Effective Date: June 23, 2026 · Last Updated: June 23, 2026
This Privacy Policy describes how PokeCardRadar ("we," "us," or "our") collects, uses, discloses, and safeguards your information when you visit pokecardradar.com and use our Pokémon TCG restock alert and membership services (the "Service"). Please read this policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Who We Are
PokeCardRadar is a Pokémon TCG restock alert and community membership platform operated from Florida, United States. Our Service notifies members when Pokémon Trading Card Game products restock at retailers and provides an authenticated member dashboard, community Discord access, and related features.
Privacy Contact:
2. Information We Collect
2.1 Information You Provide Directly
Anthropic PBC: Messages you send to the support assistant are transmitted to Anthropic to generate a reply. Anthropic acts as our service provider for this feature and does not use the content of these messages to train its models.
Discord Account Data: When you sign in using Discord OAuth ("Sign in with Discord"), Discord provides us with your Discord user ID, username, and avatar image URL. We request only the identify scope. We do not receive your Discord password, email address, phone number, or direct messages.
Payment Information: Subscription payments (Trainer and Champion tiers) are processed entirely by Square. We never receive, store, handle, or process your credit or debit card number, CVV, billing address, or any other sensitive payment data. We receive only a confirmation signal indicating whether a payment was successful.
Support Chat Messages: If you use the support assistant (the chat button on our site), we store the messages you send and the assistant's replies. Your messages are sent to Anthropic, which operates the AI model that generates the replies. Please do not enter passwords, payment card numbers, or other sensitive personal information into the chat. If you ask to speak with a person, we also store the email address you provide and send it, along with the conversation, to our support inbox.
2.2 Information Collected Automatically
Session Cookie (dsess): After you sign in, we set a single authentication cookie on your device. This cookie contains a cryptographically signed reference to your Discord user ID. It is set with HttpOnly, Secure, and SameSite=Lax flags to prevent JavaScript access and cross-site misuse. The cookie expires after 30 days.
Server Access Logs: Our hosting infrastructure (Hetzner, Germany) automatically records standard HTTP request data, including IP address, browser user-agent string, pages requested, HTTP response codes, and timestamps. These logs are used exclusively for security monitoring, abuse prevention, and operational diagnostics, not for advertising or behavioral profiling.
2.3 Information Received From Third Parties
Discord Guild Membership Status: Our Discord Bot periodically verifies whether your account is a member of the PokeCardRadar Discord server and holds a qualifying role (e.g., paid Trainer or Champion member role). This check is performed via Discord's Bot API and the result is cached on our server for up to 5 minutes to reduce API load. We store only a boolean membership flag linked to your Discord user ID.
Square Payment Confirmation: Upon successful payment or subscription event, Square notifies our server via a cryptographically signed webhook. We record only the subscription status outcome (active, cancelled, etc.) linked to your Discord user ID. No raw payment data is transferred to us.
3. How We Use Your Information
We use information collected only for the following purposes:
Purpose
Data Used
Legal Basis
Authenticate your identity and maintain your signed-in session
Discord user ID, dsess cookie
Contract performance
Determine your subscription tier and grant access to paid features
Discord user ID, guild role, Square payment status
Contract performance
Display your personalized member dashboard
Discord username, avatar, tier status
Contract performance
Deliver restock alerts via Discord channels
Discord guild membership, member role
Contract performance
Security monitoring, fraud prevention, and abuse detection
IP address, server logs
Legitimate interests
Comply with applicable legal obligations
As required by law
Legal obligation
We do not sell your personal information to any third party. We do not use your data for behavioral advertising, targeted ads, or third-party marketing. We do not build advertising profiles.
4. How We Share Your Information
We share your information only as described below. We do not sell, rent, or trade your personal information.
Discord: Your use of "Sign in with Discord" and our Discord Bot is governed in part by Discord's Privacy Policy. We interact with Discord's API to authenticate you and verify your guild membership status.
Square: All payment processing is handled by Square, Inc. Your payment data is governed by Square's Privacy Policy. PokeCardRadar receives only payment status signals from Square and never touches your raw payment credentials.
Hetzner Online GmbH (Hosting): Our servers are hosted at Hetzner data centers in Germany. Server log data may reside on Hetzner infrastructure. Hetzner is subject to the GDPR and maintains its own data protection policies.
Legal Requirements: We may disclose your information if required to do so by law, regulation, court order, or valid governmental authority, or if we reasonably believe such disclosure is necessary to protect our rights, your safety, the safety of others, or to investigate fraud or a security incident.
Business Transfer: In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, your information may be transferred to the successor entity, provided that entity agrees to honor the terms of this Privacy Policy or provides you with equivalent protection.
5. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law:
Active subscribers: Your Discord user ID, username, and subscription status are retained for the duration of your active membership.
Session cookie: Expires automatically 30 days after issuance or immediately upon sign-out.
