TOPLOADDE

Privacy Policy

Last updated: 26 September 2026

This policy covers the website gettopload.com and the Topload app for iOS. It tells you which data we process, why, for how long — and what rights you have.

1. Controller

Klemens Kaindl
Wien, Austria

Email: access@gettopload.com

For any privacy question, an informal email is enough. We are not required to appoint a data protection officer under Art. 37 GDPR.

2. In short

  • No cookies, no tracking, no ads — neither on the website nor in the app. Fonts and scripts are served from our own server.
  • Your collection is stored in the EU (Supabase, Paris region). Only you can see it.
  • Scan photos exist to recognise cards. The downscaled photo stays in your scan history for at most 365 days; the original is stored only with your explicit consent — and for at most 180 days.
  • We never see payment data. Topload Pro is billed by Apple.
  • Delete your account anytime in the app (Profile) — this removes all data, photos and the subscription customer at RevenueCat.

3. Website gettopload.com

3.1 Hosting and server logs

The website is delivered by Vercel Inc. (USA). When you visit, Vercel processes technically necessary connection data in server logs: IP address, time, requested page, referring page and browser identifier. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Vercel keeps these logs only briefly; we do not analyse them. Vercel is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply in addition.

3.2 No cookies, no analytics

gettopload.com sets no cookies, embeds no analytics or advertising services and loads no external fonts. That is why there is no cookie banner.

3.3 Waitlist (early access)

When you join the waitlist, the form sends to our database at Supabase (Paris region): your email address, the chosen language, whether you expressed interest in Pro, the campaign parameters of the page address (UTM), the referring page and a salted hash of your IP address. The hash only serves to slow down bulk signups, cannot be traced back to you and is deleted after 24 hours.

The purpose is to notify you once about the launch of the app and to see which channels signups come from. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by submitting the form. We secure the signup with double opt-in: you are only on the list once you click the link in our confirmation email.

You can withdraw your consent at any time — an email to access@gettopload.com is enough and we will delete the entry. We delete it anyway once we have notified you about the launch.

3.4 Contact by email

If you write to us, we process your address and the content of your message to answer you (Art. 6(1)(b) or (f) GDPR). We delete enquiries once they are resolved and no retention obligation applies.

4. Topload app

The app stores your data in our database at Supabase (Paris region, EU), protected by row-level access rules: your collection is readable by your account only. Unless stated otherwise below, the legal basis for all core features is the performance of our user agreement with you (Art. 6(1)(b) GDPR).

4.1 Account and sign-in

You sign in with your email address (login code by email) or via Sign in with Apple. From Apple we receive your Apple user identifier and — depending on your choice — your real email address or a relay address generated by Apple. We store your email address, an internal user ID, your display name and, if you set one, your profile picture. Profile pictures and images of custom cards are kept in publicly accessible storage — anyone with the link can view them. Do not upload anything there that should stay private.

4.2 Collection, portfolio and lists

The cards and products you add (condition, quantity, language, purchase price, purchase date), your transactions, wishlist, watchlist and price alerts. From this data we compute portfolio value and profit/loss. Market prices themselves are public, non-personal data; requests to price sources (Cardmarket, TCGplayer, PriceCharting, PSA, eBay) contain no user data.

4.3 Card scanning and photos

When you scan, the photo of the card is sent to our recognition service on Google Cloud Run (region europe-west1, Belgium) for matching. It is only compared there, not stored.

  • Downscaled photo (1280 px): We keep it in your scan history so you can review scans and add them to your collection later. It is deleted when you remove the entry or delete your account, and at the latest after 365 days (Art. 6(1)(b) GDPR).
  • Original full-resolution photo: Only with your explicit consent (opt-in in the app). Purpose: improving card recognition and testing new recognition models on real photos. The photos are kept in private EU storage, linked to your account, invisible to other users, and deleted after 180 days. You can withdraw your consent at any time under Profile → Privacy; we then delete the originals within one day (Art. 6(1)(a) GDPR).
  • Scan diagnostics: For each scan we store the recognised text fragments and the candidate list so we can trace and fix misidentifications (legitimate interest, Art. 6(1)(f) GDPR).

4.4 Search and “Trending”

We store search queries with your user ID to compute the “Trending” section from the most searched cards (Art. 6(1)(f) GDPR). You can object to this processing (see section 8).

4.5 Push notifications

Only if you allow notifications in iOS do we store your device’s push token and use it to send price alerts and notices via the Apple Push Notification Service (Art. 6(1)(a) GDPR). If you turn notifications off in iOS settings, the token is no longer used and is removed.

4.6 Topload Pro (subscription)

Purchase, billing and management of the subscription run through your Apple account (in-app purchase). Only Apple sees payment data. To verify your entitlement we use RevenueCat (USA): it receives subscription events such as purchase, renewal and expiry, linked to your user ID. We store only your purchase status (tier and expiry date). The transfer to RevenueCat is secured by the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).

4.7 Grading check

Photos for the grading check are processed for analysis (centering, corners, edges, surface). What we store is the report with measurements and prediction in your account, so you can open it again later.

