MintyThe TCG Marketplace
Start free

Privacy Policy

Last updated: September 2026

1. Who we are

Minty is an independent European marketplace and portfolio tracker for Pokémon Trading Card Game cards. Minty acts as the data controller for the personal data processed through this application. You can reach us at support@minty.cards.

2. Data we process

  • Account data: name, e-mail address, country, preferred language.
  • Profile data: display name, avatar, subscription plan, scan credits.
  • Marketplace data: listings you publish (card details, condition, photos of the front and back of cards you sell).
  • Auction data: bids you place, your maximum automatic bid, and the outcome of auctions you take part in.
  • Order data: purchases, sales, amounts, shipping method, tracking code and order status.
  • Payment data: payments are processed by our payment provider; Minty never stores full card or bank account numbers.
  • Collection data: cards you track in My Collection and price alerts.
  • Communications: messages and photos you send in chat (chat photos are deleted automatically after 12 hours), sale-notification e-mails and their delivery logs.
  • Technical data: cookie-consent choices, push-notification subscriptions, and standard logs needed to run the service securely.
  • Tax data (DAC7): sellers who cross reporting thresholds may be asked for address and tax identification details, stored encrypted.

3. Legal bases (GDPR art. 6)

  • Performance of a contract: running your account, marketplace, auctions, orders and payouts.
  • Legal obligation: financial records and DAC7 seller reporting.
  • Legitimate interest: platform security, fraud prevention and service improvement.
  • Consent: non-essential cookies and push notifications. You can withdraw consent at any time via Cookie Settings or your device settings.

4. Who receives your data

We use a limited set of processors to operate Minty: our hosting and database provider, our payment provider for transactions, our e-mail delivery service for notifications, our shipping-label provider and our AI/scan providers for card recognition. These parties process data only on our instructions. Public listing and auction information (card, price, bid history, seller display name and country) is visible to other users — never your e-mail address or full name.

5. How long we keep your data

We keep each type of data only as long as it is needed for the purpose it was collected for. Temporary data is deleted automatically by a daily clean-up job.

DataRetention periodAfter that
Account basics (e-mail, display name, country, language)While your account is activeDeleted or anonymised
Acceptance of terms and privacy policyAccount lifetime + 5 yearsAnonymised
PasswordsStored only as a secure hash by our authentication providerDeleted with your account
Password-reset linksValid for up to 1 hour, invalid after useDeleted immediately
Login and security logs90 days (up to 12 months in proven fraud cases)Deleted or anonymised
Saved addressesUntil you remove them or close your accountDeleted (order addresses follow the order period)
Orders, invoices and payoutsUp to 7 years, as tax and accounting law requiresDeleted or anonymised
Auctions and bids5 years after the auction ends (7 years when part of financial records)Anonymised
Disputes, fraud and counterfeit reportsCase closure + 5 years (longer only during an ongoing legal case)Deleted
Listing photos without a sale90 days after the listing expires or is removedDeleted
Listing and proof photos with a sale or claimSame period as the order or disputeDeleted
Photos sent in chat12 hoursDeleted automatically
Chat messages2 years after the last message (5 years when linked to an order or dispute)Deleted or anonymised
Collection, portfolios and Pokédex binderUntil you remove them or close your accountDeleted
Scan data and graded slab detailsUntil removed from your collection; sold items follow the order periodDeleted
Notification e-mail logs24 monthsDeleted
In-app notifications12 monthsDeleted
Push-notification registrationsUntil you unsubscribe or your account is closedDeleted
Cookie-consent records13 monthsDeleted
Price and catalogue caches30 daysDeleted
Beta and invitation codesEnd of beta + 12 monthsDeleted or anonymised
Encrypted backupsRolling 30 daysOverwritten

6. Deleting your account

You can delete your account at any time from Settings → Privacy & Data. Your profile, collection, listings, chats and notification settings are removed. Some records cannot be deleted immediately: order, invoice and payout data is kept for the legally required accounting period, and data needed for an open dispute, counterfeit report or fraud investigation is kept until that case is closed. Whatever we must keep is reduced to the minimum — names, addresses and message content are removed as soon as they are no longer needed.

7. Passwords and account security

  • Minty never stores or sees your password. It is kept only as a secure, irreversible hash by our authentication provider.
  • We will never ask for your password by e-mail, in chat or by phone. Our support team cannot read it.
  • Forgot your password? Request a reset with your e-mail address. For your protection we always show the same confirmation message, whether or not an account exists for that address.
  • The reset link is single-use and expires within an hour. We never send a password by e-mail.
  • After a successful change we sign out your other sessions, send a confirmation e-mail and record the event in our security log.
  • Sensitive changes — e-mail address, payout details, seller profile — can require you to confirm your identity again.

8. Your rights

  • Access and portability: download all your data from Settings → Privacy & Data.
  • Rectification: correct your profile and listings at any time.
  • Erasure: delete your account from Settings → Privacy & Data.
  • Objection and restriction: contact us at support@minty.cards.
  • Complaint: you may lodge a complaint with your national data protection authority (in Belgium: the Gegevensbeschermingsautoriteit / Autorité de protection des données).

9. Security

We apply row-level access control on all user data, encrypt sensitive seller tax fields, keep API keys server-side only and serve all traffic over HTTPS. A scheduled clean-up job enforces the retention periods above automatically.

10. Changes

We may update this policy when the service changes. Material changes will be announced in the app before they take effect.

Feedback & Bugs