1. Who is responsible
The company named on our invoices is the data controller for everything described here. You can reach us through the contact page for any question about your data, including a request to see, correct or delete it.
2. What we collect
Your name, email address, postal address, phone number and bank details; the contents of every submission you build; the photographs taken while scanning cards; shipping and tracking data from the carrier; and the messages you send us. We do not ask for anything we do not use.
3. Why we are allowed to
Most of it is needed to perform the contract you enter into when you submit cards. Invoices and payout records are kept because tax law requires it. Fraud and counterfeit checks rest on our legitimate interest in not buying stolen or fake goods.
4. The photographs we take
Scanning a card stores the cropped image of that card. It is evidence of what arrived and what was assessed, which protects both of us in a dispute. Frames that matched nothing are discarded automatically; the rest are kept with the submission.
5. Who else sees it
The carrier, to deliver your parcel. Our hosting and email providers, to run the service. Our accountant, for the records tax law requires. That is the whole list. We do not sell your data and we do not share it for advertising.
6. How long we keep it
Invoices, payouts and the records behind them are kept for seven years, because Dutch tax law requires it. Scan photographs and submission details are kept while your account is open. Close your account and everything not legally required is deleted.
7. Your rights
You can ask for a copy of your data, have it corrected, have it deleted where we are not required to keep it, object to processing, and receive it in a portable format. Ask through the contact page and we will respond within one month.
8. Cookies
We set the cookies needed to keep you signed in, remember your language and protect forms against cross-site abuse. Nothing tracks you across other websites, so there is no consent banner to click away.
9. Where your data is stored
On servers in the European Union. If a provider we rely on ever processes data outside the EU, it will be under the safeguards the GDPR requires, and this page will say so.
10. Security
The site is served over HTTPS only, bank details are stored encrypted, and access to the operations console is limited to named staff accounts. No system is perfect; if something goes wrong that affects you, we will tell you.
11. Complaints
Talk to us first — most things are a misunderstanding we can fix the same day. If you are not satisfied, you have the right to complain to your national data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.