CardPrime is operated by CardPrime Korlátolt Felelősségű Társaság ("CardPrime", "we", "us"), the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).
We have not appointed a Data Protection Officer, as our processing does not meet the Article 37 thresholds (no large-scale or systematic monitoring, no large-scale special-category processing). Privacy questions and rights requests can be sent to the contact above.
| Data | When | Purpose |
|---|---|---|
| Email address | Account registration (Cognito) | Login, account identification |
| Display name | Account registration (required; a nickname is fine) | Personalizing your profile, and identifying you as the owner of any card you publish to the public catalog (see Section 3) |
| Password | Account registration | Authentication (stored only as a salted hash by AWS Cognito — CardPrime never sees or stores your plaintext password) |
| Card records you add | Every time you add a card (photo + manual details) | Building your collection |
| Approximate location (coarse, rounded to ~1.1 km) | Only at the moment you save a card you've added | Fraud detection — flagging implausible location patterns (e.g. the same card added in two distant cities minutes apart) |
| Login timestamps | Every sign-in | Security monitoring |
| Content reports you submit | Only when you report a card in the public catalog | Reviewing reported content, meeting our content-moderation obligations |
| Accounts you block | Only when you block a collector | Hiding that collector's cards from you, and yours from them |
We do not collect precise/continuous location, contacts, photos outside the card-entry flow, or any advertising identifiers. We do not use analytics or crash-reporting SDKs (no Firebase, Sentry, Amplitude, Mixpanel, or similar).
What's required vs. optional: email, password and a display name are required to create an account — without them we cannot provide the service. The display name does not have to be your real name; a nickname or pseudonym is fine, and you can change it at any time in Settings → Edit Profile (see Section 3, which explains where it is shown). Approximate location is only requested at the moment you save a card; declining the permission prompt does not block adding the card, but the geo-velocity fraud check will have less information to work with for that entry.
Every card you add is private by default. It is visible only in your own account unless you deliberately turn on "Show in public catalog" for that specific card — a per-card switch you can turn off again at any time from the card's edit screen.
When a card is shared publicly, this is what other signed-in users can see:
They do not see your email address, your account ID, the location captured when you added the card, or any other card in your collection.
Your display name is the only part of your profile that other users see, and only on cards you have chosen to publish. It is entirely under your control: you can change it at any time in Settings → Edit Profile — a nickname or pseudonym is perfectly acceptable — and the change applies immediately everywhere your published cards appear. If you would rather not be identified at all, turn the "Show in public catalog" switch off; a private card never shows your name to anyone. Accounts that have no display name stored are shown under the anonymous collector ID instead. Nothing else about your profile is ever displayed, and your display name is not shown anywhere while all of your cards are private.
Automated screening. When you turn the switch on, the card's photo is automatically checked for sexual, violent, hateful, or otherwise objectionable imagery before it can appear in the catalog. A photo that fails this check is not published; the card itself stays saved in your private collection.
Reporting and blocking. Other users can report a publicly shared card and can block you as a collector; you can do the same to them. If enough distinct users report the same card, it is automatically removed from the public catalog while we review it. Blocking is symmetric — a blocked collector's cards disappear from your Explore feed, and yours disappear from theirs. Blocks you've made can be undone in Settings → Blocked Accounts & Reports.
Turning the switch off removes the card from the public catalog immediately.
Performance of a contract — account creation, authentication, and collection management are necessary to provide the service you request.
Consent — publishing a card to the public catalog happens only when you turn on that card's visibility switch. You can withdraw this at any time by turning the switch off, with no effect on anything else.
Legitimate interest — approximate location capture when you add a card and the resulting fraud/geo-velocity checks; automated screening of photos submitted to the public catalog; and processing of reports and blocks. These protect the integrity of the card catalog and the safety of other users, and are limited to the minimum needed for that purpose. We are also legally required to operate a notice-and-action mechanism for illegal content under the EU Digital Services Act.
Your data is processed only by our infrastructure provider, Amazon Web Services (AWS), in the following services: Cognito (authentication), DynamoDB (database), S3 (card images), Lambda/API Gateway (application logic), Rekognition (automated image screening, only for photos you submit to the public catalog), and SES (system email). AWS acts as our data processor and processes this data only on our instructions, under the AWS Data Processing Addendum that forms part of the AWS Service Terms and meets the requirements of Article 28 GDPR.
We do not sell, rent, or share your data with advertisers, data brokers, or any other third party.
All data is stored and processed within the European Union, in AWS's eu-north-1 (Stockholm, Sweden) region. The single exception is the automated image screening described in Section 3: because AWS does not offer that service in Stockholm, photos you submit to the public catalog are screened in AWS's eu-central-1 (Frankfurt, Germany) region. Both regions are inside the EU — we do not transfer your personal data outside the EU/EEA. The screening call is a one-off check with no storage: the image is not retained by that service.
We retain your data for as long as your account remains active. We do not keep it "just in case" beyond that — there is no separate archive of former users.
| Data | Retention |
|---|---|
| Account, profile, cards, card images | Until you delete your account |
| Login timestamps | Until you delete your account |
| Approximate location captured on card add | Stored with that card record; deleted with it |
| Content reports and block records | Until you delete your account, or until you unblock the collector |
If you request deletion, your account and all associated data are erased automatically — not through a manual, delayed process. This includes uploaded card images (every stored version of them, not only the latest), reports you have submitted, reports submitted about your cards, and block records in both directions.
Backups. Our database has point-in-time recovery enabled, which continuously retains a rolling 35-day window so we can recover from an outage, a faulty deployment, or accidental data loss. This is a whole-database safety net, not a per-user archive: individual records cannot be removed from it, so for up to 35 days after deletion your data may still exist inside that recovery window. It is not accessible to the application, is never used to serve or restore an individual account, and rolls off automatically. This is the one place where erasure is not instantaneous, and we mention it rather than claim otherwise.
Under GDPR, you have the right to:
For any other request — including access, rectification, restriction, objection, or a data portability export — or if you cannot access the app, email info@cardprime.io.
We run three automated checks. None of them produces a legal or similarly significant automated decision about you or your account, and none of them results in an automated account suspension — a human reviews anything that could lead to that.
You can contest any of these outcomes by emailing info@cardprime.io.
CardPrime is intended for collectors aged 16 and older — which is also the age at which a person can consent to their own personal data being processed by an online service in Hungary.
How the requirement is applied. Being at least 16 is a condition of our Terms of Service (Section 2, "Who may use CardPrime"), which you accept before the app can be used. Accepting those terms, and continuing to use CardPrime afterwards, is your representation that you meet the condition. We deliberately do not ask for a date of birth and do not verify age against identity documents. GDPR asks for efforts that are reasonable "taking into consideration available technology", and for an app that catalogues sports cards — with no chat, no advertising, no profiling and no content aimed at children — requiring identity documents would collect far more personal data about every user than it could ever protect. That representation is the proportionate measure here, and we describe it as exactly what it is: a declaration, not a verification.
What this means honestly. Because we do not verify, we cannot rule out that someone under 16 uses CardPrime despite the requirement. We do not claim otherwise. What we do:
If you are between 16 and 18, please make sure a parent or guardian is aware you are using the app.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the NAIH within 72 hours and inform you as required by Articles 33–34 GDPR.
If we materially change what data we collect or how we use it, we will update this policy and notify you in the app.
CardPrime Korlátolt Felelősségű Társaság
Registered office: 2085 Pilisvörösvár, Semmelweis köz 1.
Company registration number: 13-09-248460 · Tax number: 33096810-2-13
Email: info@cardprime.io
Supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), naih.hu