Privacy Policy

This is a non-binding translation for convenience — the German version is legally authoritative.

Last updated: September 24, 2026

1. Controller

Responsible for data processing on this website is: Andreas Härtel, Rheinstrasse 2, 64319 Pfungstadt, Email: support@lumex-tcg.de

2. What data we process

Account & collection: When you register, we process your email address and a (hashed) password. After signing in, we process the collection, deck, and wishlist data you enter in order to provide you the service (Art. 6(1)(b) GDPR — contract performance).

Sign in with Google: If you sign in with your Google account, we receive your email address, name, and profile picture from Google to create or sign you into your Lumex account (Art. 6(1)(b) GDPR – contract performance). This data is not shared with third parties and is not used for any other purpose.

Server logs: When you access the site, technically necessary data (IP address, timestamp, user agent) is processed by our hosting provider (Art. 6(1)(f) GDPR — legitimate interest in operation and security).

3. Processors / hosting

Vercel: The web app is hosted via Vercel. A data processing agreement is in place with Vercel.

Vercel Analytics & Speed Insights: In addition to hosting, we use Vercel Analytics and Speed Insights for anonymized, cookieless evaluation of page views and load times (Art. 6(1)(f) GDPR — legitimate interest in operating and improving the service). No cookies are set and no personal profiles are built.

Upstash: For rate limiting on certain API routes (including Archidekt import, tournament calculator), we use Upstash Redis; your IP address is processed briefly to prevent abuse (Art. 6(1)(f) GDPR — legitimate interest in abuse prevention). A data processing agreement is in place with Upstash.

Supabase: Authentication and database run via Supabase (EU region, eu-west-1). Your collection and account data is stored there. Access is restricted to your own account via row-level security.

Sentry: We use Sentry (EU region) for error tracking; this processes error reports including your IP address and device/browser information (Art. 6(1)(f) GDPR — legitimate interest in reliable, error-free operation). No recording of user interactions (session replay) takes place. A data processing agreement is in place with Sentry.

Firebase (Google): We use Firebase Cloud Messaging (FCM) from Google to send push notifications. A data processing agreement is in place with Google (Firebase Data Processing Terms); see Section 9 for details on the processing and the transfer to the US.

4. Cookies

We use exclusively technically necessary cookies to manage your login session. There is no tracking and no advertising.

5. Retention period

Your account data and collection contents are stored until you delete your account. On request to support@lumex-tcg.de, we delete your account along with the associated data. In addition, chat messages (see Section 10) and reports (see Section 12) are deleted automatically 12 months after they were created.

6. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a supervisory authority. Contact support@lumex-tcg.de for this.

7. External card content

Card images are loaded from third-party providers (including the Scryfall CDN and pokemontcg.io). Your IP address may be transmitted to these providers in the process (Art. 6(1)(f) GDPR).

8. External content in the app (news feed)

The news feed in the Lumex app primarily fetches RSS feeds via the third-party service rss2json.com as a JSON proxy, to work around Cloudflare/CORS restrictions on direct RSS fetches from mobile devices (only if that fails does it fall back to a direct RSS/Atom fetch). In doing so, the fetched feed URL and your IP address are transmitted to rss2json.com (Art. 6(1)(f) GDPR — legitimate interest in a reliable news feed).

9. Push notifications

If you allow push notifications, we process a device token generated by Firebase Cloud Messaging (FCM) (token, platform Android/iOS, timestamp), which we associate with your account to deliver you two types of notifications (Art. 6(1)(b) GDPR — providing the feature you activated):

Wishlist price alert: The notification contains the card name and current price in plain text (for example, “Lightning Bolt is now available for €2.50”) — visible only to you as the recipient, but technically transmitted to Google.

New chat message: The notification only names the alias of the person writing to you (for example, “New message from Lightning_Trader”); when you write, the other person sees your alias in the same way. The message text itself is not transmitted to Google.

Lock screen: If your device shows notification content on the lock screen, that also shows the card name and price of a price alert, or the alias of your chat partner, in plain text — visible to anyone holding your locked device, even without unlocking it. Lumex does not control this visibility itself; whether and how much notification content your lock screen shows is a setting in your device's notification settings (depending on the manufacturer, often under “sensitive/private notifications” or “lock screen content”).

