6(1)(f) legitimate interest in understanding and improving the App. Analytics is enabled by default; you can opt out at any time in the App's settings Event-level data up to 12 months, then deleted or aggregated PostHog (hosted in the United States)
Session recordings (replays of your interactions with the App's screens, which can include the contents of your portfolio, card lists and estimated values as they appear on screen) Understand how the App is used; find usability problems and bugs Art. 6(1)(f) legitimate interest in improving the App. Recording is enabled by default; opting out of analytics in the App's settings also stops session recording Up to 12 months PostHog (hosted in the United States)
Crash & error diagnostics (crash logs, stack traces, device state) Detect and fix crashes and bugs Art. 6(1)(f) legitimate interest in a working, secure App Up to 12 months Sentry
Push notification token Deliver push notifications you enable Art. 6(1)(a) consent (device permission) Until you disable notifications or delete your account Expo, Apple (APNs), Google (FCM)
Advertising data (advertising identifier where permitted, device/ad-interaction data) Show ads that fund the free App; personalised ads only with consent Art. 6(1)(a) consent (personalised ads / device storage); Art. 6(1)(f) for non-personalised ads Controlled by the ad networks per their policies Google AdMob, AppLovin, Google Play services

We do not use AI/LLM features, card image scanning, OCR, or photo uploads, and we do not knowingly process special-category data.

2. Advertising, tracking and your choices

The App is free and funded by ads served by Google AdMob and AppLovin (MAX). For ad personalisation, these companies generally act as independent controllers of the data they collect through their SDKs, not merely as our processors.

Learn more / manage choices: AdMob & Google (https://policies.google.com/privacy and https://policies.google.com/technologies/ads); AppLovin (https://www.applovin.com/privacy/).

3. Third parties, sub-processors and business transfers

The following organisations process data for or with us. Better Auth is not a third party — it is open-source authentication software we self-host on our own AWS infrastructure, with records stored in our Neon database.

Business transfers. If the App or our business is transferred to a company we form or control (for example, a limited company incorporated to run TCG Portfolio), or to a successor in a merger, acquisition or sale of assets, your personal data may be transferred to that entity. It will remain subject to this policy (or a successor policy offering at least equivalent protection), and we will notify you of any such transfer.

We may also disclose data where required by law (for example, a court order), or where necessary to protect our rights, your safety or the safety of others, or to investigate fraud.

4. International transfers

Some providers are established in the United States and may process data outside the EEA/UK. In particular, our analytics provider (PostHog) is hosted in the United States, so analytics data — including your email address and account identifier where you are signed in — is processed there. Where data is transferred to the US we rely on the EU-US Data Privacy Framework (and the UK Extension / Swiss-US framework for UK and Swiss users) where the provider is certified, and on the European Commission's Standard Contractual Clauses as a safeguard where it is not. You can ask us for current details of the safeguards used for any provider.

5. Data retention

We keep account and portfolio data for as long as your account exists. When you delete your account (from within the App, via our account deletion page, or by emailing us at tcgportfoliodev@gmail.com) we delete your account and portfolio data from our live systems without undue delay and purge them from backups within 30 days, except where we must keep limited records to comply with law or to resolve disputes or security incidents, which we delete once no longer needed.

Residual data collected before deletion — server logs, crash diagnostics, session recordings and event-level analytics — is not individually erased when your account is deleted; it expires automatically under its retention period, which in each case is up to 12 months. This means some of this data may persist for up to 12 months after account deletion. If you would like it deleted sooner, email tcgportfoliodev@gmail.com and we will action your request, subject to any legal obligation to retain it.

6. Your GDPR/UK rights

You have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests (for analytics, the quickest way is the opt-out toggle in the App's settings), and to withdraw consent at any time (without affecting prior processing). To exercise these rights, email tcgportfoliodev@gmail.com. You also have the right to lodge a complaint with the Irish Data Protection Commission — 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland; info@dataprotection.ie; +353 1 765 0100; www.dataprotection.ie — or with your local supervisory authority. UK users may complain to the UK ICO (ico.org.uk).

7. US state privacy rights

Depending on your state (e.g., California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island), you may have the right to access, delete, correct and port your data, and to opt out of the "sale" or "sharing" of personal information and of targeted advertising. Serving personalised ads may be considered a "sale"/"share" under some of these laws. To opt out, use the in-app "Do Not Sell or Share My Personal Information / Opt out of targeted advertising" control, decline ad-personalisation consent, or email tcgportfoliodev@gmail.com. We honour the Global Privacy Control (GPC) signal where required. We do not discriminate against you for exercising these rights.

8. Children

The App is intended for users aged 13 and over (and 16 and over in the EEA, where consent for ad-related processing requires that age). We do not knowingly collect personal data from children below these ages. If you believe a child has provided us data, contact us and we will delete it. The App is not directed to children and is not part of any "designed for families" programme.

9. Security

We use reasonable technical and organisational measures, including encrypted transport (HTTPS/TLS), hashed passwords, access controls, and reputable infrastructure providers. No system is perfectly secure, and we cannot guarantee absolute security.

10. Breach notification

If a personal-data breach is likely to result in a risk to your rights, we will notify the Irish DPC within 72 hours where required, and affected users where the risk is high.

11. Changes

We may update this policy. We will change the effective date and version above and, for material changes, provide notice in the App. Continued use after changes take effect means you accept the updated policy.

← Back to TCG Portfolio