Privacy statement
What we keep about you, why, for how long and who else sees it. And what you can ask us to do with it — or to stop doing.
01Who is responsible
Chroma TCG decides what happens to the personal data on this website, and so is the controller within the meaning of the General Data Protection Regulation (GDPR, in Dutch the AVG). This statement applies to chromatcg.nl, to the emails we send and to the chat on the site.
- Chroma TCG
- info@chromatcg.nl
- chromatcg.nl
A question about your data? Mail info@chromatcg.nl. A person reads it, usually the same day.
02In short
- We keep only what a reservation, a sale to us, an account or a question needs.
- Everything is stored in the European Union.
- We never sell your data and never share it for advertising.
- No analytics, advertising or tracking cookies — so no cookie banner either.
- You can see, correct or delete your data. One email is enough.
03What we keep, why and for how long
Per thing you do on the site: which data, what we use it for, the legal ground in the GDPR (article 6(1)) and how long we keep it.
Reserving and buying
- Email address, phone number, delivery address from your account, what you reserved and the amounts, your note, how you want to be contacted (WhatsApp, chat or email), the order number and support code.
- Holding the cards for you, contacting you to complete the sale, arranging payment and shipping, and answering questions about your order.
- Performance of the contract (b). Keeping the administration: legal obligation (c).
- Phone number, note and address are erased one year after the reservation is settled. The order itself — number, lines, amounts, status and email address — is kept for seven years, because Dutch tax law requires it.
Selling to Chroma
- Name, email address, country, the games and kinds of cards you offer, the size of the lot, your description of it and how you want to be paid. If we buy, also the account number we pay into.
- Making you an offer, talking about your cards, and completing and paying for the purchase.
- Steps at your request before a contract, and performing it (b). The purchase administration: legal obligation (c).
- The description of your collection is replaced one year after the request is closed. If we bought from you, the details of that purchase are kept for seven years for the administration. If we did not, the request itself (reference, name, email, status) is kept for at most seven years so we can find it back, and deleted sooner if you ask.
Your account
- Name, email address, password (stored as a hash we cannot read back), phone number, delivery address, language, your saved cards and, if you add one, a profile photo, which is stored privately and never shown publicly.
- Signing in, not having to type your details every time, showing your reservations, sell requests and saved cards, and mailing you when a card you saved is back in stock. Every such mail has a link to stop them.
- Performance of the contract (b): the account you asked for.
- As long as the account exists. Ask us to delete it and the account, profile, photo, saved cards, stock alerts and conversations go; reservations and sell requests are detached from your name, except what the administration must keep.
Chat about an order
- Your name, email address, order number and the messages we exchange.
- Answering your question about a reservation or order.
- Performance of the contract (b).
- The conversation is deleted one year after it is closed.
Stock alerts
- Your email address, your language and, if you are waiting for one card, which card.
- Mailing you when something new comes in, or when that card is back. At most one mail a week for the general list.
- Consent (a). Withdraw it any time with the unsubscribe link at the bottom of every mail.
- Until you unsubscribe.
Email, Instagram or WhatsApp
- Your name, your contact details and what you write to us.
- Answering your question.
- Our legitimate interest in answering the people who write to us (f), or performance of the contract (b) if it is about an order.
- As long as needed to deal with your question, and at most one year after that.
Keeping the site safe
- Technical data such as your IP address, browser and the time of a request, and the outcome of the check that you are a person.
- Keeping robots off the forms, limiting how many requests one address can make, and investigating abuse and outages.
- Our legitimate interest (f) in a safe shop where one-of-one cards cannot be taken by a script.
- Briefly — only as long as needed to investigate abuse or an outage.
04Who else sees your data
We run the shop with a small number of services. Companies that process data for us do so only on our instructions and under a data processing agreement. We never sell data and never share it for advertising.
- Supabase — the database, sign-in and file storage. Servers in Frankfurt, Germany.
- Hetzner — the server the website runs on, in Germany.
- Resend — sends our emails: confirmations, offers and stock alerts.
- Cloudflare — the check on forms that you are a person (Turnstile). Sees technical data such as your IP address.
- Anthropic — reads photos of cards that the shop itself takes for the catalogue. No customer data goes there.
- The carrier that delivers your parcel — your name and address, to deliver it.
- WhatsApp (Meta) — only if you choose to talk to us on WhatsApp.
- Our bank — for payments and payouts.
- Authorities such as the Dutch Tax Administration — only when the law requires it.
05Outside the European Union
Our database and server are in Germany. Resend, Cloudflare and Anthropic are American companies, so data can reach the United States through them. That only happens with the safeguards the GDPR requires: the EU–US Data Privacy Framework where the company is certified under it, or the standard contractual clauses of the European Commission.
07Security
- Every connection runs over HTTPS.
- The database decides who sees what: a customer only ever sees their own data, staff only what their role needs.
- Passwords are stored as a hash; nobody at Chroma can read them.
- Staff accounts sign in with two-step verification.
- Forms are protected against robots and against being sent too often.
Should something still go wrong with your data, we report it to the Dutch Data Protection Authority within 72 hours where the law requires it, and tell you directly if it puts you at risk.
08Your rights
Under the GDPR you can ask us to:
- show you which data we hold about you (access);
- correct data that is wrong (rectification) — name, phone and address you can also change yourself under your account;
- delete your data (erasure), except what the law requires us to keep;
- use your data for less for a while (restriction);
- give you your data in a common, machine-readable format (portability);
- stop using it where we rely on our legitimate interest (objection);
- withdraw consent you gave, for stock alerts for example. What we did before stays lawful.
Mail info@chromatcg.nl, preferably from the address we know you by, so we can tell it is really you. It costs nothing. We answer within one month — usually the same day. If a request is complicated, the law allows two more months; we would tell you within the first.
09A complaint
Not happy with how we handle your data? Tell us first — we would rather put it right. You can always file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the authority in the EU country where you live.
10Younger than 16
Under 16, you need a parent's or guardian's permission to open an account, reserve or send us a request. Selling cards to us is only possible from 18, or with that permission. If we find we hold data of someone under 16 without it, we delete it.
11No automated decisions
No computer decides anything about you here. An offer for your cards is made by a person, and nobody is profiled.
12Changes
When the shop changes — a new service, online payment — this statement changes with it. The date at the top tells you which version you are reading. For an important change we mail everyone with an account.