Privacy Policy
Last updated: January 2025
1. Data Controller
The data controller responsible for processing your personal data on deckdiver.app is identified in our Legal Notice (Impressum). For data protection inquiries, please contact us at the email address provided there.
2. Data We Collect
We collect and process the following categories of personal data:
Account Data
- Email address (for account identification and communication)
- Username (for display purposes)
- Password (stored only as a secure bcrypt hash, never in plain text)
- Subscription tier and status
Technical Data
- IP address (for security and abuse prevention)
- Browser type and version
- Session identifiers
Usage Data
- Search queries and filter preferences
- Saved deck lists and preferences
Payment Data
Payment processing is handled entirely by Stripe. We do not store credit card numbers or full payment details. We only receive confirmation of payment status, subscription ID, and billing period from Stripe.
3. Legal Basis for Processing (Art. 6 GDPR)
We process your data based on the following legal grounds:
Contract Performance (Art. 6(1)(b) GDPR)
- Account data: Required to provide and manage your account
- Session cookies: Required for authentication and service functionality
- Payment processing: Required to fulfill subscription services
- Usage data (searches, saved lists): Required to provide core service features
Legitimate Interest (Art. 6(1)(f) GDPR)
- Server logs (IP address, request data): Security, abuse prevention, and service stability
- Rate limiting data: Preventing abuse and ensuring fair usage
4. Data Retention
We retain your data for the following periods:
- Session data: Until logout or session timeout (typically 24 hours of inactivity)
- Account data: Until you delete your account, plus any statutory retention periods
- Server logs: 30 days
- Payment records: 10 years (required by German tax law)
- Saved preferences and lists: Until you delete them or your account
5. Third-Party Recipients
Your data may be shared with the following third parties:
Stripe (Payment Processing)
Stripe, Inc. (USA) processes all payments. When you subscribe, your payment data is sent directly to Stripe. Data transfer to the USA is covered by Stripe's adherence to Standard Contractual Clauses (SCCs). See Stripe's Privacy Policy.
Hetzner (Hosting Provider)
Hetzner Online GmbH (Germany) hosts our servers. Your data is stored on servers located in Germany within the EU. See Hetzner's Privacy Policy.
Scryfall (Card Data)
We use Scryfall's API to display Magic: The Gathering card images and data. When viewing cards, your browser may load images directly from Scryfall's servers. See Scryfall's Terms.
We do not sell your data to any third parties. We do not use advertising networks, analytics trackers, or social media plugins that would share your data with those services.
6. Cookies
We use only technically necessary cookies for authentication and session management. These cookies are essential for the service to function and do not require your consent under Article 5(3) of the ePrivacy Directive and Section 25(2) of the German TDDDG.
Session Cookie
- Purpose: Maintains your login state and session
- Duration: Deleted when you log out or close your browser (session cookie)
- Legal basis: Technically necessary (no consent required)
We do NOT use: Analytics cookies, tracking cookies, advertising cookies, social media cookies, or any third-party cookies. Your browsing is not tracked or profiled.
7. Your Rights (GDPR Articles 15-21)
Under the General Data Protection Regulation, you have the following rights:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you
- Right to Rectification (Art. 16): Request correction of inaccurate data
- Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to Restriction (Art. 18): Request limitation of processing in certain circumstances
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
To exercise these rights, contact us at the email provided in our Legal Notice. We will respond within one month as required by GDPR.
8. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Germany, you may contact the data protection authority of the federal state where we are located, or the authority of the state where you reside.
A list of German data protection authorities is available at: www.bfdi.bund.de
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All connections encrypted via HTTPS/TLS
- Passwords stored using bcrypt with salt (never stored in plain text)
- Rate limiting to prevent brute-force attacks
- Regular security updates and monitoring
- Access to personal data limited to what is necessary
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. For significant changes affecting your rights, we will notify you via email (if you have an account) or a prominent notice on our website.
11. Contact
For questions about this Privacy Policy or to exercise your data protection rights, please contact us at the address provided in our Legal Notice or via our contact page.