Delivery runs via Firebase Cloud Messaging, operated by Google Ireland Limited; processing may also be carried out by Google LLC (USA) as a sub-processor. A data processing agreement is in place with Google (Firebase Data Processing Terms). Based on our current assessment, the transfer to the US relies on Google's self-certification under the EU-US Data Privacy Framework, alternatively on EU standard contractual clauses. You can disable push notifications at any time via your device permissions, and per conversation via muting.

10. Messages between users (chat)

If you chat with a confirmed friend, we process the message text, timestamps (sent/delivered/read), an optional reference to a message being replied to, and, where applicable, an automatically attached reference to the trading context (offer/match/card) through which you found each other, in order to provide you the chat feature (Art. 6(1)(b) GDPR).

“Delivered” means the app has technically retrieved the message for the other side — not that it has been displayed or read. “Read” is only set once the other side opens the conversation.

End-to-end encryption is not used; messages are encrypted in transit like your other account data, but are stored in plain text in our database at Supabase (see Section 3).

Only you and your respective conversation partner can view a conversation; we do not routinely access its contents, except when reviewing a report (Section 12) or where required by law.

Retention: Each message is automatically deleted 12 months after it was sent (weekly cleanup run). A message also disappears as soon as both of you have deleted the conversation for yourselves; a conversation with no remaining messages is removed as well.

If the friendship ends, the existing history remains readable, but you can no longer send new messages.

If you delete your account, all messages you sent and received are permanently removed — this also affects your conversation partners' history.

11. Friends, trade offers, ratings, and share links

For the trading and community features, we additionally process:

Friends: We process friend requests and their status (pending/confirmed/declined/blocked/removed) as well as, if you send a request from within a trade offer, an optional note to the other person (Art. 6(1)(b) GDPR).

Trade offers & matches: We process which of your collection cards you mark as tradeable, as well as an automatic match against other users' wishlists (Art. 6(1)(b) GDPR). The result is a plain suggestion list with no legal or similarly significant effect on you — not an automated individual decision within the meaning of Art. 22 GDPR.

Trading profile: You can set a freely chosen alias instead of your real name, and optionally a postal code/city for local search (Art. 6(1)(b) GDPR — voluntary information for this additional feature). Your city is never shared with other users; your postal code is shown to others only shortened to its first three digits (for example, “641xx”).

Ratings: After a completed trade, you can rate each other (positive/neutral/negative, optional comment; Art. 6(1)(b) GDPR for submitting it). For fairness, a rating only becomes visible once both sides have rated, or automatically after 30 days at the latest. A rating is visible to all users with their own trading profile, not just to friends (Art. 6(1)(f) GDPR — legitimate interest in a working trust system for all trading participants, comparable to ratings on Cardmarket/eBay).

Share links: You can generate a link for your trade list, wishlist, or an individual deck (Art. 6(1)(b) GDPR). Anyone who knows the link can view the shared content — for the trade list, this includes your alias and requires a prior login; for the wishlist and deck, no login and no name are required, only the card/deck contents. A link remains valid until you revoke it via “Refresh link”; the old link is invalidated immediately afterward.

Retention: Friendships, trade offers, matches, and ratings remain in place until you remove them yourself, and are deleted at the latest when your account is deleted.

12. Reporting and blocking

If you report a conversation, we process your user ID, the ID of the reported person, the affected chat, and your reason (Art. 6(1)(f) GDPR — legitimate interest in a safe environment free of abuse). Reports are visible exclusively to us as the operator — not to the reported person, and not retroactively to you either. We use reports for manual review of abuse cases; no automated suspension takes place. Reports are automatically deleted 12 months after they are created.

You can also block other users: a blocked person can no longer send you friend requests or messages; only you can undo the block (Art. 6(1)(b)/(f) GDPR).

13. Beta tests

If you submit a test plan via /beta, we process the name or alias you provide, the version and kind of test plan (full/delta), and your input per test case — checked or not, with an optional comment. This runs without an account and without any link to an existing Lumex account (Art. 6(1)(f) GDPR — legitimate interest in structured beta feedback ahead of a release).

The public results page for a test plan version shows only how often each test case was checked overall (for example, “7/9”). Your name or alias and your comments never appear there — they remain visible to the Lumex team only.

Retention: Each submission is deleted completely 12 months after it was made (weekly cleanup run) — not just the name, but the entire row including all test case results. The corresponding counts on the results page disappear accordingly.