Legal
Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how TRAlART(“TRAlART”, “we”, “us”) collects, uses, and protects your personal data when you use our virtual-binder web application (the “Service”). We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, or “GDPR”) and Italian Legislative Decree no. 196/2003 (the “Italian Privacy Code”), as amended by Legislative Decree no. 101/2018.
1. Data controller
The Service is operated and its data controlled by an individual based in Italy. TRAlART is a single-person, non-commercial project, so we do not publish a postal address; you can reach the controller for any privacy matter — including a request for our full identity and postal contact details — at [email protected]. Where the law requires it, we will provide those details directly to you or to the supervisory authority. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; the contact above handles all data-protection enquiries.
2. What data we collect
We collect only what the Service needs to work:
- Account data. When you register, we store your email address, an optional display name, and a securely hashed version of your password (we never store passwords in plain text). If you sign in through a third-party provider (for example Discord or Google), we receive your email address, a display name, and an avatar image from that provider, plus the access and refresh tokens needed to keep you signed in.
- Your binders. The collections you build — which cards you add, how you arrange them, cover art, and any custom slice art you upload — are stored so you can return to them across devices.
- Sharing status. Whether a binder is private or public. Binders are private by default; a binder appears in the public showcase only if you choose to make it public.
- Technical data. A strictly necessary session cookie (a signed token) keeps you logged in. Our servers may process your IP address and browser information transiently to deliver pages and protect against abuse; we do not build advertising or tracking profiles.
We do notuse analytics or advertising cookies, and we do not sell your personal data. If you use the Service as a guest without an account, your binder is kept only in your browser’s local storage and is not sent to us until you sign in.
3. Why we process your data, and our legal basis
- To provide the Service — creating your account, saving and syncing your binders, and signing you in. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- To keep the Service secure and working — preventing abuse, debugging, and maintaining reliability. Legal basis: our legitimate interests (Article 6(1)(f) GDPR).
- To show a binder publicly when you choose to share it. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by making the binder private again.
- To comply with the law where we are legally required to. Legal basis: legal obligation (Article 6(1)(c) GDPR).
4. Card data and images
Card names, text, and artwork shown in the Service are fetched from third-party card databases and are the property of their respective rights holders (for example Bandai, The Pokémon Company, Nintendo, Bandai Namco, and Riot Games). TRAlART is an independent fan project and is not affiliated with, endorsed by, or sponsored by any of them. This card data is not your personal data.
5. Who we share data with
We share personal data only with service providers who help us run the Service, acting as our data processors under Article 28 GDPR:
- our hosting and database providers, which store the Service and your binders;
- the authentication providers you choose to sign in with (for example Discord or Google), which process your login on our behalf.
We do not sell or rent your personal data to anyone.
6. International transfers
Some of our providers may process data outside the European Economic Area. Where that happens, the transfer is protected by an adequacy decision of the European Commission or by Standard Contractual Clauses (Article 46 GDPR), so your data keeps an equivalent level of protection.
7. How long we keep your data
We keep your account and binder data for as long as your account exists. If you delete your account, we delete the associated personal data without undue delay, except where we must keep certain records to meet a legal obligation. Transient technical logs are kept only for as long as needed for security and reliability.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these rights, email us at [email protected]. You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the authority in your country of residence.
9. Children
The Service is not directed at children. In Italy, users must be at least 14 years oldto consent to online services under Legislative Decree no. 101/2018; below that age a parent or guardian’s consent is required. If you believe a child has given us personal data, contact us and we will delete it.
10. Security
We apply appropriate technical and organisational measures to protect your data, including hashing passwords, encrypting traffic in transit (HTTPS), and a strict content-security policy. No method of transmission or storage is completely secure, but we work to keep your data safe.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the Service.
12. Contact
Questions about this policy or your data? Email [email protected].