wabisabi

Privacy policy

Last updated: 8 October 2026

This is a translation for convenience. The German version is legally binding.

This policy explains which personal data we process when you use wabisabi.cards, for what purposes, on what legal basis, and which rights you have.

1. Controller

Pascal Claisse c/o flexdienst – #22363 Kurt-Schumacher-Straße 74 67663 Kaiserslautern Germany Email: [email protected]

We have not appointed a data protection officer because we are not required to. For any privacy questions, contact us at the email address above or through our contact form.

2. Overview

  • You do not need an account to read the website. We only use strictly necessary cookies and settings and measure reach without cookies (section 6).
  • With an account we store your email address and the data you create yourself – such as your portfolio, favourites or price alerts (section 4).
  • We do not sell data and do not show personalised advertising.
  • Our servers are located in the EU. Some service providers are based in the USA; the safeguards in section 10 apply.

3. Visiting the website

3.1 Hosting and server log files

The website runs on Railway (Railway Corporation, 548 Market St, San Francisco, CA 94104, USA) on servers in the Netherlands (region europe-west4). With every request, the server processes technically necessary data:

  • IP address
  • date and time of access
  • requested page or file, HTTP status code and amount of data transferred
  • referrer URL (the previously visited page), if transmitted
  • browser, operating system and device type (user agent)

We need this data to deliver the website, keep it stable and secure, and fix errors. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure and stable operation. Server log files are available at Railway for no more than 30 days. We have concluded a data processing agreement with Railway.

3.2 Content delivery and protection against attacks

We use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare routes requests, delivers content faster and protects the website against overload and bot attacks. In doing so, Cloudflare processes the data listed in section 3.1, in particular your IP address, and sets the cookie __cf_bm (section 5). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the security and availability of the website. We have concluded a data processing agreement with Cloudflare; Cloudflare is certified under the EU-U.S. Data Privacy Framework.

3.3 Fonts

The fonts of this website are loaded from our own server. No connection is made to Google or other font providers.

3.4 Contact form and enquiries by email

You can reach us through the contact form or by email. We process your name, your email address, the topic you chose, your message, the language of the page, the time and – if you are signed in – your account. We store enquiries from the form in our database at Supabase and send them by email to our address via Resend (both: section 4.1). Emails to [email protected] – including the ones you write directly – are forwarded by Cloudflare (section 3.2) to our mailbox at Proton (Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland). Proton stores the messages encrypted on servers in Switzerland; the European Commission has adopted an adequacy decision for Switzerland (Art. 45 GDPR).

To protect against spam, the form contains a field that is invisible to people and a timing check; we also limit the number of enquiries per IP address. For this the server keeps your IP address in memory for at most 24 hours; we do not store it with your enquiry. We do not use third-party services such as captchas for this.

The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns your account or a contract with us, and otherwise Art. 6(1)(f) GDPR; our legitimate interest lies in answering enquiries and protecting the form against misuse. We delete enquiries no later than twelve months after receipt unless a statutory retention obligation prevents this. On request we delete them sooner.

4. Account and features

4.1 Registration and sign-in

All you need for an account is your email address. To sign in, we send you a one-time code by email; we do not store a password. Optionally, you can additionally protect your account with a second factor (authenticator app) or a passkey. We process:

  • email address
  • times of registration and sign-ins, and technical sign-in data (IP address, user agent) in security logs
  • your chosen language and account settings
  • if you activate a second factor or passkey, the technical data required for it (e.g. a public key); your private key never leaves your device

The legal basis is Art. 6(1)(b) GDPR (providing the account at your request). We also process the security logs on the basis of Art. 6(1)(f) GDPR in order to detect and prevent misuse.

Our database and sign-in are operated for us by Supabase (Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992) on servers in Frankfurt am Main (region eu-central-1). The emails with sign-in codes are sent by Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). We have concluded a data processing agreement with both.

4.2 Portfolio, profile, favourites, lists and saved searches

When you add cards to your portfolio or to lists, or save searches, we store this information (e.g. card, variant, language, quantity, condition, time) with your account. The legal basis is Art. 6(1)(b) GDPR.

