1. Controller
The data controller within the meaning of Art. 4 (7) GDPR is:
Eladio Rubio Hernandez Fermanagh-Weg 3 33647 Bielefeld Germany
Email: contact@getriftr.app
The platform is currently operated by the above-named individual. Should the platform later be operated by an incorporated entity (e.g. a Riftr UG once founded and registered in the German commercial register), this Privacy Policy will be updated and existing users notified in-app.
A Data Protection Officer is not appointed. Riftr does not meet the thresholds in § 38 BDSG that would require one.
2. Early-access notice
Riftr currently runs in supervised early access. The marketplace runs in the TEST mode of our payment provider, Stripe. When you try the purchase flow you enter payment data (test-card numbers) into a form that is transmitted to and processed by Stripe in a test environment. If you go through the seller flow, Stripe's onboarding additionally collects KYC data (name, date of birth, address, bank details). No real charge is made and no real money moves. Please enter ONLY the test-card numbers we provide and never your real card details. Riftr itself never sees or stores your card or bank details at any time. That processing happens solely at Stripe. When live payments switch on, this Privacy Policy will be updated and existing users notified.
3. Data we collect
The following categories of personal data are processed when you use Riftr:
(a) Account data
- Email address (mandatory, login + verify)
- Hashed password (Firebase Authentication)
- Display name
- Profile photo URL (optional, from Google Sign-In or manual)
- Push-notification token (FCM, optional)
- Apple Sign-In: an Apple-issued OAuth refresh token (stored solely so we can revoke your Apple session when you delete your account, as required by Apple)
(b) Seller-onboarding data (only when you list cards for sale)
- Postal address (street, ZIP, city, country)
- Verified email
- For commercial sellers (§ 14 BGB): legal entity name, VAT identification number
- Counters required by the German PStTG (DAC7): yearly transaction count + gross revenue per calendar year
- Tax identification number (TIN), where required for DAC7 reporting (§ 15 PStTG)
- Note: when one of your listings is purchased, your email address and shipping address are shared with the buyer for contract execution (Art. 6 (1) (b) GDPR)
(c) Order data (marketplace purchases)
- As a buyer: your shipping address including recipient name (shared with the seller for delivery)
- Order records: items, prices, order status, plus the seller's email address in your order confirmation and the seller's shipping address in your order view (all orders); for commercial sellers additionally the full business imprint
(d) App usage data
- Listings you create (cardId, price, condition, quantity, foil flag)
- Decks, recorded matches, card collection
- Anonymous scanner telemetry (strategy/confidence/latency, no user identifier attached) for service improvement
(e) Reports, complaints & moderation
- Reports you submit (reported content/account, reason, optional description, good-faith declaration)
- Complaints against moderation measures (your text + a snapshot of your sanction state)
- Moderation records affecting you (strikes with order reference, sanction audit trail)
(f) Technical data
- IP address (logged by Firebase / Cloud Functions for security and abuse prevention)
- Device push token
We do NOT collect: phone numbers, date of birth, GPS / location data, contacts, IDFA / advertising identifiers, biometric data, social-graph data from third parties, or any data not listed above.
4. Purposes and legal bases
We process your data only for the purposes listed below.
(a) Providing the app and your account: Art. 6 (1) (b) GDPR (contract performance). Includes: account creation, login, displaying your profile, syncing your decks / matches / collection across devices.
(b) Providing the marketplace: Art. 6 (1) (b) GDPR (contract performance). Includes: showing your listings to other users, transmitting your seller country to enable shipping calculation, displaying your public seller profile (rating, sales count) to potential buyers.
(c) Statutory obligations: Art. 6 (1) (c) GDPR (legal obligation). Includes: tracking yearly sales counters under the German PStTG / DAC7, retaining order records for the periods required by the Handelsgesetzbuch (HGB § 257) and the Abgabenordnung (AO § 147).
(d) Push notifications: Art. 6 (1) (a) GDPR (consent). You opt in by accepting the iOS / Android push permission prompt. You can revoke at any time in your device settings or by signing out.
(e) Service improvement (anonymous telemetry): Art. 6 (1) (f) GDPR (legitimate interest in improving scanner accuracy and app stability). The telemetry contains no user identifier and cannot be linked to a specific account.
(f) Security and abuse prevention: Art. 6 (1) (f) GDPR (legitimate interest). Includes IP-address logging by our hosting provider, rate-limit counters, and Firebase App Check integrity tokens.
