Privacy Policy

Last updated: August 9, 2026

1. Data controller

The controller of the personal data collected via the site www.pokeitem.fr and the application PokéItem is:

SAS POKEITEM

SIREN: 105 186 597, RCS Toulouse

Address: 26A route de Léguevin, 31820 Pibrac, France

Contact for your data: [email protected]

2. Data collected

Depending on the services used, the following data may be collected:

DataSourceRequired
Email addressAccount registrationYes
Password (hashed)Account registrationYes
Username / handleAccount registrationYes
Profile pictureUser profileNo
Collection data (cards)App usageNo
Purchase prices enteredApp usageNo
Card condition / gradeApp usageNo
Payment dataPro subscription (via Stripe)No
IP address, browserAutomatic browsingNo
Usage data (pages visited)Anonymous analyticsNo
Referral codeReferralsNo
In-app transaction IDiOS/Android subscription (via RevenueCat)No
Card photos (AI scan)App scan featureNo
Date of birthAccess to the social features and messagingYes
Published content (username, profile picture, banner, bio, showcase, Marketplace listings, feed posts)Social featuresNo
Private messages (content, timestamps, read receipts)Messaging between usersNo
Social relationships (follows, blocks, reports sent and received)Social featuresNo
App usage data (interaction events)App usageNo
Acquisition parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), from the install link or the landing pageApp install / website visitNo

Stripe note: Payment data (card number, etc.) is never stored by PokéItem. It is processed exclusively by Stripe, a PCI DSS certified payment provider. PokéItem retains only the transaction ID, the subscription status and the billing dates.

PokéItem never collects sensitive data within the meaning of the GDPR (health data, ethnic origins, political opinions, etc.).

Some data is made public by the user themselves: username, profile picture, banner, bio, showcase and Marketplace listings. It is visible to other users and, through a binder sharing link, to anyone holding that link, even without an account. A profile can be switched to private at any time in the settings, and collection values can be hidden separately.

3. Processing purposes

Personal data is processed for the following purposes:

  • Creating and managing user accounts
  • Providing the Service (collection management, price estimates)
  • AI card identification (scan feature)
  • Managing the Pro subscription and billing
  • Sending transactional emails (confirmation, renewal reminder)
  • Improving the Service (anonymous analytics)
  • Complying with legal obligations (accounting retention)
  • Verify the minimum age for the social features (15) and for private messaging (16)
  • Automatically moderate published images before they go live and filter text
  • Handle reports and blocks, suspend abusive accounts
  • Measure app usage in order to improve it
  • Measure where installs and subscriptions come from, in order to assess the effectiveness of acquisition campaigns

4. Legal basis for processing

PurposeLegal basis
Account and Service managementPerformance of the contract (Art. 6.1.b GDPR)
Billing and subscriptionPerformance of the contract (Art. 6.1.b GDPR)
Accounting obligationsLegal obligation (Art. 6.1.c GDPR)
Anonymous analyticsLegitimate interest (Art. 6.1.f GDPR)
Marketing emails (if applicable)Consent (Art. 6.1.a GDPR)
Published content, listings and messagingPerformance of the contract (Art. 6.1.b GDPR)
Age verification and moderationLegal obligation (Art. 6.1.c and Art. 8 GDPR, age of digital consent set at 15 in France) and legitimate interest (Art. 6.1.f GDPR)
App usage measurementLegitimate interest (Art. 6.1.f GDPR)
Measuring the origin of installs and subscriptionsLegitimate interest (Art. 6.1.f GDPR)

5. Retention period

DataPeriod
Active user accountLifetime of the account
Account data after deletion30 days (permanent purge)
Billing data10 years (legal obligation)
Connection logs12 months
Anonymous analytics data26 months
Scanned card photosNot retained by PokéItem (ephemeral processing, see section 6)
Private messagesAs long as the conversation exists; deleted with the account
Marketplace listingsDeleted when the listing or the account is closed
ReportsFor the time needed to handle them, then kept as evidence in case of repeat offences
Date of birthAs long as the account exists

6. Data recipients

Users' personal data is processed by SAS POKEITEM and its technical subprocessors:

