Legal
Privacy Policy
Last updated: 17 May 2026 · Effective immediately
ShowBinder is a tool for Pokémon card show vendors to publish their inventory online. This policy explains what data we collect, why, and what your rights are under UK and EU GDPR.
At a glance
We collect only what's needed to run your account and show your inventory to buyers. We don't sell your data, we don't run ads, and we don't track you across other sites. You can delete your account and all your data at any time by emailing us.
1. Who runs ShowBinder
ShowBinder is operated as a sole-trader project by Arlen Mardoian, based in the United Kingdom. For the purposes of UK GDPR and EU GDPR, Arlen Mardoian is the data controller.
For any privacy questions, requests or complaints, contact [email protected].
2. What data we collect
If you sign up as a vendor
- Account data: your email address and a password (hashed, never stored as plain text), or your Google/Discord profile basics (name, email, avatar URL) if you sign in using one of those.
- Profile data: your vendor or store name, optional social handle, optional social profile URL, and an optional profile photo you choose to upload.
- Inventory data: the cards, prices, conditions, grades and other details you choose to list. This data is intended to be public — it's the whole point of the service.
If you're a buyer browsing a vendor page
No account is required and we don't ask you for anything. Standard technical logs (IP address, browser type, timestamp) are kept by our hosting provider Cloudflare for security and abuse-prevention purposes. We don't link these to any individual identity.
If you contact us via the contact form
Your name, email address and message are sent to us through our email delivery provider Brevo. We use this only to reply to your enquiry.
We do not use analytics tools, advertising trackers, or cross-site cookies on ShowBinder.
3. Why we collect it and our legal basis
- Account data — to create and operate your account. Legal basis: contract.
- Profile and inventory data — to display your inventory to buyers as you've requested. Legal basis: contract.
- Technical logs — to keep the service secure and prevent abuse. Legal basis: legitimate interest.
- Contact form messages — to respond to enquiries. Legal basis: legitimate interest.
4. Who we share it with
We only share data with the third-party processors needed to run the service:
- Supabase — hosts our database and handles authentication (including Google and Discord sign-in). Data is stored in the EU.
- Cloudflare — hosts our website and provides DNS, caching and security.
- Brevo — delivers contact form submissions to our inbox.
- Google / Discord — if you choose to sign in using one of these providers, they verify your identity and share basic profile info (name, email, avatar) with us.
We do not sell or rent your personal data to anyone, ever. We do not share it for advertising or marketing.
5. Where your data is stored
Our database is hosted in the European Union. Our hosting, CDN and email providers may process data across regions including the UK, EU and US, all under standard data protection safeguards (Standard Contractual Clauses where applicable).
6. How long we keep it
- Account, profile and inventory data: for as long as your account is active. We delete it when you ask us to, or within 90 days of you closing your account.
- Technical logs: typically 30 days, set by our hosting provider.
- Contact form messages: until your enquiry is resolved, plus up to 12 months for our records.
7. Your rights
Under UK GDPR and EU GDPR you have the right to:
- Ask what data we hold about you (right of access)
- Ask us to correct anything that's wrong (right to rectification)
- Ask us to delete your data (right to erasure)
- Ask us to restrict or stop processing your data (right to restriction / objection)
- Get a copy of your data in a portable format (right to data portability)
- Withdraw consent at any time where we rely on consent
- Lodge a complaint with the UK ICO (ico.org.uk) or your local EU data protection authority
To exercise any of these, email [email protected] and we'll respond within 30 days.
8. Cookies and tracking
We use a small amount of essential browser storage (localStorage) to keep you signed in when you return to the vendor dashboard. This is technical and required for the service to work — no cookie banner needed under PECR. We do not use analytics cookies, advertising cookies, or any cross-site tracking.
9. Children
ShowBinder is intended for adults running a card vendor business. We don't knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we'll delete it.
10. Changes to this policy
If we make material changes we'll update the "Last updated" date at the top and, where appropriate, notify active vendors by email.
11. Contact
Questions, requests, or complaints: [email protected]