Skip to content
pokemontcgapi.com

Legal

Privacy notice

A read-only data API has an unusually small privacy surface: there is nothing to sign in to on the website, nothing to upload, and no collection to keep. This page lists what is left.

Last updated

Who is responsible

The controller for the processing described here is [OWNER: legal entity name and registered address of the controller] reachable at [email protected]. [OWNER: whether a Data Protection Officer is required and, if so, their contact]

What an API request records

One line per request, with these fields and nothing else.

  • IP addressAbuse handling and rate limiting. It is the only field here that identifies a person in most jurisdictions, which is why it has the shortest life.
  • User agentTelling a library apart from a browser, and finding which client version broke.
  • Request idThe value returned to you in x-request-id. It is what makes a support mail answerable.
  • Method, path and query stringWhich endpoint you called and with which filters. The API is read-only, so this is the whole of the request.
  • Status code and response timeError rates and latency. Aggregated, this is how we know something is broken before you mail us.
  • TimestampOrdering. Without it the rest is unusable.
  • API key idThe identifier of the key presented, never the key itself, and only when a key is presented.

The API serves data; it does not receive any. There are no request bodies to log, no uploads, and no free text field anywhere in it. The legal basis for keeping these lines is our legitimate interest in running a service that stays up and is not abused.

How long it is kept

Raw request lines are kept for [OWNER: retention period for raw request logs — proposed: 30 days] and then deleted. Aggregated counters — requests per key per day, error rates per endpoint — outlive them because they carry no IP address and no request id, and they are what a plan is billed against.

Billing records are kept for as long as tax law requires, which is a longer period than anything else on this page. [OWNER: statutory retention period for invoices in the chosen jurisdiction]

What we never collect

No collection data of any kind. The API has no endpoint that accepts a card list, a portfolio, a wishlist, a deck or a valuation. We cannot know which cards you own, look up or care about beyond the fact that a request for a card id passed through a log line, and that line is deleted with the rest.

No advertising identifiers, no fingerprinting, no data sold or shared with anyone for their own purposes, and no profiling or automated decision-making.

Cookies, and the one thing this site stores

This website sets no cookies and runs no analytics script. Nothing on it needs a consent banner, which is why it does not have one.

It writes exactly one value into your browser: a localStorage key called ptcgapi-theme, holding light, dark or system, so the theme you pick survives a reload. It never leaves your browser and we never receive it. Clear your site data and it is gone.

Payments

Paid plans are processed by Stripe, which acts as an independent controller for the payment itself and as our processor for the rest. Card numbers are entered on their infrastructure and never reach ours; we keep a customer identifier, the plan, and the invoice history against your account.

[OWNER: confirm the Stripe entity that contracts with us and that a DPA plus SCCs are signed and linkable]

Where the data physically is

The API, the database and the logs run on dedicated hardware in Germany, inside the EU. Nothing is replicated outside it. The exception is the payment processor above, which operates internationally.

[OWNER: hosting provider name and data-centre location to publish, plus its DPA reference] [OWNER: the sub-processor list to publish and keep current]

Your rights, and how to use them

If you are in the EU or the UK you have the right to ask what we hold about you, to have it corrected, to have it deleted, to receive it in a portable form, and to object to processing based on legitimate interest. There is one route to all of them.

Mail [email protected] from the address on the account, or quote an API key id or an x-request-id if there is no account. We answer within thirty days, usually the same week. Deletion removes the account, its keys and its aggregated counters; invoices survive only because tax law requires it, and the log lines are already gone or go with it.

You may also complain to your national supervisory authority. [OWNER: name the lead supervisory authority once the establishment is decided]

Changes to this notice

The date at the top is the date this text last changed, and a material change is also recorded, dated, on the changelog — so a notice quietly rewritten is not a thing that can happen here without a line about it.

Related

The terms that govern use of the service are in the terms of service, and where the data itself comes from is set out on the attribution page.