Effective from: 8 September 2026
01 Who we are
TCGshopkeeper (the “Extension”, formerly Cardmarket Buyout Helper) is a Chrome browser extension operated by IamLadi s.r.o., č.p. 332, 739 45 Fryčovice, Czech Republic, company ID 09877169, VAT ID CZ09877169, registered in the Commercial Register kept by the Regional Court in Ostrava, section C, insert 84636.
Contact for anything in this policy: [email protected].
02 What the Extension does
The Extension helps a trading-card vendor run a buyout: it reads the Cardmarket.com page you are viewing, calculates a buying price, and keeps the resulting buyout list, wishlist and contract template on your device.
03 The most important part
This is a change from the previous version of this policy. The earlier version said we operate no server and that the Extension transmits nothing. That is no longer the whole picture: the Extension can now create an optional Account, and that Account lives on our servers.
What has not changed and will not: the Bag stays on your device. The
Bag is the contents of the browser’s local storage (chrome.storage.local)
on this device — buyout lists, wishlists, settings and contract templates.
We do not store buyout lists on our servers. Sign-in is not required to
capture cards, keep lists, export, or make a local backup.
Also unchanged: the personal data of the seller you sign a purchase contract with never reaches us. See § 06.
The Extension still contains no advertising and loads no remote code.
04 Your account
The Account is optional. You can use the Extension without signing in.
You may sign in with a Google account or with an email address. Signing in is how you pay, receive a grant of the paid features (PRO), and unlock PRO on another device when you sign in there.
At Google sign-in Google sends us your email address, your account name, your profile picture and your Google account identifier. We keep only the email address and the account identifier. The name and the picture are discarded as the Account is written and are never stored. We do not request access to your mail, your contacts, or any other Google service.
At email sign-in we use the address you type and send a one-time code to it. We do not request access to your mailbox.
We use the Account only to know who you are, to record whether you may use PRO (Entitlement), and to manage a paid subscription.
Google account data is used only for that Account. We do not use it for advertising, we do not sell it, and we do not combine it with the Bag — the Bag never leaves the device.
05 What we store on our servers
If you never sign in, we store nothing about you on our servers.
If you create an Account, we store:
- Identity — email address; if you signed in with Google, also your Google account identifier.
- Entitlement — whether the Account may use PRO, from a grant we recorded or from an active subscription.
- Billing — subscription status and a Stripe customer identifier. Payment card details never reach us (§ 11).
- Sign-in session — while you stay signed in on a device, the IP address and the browser identification of that sign-in. Signing out on that device deletes them.
We do not store buyout lists, wishlists, settings, contract templates, or any other part of the Bag. Evidence codes and stock codes stay on the device with the list they belong to.
Access to Account data on the server is held by the company’s director alone.
06 What never reaches us
When you generate a purchase contract you fill in the seller’s details — name, permanent address, date of birth, and optionally a bank account number.
Those details never leave your device. They are not transmitted and not stored anywhere — not on our servers, and not in the browser’s local storage. They exist only while the contract dialog is open, and disappear when you close it.
The finished contract does not reach us either. It is produced inside your browser. You print it or save it to your computer, and at that point it has left our systems.
This is a deliberate architectural decision, not a coincidence. It means we cannot offer server-side reprinting of a contract — and it means your customers’ personal data cannot leak from us, because we do not have it.
07 Data on your device
The Bag lives in the browser’s local storage (chrome.storage.local) on this
device. It is not a working copy of a server record. It is the record.
Exports (XLSX) and JSON backups (Záloha) — including the automatic weekly backup — are saved as ordinary files to your computer through the browser’s download mechanism. They do not leave your computer unless you move them yourself. A backup does not create an Account and does not upload the Bag.
Removing the Extension from Chrome deletes its local storage (that is how Chrome works). Files you already saved stay on disk. An Account, if you have one, is not deleted by removing the Extension — for Account deletion see § 13.
08 Browser permissions in plain language
storage,unlimitedStorage— local storage of your buyout data; “unlimited” only raises the local quota for large histories and backups.identity— signing in with a Google account. This permission gives no access to the contents of your Google account.sidePanel— the Extension’s user interface (the side panel).declarativeNetRequest— a single static rule that lets card previews from Cardmarket’s own image CDN display in the side panel. No other requests are observed or modified.downloads,alarms— saving exports and the scheduled local backup.cookies— a rescue tool for one specific fault: when Cardmarket returns HTTP 431 because its cookies have grown too large, the Extension offers a one-off clear of cardmarket.com cookies (Cloudflare verification cookies are kept). It runs only on your click; cookies are not read, stored or transmitted for any other purpose.
09 How we measure usage
We do not record what you buy. Buyout lists never reach our servers, so we cannot analyse which cards, sets or games you captured. There is no switch for aggregate buyout analysis — there is nothing on the server to switch off.
When you use an Account, we keep the records in § 05 and § 11. We do not add a log of captures, contracts, or exports.
