Last updated 29 August 2026
Privacy & Data
No account is required. Browser binders stay local unless you deliberately create a shared link or enable account cloud sync. This notice explains the information used to operate, protect and improve the service.
Who operates the site
Pokémon TCG Virtual Collector is independently operated in the United Kingdom by mattG. For questions, privacy requests or concerns, email mattg@pokemontcgvc.com.
For the limited personal information described here, the independent site operator is the data controller. Pokémon TCG Virtual Collector is not affiliated with The Pokémon Company, Nintendo, Game Freak, Creatures Inc. or Vault X®.
What stays in your browser
Binder layouts, binder names, card positions, ownership markers, preferences, cached price information and compressed custom or extended-art images are stored locally using IndexedDB or local storage. They are not uploaded simply because you create or edit a binder.
Browser data can be cleared by you, your browser, a device-management policy or privacy software. Use the JSON export as a restorable backup; PDF and spreadsheet exports are saved or attached only where you choose.
Read Cookies & browser storage for a detailed description of the storage used and how to control it.
Optional accounts and cloud binder sync
You may continue without an account. If you create one, Supabase processes the email address, a generated account identifier, email-verification status, sign-in identities, security and authentication records, and any display name or optional profile information you provide. Passwords, password-reset links, Google authentication and authenticator-app MFA are handled through Supabase Auth; the site operator does not receive your plain-text password or the secret stored in your authenticator application.
Optional profile information can include a display name or alias, favourite Pokémon, short biography, profile picture and banner. Accepted profile images are decoded, resized and re-encoded as WebP before being stored in a private Supabase Storage bucket. They are available only through short-lived authenticated links.
Cloud sync is not enabled merely because you sign in. The site first asks whether to copy binders already stored in the browser into the account. If you agree, cloud records contain the binder name and settings, card identities and artwork links, card order and pocket positions, owned or needed status, compressed custom artwork within the binder, update timestamps and revision information used to prevent one device silently overwriting another. Browser copies are retained.
When cloud sync is enabled, later binder changes save in the browser first and are then sent to Supabase. The application checks for updates when it opens, returns to the foreground and while it remains in use. If two devices edit the same binder before synchronising, the site asks you which copy to keep.
When you create a shared link while signed in, the account also stores the link identifier, binder name, whether a preview exists, and its creation and expiry dates. This lets My account → Shared links show, copy, open and delete links you created; it does not make the unlisted link private. Expired history rows are pruned when the account next accesses this list.
You can pause cloud sync without deleting the existing cloud copies, export the account data from My account, or delete the account and its remote profile, binder records, profile images and account-owned shared links. Account deletion deliberately preserves binders stored in the current browser. Provider backups and security logs may persist for limited periods under the provider's documented retention and legal obligations.
Administrative access and safety actions
The operator has one restricted administration account for responding to verified privacy requests, account-support issues, security incidents, abuse reports, legal obligations and breaches of the Terms of use. The administration tools can search registered accounts and, where reasonably necessary for one of those purposes, view limited account details, remotely stored profile information and images, cloud-synchronised binder content, and account-owned shared links. A reported anonymous shared link can also be removed when its full URL or identifier is supplied.
The tools can correct a display name, reset profile images, suspend or restore an account, remove a cloud binder or shared link, or permanently delete an account and its remote data. Administrative access is not used for routine browsing. Binders kept only in a visitor's browser are never available to the operator.
Access is restricted on the server to a single immutable account identifier and requires verified authenticator-app MFA. Directory views and searches are logged with a standard directory-access reason. Before private user data is opened or changed, the operator either enters a specific case or action reason or explicitly selects routine administration, which records a standard owner-authorised reason. A protected audit record stores the administrator and affected account identifiers, action, reason, outcome and timestamps; it does not contain passwords, MFA secrets or binder contents. Audit records are retained for 12 months and then deleted automatically, unless a longer period is required to establish, exercise or defend legal claims or comply with law.
This processing is limited to providing requested support, complying with legal obligations, and the operator's legitimate interests in protecting users, third parties and the security and integrity of the free service. Decisions and actions should be necessary and proportionate to the report or request.
Shared binders
When you deliberately select Share binder, the site creates a sanitised, view-only snapshot in a private Cloudflare R2 bucket. The snapshot contains the binder name and layout, card identifiers and artwork links, card order, pocket positions, owned or needed status, the selected binder background and compressed copies of any custom artwork placed in the binder.
New shared links also store one compressed social-preview image generated from a populated spread in that snapshot. It lets compatible messaging services show the shared binder when its link is pasted. The preview contains only the binder name and rendered cards already present in the shared snapshot, and expires with the same link.
Each link is unlisted rather than private: anyone who receives it can view and pass it on. Opening a shared link never imports that snapshot or replaces binders saved in the visitor's browser.
Custom artwork files are checked, decoded and re-encoded as static images in the browser to reduce file-based risks. This technical processing does not assess the subject of an image. Unlawful or abusive content is prohibited under the Terms of use.
Shared links expire 180 days after creation. The Worker blocks expired links and the stored snapshot is removed through an R2 lifecycle rule. A signed-in creator can delete their own link immediately from My account → Shared links. For an anonymous link or another removal issue, email the full shared URL to mattg@pokemontcgvc.com.
Analytics and service statistics
The site uses Cloudflare Web Analytics to understand aggregate visits and page performance so the service can be maintained and improved. Cloudflare states that this service does not use cookies or local storage, collect personal data or fingerprint visitors. Read the Cloudflare Web Analytics documentation.
