Privacy Policy
Last updated: April 10, 2026
At Binder Placeholders, we take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data. By creating an account or using our services, you agree to the practices described here.
1.Information We Collect
Account Information (via Clerk)
Binder Placeholders uses Clerk to handle user authentication. When you create an account, Clerk collects and stores on our behalf:
- Email address — used for account verification, transactional notifications, and (with your explicit consent) marketing communications.
- Name — if you provide it during sign-up.
- Authentication credentials — passwords are hashed and never stored in plaintext. If you use a social login (e.g. Google), we receive only the profile information that provider shares with us.
- Session data — Clerk issues secure, short-lived session tokens to keep you signed in.
Clerk is SOC 2 Type II certified. Their full privacy policy is available at clerk.com/legal/privacy.
Collection & Binder Data
When you use the app to track your card collection or build binders, we store the following in our database (hosted on Supabase / PostgreSQL):
- Owned card records — which card IDs you have marked as owned, associated with your user ID.
- Binder layout data — card arrangements, variants, and quantities saved in your binder sessions (currently stored in your browser's
localStorageand synced server-side where applicable).
This data is linked to your Clerk user ID. It is never sold or shared with third parties for advertising purposes.
Usage Analytics
We use Google Analytics (via Google Tag Manager) to collect aggregate, anonymised usage data such as pages visited, popular card sets, and browser/device type. This data does not include Personally Identifiable Information (PII) and is used solely to improve the product.
2.How We Use Your Information
- To provide the service — authenticating you, saving your collection, and displaying your binder data across sessions and devices.
- Transactional communications — emails related to your account (e.g. sign-up confirmation, password reset, important security notices). These are sent regardless of marketing preferences as they are necessary to operate the service.
- Marketing communications — occasional emails about new features, improvements, or Pokémon TCG content. We will only send marketing emails to users who have explicitly opted in. You can opt in during sign-up and withdraw consent at any time by clicking the unsubscribe link in any email or contacting us directly.
- Product improvement — anonymised analytics data helps us understand how the app is used and where to focus development.
3.Email Communications & Your Choices
We respect your inbox. Here is exactly what you can expect:
- Transactional emails (account verification, password reset, security alerts) are sent as needed to operate the service. You cannot opt out of these while you have an active account.
- Marketing emails (new features, product updates, TCG news) are sent only if you explicitly opt in. We will never add you to a marketing list automatically.
- Unsubscribing — every marketing email contains a one-click unsubscribe link. You can also opt out at any time by contacting us. Opt-out requests are honoured within 10 business days.
- No third-party sharing — your email address is never sold, rented, or shared with advertising networks or other companies for their marketing purposes.
4.Third-Party Services
- Clerk — authentication and user management. See Section 1 above.
- Supabase — database hosting for collection and binder data. Supabase stores data in a PostgreSQL database. See supabase.com/privacy.
- TCGDex — public API used to fetch Pokémon card images and data. Your browser may make direct requests to TCGDex servers. See their privacy policy for details.
- Vercel — our hosting provider. Vercel may log request metadata (IP address, user-agent) for security and performance. See vercel.com/legal/privacy-policy.
- TCGPlayer / eBay affiliate programs — when you click buy buttons, non-personal tracking parameters (card set, card number, click context) are included in the URL. We do not send your personal information. See Section 5.
- Buy Me A Coffee — if you choose to donate, you are redirected to their platform. We do not receive payment information.
5.Affiliate Links and Tracking
Binder Placeholders participates in the TCGPlayer and eBay affiliate programs. When you click "Buy on TCGPlayer" or "Buy on eBay" buttons:
- Referral parameters — links contain tracking identifiers that attribute purchases to our site, enabling us to earn a commission at no extra cost to you.
- What we send — non-personal identifiers only: card set ID, card number, and the page context (e.g. "set-browser"). We do not send your name, email, or user ID.
- Third-party data handling — once you leave our site, TCGPlayer's and eBay's respective privacy policies govern your data.
6.Cookies & Local Storage
We use the following storage mechanisms:
- Authentication cookies — set by Clerk to maintain your signed-in session. These are necessary for the service to function.
- Local storage — used to persist binder layout state in your browser between sessions.
- Analytics cookies — set by Google Analytics to track anonymised usage patterns. You can disable these via your browser settings without affecting core functionality.
7.Data Retention & Deletion
We retain your account and collection data for as long as your account is active. If you wish to delete your account and all associated data, please contact us using the details in Section 9. We will process deletion requests within 30 days.
Anonymised analytics data does not contain personal information and is retained per Google Analytics' standard retention settings (26 months by default).
8.Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — request that we delete your account and personal data.
- Opt-out of marketing — withdraw consent for marketing emails at any time via the unsubscribe link in any email or by contacting us.
- Data portability — request your collection data in a machine-readable format.
To exercise any of these rights, contact us via the details in Section 9.
9.Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the date at the top of this page. Where required by law, we will notify you by email. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.
10.Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or want to opt out of marketing communications, please contact us via Twitter: @pragmaticivan.