The Extension and the account service do report their own errors. When something goes wrong, a report goes to Sentry so that we can find the fault and fix it. The report carries the error message, the technical stack trace, the version of the Extension, and whether the build is a published one or a test one.
Everything the tool collects on its own is switched off: no local variable values, no cookies, no request or response headers, no request bodies, no URL query strings, no trail of what you clicked, and no user identity. No IP address is stored, and no location derived from one. Before a report leaves your browser, its text is searched for anything shaped like an identification number, a bank account, an IBAN, an e-mail address or an access token, and those are replaced.
Seller details from the contract dialog are not in an error report. They exist only as values inside the running page, and the collection of those values is switched off. § 06 still holds.
Only a published build reports at all. A development build sends nothing.
10 Your customers’ data and GDPR
If you enter your customers’ personal data into the Extension (for example when generating a purchase contract), you are their controller within the meaning of the GDPR.
This holds because that data never travels to us (§ 06) and because the Bag stays on your device (§ 07). We are not its processor. You meet your own information obligations toward your customers; we are not party to that relationship.
11 Who we share data with
We do not sell data and do not share it for marketing. We use these processors to run the Account and billing:
| Processor | For what | Where |
|---|---|---|
| Supabase Pte. Ltd. | authentication and Account records | hosted in the EU (Ireland); the company is based in Singapore, transfer relies on Standard Contractual Clauses |
| Cloudflare, Inc. | the API between the Extension and the Account service | a US company. The API runs in the Cloudflare data centre nearest you, and request metadata is processed in the EU and the United States. Standard Contractual Clauses and the EU-US Data Privacy Framework |
| Google Ireland Ltd. | Google account sign-in | EU |
| Plus Five Five, Inc. (Resend) | delivering the one-time sign-in code by email | United States, Standard Contractual Clauses and the EU-US Data Privacy Framework |
| Stripe Payments Europe, Ltd. | payments and subscriptions | EU/US, Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | receiving error reports from the Extension and from the API | error reports are stored in the EU (Frankfurt, Germany), fixed when the organisation was created and not changeable afterwards. The company is based in the United States and keeps account data, organisation settings and access keys there. EU-US Data Privacy Framework, with Standard Contractual Clauses as the fallback |
Payment details never reach us. Payment happens on Stripe’s pages; we receive only whether a subscription is active, and a customer identifier.
The sign-in code travels through an email provider. If you sign in with an email address, the message carrying your one-time code is delivered by Resend and stored on their servers in the United States for 30 days. That message contains your email address and the code, and nothing else. The code stops working within an hour and cannot be used twice. We send you no other email about the Account.
Who inside the company can see Account data and usage statistics. Usage statistics here means the Web Store’s install and user figures and queries over the Account records described in § 05; we run no analytics product and no event tracking (§ 09). Access to any of it at the level of an individual Account — including the admin screens that show a named Account and its PRO state — sits with Ladi alone, the contact named in § 01. Anyone else working on the product, including Tom, receives aggregate figures only and never per-Account records.
Error reports are held in Germany by a US company. The Sentry organisation was created in its EU region, which is what fixes where error events are stored; that choice cannot be undone afterwards. Sentry’s published list of sub-processors, version 2.3.0 effective 1 June 2026, names AI vendors in the United States. Those serve features we keep switched off.
The Extension is not affiliated with Cardmarket or Google; your use of Cardmarket itself is governed by its own terms and policies.
12 Lawful basis
- Performance of a contract (Art. 6(1)(b) GDPR) — your Account, Entitlement, and subscription.
- Legal obligation (Art. 6(1)(c) GDPR) — retention of accounting records.
- Legitimate interest (Art. 6(1)(f) GDPR) — error reports, so that faults in the Extension can be found and fixed. A report carries no identity, no IP address and no location.
If you never create an Account, the first two bases do not apply: we hold no Account data about you. Error reporting does not depend on an Account, and works the same either way.
13 How long we keep data
| Data | Period |
|---|---|
| Account identity and Entitlement records | until you delete your Account, then permanently deleted |
| Subscription status | until you delete your Account, then permanently deleted |
| Stripe customer identifier | until you delete your Account, then permanently deleted |
| Error reports | 30 days, then deleted by Sentry |
| Accounting and tax records | 10 years — required by law; we cannot delete these earlier, even on request |
Error reports are not tied to an Account and are not affected by deleting one; they carry nothing that identifies you, and Sentry deletes them on the schedule above.
Deleting the Account removes identity, Entitlement, subscription status, and the Stripe customer identifier. Those billing fields are not accounting or tax records. It does not delete the Bag on your device. Removing the Extension deletes the Bag on that device; a Záloha file you already saved is how you keep a copy.
14 Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, portability and objection. Exercise them at [email protected]; the built-in Export will give you the Bag in a machine-readable form at any time.
You may lodge a complaint with the Office for Personal Data Protection (uoou.gov.cz).
15 Changes to this policy
If the Extension’s behaviour changes in a way that affects this policy, we will update this page and note the change in the Extension’s release notes before the change ships.
© 2026 IamLadi s.r.o. · company ID 09877169