Poketrax
PrivacyTermsCookies

Privacy Policy

Last updated: 25 June 2026

This Privacy Policy explains how Poketrax ("Poketrax", "we", "us", "our") collects, uses, and protects your personal data when you use the Poketrax website and application at poketrax.co.uk (the "Service").

Poketrax is a Pokémon Trading Card Game price-aggregation service. We take your privacy seriously and handle your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


1. Who we are (Data Controller)

The data controller responsible for your personal data is:

  • Company: Strife Solutions Ltd (trading as Poketrax)
  • Company number: 13416557
  • Registered address: update me
  • Contact email: contact@poketrax.co.uk

For any questions about this policy or your personal data, or to exercise your rights, contact us at contact@poketrax.co.uk.


2. What data we collect

We collect the following categories of personal data:

2.1 Account data

When you create an account, our authentication provider (Clerk) collects and stores your email address, name (if provided), a securely hashed password or third-party sign-in identifier (e.g. Google), and authentication metadata such as sign-in timestamps and session tokens. We do not store your raw password — authentication is handled by Clerk.

2.2 Billing data

When you subscribe to a paid plan or start a free trial, our payment processor (Stripe) collects your payment-card details, billing name, billing address, and country. We never see or store your full card number — Stripe processes payments directly and provides us only with limited information (such as the last four digits of your card, card brand, subscription status, and plan tier) needed to manage your subscription.

2.3 Product and usage data

We store the data you create within the Service, including your owned-card collection, wishlists, watchlist targets, grading recommendations, blocked-seller lists, and search history. By default, each record is associated with your account and kept separate from other users' data. Some optional features let you share parts of your data with other members or publicly — see Section 2.6.

2.4 Analytics data

We use PostHog (hosted on its EU cluster) to understand how the Service is used. This includes events such as pages viewed, features used (e.g. card searches, watchlist saves, checkout completions), device and browser type, approximate location derived from IP address, and referral source. Analytics requests are routed through our own domain to function reliably; analytics are only active where configured and can be limited by your browser settings.

2.5 Technical data

Our servers and infrastructure automatically log technical information including IP address, browser user-agent, request timestamps, and error diagnostics, for security, debugging, and abuse prevention.

2.6 Information you choose to share

Some optional features let you make parts of your collection data visible to others. They are off by default and under your control:

  • Public collection showcase — if you turn on a public profile, the collection you choose to display becomes viewable by anyone with the link and may be indexed by search engines. You can make it private again at any time.
  • Shareable watchlist link — if you create a read-only watchlist share link, anyone with that link can see the cards on it. It never exposes your buy/sell targets or notes, and you can disable or rotate the link at any time.
  • Trade matching — if you opt in, the limited details needed to surface a potential trade (such as cards you mark as available for trade and items on your wishlist) may be shown to other members you match with. You are identified to them only by an opaque public identifier, never your email address.

Outside these features, your data stays isolated to your account.

2.7 Marketing and waitlist sign-ups

If you join a waitlist or sign up for product updates without creating an account, we collect the email address you provide (and which list you joined) so we can send the updates you asked for. We use double opt-in — you must confirm via a link we email you before we add you — and every marketing email includes an unsubscribe link you can use at any time.

We do not intentionally collect special-category data (e.g. health, ethnicity, political opinions). Please do not submit such data to the Service.


3. How and why we use your data (lawful bases)

Purpose Data used Lawful basis (UK GDPR)
Create and operate your account Account data Contract (Art. 6(1)(b))
Provide the price-aggregation Service and store your collection Product/usage data Contract
Process subscriptions, trials, and payments Billing data Contract
Send service and transactional emails (e.g. trial expiry, receipts) Account, billing data Contract / Legitimate interests
Understand and improve the Service Analytics data Legitimate interests (Art. 6(1)(f))
Maintain security, prevent fraud and abuse Technical data Legitimate interests / Legal obligation
Comply with legal and tax obligations Billing data Legal obligation (Art. 6(1)(c))
Send marketing communications and waitlist updates Account or marketing sign-up data Consent (Art. 6(1)(a))

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You can object to such processing at any time (see Section 8).


4. Sub-processors and third parties

We share personal data with the following service providers ("sub-processors") who process it on our behalf under appropriate contractual safeguards:

Sub-processor Purpose Location
Clerk Authentication and user-account management United States
Stripe Payment processing and subscription billing United States / EU / UK
PostHog Product analytics (EU cluster) European Union
Resend Transactional and marketing email delivery United States
Hetzner Server hosting and infrastructure Germany (EU)
Backblaze (B2) Encrypted off-site backups United States

We do not sell your personal data to third parties. We may disclose data where required by law, court order, or to protect our legal rights.


5. International data transfers

Some of our sub-processors are located outside the UK and EEA (notably Clerk, Stripe, Resend, and Backblaze in the United States). Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision/data bridge where one applies. You can request details of these safeguards by contacting us.


6. How long we keep your data

We retain your personal data only as long as necessary:

  • Account and product data — for the lifetime of your account. If you delete your account, we delete or anonymise this data within 30 days, except where retention is required by law.
  • Billing records — retained for 6 years to meet UK accounting and tax obligations.
  • Analytics data — retained in aggregated/pseudonymised form for up to 24 months.
  • Backups — encrypted backups are retained on a rolling basis (local retention of 7 days plus off-site lifecycle retention) and are overwritten in the normal backup cycle.

7. Cookies and similar technologies

We use cookies and similar technologies for essential functions (e.g. keeping you signed in via your authentication session) and for analytics. Essential cookies are required for the Service to work. Non-essential analytics cookies are used in accordance with the Privacy and Electronic Communications Regulations (PECR) and your choices. You can control cookies through your browser settings; disabling essential cookies may prevent the Service from functioning. See our Cookie Policy for full details.


8. Your rights

Under the UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data ("right to be forgotten"), subject to legal retention obligations.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests, or to direct marketing.
  • Withdraw consent — where we rely on consent, withdraw it at any time.

To exercise any right, email contact@poketrax.co.uk. We will respond within one month. You also have the right to lodge a complaint with the UK's Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113, though we ask that you contact us first so we can try to resolve your concern.


9. Security

We implement appropriate technical and organisational measures to protect your data, including encrypted backups, per-user data isolation, secure (TLS) connections, secrets management, and restricted administrative access. No system is completely secure, but we work to protect your information and will notify you and the ICO of any qualifying personal-data breach as required by law.


10. Children

The Service is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.


11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Material changes will be notified to you by email or an in-app notice.


12. Contact

Questions, requests, or complaints: contact@poketrax.co.uk Strife Solutions Ltd (trading as Poketrax), update me

© 2026 Strife Solutions Ltd (trading as Poketrax)Privacy·Terms·Cookie Policy·