Privacy & your data

Your collection.
Your information.

A clear explanation of the information involved in Deckmates, what it is used for and how to ask for help.

Contact us about your data →

Who is responsible?

Deckmates is responsible for deciding how personal information is used to run its website and app. For privacy questions or requests, email hello@deckmates.uk.

This notice covers the Deckmates app, shop application process, website and launch mailing list.

What information is involved?

The information depends on the features you use. The current app code includes the following categories; some connected features are still being prepared for launch.

Accounts and profiles
Email address, authentication information, name, username, date of birth, selected region and your chosen avatar or uploaded profile picture. The current self-service account creation flow is for adults aged 18 and over.
Your collection
Cards you record, quantities, condition and finish, binders, bulk, collection preferences, imported collection details, valuation history and trading preferences.
Challenges and community
Challenge entries and progress, achievements, participation history, profile presentation choices and activity shared through the features you use. Trade records may include the other participant and the status of the trade.
Shops
Shop check-ins and event attendance where used. Shop applications include the applicant’s name, contact email and phone number, relationship to the business, business address, website, application messages, appointments and review records.
Membership and connected services
Membership status, entitlement and transaction references where purchases are enabled. If you connect Discord, the integration uses your Discord identity and membership/role information to manage that connection.
Support and technical information
Information you send us in enquiries or concerns, plus technical information processed to deliver and protect the service. The exact provider logs and their retention settings are being checked.

Information is supplied by you, generated through your use of the app, or received from connected services and other participants where the feature requires it. Required account information enables registration; without it you may not be able to create an account. Optional features require only the information relevant to taking part.

Why we use it.

The proposed lawful-basis mapping for launch is:

  • Providing the service: account access, collections, challenges, membership and requested shop services, where necessary to perform our contract with you or take steps you request before entering it.
  • Running and protecting Deckmates: proportionate security, support, moderation and service administration, based on legitimate interests where those interests are not overridden by your rights.
  • Optional marketing: consent for the launch emails you choose to receive. You can withdraw that consent.
  • Legal duties: records we must keep or disclose under an applicable legal obligation.

These bases need to be confirmed against the launch features and business arrangements. Any sensitive safeguarding information or additional eligibility information needs its own assessment before collection.

Who can see information?

Visibility depends on the feature and the choices available in the app. Other collectors may see profile details, shared activity and the information needed for a trade or community interaction. Authorised shop team members can access relevant shop activity and application or operational information according to their permissions.

Recognising regular shop visitors does not establish whether someone is a scalper. The launch notice must explain any participation-based indicators shown to shops, how they are calculated and how a collector can question inaccurate information before those indicators are introduced.

Service integrations found in the current code include Supabase for account and database services, Cloudflare for this website, RevenueCat and the app stores where subscriptions are enabled, Resend for configured operational emails and Discord if you connect it. Each receives information relevant to its role; inclusion here does not mean every integration is enabled for every account.

We may also need to share relevant information to meet a legal obligation or respond appropriately to a safety concern. The final processor list, mailing-list provider, hosting countries and any international-transfer safeguards remain to be verified. We are not claiming that all processing stays in the UK.

How long should information stay?

We are adopting a category-based approach: keep what is needed for the purpose, then delete it or anonymise it so it no longer identifies someone. These are the proposed operating periods. They must be matched to database jobs, storage, backups and third-party settings before they can be described as enforced limits.

Account, profile and collection

While your account is open. Target: remove or anonymise eligible live records within 30 days of a verified deletion request.

Provide your account, collection and challenge history. Any legally necessary exceptions must be identified separately.

Inactive accounts

Review after 24 months without a sign-in; give 90 days’ notice before any proposed closure.

Avoid keeping abandoned accounts indefinitely without silently removing a collector’s long-term collection.

Routine support enquiries

12 months after the enquiry is resolved.

Follow up issues and identify recurring service problems.

Shop check-ins and routine participation records

12 months from the activity, then remove or genuinely anonymise unless needed for an active challenge or dispute.

Support recent participation history without creating a permanent visit trail.

Unsuccessful or withdrawn shop applications

6 months after closure. Approved application records: while the shop relationship continues, with a review within 12 months of it ending.

Handle queries about decisions and administer the shop relationship.

Routine technical logs

30 days; security investigation records reviewed after 90 days.

Diagnose faults and investigate misuse. Provider-specific limits still need checking.

Mailing list

Until you unsubscribe or the list is closed. Review inactive subscriptions after 24 months; keep only the minimum suppression record needed to respect an opt-out.

Send requested updates and avoid adding unsubscribed people back to marketing.

Accounting records

Where UK company accounting requirements apply, 6 years from the end of the relevant financial year, or longer where legally required.

Meet accounting and tax obligations; this does not justify keeping an entire app profile.

Backups

Target: a maximum 35-day rolling window, subject to confirming provider configuration.

Recover from failures. A restore must reapply recorded deletions before normal use.

Safety concerns, disputes and legal holds

Case-specific retention, with a recorded reason and review date; routine closed moderation matters targeted for review after 12 months.

Protect people and resolve complaints. Serious safeguarding cases need a separate approved schedule; no automatic purge is proposed.

For context, the ICO explains storage limitation, and GOV.UK explains company accounting record requirements. The non-statutory periods above are Deckmates’ proposed choices, not universal legal deadlines.

Your choices and rights.

The app includes profile and preference settings, optional Discord disconnection and an account-deletion action. Deletion can require resolution of responsibilities such as being the remaining responsible adult or shop owner. Contact us if you cannot complete it or need a broader data request.

Depending on the circumstances, UK data-protection law gives you rights to access your information, correct it, request erasure, restrict its use and receive certain information in a portable format. These rights can have exceptions; we’ll explain any that apply to a request.

Where we rely on consent, you can withdraw it without affecting the lawfulness of earlier processing. We normally respond to a rights request within one month, subject to permitted extensions, and may need information to verify that the request concerns your data.

On your device and this website.

The app stores authentication sessions and local preferences or cached collection information so it can work across sessions. Camera access is requested when you use card scanning; you can manage permissions in your device settings.

This development website does not include advertising or analytics scripts in its current code. Hosting providers can still process connection information to serve and protect the site. The mailing-list destination and any connected third-party services have their own relevant storage and privacy information.

Younger collectors.

The current self-service sign-up is limited to adults. Family and protected-space features need age-appropriate privacy information and confirmed guardian arrangements before they are made available. We will not treat a general adult notice as sufficient explanation for children.

Ask us about your data.

Email hello@deckmates.uk with your question or request. Please don’t send a password or identity document in your first message.

You can also complain to the UK Information Commissioner’s Office through the ICO complaints service.

We will update this notice as the remaining launch details are confirmed and identify material changes before new uses of information begin.