In your profile you can choose to set a display name and a profile picture. You pick the picture from our ready-made figures and colours – nothing can be uploaded. Until you choose one, we show a figure derived from your account.

Shared portfolios: When you share a portfolio, anyone who knows the link can open it – with cards, quantities, condition and values, as well as your display name and profile picture. We never show your e-mail address. Shared portfolios are not listed anywhere public and are closed to search engines; anyone who has the link can pass it on, though. You can stop sharing or change the link at any time – the previous link then stops working immediately. The legal basis is Art. 6(1)(b) GDPR: you are using a feature you switch on yourself.

4.3 Price alerts

When you create a price alert, we store the chosen card and your conditions. When an alert is triggered, we send you an email via Resend. The legal basis is Art. 6(1)(b) GDPR. You can delete alerts in your account at any time.

4.4 Reports

Using “Report a problem” you can tell us about incorrect cards, prices or offers. We store the reason, your optional description, the item concerned, the time and – if you are signed in – your account. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the quality of our data. If you delete your account, the report is kept without any reference to you.

4.5 Access for AI assistants (MCP)

You can connect an AI assistant of your choice (e.g. Claude, ChatGPT or Cursor) to wabisabi. It then retrieves card data through our MCP server and – if you allow it – reads and changes your portfolio and favourites. There are two ways to connect it:

  • Sign-in: the app sends you to us; you sign in and allow access. For this we store the name and the redirect addresses the app registers with us, and with your account the connection (when it was granted, when it was last used, whether the app may write) as well as irreversible checksums of the sign-in tokens. An access token is valid for one hour, a refresh token for at most 90 days.
  • Key: under “AI assistants” in your account you create a key. We store an irreversible checksum of it – we show you the key itself only once –, its first and last characters for display, whether it may write, when it was created and when it was last used.

For both, we count the number of your requests per day to enforce the usage limits.

We do not store the content of the requests; only the server log files from section 3.1 apply. Whatever you send to your assistant – such as a photo of a card or your messages – goes to its provider, not to us; their privacy policy applies to it. We only receive the requests the assistant sends to our server.

The legal basis is Art. 6(1)(b) GDPR, and for the usage counters also Art. 6(1)(f) GDPR; our legitimate interest lies in protection against misuse and overload. You can disconnect connected apps at any time, and revoke or replace the key at any time.

4.6 Deleting your account

You can delete your account yourself at any time in your account settings. We then delete your profile, portfolio, favourites, lists, alerts, saved searches as well as your connected AI assistants, your key and the usage counters. A running subscription is cancelled first. Data we are required by law to retain (section 4.7) is blocked until the retention period ends.

4.7 Pro subscription and payment

Where we offer paid Pro features, payment is handled by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). You complete the payment on a Stripe page; we never receive your payment details (e.g. card number). We store Stripe’s customer and subscription identifiers, the status of your subscription, and invoice and payment information. The legal basis is Art. 6(1)(b) GDPR and, for retention under tax and commercial law (up to ten years), Art. 6(1)(c) GDPR. Stripe’s privacy policy additionally applies to processing by Stripe: https://stripe.com/privacy.

5. Cookies and browser storage

We only store information in your browser that is strictly necessary for operation or that you have explicitly requested (§ 25(2) no. 2 TDDDG). No consent is required for this, which is why there is no cookie banner.

Cookies

  • sb-…-auth-token: keeps you signed in; until you sign out or the session expires.
  • tcg_lang: stores your chosen language; 1 year.
  • tcg_price_pref: stores your price display settings (e.g. condition and language); 1 year.
  • __cf_bm (Cloudflare): detects bots and protects against misuse; 30 minutes.

Local storage

  • appearance (light, dark or system)
  • recently searched terms, chosen view and table settings
  • umami.disabled: only if you have switched statistics off (section 6)

These entries remain until you delete them in your browser. They are not transmitted to us, except for the cookies your browser sends with every request.

