Privacy policy
Last updated: 30 August 2026
Who controls your data
TCGHaven is the controller responsible for the personal data described in this policy.
- Company
- TCGHaven
- KVK
- 88839621
- VAT ID
- NL004659858B77
- Address
- Herman Robbersstraat 68e, 3031 RJ Rotterdam, Netherlands
- Privacy email
- info@tcghaven.com
- Phone
- +31 6 87888458
Data we process
- Identity and contact data: name, email address, phone number, billing address, delivery address, and return details.
- Account data: profile name, profile image, encrypted or hashed authentication information, verification status, two-factor settings, sessions, wishlist, and saved address.
- Order data: products, condition and variants, price, discounts, delivery method, payment status, order history, returns, refunds, and support notes.
- Communications: messages submitted through contact, return, account, or email channels.
- Technical and security data: IP address, device and browser information made available with requests, timestamps, authentication attempts, rate-limit records, and administrative audit events.
We do not receive or store complete card numbers or online banking credentials. Mollie collects the payment information needed for its payment service.
Purposes and legal bases
- Contract: create accounts, accept payments, fulfil orders, deliver products, process returns, and provide customer support.
- Legal obligation: keep required invoices, transaction records, tax records, and information needed to answer lawful requests.
- Legitimate interests: secure the webshop, prevent fraud, maintain reliable stock, investigate errors, keep an audit trail, and defend legal claims. We balance these interests against your rights.
- Consent: send optional marketing messages or use non-essential tracking if these features are introduced. Consent can be withdrawn at any time.
We do not use customer data for solely automated decisions that produce legal or similarly significant effects. Security systems may temporarily limit suspicious activity, with owner review available.
Service providers and recipients
We share only the information needed for the following services:
- Mollie: payment creation, payment status, refunds, and fraud controls.
- PostNL: delivery, labels, tracking, and transport claims.
- Vercel: application hosting, delivery, and operational request logs.
- Railway: PostgreSQL database hosting and related infrastructure.
- The configured mail host: account verification, password reset, order, return, and customer-service email.
- Google: authentication information if you choose Google sign-in.
- Authorities and advisers: information required by law, necessary for legal claims, or needed to investigate fraud.
Providers may also act as independent controllers for parts of their service. Their own privacy information explains those activities. TCGHaven does not sell personal data.
Retention periods
- Orders, invoices, payments, and required accounting records: normally 7 years to meet Dutch fiscal record-keeping duties.
- Account and wishlist data: while the account is active, then deleted or anonymised when no longer needed, except where linked records must be retained.
- Contact and complaint records: for the time needed to resolve the matter and normally no longer than 2 years afterward, unless a dispute or legal duty requires longer.
- Security and audit records: for a limited period proportionate to fraud prevention, incident investigation, and legal-claim needs.
- Local cart data: until you clear the cart, clear browser storage, or remove the site data from your device.
When a retention period ends, data is deleted, anonymised, or kept inaccessible until a protected backup expires.
Security
We use access controls, encrypted HTTPS connections, secure cookies, password hashing, optional two-factor authentication, server-side validation, rate limiting, restricted administrative access, payment verification, and audit logging. No internet service can guarantee absolute security. If a personal-data breach creates a legal duty to notify affected people or the regulator, we will do so as required.
International transfers
Some service providers may process data outside the European Economic Area. Where GDPR transfer restrictions apply, we rely on an adequacy decision, approved contractual safeguards, or another lawful transfer mechanism offered by the provider.
Your privacy rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting processing that was lawful before withdrawal.
Send a request to info@tcghaven.com or use the contact page. We normally respond within one month. We may ask for information needed to confirm identity, but will not request more identification than reasonably necessary.
You may also submit a complaint to the Autoriteit Persoonsgegevens.
Children
The webshop is not directed at children under 16 acting without a parent or guardian where consent is legally required. Contact us if you believe a child supplied personal data improperly so we can investigate and remove it where appropriate.
Changes and contact
We update this policy when our processing or providers change. The current date appears at the top. Material changes are communicated through the webshop or by email where appropriate.
Privacy questions can be sent to info@tcghaven.com.