  • Railway Corp. (United States), hosting of the website, the web application, the API and the PostgreSQL database
  • Brevo SA (France), sending of transactional emails (registration confirmation, subscription-renewal reminder)
  • Stripe, Inc. (United States / Ireland), processing of web transactions (Premium subscription via the site)
  • Apple Inc. (United States), authentication via "Sign in with Apple". If the user enables the "Hide My Email" option, PokéItem receives only the Apple private-relay address (@privaterelay.appleid.com); the real address remains confidential on Apple's side.
  • Google LLC (United States), authentication via "Sign in with Google" (OAuth 2.0). Only the Google ID, email address and profile picture are transmitted to PokéItem at sign-in.
  • RevenueCat, Inc. (United States), technical management of in-app subscriptions on iOS and Android (validation of Apple App Store and Google Play receipts, subscription-status tracking). Data shared with RevenueCat: anonymous appUserID, device ID, purchase events, Apple/Google receipts. Banking information is never transmitted to RevenueCat. RevenueCat also receives the acquisition parameters, in order to link a subscription to the campaign it came from.
  • TCG API, tcgapi.io (European Union), the technical card-recognition and pricing platform used by the scan feature. When a user scans a card via the app, the captured photo is transmitted to the tcgapi.io API, which orchestrates the card's identification and its matching against the price catalogue. Only the image is sent: no user ID, email or name is included in the request. The photo is not retained once the identification result is returned, and is not stored by PokéItem.
  • Google LLC (United States), AI identification of Pokémon TCG cards via the Gemini API (the scan's primary provider). The card photo is analysed by the Gemini model to recognise the card (name, set, number). In accordance with the Gemini API terms applicable to paid offerings, the transmitted data is not used to train the models and is retained only temporarily for abuse-detection purposes, then deleted.
  • Anthropic, PBC (United States), AI identification of Pokémon TCG cards via the Claude API, used as a fallback when the primary provider is unavailable. Same guarantees: only the image is transmitted, without any user ID. In accordance with the Anthropic API terms of use, the transmitted data is not used to train the models and is retained for up to 30 days for trust & safety purposes, then deleted.
  • Google LLC (United States), automated analysis of published images via the Gemini API, for moderation purposes only
  • PokéItem image CDN (cdn.pokeitem.fr), hosting of published photos
  • Mixpanel, Inc. (United States), app usage measurement and origin of installs

Sessions and authentication: Session management is handled by NextAuth.js v4 (open source, self-hosted, no data transfer to a third party). Sessions are secured with JWT tokens, valid for 30 days and renewed automatically.

PokéItem does not sell, rent or transfer its users' personal data to third parties for commercial purposes.

7. Transfers outside the European Union

The following services involve a transfer of data to the United States:

ProviderUseSafeguard
Railway Corp.Hosting and databaseSCC (decision 2021/914)
Stripe, Inc.Web paymentSCC + DPF
Apple Inc.iOS payment, Sign in with Apple, App StoreDPF (certified July 2023)
Google LLCSign in with Google (OAuth), AI scan (Gemini API), moderation of published images (Gemini API)DPF (certified July 2023)
RevenueCat, Inc.In-app subscription management (iOS + Android)SCC (decision 2021/914)
Anthropic, PBCAI scan (Claude API, fallback)SCC (decision 2021/914)
Mixpanel, Inc.App usage measurementSCC (decision 2021/914)

The Standard Contractual Clauses (SCC) are approved by the European Commission (decision 2021/914). The EU–US Data Privacy Framework (DPF) guarantees an adequate level of protection in accordance with the GDPR.

Brevo SA is a French company (head office in Paris): no transfer outside the EU for this service.
TCG API (tcgapi.io) is hosted in the European Union: no transfer outside the EU for this service.
NextAuth.js is self-hosted: no data transfer to a third party.

8. Your rights (GDPR)

In accordance with Regulation (EU) 2016/679 (GDPR), you have the following rights over your personal data:

  • Right of access, obtain a copy of your data
  • Right to rectification, correct inaccurate data
  • Right to erasure, request the deletion of your data
  • Right to portability, receive your data in a structured format
  • Right to object, object to certain processing
  • Right to restriction, temporarily restrict a processing operation
  • Right to withdraw your consent at any time

To exercise these rights, contact us at [email protected]. We undertake to respond within one month.

If the response is unsatisfactory, you may lodge a complaint with the CNIL (French Data Protection Authority), www.cnil.fr.

9. Cookies and trackers

The site www.pokeitem.fr uses:

Tool / CookiePurposeConsent required
Technical cookiesSite operation, user sessionNo
Authentication cookies (JWT)Keeping the logged-in user sessionNo (necessary for the Service)
Google Tag Manager (GTM)Conditional loading of analytics tools, active only after consentYes (via the cookie banner)
Google Analytics 4 (GA4)Anonymised traffic statistics (via GTM)Yes (via the cookie banner)
Meta PixelAdvertising analytics, in preparation, not yet activeYes (upon activation)
TikTok PixelAdvertising analytics, in preparation, not yet activeYes (upon activation)

Google Tag Manager (GTM) is active on www.pokeitem.fr. It is loaded only after your explicit consent via the cookie banner. If you decline, no analytics script is run. You can change your choice at any time via the "Manage cookies" link at the bottom of the page.

The Meta Pixel and the TikTok Pixel are not active on the www.pokeitem.fr website and will be subject to your consent should they ever be activated. The Facebook SDK is present in the mobile application binary but is never initialised: its automatic initialisation and automatic event logging are disabled, and the Android permission required to read the advertising identifier (AD_ID) is not declared. No data is therefore sent to Meta from the application. You can configure your browser to refuse cookies, which may affect some features of the Service.

10. Data security

PokéItem implements appropriate technical and organisational measures to protect your personal data against any unauthorised access, loss, alteration or disclosure, notably:

  • Encryption of communications (HTTPS/TLS)
  • Secure hashing of passwords (bcrypt)
  • Data access restricted to authorised personnel
  • Hosting on certified infrastructure (Railway)

In the event of a data breach likely to create a risk to your rights, you will be informed as soon as possible, in accordance with Article 34 of the GDPR.

11. Changes to the policy

PokéItem reserves the right to amend this privacy policy at any time, notably to comply with regulatory developments. Material changes will be notified to users by email or via the Service.

The version in force is the one published on this page, with the last-updated date shown at the top of the page.

For any question: [email protected]