6. Reach measurement with Umami

To understand which pages are used, we use Umami. We run Umami ourselves on our servers at Railway in the Netherlands; the data is not passed on to third parties. Umami sets no cookies and stores nothing in your browser. It records:

  • the page visited, referrer and time
  • browser, operating system, device type, screen size and language
  • country, derived from the IP address; the IP address itself is not stored
  • individual events without reference to your account, e.g. that a card was added to favourites

To group requests from the same visitor, Umami creates a checksum from the IP address, user agent and a value that changes at the start of every calendar month; your IP address cannot be recovered from it. You are therefore not recognised beyond the change of month. Analysis is carried out exclusively in aggregated form.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in improving our service. If your browser sends the “Do Not Track” signal, you are not recorded. You can also switch statistics off for your browser at the bottom of this page.

7. Links to marketplaces and affiliate links

We link to offers on eBay and Cardmarket. Only when you click a link are you taken to their website; from then on, their privacy policies apply.

Links to offers that we hand out through AI assistants (section 4.5) first lead to a redirect page on our site that shows the destination. You go on to eBay only after you click, to Cardmarket after a few seconds. If you have not chosen a language, the page follows your browser's language setting. We only process the data from section 3.1 for this.

Links to eBay are affiliate links of the eBay Partner Network (eBay GmbH, Albert-Einstein-Ring 2–6, 14532 Kleinmachnow, Germany). On a click, an identifier is added to the link so that eBay can attribute a purchase to us and pay a commission. No cookies are set on our website for this and no data is transmitted to eBay; after the click, eBay processes data under its own responsibility: https://www.ebay.com/help/policies/member-behaviour-policies/user-privacy-notice-privacy-policy?id=4260.

8. Offers from marketplaces

For the price comparison we collect publicly visible offers from eBay (via eBay’s official interface) and Cardmarket: title, price, shipping costs, condition, language and link to the offer. We do not store or display any information about the seller – such as name, rating or location. You only see who listed an offer on the respective marketplace.

We delete offers 90 days after they were last visible on the marketplace or were sold. What remains are only average and lowest prices per card.

9. Emails

We only send you emails that belong to a feature you use: sign-in codes, triggered price alerts, important notices about your account or subscription and replies to your enquiries. We do not send a newsletter. Emails are sent via Resend (section 4.1).

10. Recipients and transfers to third countries

We only pass personal data to the service providers named in this policy (including Proton for our email mailbox, section 3.4), who process it on our behalf and according to our instructions (Art. 28 GDPR), and to Stripe as an independent controller for payment processing.

Some service providers are based in the USA (Railway, Cloudflare, Resend) or belong to companies based outside the EU (Supabase). Even though our servers are located in the EU, access from these countries cannot be ruled out. We base such transfers on an adequacy decision of the European Commission (EU-U.S. Data Privacy Framework, Art. 45 GDPR) where the recipient is certified, and otherwise on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR). We will provide you with a copy on request.

11. Retention

We only store personal data for as long as necessary for the respective purpose:

  • account data and the data of your features: until you delete your account
  • connected AI assistants and key: until you disconnect or revoke them or delete your account; sign-in tokens: at most 90 days; the number of requests per day: 90 days
  • server log files: no more than 30 days
  • sign-in security logs: 7 days
  • offers from marketplaces (without seller information): 90 days after the offer was last visible or was sold
  • reports: until processed, then without reference to your account
  • contact enquiries: no more than twelve months after receipt
  • invoice and payment data: up to ten years (statutory retention obligation)

12. Your rights

You have the right to

  • access the data we process about you (Art. 15 GDPR),
  • rectification of incorrect data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • withdraw any consent given, with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.

An informal message to [email protected] or through our contact form is sufficient for all of this.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority at your place of residence or the authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

13. Obligation to provide data, automated decisions

You do not need to provide any data to use the website without an account. An account requires an email address; without it we cannot create an account. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.

14. Changes

We update this privacy policy when our service or the legal situation changes. The version published here applies.

Statistiques

Nous comptons les pages vues avec Umami sur notre propre serveur – sans cookies et sans rien enregistrer dans votre navigateur. Si vous préférez ne pas être compté, désactivez les statistiques ici pour ce navigateur.