4.8 Crash reports

Once we activate crash reporting, the app will send the error message, device type, iOS and app version and your user ID to Sentry (EU region, Frankfurt) after a crash, so we can fix bugs (Art. 6(1)(f) GDPR). Collection data or photos are not part of these reports. Until activation, no crash reports are transmitted.

5. Recipients and processors

We share data only with service providers we need to operate Topload. Processors are bound by a contract under Art. 28 GDPR; Apple acts as an independent controller. Market data providers receive no personal data.

Supabase
Supabase Inc.
Purpose: Database, login, file storage for the app and the waitlistData: Account, collection and scan data, photos, waitlistLocation and safeguard: Project region Paris (EU)
Stored in the EU; data processing agreement, standard contractual clauses for support access
Google Cloud Run
Google Cloud EMEA Ltd.
Purpose: Card recognition (image matching)Data: Every scan image during recognition — not storedLocation and safeguard: Region europe-west1 (Belgium, EU)
Processed in the EU; data processing agreement
Apple
Apple Distribution International Ltd. / Apple Inc.
Purpose: Sign in with Apple, push notifications, in-app purchase (StoreKit)Data: Apple ID identifier, push token, purchase and billing (only Apple sees payment data)Location and safeguard: Ireland / USA
Independent controller; EU-US Data Privacy Framework, Apple privacy policy
RevenueCat
RevenueCat Inc.
Purpose: Managing Pro subscriptionsData: Subscription events (purchase, renewal, expiry) with your user ID — no payment dataLocation and safeguard: USA
Standard contractual clauses (Art. 46(2)(c) GDPR)
Sentry
Functional Software Inc.
Purpose: App crash reports — once activatedData: Error message, device type, iOS and app version, user IDLocation and safeguard: EU region (Frankfurt)
Stored in the EU; data processing agreement, standard contractual clauses for support access
Vercel
Vercel Inc.
Purpose: Hosting of gettopload.comData: Server logs: IP address, time, requested page, browserLocation and safeguard: USA (delivered worldwide)
EU-US Data Privacy Framework, standard contractual clauses

6. Transfers outside the EU

Your collection and scan data stay in the EU. Only the subscription events described above (RevenueCat), the website server logs (Vercel) and the data Apple itself processes for sign-in, push and purchases go to the USA. The basis is the EU Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) and — for Vercel and Apple — certification under the EU-US Data Privacy Framework (Art. 45 GDPR). Copies of the clauses are available on request.

7. Retention

We keep data only as long as needed for its purpose. If you delete your account in the app, we remove all tables and file storage belonging to your account, delete the customer at RevenueCat and revoke the Apple sign-in token.

Account, collection, portfolio, transactions, wishlist, price alertsRetention: Until you delete your account
Downscaled scan photo (1280 px) in your scan historyRetention: Until you remove the entry or delete your account, at the latest after 365 days
Original scan photo (only with your consent)Retention: 180 days; deleted within one day after you withdraw consent
Scan diagnostics (text recognition, candidate list) and search eventsRetention: Until you delete your account
Push tokenRetention: Until you turn notifications off or delete your account
Purchase status (tier, expiry date) and RevenueCat customerRetention: Until you delete your account
Grading reportsRetention: Until you delete the report or your account
Waitlist entry (website)Retention: Until we have notified you about the launch or you unsubscribe
Salted IP hash of the waitlist (protection against bulk signups)Retention: 24 hours
Website server logsRetention: Held briefly by the hosting provider; we do not analyse them

8. Your rights

  • Access, rectification, restriction (Art. 15, 16, 18 GDPR) — by email to access@gettopload.com.
  • Erasure (Art. 17 GDPR) — fastest directly in the app: Profile → Settings → Delete account. Individual scans can be deleted in the scan history.
  • Data portability (Art. 20 GDPR) — you can export your collection as CSV in the app at any time.
  • Objection (Art. 21 GDPR) to processing based on our legitimate interest (scan diagnostics, search events, crash reports).
  • Withdrawal of consent (Art. 7(3) GDPR) — original photos under Profile → Privacy, push in iOS settings, waitlist by email. Processing carried out before the withdrawal remains lawful.
  • Complaint with a supervisory authority: Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb.gv.at. You may also contact the authority of your country of residence.

9. Children

Topload is rated 4+ on the App Store. In Austria, consent (original photos, push, waitlist) can be given by persons aged 14 or older (§ 4(4) Austrian Data Protection Act); for younger children we need the consent of a parent or guardian. If you believe a child has provided us with data without such consent, write to us — we will delete it.

10. Security

All connections are TLS-encrypted. Collection data and scan photos are kept in private storage with per-account access rules; only the controller has database access. We do not process payment data.

11. Changes

We update this policy when features, service providers or the legal situation change. The current version is always available at this address; the date is shown at the top. We will point out material changes that affect you in the app.

This is an English translation for your convenience. The German version at gettopload.com/datenschutz is the reference version.