Support chat transcripts: Retained for up to 12 months so we can improve our help content and follow up on unresolved questions, then deleted. You may ask us to delete your transcripts sooner using the contact details in Section 14.
Cancelled / expired subscriptions: Your Discord user ID and subscription history record are retained for up to 12 months after cancellation for fraud prevention, dispute resolution, and compliance purposes. After that period, your data is permanently deleted.
Server access logs: Retained for up to 90 days for security and operational purposes, then permanently purged.
Membership cache: Guild membership status cache (in-memory) expires after 5 minutes automatically.
You may request early deletion of your data at any time by contacting .
6. Security
We implement industry-standard technical and organizational security measures to protect your information:
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). Plain HTTP connections are automatically upgraded to HTTPS.
Session cookies are cryptographically signed using a SHA-256-derived server secret. Tampering with a cookie value invalidates it immediately.
Session cookies are set with HttpOnly (inaccessible to JavaScript), Secure (HTTPS-only transmission), and SameSite=Lax (cross-site request protection) flags.
Our server firewalls restrict access to essential ports only. SSH access requires key-based authentication.
We never store payment card data. All payment processing is delegated to Square's PCI DSS-compliant infrastructure.
Discord client secrets and API keys are stored as server-side environment variables and are never exposed to client-side code or public repositories.
No method of data transmission over the internet or electronic storage is 100% secure. While we implement strong protections, we cannot guarantee absolute security against all threats.
7. Your Rights and Choices
Depending on your location, you may have the following rights with respect to your personal information. We honor all of these rights regardless of your jurisdiction:
Right to Access: Request a copy of the personal data we hold about you.
Right to Correction: Request correction of inaccurate or incomplete data.
Right to Deletion: Request that we delete your personal data ("right to be forgotten"), subject to certain exceptions (e.g., legal compliance obligations).
Right to Portability: Request your personal data in a structured, machine-readable format.
Right to Object: Object to the processing of your data based on legitimate interests.
Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
Right to Opt-Out of Sale: We do not sell your personal information, so no opt-out is needed. If our practices change, we will update this Policy and provide an opt-out mechanism before any such sale begins.
To exercise any of these rights, email with your Discord username and a clear description of your request. We will acknowledge your request within 5 business days and respond fully within 30 days.
California Residents CCPA / CPRA
California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know, delete, correct, and opt out of sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To submit a CCPA request, contact . We will not discriminate against you for exercising your privacy rights.
European Economic Area / United Kingdom Residents GDPR / UK GDPR
If you are located in the EEA or UK, you have rights under the General Data Protection Regulation (GDPR) including the right to access, rectify, erase, restrict, and port your data, and the right to lodge a complaint with your local data protection supervisory authority. We process your data on the basis of contract performance (to provide the Service you subscribed to) and legitimate interests (security and fraud prevention). You may withdraw consent or object to processing based on legitimate interests at any time by contacting us.
8. Children's Privacy COPPA
PokeCardRadar is intended for users aged 13 and older. We do not knowingly collect personal information from children under the age of 13. Discord's Terms of Service independently require users to be at least 13 years old.
If you are a parent or guardian and believe your child under 13 has registered for or accessed our Service, please contact us immediately at . We will promptly investigate and delete any such account and associated data.
9. Cookies and Tracking Technologies
We use a minimal, purposeful cookie footprint:
Cookie Name
Purpose
Duration
Type
dsess
Maintains your authenticated session after Discord sign-in. Contains a cryptographically signed Discord user ID reference.
30 days
First-party, essential
We do not use advertising cookies, tracking pixels, cross-site tracking, or third-party analytics cookies. Our public-facing pages function fully without cookies. The dsess cookie is required only to access your authenticated member dashboard.
10. Third-Party Links and Services
Our Service may contain links to third-party websites and services (including Discord, Square, and retail store websites). We are not responsible for the privacy practices, content, or security of those third-party sites. We encourage you to review their privacy policies before providing any personal information.
11. International Data Transfers
PokeCardRadar is operated from the United States. Your information may be transferred to, stored, and processed in the United States (operational base) and Germany (Hetzner hosting). Data protection laws in these countries may differ from those in your home jurisdiction.
For users in the EEA or UK, transfers to the United States are made on the basis of Standard Contractual Clauses (SCCs) or other approved transfer mechanisms where applicable. For questions about international transfers, contact .
12. Do Not Track
Some browsers send "Do Not Track" (DNT) signals. Because we do not engage in cross-site behavioral tracking, our Service functions consistently regardless of DNT signal status.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
Update the "Last Updated" date at the top of this page;
Post a notice in the PokeCardRadar Discord server for members; and
Where required by law, provide more prominent notice or obtain fresh consent.
Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the changes. We encourage you to review this page periodically.
14. Contact Us
For any questions, concerns, data access requests, or complaints related to this Privacy Policy or the handling of your personal information, please reach out:
We will acknowledge all privacy inquiries within 5 business days and provide a full response within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.