Privacy Policy

How TCGIndex collects, stores and uses your information, and how to manage your rights and choices.

01

Information we collect and why

When you sign up or sign in, we process your email address, confirmation that you are at least 14, and the versions and times of your terms and privacy consent. These are needed for email verification, account management and protection. We do not collect your date of birth or a password. If you do not agree to provide the required information, member features are unavailable, but you can still browse public cards and prices.

When you use member features, we process saved cards, price-alert rules and email language, sign-up and sign-in times, daily activity status, delivery results and rate-limit records. We send only the price alerts you set. This is not consent to marketing or newsletters. If you contact us, we use your email and message to respond and handle your rights request. Please do not send unnecessary information such as national identification numbers.

02

Retention and deletion

We retain account details, consent records, saved cards and alert settings until you delete your account or the relevant item. Account deletion removes associated sessions, cards, alerts, activity and individual delivery records from the operational database. Daily sign-up totals without personal identifiers remain as service statistics.

Sign-in requests are valid for 15 minutes and sessions for 30 days. Expired requests, sessions and rate-limit records are cleaned up daily. Consented detailed analytics, member activity and individual delivery records are deleted at the next daily cleanup after 30 days. Enquiries are deleted within 30 days of resolution. If retention is required by law, we separately explain the records, basis and period, and do not use them for other purposes.

Electronic records are deleted from operational storage; any paper copies are shredded. Recovery history in the former Cloudflare database may retain pre-deletion data for 7 or 30 days, depending on the plan, solely for recovery. Cloudflare recovery-history details.

03

Service providers and international transfers

We use the providers below for hosting, account storage, authentication emails and requested price alerts. This notice describes processing and storage needed to provide member services. We do not sell personal information or provide it for a third party's independent purposes without separate consent or a legal basis.

Amazon Web Services (AWS) — current hosting, member database and storage

Data processed includes email, account and consent records, hashed authentication and session values, saved cards, alerts, activity, delivery records and consented analytics. IP addresses, request paths and browser information pass through the server when handling web requests; the original IP and browser information are not stored in the TCGIndex analytics database.

The current web server and member database operate in the AWS Seoul region (ap-northeast-2). The operational S3 storage is also in Seoul. Retention and deletion follow the periods above. Data is processed when you request or save information, with encrypted network connections for external transfers. AWS privacy information and contact details.

The former hosting provider was Cloudflare, Inc.; the current member database is no longer Cloudflare D1. The recovery-history periods above apply to the former storage. Former provider's privacy notice.

Plus Five Five, Inc. (Resend) — email delivery

Data is stored and processed in the United States; the sending region is Tokyo, Japan. Recipient email, subject, body (a one-time sign-in link or a requested price alert), delivery time and result are sent over HTTPS when you request a sign-in link or an alert meets its condition.

The purpose is authentication and requested alerts. On the current plan, emails and logs are retained for 30 days and backups for 7 days. Remaining customer data is deleted within 90 days after termination of the Resend service agreement. These periods are separate from deletion in the TCGIndex operational database. Provider contact: support@resend.com. Storage and retention details · Subprocessors.

If you do not want these transfers, do not register, or delete your account and contact contact@smileon.app to request a restriction on processing. Member features requiring email verification and account storage cannot then be provided. To stop only price alerts, delete the relevant rules. Optional analytics can be declined or withdrawn separately.

04

Visitor statistics

Daily visitor totals — from 22 September 2026

To understand public-page usage, we count estimated daily visitors and page views separately from consent to detailed analytics. We do not create a new tracking identifier in cookies or browser storage. The server transforms the IP address and User-Agent received with a request together with the date and a server secret to reduce duplicates within that day. This database does not retain the original IP or User-Agent, search terms, referring URLs or individual browsing paths, and the totals are not linked to member information.

Processing takes place on the production server in AWS Seoul. Daily transformed values expire at midnight Korea time and are deleted at the next count or daily cleanup. Date-level visitor and page-view totals without individual information remain as operational statistics. Values are not linked across dates. Shared networks and browsers can be merged, or network changes can result in duplicate counts. Known bots, signed-in operators and private pages are excluded. We do not make these counts when a browser sends Do Not Track or Global Privacy Control.

Optional detailed analytics

Detailed analytics are collected only after separate consent. Fields include a hash of a random browser identifier, public-page path, view time, a limited source category and predefined content codes. They are processed on the operational server and database. Emails, IP addresses, search terms and authentication URLs are not stored in this analytics database. Consented visits by signed-in members also contribute to a separate daily member-activity indicator.

Your browser's consent choice and random identifier are kept in local storage for 30 days. Only with consent, content-source codes remain in the tab's session storage for up to 30 minutes to connect card-discovery activity. Individual server records are removed by daily cleanup after 30 days. Withdraw consent using Analytics settings at the bottom of this privacy page to stop further collection; existing records expire under the retention policy. Declining does not prevent use of member or public features. You can also clear this site's local storage in your browser to reset consent.

05

Your rights and safeguards

You can ask LeeJunhee at contact@smileon.app to access, correct or delete your information, restrict processing or withdraw consent. After verifying your identity, we handle the request under applicable law and explain the result. You can also delete your account in Account settings. We do not accept registrations from children under 14.

We use encrypted transmission, restricted operator access, one-use and expiring sign-in links, and rate limits. The member database stores hashes of sign-in links and sessions instead of the original credentials. The original sign-in link appears in the email and the session is stored in a secure browser cookie, so do not share them. Blocking essential sign-in cookies prevents login. We do not use personal information to make automated decisions with significant effects.