Skip to content

Free shipping on orders over €150

CHROMATCG

Privacy statement

What we keep about you, why, for how long and who else sees it. And what you can ask us to do with it — or to stop doing.

01Who is responsible

Chroma TCG decides what happens to the personal data on this website, and so is the controller within the meaning of the General Data Protection Regulation (GDPR, in Dutch the AVG). This statement applies to chromatcg.nl, to the emails we send and to the chat on the site.

Name
Chroma TCG
Email
info@chromatcg.nl
Website
chromatcg.nl

A question about your data? Mail info@chromatcg.nl. A person reads it, usually the same day.

02In short

  • We keep only what a reservation, a sale to us, an account or a question needs.
  • Everything is stored in the European Union.
  • We never sell your data and never share it for advertising.
  • No analytics, advertising or tracking cookies — so no cookie banner either.
  • You can see, correct or delete your data. One email is enough.

03What we keep, why and for how long

Per thing you do on the site: which data, what we use it for, the legal ground in the GDPR (article 6(1)) and how long we keep it.

Reserving and buying

Data
Email address, phone number, delivery address from your account, what you reserved and the amounts, your note, how you want to be contacted (WhatsApp, chat or email), the order number and support code.
Purpose
Holding the cards for you, contacting you to complete the sale, arranging payment and shipping, and answering questions about your order.
Ground
Performance of the contract (b). Keeping the administration: legal obligation (c).
Retention
Phone number, note and address are erased one year after the reservation is settled. The order itself — number, lines, amounts, status and email address — is kept for seven years, because Dutch tax law requires it.

Selling to Chroma

Data
Name, email address, country, the games and kinds of cards you offer, the size of the lot, your description of it and how you want to be paid. If we buy, also the account number we pay into.
Purpose
Making you an offer, talking about your cards, and completing and paying for the purchase.
Ground
Steps at your request before a contract, and performing it (b). The purchase administration: legal obligation (c).
Retention
The description of your collection is replaced one year after the request is closed. If we bought from you, the details of that purchase are kept for seven years for the administration. If we did not, the request itself (reference, name, email, status) is kept for at most seven years so we can find it back, and deleted sooner if you ask.

Your account

Data
Name, email address, password (stored as a hash we cannot read back), phone number, delivery address, language, your saved cards and, if you add one, a profile photo, which is stored privately and never shown publicly.
Purpose
Signing in, not having to type your details every time, showing your reservations, sell requests and saved cards, and mailing you when a card you saved is back in stock. Every such mail has a link to stop them.
Ground
Performance of the contract (b): the account you asked for.
Retention
As long as the account exists. Ask us to delete it and the account, profile, photo, saved cards, stock alerts and conversations go; reservations and sell requests are detached from your name, except what the administration must keep.

Chat about an order

Data
Your name, email address, order number and the messages we exchange.
Purpose
Answering your question about a reservation or order.
Ground
Performance of the contract (b).
Retention
The conversation is deleted one year after it is closed.

Stock alerts

Data
Your email address, your language and, if you are waiting for one card, which card.
Purpose
Mailing you when something new comes in, or when that card is back. At most one mail a week for the general list.
Ground
Consent (a). Withdraw it any time with the unsubscribe link at the bottom of every mail.
Retention
Until you unsubscribe.

Email, Instagram or WhatsApp

Data
Your name, your contact details and what you write to us.
Purpose
Answering your question.
Ground
Our legitimate interest in answering the people who write to us (f), or performance of the contract (b) if it is about an order.
Retention
As long as needed to deal with your question, and at most one year after that.

Keeping the site safe

Data
Technical data such as your IP address, browser and the time of a request, and the outcome of the check that you are a person.
Purpose
Keeping robots off the forms, limiting how many requests one address can make, and investigating abuse and outages.
Ground
Our legitimate interest (f) in a safe shop where one-of-one cards cannot be taken by a script.
Retention
Briefly — only as long as needed to investigate abuse or an outage.

04Who else sees your data

We run the shop with a small number of services. Companies that process data for us do so only on our instructions and under a data processing agreement. We never sell data and never share it for advertising.

  • Supabase — the database, sign-in and file storage. Servers in Frankfurt, Germany.
  • Hetzner — the server the website runs on, in Germany.
  • Resend — sends our emails: confirmations, offers and stock alerts.
  • Cloudflare — the check on forms that you are a person (Turnstile). Sees technical data such as your IP address.
  • Anthropic — reads photos of cards that the shop itself takes for the catalogue. No customer data goes there.
  • The carrier that delivers your parcel — your name and address, to deliver it.
  • WhatsApp (Meta) — only if you choose to talk to us on WhatsApp.
  • Our bank — for payments and payouts.
  • Authorities such as the Dutch Tax Administration — only when the law requires it.

05Outside the European Union

Our database and server are in Germany. Resend, Cloudflare and Anthropic are American companies, so data can reach the United States through them. That only happens with the safeguards the GDPR requires: the EU–US Data Privacy Framework where the company is certified under it, or the standard contractual clauses of the European Commission.

06Cookies and local storage

We only use cookies and browser storage that the site needs to work the way you expect:

  • chroma.locale — remembers whether you read the site in Dutch or English. One year.
  • Supabase session cookies (sb-…-auth-token) — keep you signed in. Gone when you sign out.
  • chroma.preview — only for testers while the shop is closed. Thirty days.
  • Local storage in your browser, not with us: your bag (chroma.cart.v1), your saved cards without an account (chroma.wishlist.v1) and an open chat (chroma.support.v1).

We use no analytics, advertising or tracking cookies and no social media pixels, and Cloudflare's check places no tracking cookies. Functional cookies need no consent, which is why this site shows no cookie banner. Clearing them in your browser is always fine — you are then signed out and your bag is empty.

07Security

  • Every connection runs over HTTPS.
  • The database decides who sees what: a customer only ever sees their own data, staff only what their role needs.
  • Passwords are stored as a hash; nobody at Chroma can read them.
  • Staff accounts sign in with two-step verification.
  • Forms are protected against robots and against being sent too often.

Should something still go wrong with your data, we report it to the Dutch Data Protection Authority within 72 hours where the law requires it, and tell you directly if it puts you at risk.

08Your rights

Under the GDPR you can ask us to:

  • show you which data we hold about you (access);
  • correct data that is wrong (rectification) — name, phone and address you can also change yourself under your account;
  • delete your data (erasure), except what the law requires us to keep;
  • use your data for less for a while (restriction);
  • give you your data in a common, machine-readable format (portability);
  • stop using it where we rely on our legitimate interest (objection);
  • withdraw consent you gave, for stock alerts for example. What we did before stays lawful.

Mail info@chromatcg.nl, preferably from the address we know you by, so we can tell it is really you. It costs nothing. We answer within one month — usually the same day. If a request is complicated, the law allows two more months; we would tell you within the first.

09A complaint

Not happy with how we handle your data? Tell us first — we would rather put it right. You can always file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the authority in the EU country where you live.

10Younger than 16

Under 16, you need a parent's or guardian's permission to open an account, reserve or send us a request. Selling cards to us is only possible from 18, or with that permission. If we find we hold data of someone under 16 without it, we delete it.

11No automated decisions

No computer decides anything about you here. An offer for your cards is made by a person, and nobody is profiled.

12Changes

When the shop changes — a new service, online payment — this statement changes with it. The date at the top tells you which version you are reading. For an important change we mail everyone with an account.