LogoTo the collection

Privacy policy

Last updated: September 2026

This is an English translation provided for convenience. Only the German version is legally binding.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dennis Oeder
c/o Oeder Group FZCO, Building A1, IFZA Properties, Dubai Silicon Oasis, Dubai, Vereinigte Arabische Emirate
Email: dennis@oederstudios.com

2. Overview of processing

This website serves to present a private collection of trading cards and to initiate sales and trades. We process personal data only insofar as this is necessary to provide the website and to handle your inquiries and reservations.

3. Hosting (Vercel)

The website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When the pages are accessed, Vercel processes technically necessary access data (including IP address, date and time of access, URL accessed, volume of data transferred, browser and operating system information) in server log files. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). The transfer to the USA takes place on the basis of the EU standard contractual clauses.

4. Database, sign-in and image storage (Supabase)

For the database, the operator's sign-in (magic-link login) and the storage of card photos we use Supabase (Supabase Inc., 970 Toa Payoh North #07-04, Singapore; data centre in the Ireland region (eu-west-1)). During a normal visit to the site, no personal data of visitors is stored; we process the information you submit via the forms (see section 7). The legal basis is Art. 6(1)(b) and (f) GDPR.

5. Email delivery (Resend)

For sending emails (notifications about inquiries and reservations as well as the operator's sign-in emails) we use Resend (Resend, Inc., USA). The data required for delivery — in particular the email address you provide and the message content — is transmitted to Resend. The legal basis is Art. 6(1)(b) GDPR (handling your request) or (f) GDPR (efficient communication). The transfer to the USA takes place on the basis of the EU standard contractual clauses.

6. Card images and price data (CardNexus)

The official card images shown in the collection book as well as the market-price and master data (name, set, number, rarity, etc.) come from the CardNexus Public API (CardNexus). The card images are not loaded directly from your browser via CardNexus, but delivered through our own server (same-origin image proxy). When you view a card, your browser therefore does not establish any connection to CardNexus or its image CDN; no third-party cookies are set and your IP address is not transmitted to CardNexus. Prices are shown with the source note “Price data: Cardmarket via CardNexus”. The legal basis for the integration is our legitimate interest in presenting the collection (Art. 6(1)(f) GDPR).

7. Inquiry and reservation form

If you submit an inquiry or reserve a card via the website, we process the data you provide:

  • for inquiries: name (optional), contact detail (e.g. email or phone number), message and the card concerned;
  • for reservations: name, contact detail, the reserved card and the reservation period.

This data is stored in our database (Supabase) and delivered to the operator by email (Resend) so that we can handle your request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR. To protect against misuse (spam) we use a hidden form field (“honeypot”) and a technical rate limit on submissions; your IP address is briefly processed in memory for this purpose but not stored permanently.

We retain the inquiry and reservation data until your request has been fully handled and no statutory retention obligations stand in the way. The data is then deleted.

8. Cookies and local storage

The public collection-book view does not set any marketing or tracking cookies. Only the operator's sign-in uses a technically necessary session cookie (legal basis Art. 6(1)(f) GDPR, § 25(2) TDDDG — German Telecommunications Digital Services Data Protection Act).

9. Recipients and transfers to third countries

The recipients of the data are the service providers named above acting as processors. Insofar as data is transferred to the USA, this takes place on the basis of the EU standard contractual clauses or — where available — a certification under the EU-US Data Privacy Framework.

10. Your rights

Under the GDPR you have the right to:

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR), and
  • objection to processing (Art. 21 GDPR).

You also have the right to lodge a complaint with a data protection supervisory authority — in particular with an authority in the EU member state of your habitual residence, place of work or the place of the alleged infringement.

11. Contact for data protection matters

For questions about data protection you can reach us at: dennis@oederstudios.com.

Legal noticePrivacyTerms of participation
AMARU