(g) Sanctions screening (sellers only): Art. 6 (1) (c) GDPR (legal obligation). EU sanctions law forbids making funds or economic resources available to listed persons, and that obligation binds us. When you start seller onboarding, the name in your seller profile is compared against the consolidated list of persons and entities subject to EU financial sanctions. We download that list to our own server and match locally: your data is not sent to the European Commission or to anyone else for this. A matching name is not an identification. It never blocks or suspends anything by itself. It is recorded for a human at Riftr to look at, and you are not treated differently unless a person decides otherwise (see section 9).
5. Service providers (processors)
We use the following carefully selected service providers, each bound to a Data Processing Agreement (Art. 28 GDPR):
(a) Google Ireland Limited / Google LLC : Firebase platform
- Firebase Authentication (email + Google Sign-In)
- Cloud Firestore (app database)
- Cloud Functions (server logic)
- Firebase Cloud Messaging (push, via APNs on iOS)
- Firebase App Check (anti-abuse)
- Firebase Crashlytics (crash diagnostics: device model, OS version, crash stack traces , used solely for app stability, no advertising use)
Server location: EU (Frankfurt / europe-west). Some sub-services may transfer data to the United States.
(b) Resend Inc.: transactional email Used for (i) account emails (sign-in verification links, password-reset links) and the 6-digit code that confirms your seller email, (ii) order and contract confirmation emails to buyers (order details, seller identity and, for commercial sellers, the statutory withdrawal notice; § 312i BGB durable-medium requirement), (iii) seller notices required by law (e.g. DAC7 threshold notifications), (iv) internal operational alerts to the platform operator, and (v) occasional launch announcements to sellers whose listings are waiting for launch; every such announcement carries a one-click unsubscribe link. Data: your email address and the respective order/notice content. No third-party marketing and no newsletter beyond (v).
(c) Stripe Payments Europe Limited / Stripe Inc.: payment processing (test mode during early access) During early access, Stripe processes the purchase and seller-onboarding flows in its TEST environment (see section 2); no real charges are made. Once live payments switch on, Stripe will process real payments between buyers and sellers under its own privacy policy. Stripe is an independent payment service provider; the seller enters a direct contract with Stripe (Stripe Connected Account Agreement) for KYC and payouts.
(d) Apple Inc. / Google LLC: push notification routing APNs (iOS) and FCM (Android) deliver push notifications to your device. Apple / Google cannot read the notification content.
(e) Cloudflare, Inc.: email forwarding and website analytics Email Routing forwards mail addressed to @getriftr.app to our internal mailbox. Cloudflare Web Analytics on getriftr.app is cookieless and does not store IP addresses per visitor, aggregated server-side only.
(f) Apple Inc. / Google LLC: app distribution The App Store and Google Play deliver the app and provide aggregate install metrics to us under their respective privacy policies.
(f2) Reach measurement (our own, no third party) We count page views on our website to see which pages are read. We store only the day, the page path, the host of the site you came from and whether you are on a phone or a desktop. No IP address, no cookie, no identifier, nothing that could recognise you again or link two visits. The numbers are added up as they arrive, so no per-visit record exists in the first place.
(g) OpenStreetMap Foundation (United Kingdom): address validation When you save a seller address, the street name (without your house number), postal code, city and country are sent to the public Nominatim geocoding service to check that it is a plausible, deliverable address (Art. 6 (1) (f) GDPR, legitimate interest in marketplace integrity). Your house number, name, email and account data are never transmitted.
(h) European Commission: VAT number validation (VIES) For commercial sellers, the VAT identification number you provide is checked against the EU VIES service (Art. 6 (1) (c) GDPR, statutory verification duties).
(i) Federal Central Tax Office, Germany (Bundeszentralamt für Steuern) If you sell on the marketplace and reach the thresholds set by the German Platform Tax Transparency Act (PStTG), we are required by law to report your identifying data and your sales totals for that year to the Federal Central Tax Office, which forwards them to the tax authority of your country of residence (Art. 6 (1) (c) GDPR, §§ 13 to 15 PStTG). We will tell you what exactly was reported about you, by 31 January of the following year at the latest (§ 22 (1) PStTG). Below those thresholds nothing is reported. The thresholds themselves are in our Terms; we warn you before you reach them.
6. Third-country transfers
Some of the processors listed above are located outside the EU/EEA (United States). For these transfers we rely on the EU Standard Contractual Clauses (SCC) under Art. 46 (2) (c) GDPR, supplemented by additional safeguards documented by the respective providers (Google, Resend, Stripe, Cloudflare).
