LEGAL / PRIVACY
Privacy Policy
Last updated
2026-04-18
This Privacy Policy explains what data PokeDAQ collects, how we use it, who we share it with, and the rights you have over your information. It applies to all users of the PokeDAQ terminal, website, and related services.
§ 01
What we collect
- —Account information: email address, display handle, and password hash (bcrypt). We do NOT require or store your real name unless you choose it as your display handle.
- —Portfolio data: cards, grades, cost basis, notes, and watchlist selections you enter into the terminal. This data is stored encrypted at rest.
- —Session and security data: IP address, user agent, and session tokens used for authentication and abuse prevention.
- —Browser preferences: theme selection, data mode, and landing page preference stored in your browser's localStorage.
- —We do NOT collect: home address, payment card numbers (Stripe handles all payment processing under PCI compliance), biometric data, or data from children under 13.
§ 02
How we use it
- —Operate the terminal: display your portfolio P/L, deliver alerts, compute watchlist data, and render your personalized dashboard.
- —Compute aggregate market data: anonymized and de-identified trade volumes feed sector charts and the PDQ100 index. No individual portfolio data is exposed.
- —Prevent fraud and abuse: IP and session data help us detect automated scraping, credential stuffing, and other malicious activity.
- —Send transactional email: alert notifications, account security events (password reset, new device login), and required legal notices. We do not send marketing email without explicit opt-in.
- —Improve the product: aggregate, anonymized usage analytics help us understand which features are used and where the terminal can be improved. We do not use individual browsing behavior for advertising.
§ 03
Third-party services
- —Stripe: payment processing for Pro and Desk subscriptions. Stripe is PCI-DSS Level 1 compliant and maintains its own privacy policy at stripe.com/privacy. We never see or store your full card number.
- —Cloudflare: CDN, DDoS protection, and Workers runtime. Cloudflare processes request metadata (IP, headers) to serve and protect the site.
- —Neon: managed PostgreSQL database hosting. All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- —Postmark: transactional email delivery for alerts and account notifications. Postmark receives only your email address and the message content.
- —PokeAPI and pokemontcg.io: public Pokemon and card reference data. No user data is shared with these services.
§ 04
Data sharing
- —We do not sell, rent, or trade your personal data to any third party.
- —We share data only with the subprocessors listed above, and only to the extent necessary to operate the service.
- —We may disclose data when required by law, court order, or governmental regulation, or to protect our rights and safety.
§ 05
Cookies and localStorage
- —Session cookie: a single httpOnly, Secure, SameSite=Strict cookie used for authentication. It contains only a session identifier.
- —localStorage: UI preferences (theme, data mode, landing page) are stored in your browser's localStorage. These never leave your device.
- —We do not use advertising cookies, third-party tracking pixels, or analytics cookies. There are no cross-site trackers on PokeDAQ.
§ 06
Your rights
- —Export your data: download a full JSON export of your account, portfolio, watchlists, and alerts from Profile > Settings.
- —Delete your account: permanently delete your account and all associated data from Profile > Security. Deletion is processed within 24 hours.
- —Request correction: email privacy@pokedaq.app to correct inaccurate data associated with your account.
- —EU/UK residents: you have rights under GDPR including access, rectification, erasure, restriction, portability, and objection. Contact privacy@pokedaq.app.
- —California residents: you have rights under CCPA including the right to know, delete, and opt-out of sale (we do not sell data). Contact privacy@pokedaq.app.
§ 07
Data retention
- —Account data (profile, portfolio, watchlists, alerts) is retained while your account is active, plus 30 days after deletion to allow recovery if deletion was accidental.
- —Market data (prices, trades, index values) is public information and is retained indefinitely regardless of account status.
- —Server logs (IP, user agent, request path) are retained for 90 days for security and debugging purposes, then permanently deleted.
- —Database backups are retained for 30 days on a rolling basis.
§ 08
Children
- —PokeDAQ is not directed at children under 13. We do not knowingly collect personal information from children under 13.
- —If we learn that we have collected data from a child under 13, we will delete it promptly. Contact privacy@pokedaq.app if you believe a child has provided us with personal data.
§ 09
Changes to this policy
- —We may update this Privacy Policy from time to time. Material changes will be communicated via email to all registered users at least 30 days before taking effect.
- —Continued use of PokeDAQ after the effective date of a revised policy constitutes acceptance of the updated terms.
- —The "Last updated" date at the top of this page reflects the most recent revision.
Questions? Email legal@pokedaq.app.