Privacy Policy — TradeRoom
Last updated: 2026-08-04
Status: Draft template for MVP. Replace [OPERATOR_*] placeholders before public launch.
This Privacy Policy describes how [OPERATOR_LEGAL_NAME] (“we,” “us,” or “TradeRoom”) collects, uses, and shares information when you use the TradeRoom progressive web app and related services (the “Service”).
Contact: [OPERATOR_PRIVACY_EMAIL]
Operator address (if applicable): [OPERATOR_ADDRESS]
1. What TradeRoom does
TradeRoom helps users build two-sided trading card game (TCG) trade sessions (MVP: Gundam Card Game), view market-oriented price references, optionally record cash offsets, join shared trade rooms, and keep a history of confirmed trades. TradeRoom does not process card payments, hold funds in escrow, or ship physical cards.
2. Information we collect
2.1 Account information
When you create or sign in to an account (via email/password or a provider such as Google), we collect:
- Email address
- Display name (if provided)
- Authentication identifiers from our auth provider (Firebase Authentication)
- Profile preferences (for example, default price basis)
2.2 Trade and usage data
When you use the Service, we may store:
- Trade drafts, room membership, card line items, quantities, optional condition labels, optional cash amounts, and custom price overrides
- Verification and accept/decline events
- Confirmed trade history snapshots (including card names, images URLs, prices at confirm time, and counterparty display identifiers)
- Technical logs needed to operate the Service (for example, error reports)
2.3 Device and technical data
We may automatically collect:
- Browser/device type, approximate region derived from IP (via hosting/CDN providers)
- App version / PWA install context
- Diagnostic data if you consent to or we enable crash reporting (for example, Sentry)
2.4 Cookies and similar technologies
We use cookies or local storage as needed for authentication sessions, preferences, and basic analytics. You can control cookies through your browser settings; disabling them may break sign-in.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service
- Authenticate users and secure trade rooms
- Sync trade sessions and show trade history
- Display catalog and pricing references sourced from third parties (see §5)
- Monitor reliability, prevent abuse, and debug issues
- Communicate about the Service (for example, security or material policy updates)
We do not sell your personal information.
4. How we share information
We may share information with:
| Recipient | Purpose |
|---|---|
| Other users in your trade room | Display name and the card lists / cash / accept state for that room |
| Infrastructure providers | Hosting and backend (for example, Vercel, Google Firebase / Google Cloud) |
| Analytics / error tooling | Product metrics and crash diagnostics (if enabled) |
| Law enforcement or legal process | When required by law or to protect rights and safety |
Counterparties in a confirmed trade will retain a snapshot of that trade in their history, including what you offered.
5. Third-party catalog, pricing, and images
TradeRoom displays card metadata, images, and market-oriented prices that originate from TCGplayer-related data redistributed via TCGCSV (or a successor source we configure).
- Those providers have their own terms and privacy practices.
- Image URLs may be served from third-party CDNs (for example, TCGplayer’s CDN).
- TradeRoom is not affiliated with, endorsed by, or certified by TCGplayer, Bandai, or TCGCSV.
See also ATTRIBUTION.md.
6. Data retention
- Account data is kept while your account remains active.
- Trade history is retained so you and counterparties can review past trades, unless we delete it upon a verified deletion request or as required by law.
- Active/expired rooms may be deleted or archived after inactivity (for example, after expiry windows described in the product).
- Backups and logs may persist for a limited operational period.
To request account deletion, email [OPERATOR_PRIVACY_EMAIL]. We will delete or anonymize personal account data except where we must retain records (for example, fraud prevention, legal obligations, or shared trade snapshots already delivered to a counterparty).
7. Security
We use industry-standard providers and access controls (authenticated APIs, Firestore security rules, server-side privileged operations). No method of transmission or storage is 100% secure.
8. Children’s privacy
The Service is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have, contact [OPERATOR_PRIVACY_EMAIL].
9. International users
The Service may be hosted in the United States or other regions where our providers operate. By using TradeRoom, you understand your information may be processed in those locations.
10. Your choices
- Update display name and preferences in the app (when available)
- Sign out / delete account by contacting us
- Disable non-essential cookies via browser controls
- Stop using the Service at any time
11. Changes to this policy
We may update this Privacy Policy. We will revise the “Last updated” date and, for material changes, provide additional notice (for example, in-app or email) when appropriate.
12. Contact
Questions about privacy: [OPERATOR_PRIVACY_EMAIL]
Operator: [OPERATOR_LEGAL_NAME]