The planner can also report three totals: how many binders are saved in this browser, their combined capacity and how many pockets are occupied. It records aggregate counts when an export or set auto-fill succeeds. These figures help identify which features are useful and are displayed in aggregate on the Analytics page.
A random identifier is created in this browser so one browser is not counted repeatedly. The Worker immediately converts it to a one-way hash. The server does not receive or store binder names, card identities, card positions, email addresses, browser strings or raw IP addresses with these binder statistics. If Cloudflare's aggregate visitor totals are temporarily unavailable, recent check-ins from participating browsers supply the clearly labelled 24-hour and seven-day figures on the public Analytics page.
A browser is treated as active for 30 days after its latest update. Its hashed record is then deleted. Daily action totals contain no browser identifier. Share-link totals use only the link identifier, creation and expiry times, plus an aggregate view count. The binder snapshot itself is never used for these totals.
Checking this browser's setting…
Disabling this removes this browser's current anonymous binder-statistics record and stops future binder totals, action counters and participating-browser visitor figures from this browser. It does not delete or affect your binders, prevent sharing, or alter Cloudflare's separate cookie-free aggregate traffic measurement.
Security and rate limiting
Cloudflare processes ordinary request information, including connection addresses, to deliver and protect the website. Cloudflare may retain security and operational logs under its own retention arrangements.
Account records use Row Level Security so an authenticated account can access only its own profile, cloud binders, shared-link history and private profile images. Suspended accounts are blocked by the same database policy. The sole administrative exception is available only through the separately protected Worker process described above. If authenticator-app MFA is enabled, a completed second factor is required before account records or settings can be accessed. The Worker separately verifies the account and MFA assurance before it associates or deletes a share. Account creation, email delivery and sign-in may also be rate-limited or challenged to prevent abuse.
Each internet connection can create up to ten shared links in a rolling 24-hour period. The application uses a one-way hash derived from the connection address to select a short-lived rate-limit record; the raw address is not stored in that record. Deleting a link does not remove its creation from this rolling limit.
External services
Supabase provides optional account authentication, database and private profile-image storage. If you choose Google sign-in, Google processes that authentication under its own privacy terms. Account verification and password-reset messages are delivered through Supabase and the configured transactional-email provider.
English and Japanese card searches, set information and artwork primarily come from the community TCGdex API. A compact English-only fallback catalogue generated from the open Pokémon TCG API dataset is served from this site's own static files when you search English cards. When a primary scan is missing, the browser may request a matching image from Pokémon TCG API or ScryDex image delivery. No binder contents, account details or private API credential are sent with that image request.
Price information can use public exchange-rate data, and links to Cardmarket and eBay open those services only when selected. Their own privacy notices apply after you visit them.
The donation panel embeds Ko-fi only after you open it. Interacting with that panel connects to Ko-fi, which may use its own storage technologies. Any payment is handled under Ko-fi's privacy policy and the policy of its payment provider; this site does not receive your complete payment-card details.
Messages, bug reports and feedback
Bug reports, feedback forms and contact links open your own email application. The website does not transmit the message until you review and send it. Correspondence is then received in Microsoft 365 and may contain your email address, display name or alias, message, automatically supplied browser context and anything else you choose to include.
Messages are retained for as long as reasonably needed to respond, investigate a report, maintain necessary project records, prevent abuse or establish legal claims. Please avoid including unnecessary personal or sensitive information in binder names, shared binders or reports.
Why information is used
Information is used to provide features you request, operate and secure the service, answer messages, prevent abuse, understand aggregate use and improve the planner. Depending on the activity, the relevant UK GDPR basis is performance of the service requested by you, the operator's legitimate interests in maintaining and improving a secure free service, compliance with legal obligations, or your consent where specifically requested.
Browser storage used for requested binder functions is necessary to provide those functions. Preference and statistical storage is used only for the purposes explained in Cookies & browser storage, with free controls to object where applicable.
Processors and transfers
Cloudflare provides hosting, shared-link storage, security and analytics services. Supabase provides optional account authentication, database and private profile-image storage, and its configured email service delivers account messages. Google acts as an independent authentication provider if you choose Google sign-in. Microsoft provides contact-email hosting. Ko-fi and its payment partners independently handle donations, while TCGdex supplies the primary card data and imagery and the Pokémon TCG API provides fallback records and scans.
Some providers may process information outside the United Kingdom. Where UK data-protection law applies, transfers are handled through the safeguards offered by the relevant provider, such as adequacy regulations or approved contractual protections.
Your rights and choices
- Delete local binder data through the site's binder controls or your browser's site-data settings.
- Use My account to edit optional profile information, manage signed-in shared links, export account data, pause cloud synchronisation or permanently delete the account and its remote data.
- Disable anonymous binder statistics above without affecting any binder feature.
- Do not create a shared link if you do not want a snapshot, including any uploaded custom artwork it contains, stored in R2.
- Do not open the donation panel if you do not want the Ko-fi embed to load.
- Ask for access, correction, deletion, restriction, portability or object to relevant processing by emailing mattg@pokemontcgvc.com. Some rights depend on the circumstances and may not apply to information that cannot identify you.
If you remain concerned, you can complain to the UK Information Commissioner's Office through ico.org.uk/make-a-complaint.
Changes to this notice
This notice will be reviewed when the site's features or service providers change. The latest revision date appears at the top of the page, and material privacy changes will be reflected in the release history where appropriate.