Legal

Privacy Policy

Last updated: 10 August 2026

1. Who we are

This Privacy Policy describes how Gemma ("Gemma", "we", "us"), operator of the website gemma.cards (the "Platform"), collects, uses and protects your personal data when you use the Platform. For any privacy request you can reach us at support@gemma.cards.

2. Data we collect

Account data: email address and password (stored as a cryptographic hash), or your Google account identifier if you sign in with Google, plus a display name if you set one. Shipping data: full name, street address, city, ZIP, country and phone number — collected only when you request a physical shipment, and used only to deliver it. Transaction data: your coin top-ups, pack openings, card inventory, buybacks and shipment history. Payment data is never stored by us: card details are entered directly on our payment processor's secure checkout (Stripe) and never touch our servers. Technical data: IP address, device and browser information collected in server logs for security and fraud prevention.

3. What we use it for (and the legal basis)

We process your data to: provide the service — account, wallet, pack openings, shipments (performance of contract); prevent fraud and abuse and secure the Platform (legitimate interest); send transactional emails such as order confirmations, shipping updates and account notices (performance of contract); send occasional marketing emails only with your consent, which you can withdraw with one click via the unsubscribe link in every email; comply with legal, tax and accounting obligations (legal obligation).

4. Cookies and advertising

The Platform uses technical cookies strictly necessary for the service (session, language, currency). Advertising and analytics cookies — specifically the Meta (Facebook) Pixel — are loaded only after you give consent through the consent banner, and you can decline them without losing any functionality. When you consent, conversion events (such as a completed top-up) may be shared with Meta in hashed form to measure our advertising.

5. Who processes your data for us

We rely on a small number of processors, each bound by data processing agreements: Stripe (payment processing), Supabase (database and authentication), Vercel (hosting), Resend (transactional email) and Meta (advertising measurement, only with your consent). When you request a shipment, your name and address are shared with our card suppliers and carriers strictly to fulfil the delivery. We never sell your personal data.

6. Retention

Account and transaction data are kept for as long as your account is active, and afterwards only as long as required by tax and accounting law. Server logs are retained for a limited period for security purposes. Shipping addresses remain attached to past orders for warranty and dispute purposes.

7. Your rights

Under the GDPR you have the right to access, rectify, export and erase your personal data, to restrict or object to processing, and to lodge a complaint with your supervisory authority. You can delete your account yourself at any time from your profile settings — this permanently removes your personal data, and the transaction records we must keep for legal reasons are de-identified. For any other request, write to support@gemma.cards and we will respond within 30 days.

8. Changes to this policy

We may update this policy as the Platform evolves; the date below always reflects the latest revision. Material changes will be announced on the Platform before they take effect.

See also: Terms & Conditions · Refund Policy.