1. Data controller
ScanPokeCard (CoC 97042706) is the data controller under the General Data Protection Regulation (GDPR). For privacy questions, email [support email to be filled in].
2. What data do we process?
- Account data: email address, hashed password, creation date.
- Scan data: uploaded card photos and recognition results.
- Billing data: subscription status and Stripe customer ID. We never receive credit card data.
- Technical data: IP address, browser type and session logs for security.
3. Purpose and legal basis
- Performance of the contract (art. 6(1)(b) GDPR) — account, scans, subscriptions.
- Legal obligation (art. 6(1)(c) GDPR) — retention of invoices.
- Legitimate interest (art. 6(1)(f) GDPR) — fraud prevention and security.
4. Sub-processors
We use the following processors:
- Lovable Cloud (Supabase) — database, auth and file storage hosting (EU region).
- Stripe — payment processing.
- Lovable AI Gateway — image recognition of uploaded cards.
5. Retention
- Account data: while the account is active, then up to 30 days.
- Scans: until you delete them or close the account.
- Invoices: 7 years (tax retention).
6. Your rights
You have the right to access, rectify, erase, restrict, object and data portability. Send a request to [support email to be filled in]. You can also lodge a complaint with your local data protection authority.
7. Transfers outside the EU
We strive to process data within the EU. If transfers to countries outside the EEA occur, they are based on EU standard contractual clauses.
8. Security
Passwords are stored hashed. Traffic to our servers is encrypted via HTTPS. Access to production systems is restricted and logged.
9. Contact
ScanPokeCard · CoC 97042706 · VAT: [VAT number to be filled in] · Email: [support email to be filled in]