Last updated: July 2026
The controller responsible for the processing of personal data within the meaning of Art. 4(7) GDPR is:
Hariton Stuckert
Hans-Kopp-Straße 11
67227 Frankenthal
Germany
Email: support@packstorm.net
No data protection officer is required or appointed, as PackStorm does not meet the thresholds for mandatory designation under Art. 37 GDPR.
(a) Account data: your email address and a cryptographically hashed password (Argon2). If you change your email, we keep the previous address solely so that delayed payment webhooks can still be matched to your account.
(b) Authentication data: a session token stored as an HTTP-only cookie ("token") on your device and a matching record in our database for the duration of the session (up to 30 days of inactivity).
(c) Content and usage data: the card images you submit, the resulting metadata (card name, manufacturer, set, rarity, price estimate, etc.), per-scan usage, your scan history, and the cards in your collection.
(d) Payment data: subscription tier, subscription start/end timestamps, your Stripe customer and subscription identifiers, and one-time top-up records. Your actual payment instrument details (card numbers, bank details) are processed exclusively by Stripe and never reach us.
(e) Preferences: your image-publishing setting (stored server-side); your language and usage-view settings (stored only in your browser).
(f) Technical data: your IP address, browser user agent, and request timestamps are handled at the network level by our hosting provider for rate-limiting and access logging. We do not store these in our own database.
• Account creation, scanning, and collection/history management, Art. 6(1)(b), performance of contract.
• Processing card images via AI to identify cards and produce price estimates, Art. 6(1)(b).
• Billing via Stripe and retaining payment and invoice records, Art. 6(1)(b) and Art. 6(1)(c), legal obligation (§ 147 AO requires retention of payment records).
• Rate-limiting, abuse prevention, and service security, Art. 6(1)(f), legitimate interest in the integrity of the Service.
• Sending verification and account emails, Art. 6(1)(b).
• Publicly displaying your card images to other users, only where you actively choose to publish them; publishing is off by default, Art. 6(1)(a), consent, revocable at any time, per image by setting it back to private in the app and for future scans via the publishing setting.
• Translating AI-generated card text into your selected language, Art. 6(1)(b).
We share data only with the providers below, strictly as needed to operate the Service. None of them use your data for advertising or sell it.
OpenAI, L.L.C. (United States), receives card images and prompts to generate identification and pricing data. Under OpenAI's API terms, this data is not used to train OpenAI's models. Transfer safeguarded by the EU Standard Contractual Clauses (Art. 46 GDPR). OpenAI Privacy Policy.
Stripe Payments Europe, Limited (Ireland), payment processing; acts as our processor and, for fraud prevention and legal-compliance purposes, as an independent controller. Stripe Privacy Policy.
Sender.net (Lithuania), transactional email delivery (verification codes and account emails). EU-based processor.
Google LLC (United States), the public translation endpoint translate.googleapis.com, called from your browser to translate AI-generated card text into your selected language. Only that card text and your device's IP address are transmitted; no account identifiers, email, or images are sent. Transfer safeguarded by Standard Contractual Clauses.
Render Services, Inc. (United States; application hosted in its Frankfurt, Germany data center), hosting provider. Application data is stored on EU servers; the operating company is U.S.-based and acts as a sub-processor under Standard Contractual Clauses.
Some processors above are based in the United States. Transfers of personal data to the United States rely on the EU Standard Contractual Clauses (Art. 46 GDPR) concluded with the respective processor. Where a processor is U.S.-based but the data is physically stored in the EU (Render Frankfurt), the data does not leave the EU in storage. A copy of the applicable clauses is available on request.
Account data and content (email, password hash, card scans, collection, scan history, session tokens, email-change history, redemption-code links), kept for as long as your account is active, and deleted when you use the in-app "Delete Account" function.
Published card images, publicly visible while published and linked to your account so you can set them back to private at any time. If you delete your account while images are still published, the link is deleted and the images remain part of the public card database, no longer traceable to you.
Payment records (subscription and top-up records), retained for 10 years as required by § 147 AO (tax law) and § 257 HGB (commercial law). When you delete your account, these records are anonymized: the link to your account is removed, but the transaction date, amount, and Stripe transaction identifiers are retained for tax-audit purposes and can no longer be traced back to you.
Verification codes: deleted automatically 5 minutes after generation, or earlier on successful use.
Session tokens: deleted after 30 days of inactivity, on logout, or on subscription tier-down.
Network and rate-limit logs: handled at the infrastructure level by our hosting provider according to its own retention (typically short-term).
Under the GDPR you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to the tax-retention obligation in section 6), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), and withdrawal of consent (Art. 7(3)) at any time without affecting the lawfulness of prior processing. You can download a full copy of your data yourself at any time using the "Export my data" function in settings (Art. 15/20), delete your account with the "Delete Account" function (Art. 17), and change your publishing consent at any time with the publishing setting or by setting a published image back to private (Art. 7(3)). For any other request, contact support@packstorm.net; we will respond within one month (Art. 12(3)).
You have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR). The authority competent for the controller is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34
55116 Mainz
Germany
https://www.datenschutz.rlp.de
PackStorm is intended for users aged 16 and over and is not directed at children under 16. We do not knowingly process personal data of persons under 16. If you believe a younger child has registered, please contact us and we will delete the account.
PackStorm uses one strictly necessary cookie, the HTTP-only session token, and browser localStorage to remember your login, preferences, and cached content. We use no tracking, analytics, or third-party advertising cookies, so no cookie-consent banner is shown.
Card identification, rarity scoring, and price estimates are produced by automated AI systems, but they have no legal or similarly significant effect on you within the meaning of Art. 22 GDPR. They are informational estimates only and do not constitute financial, appraisal, or investment advice.
We implement technical and organisational measures appropriate to the risk under Art. 32 GDPR, including TLS encryption for all client/server traffic, Argon2 password hashing, signed Stripe webhook verification, restricted server access, and short-lived session tokens.
We may update this Privacy Policy as the Service evolves. The date at the top reflects the most recent change. We will notify you by email to the address linked to your account before material changes take effect.
For any privacy-related request or question:
Hariton Stuckert
Hans-Kopp-Straße 11
67227 Frankenthal
Germany
Email: support@packstorm.net