Privacy Policy

Last updated: 10 June 2026

This policy explains how The TCG OS (“we”, “us”, the “Service”) collects, uses, and protects your personal data when you use the platform at thetcgos.com. It covers the data we receive when you sign in with Google.

Who we are

The TCG OS is the data controller for the personal data described in this policy. You can contact us about privacy or your data at privacy@thetcgos.com.

Data we collect

Account & sign-in

  • Google sign-in: when you choose “Continue with Google”, we receive your name, email address, and profile picture. We request only the basic openid, email, and profile scopes — we do not request access to Gmail, Drive, contacts, or any other Google service.
  • Email (magic-link) sign-in: if you sign in with an email link instead, we collect your email address.

Sign-in details are stored as your account record. Your authenticated session is held in an encrypted cookie (we use a JSON Web Token rather than a server-side session store).

Content you create

As you use the Service we store the content you add, which may include:

  • your card collection, wishlist, and binders;
  • your public profile, follows, and activity feed; and
  • if you open a shop as a vendor: your inventory, listings, and trade/sale records.

How we use your data

  • to create and secure your account and authenticate you;
  • to provide the collector, vendor, marketplace, and social features you use; and
  • to operate, maintain, and improve the Service.

We do not sell your personal data, and we do not use third-party advertising or cross-site ad-tracking.

Cookies and analytics

We use a strictly-necessary cookie to keep you signed in (an encrypted session token). With your consent, we also use Google Analytics to understand how the site is used — for example, which pages are visited — so we can improve it. Analytics cookies are set only after you accept them in the cookie banner; decline and no analytics cookies are stored. You can withdraw consent at any time by clearing this site’s cookies and storage in your browser. We do not use analytics for advertising or to track you across other websites.

Service providers

We share data with a small set of processors that operate the Service on our behalf:

  • Google — sign-in / authentication, and (with your consent) Google Analytics for usage analytics;
  • Resend — sending sign-in (magic-link) emails;
  • Vercel — application hosting;
  • Neon — database (PostgreSQL) where your account and content are stored.

For vendors, when those features are enabled we also use:

  • Stripe — payments and subscription billing; and
  • eBay — to publish and manage your listings when you connect an eBay account.

Your data and Google

The TCG OS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use the basic profile data Google provides only to create and operate your account.

Legal basis (UK GDPR)

We process your data under the UK GDPR and the Data Protection Act 2018. Our lawful bases are: performance of a contract (providing the Service you sign up for), our legitimate interests (securing and improving the Service), and consent where it applies.

Your rights

You have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. To exercise any of these, email privacy@thetcgos.com. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).

Retention & deletion

We keep your data for as long as your account is active. To delete your account and associated personal data, email privacy@thetcgos.com and we will action your request. (We do not yet offer one-click self-service deletion in the app.)

Changes to this policy

We may update this policy from time to time. The “Last updated” date above reflects the latest version.

See also our Terms of Service.