Privacy Policy
Last updated: September 2026
1. Who we are
Minty is an independent European marketplace and portfolio tracker for Pokémon Trading Card Game cards. Minty acts as the data controller for the personal data processed through this application. You can reach us at support@minty.cards.
2. Data we process
- Account data: name, e-mail address, country, preferred language.
- Profile data: display name, avatar, subscription plan, scan credits.
- Marketplace data: listings you publish (card details, condition, photos of the front and back of cards you sell).
- Auction data: bids you place, your maximum automatic bid, and the outcome of auctions you take part in.
- Order data: purchases, sales, amounts, shipping method, tracking code and order status.
- Payment data: payments are processed by our payment provider; Minty never stores full card or bank account numbers.
- Collection data: cards you track in My Collection and price alerts.
- Communications: messages and photos you send in chat (chat photos are deleted automatically after 12 hours), sale-notification e-mails and their delivery logs.
- Technical data: cookie-consent choices, push-notification subscriptions, and standard logs needed to run the service securely.
- Tax data (DAC7): sellers who cross reporting thresholds may be asked for address and tax identification details, stored encrypted.
3. Legal bases (GDPR art. 6)
- Performance of a contract: running your account, marketplace, auctions, orders and payouts.
- Legal obligation: financial records and DAC7 seller reporting.
- Legitimate interest: platform security, fraud prevention and service improvement.
- Consent: non-essential cookies and push notifications. You can withdraw consent at any time via Cookie Settings or your device settings.
4. Who receives your data
We use a limited set of processors to operate Minty: our hosting and database provider, our payment provider for transactions, our e-mail delivery service for notifications, our shipping-label provider and our AI/scan providers for card recognition. These parties process data only on our instructions. Public listing and auction information (card, price, bid history, seller display name and country) is visible to other users — never your e-mail address or full name.
5. How long we keep your data
We keep each type of data only as long as it is needed for the purpose it was collected for. Temporary data is deleted automatically by a daily clean-up job.
| Data | Retention period | After that |
|---|---|---|
| Account basics (e-mail, display name, country, language) | While your account is active | Deleted or anonymised |
| Acceptance of terms and privacy policy | Account lifetime + 5 years | Anonymised |
| Passwords | Stored only as a secure hash by our authentication provider | Deleted with your account |
| Password-reset links | Valid for up to 1 hour, invalid after use | Deleted immediately |
| Login and security logs | 90 days (up to 12 months in proven fraud cases) | Deleted or anonymised |
| Saved addresses | Until you remove them or close your account | Deleted (order addresses follow the order period) |
| Orders, invoices and payouts | Up to 7 years, as tax and accounting law requires | Deleted or anonymised |
| Auctions and bids | 5 years after the auction ends (7 years when part of financial records) | Anonymised |
| Disputes, fraud and counterfeit reports | Case closure + 5 years (longer only during an ongoing legal case) | Deleted |
| Listing photos without a sale | 90 days after the listing expires or is removed | Deleted |
| Listing and proof photos with a sale or claim | Same period as the order or dispute | Deleted |
| Photos sent in chat | 12 hours | Deleted automatically |
| Chat messages | 2 years after the last message (5 years when linked to an order or dispute) | Deleted or anonymised |
| Collection, portfolios and Pokédex binder | Until you remove them or close your account | Deleted |
| Scan data and graded slab details | Until removed from your collection; sold items follow the order period | Deleted |
| Notification e-mail logs | 24 months | Deleted |
| In-app notifications | 12 months | Deleted |
| Push-notification registrations | Until you unsubscribe or your account is closed | Deleted |
| Cookie-consent records | 13 months | Deleted |
| Price and catalogue caches | 30 days | Deleted |
| Beta and invitation codes | End of beta + 12 months | Deleted or anonymised |
| Encrypted backups | Rolling 30 days | Overwritten |
6. Deleting your account
You can delete your account at any time from Settings → Privacy & Data. Your profile, collection, listings, chats and notification settings are removed. Some records cannot be deleted immediately: order, invoice and payout data is kept for the legally required accounting period, and data needed for an open dispute, counterfeit report or fraud investigation is kept until that case is closed. Whatever we must keep is reduced to the minimum — names, addresses and message content are removed as soon as they are no longer needed.
7. Passwords and account security
- Minty never stores or sees your password. It is kept only as a secure, irreversible hash by our authentication provider.
- We will never ask for your password by e-mail, in chat or by phone. Our support team cannot read it.
- Forgot your password? Request a reset with your e-mail address. For your protection we always show the same confirmation message, whether or not an account exists for that address.
- The reset link is single-use and expires within an hour. We never send a password by e-mail.
- After a successful change we sign out your other sessions, send a confirmation e-mail and record the event in our security log.
- Sensitive changes — e-mail address, payout details, seller profile — can require you to confirm your identity again.
8. Your rights
- Access and portability: download all your data from Settings → Privacy & Data.
- Rectification: correct your profile and listings at any time.
- Erasure: delete your account from Settings → Privacy & Data.
- Objection and restriction: contact us at support@minty.cards.
- Complaint: you may lodge a complaint with your national data protection authority (in Belgium: the Gegevensbeschermingsautoriteit / Autorité de protection des données).
9. Security
We apply row-level access control on all user data, encrypt sensitive seller tax fields, keep API keys server-side only and serve all traffic over HTTPS. A scheduled clean-up job enforces the retention periods above automatically.
10. Changes
We may update this policy when the service changes. Material changes will be announced in the app before they take effect.