Stripe Payments Europe Limited (Ireland) is within the EU. Onward transfers from Stripe to Stripe Inc. (US) are governed by SCCs between the Stripe entities.
7. Storage periods
- Account data: until you delete your account. Exceptions that survive deletion for the statutory periods (§ 24 PStTG, § 147 AO, § 14b UStG; Art. 17 (3) (b) GDPR): the DAC7 plausibility and threshold records (hashed digests and counter snapshots), the seller identity snapshot and the commission invoices described below. The deletion audit entry and the Stripe account reference are kept indefinitely as proof of erasure under Art. 17 GDPR.
- Listings: until you delete them or they are sold.
- Order records (post-launch only): retained for the periods required by German tax and commercial law (booking records such as invoices and receipts: 8 years, § 147 (3) AO, § 257 (4) HGB; other commercial correspondence: 6 years).
- Email verification codes: valid for 10 minutes; the stored code record is deleted when verification succeeds, overwritten by any new attempt, and removed at the latest with your account.
- Anonymous scanner telemetry: aggregated into daily counters as it arrives; no per-scan record and no user identifier exists in the first place.
- Reports, complaints and moderation records: kept for up to three years from the report, then deleted automatically. Two exceptions: reports still under review are never deleted while open, and records that substantiate a sanction still in force are kept while the measure lasts.
- Sanctions-screening records: only created if your name matched the EU list. Retained as proof that we screened and how a person decided, for five years after your account ends, then deleted automatically. If no name matched, nothing is stored at all.
- Shop logo (commercial sellers only): if you upload a logo it is stored in our EU image storage, reviewed by a person before it appears anywhere, shown publicly as your avatar once approved, and deleted together with your account.
- Seller identity snapshot: if you delete a seller account that has completed at least one sale, a snapshot of the identity data German platform-tax law requires (name, address, email address, date of birth, tax IDs, packaging register number, yearly sale counters) is kept for the statutory retention periods (Sec. 24 PStTG, up to ten years), separate from your deleted account and used for nothing else.
- Commission invoices (commercial sellers): if you sell as a registered commercial seller, we issue an invoice for our commission on each completed sale. It carries your business name, your address and, where you have one, your VAT ID, and German tax law requires us to keep a copy for eight years (Sec. 14b UStG), so it survives the deletion of your account.
- Database recovery copies: our database keeps an internal 7-day point-in-time recovery window for disaster protection. Data you delete disappears from the app immediately and ages out of this recovery window automatically within 7 days.
- Account-deletion audit log: indefinite, required as proof of erasure under Art. 17 GDPR. It contains the deletion timestamp, a deletion summary, who ran the deletion and whether that was an administrator, the reason recorded for it, your Stripe account reference and your Stripe customer reference together with whether that customer record was removed at Stripe, and, where an administrator ended a commercial seller account, the legal basis relied on for ending it with immediate effect. For deletions run by an administrator it also records whether and when the statement of reasons reached you by email, or the delivery failure we ran into instead. No email address and no email hash is stored.
- Termination pre-finding (commercial sellers only): immediately before an administrator deletes a commercial seller account, we record outside your account data that the account was a commercial seller, who took that decision, the time of that decision, and the legal basis relied on for ending the service with immediate effect. It exists so the statement of reasons we owe you survives a deletion that fails halfway through, and it is removed as soon as the audit log above carries the same information.
- Reviews you have written about other sellers: deleted automatically together with your account; the reviewed seller's average rating is recalculated without your reviews.
- Reviews other sellers / buyers have left about you: deleted together with your account (they are stored under your account).
- Stripe Connected Account (sellers): your Stripe account and its records survive the deletion of your Riftr account. Stripe retains them under its own statutory tax/AML retention duties and privacy policy; Riftr keeps only the account reference (acct_…) for payment forensics.
- Seller applications (from the form on getriftr.app): your email, country and answers, kept until the marketplace opens to you or you ask us to delete them, whichever comes first. Ask at contact@getriftr.app.
8. Your rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): ask us what data we hold about you.
- Right to rectification (Art. 16): correct inaccurate data via the in-app profile editor.
- Right to erasure (Art. 17): built into the app: Profile → Edit Profile → Delete Account. The action is performed by a server-side cascade and cannot be undone.
- Right to restriction (Art. 18): contact us at contact@getriftr.app.
- Right to data portability (Art. 20): contact us; we will provide your account data in a structured, commonly used format (JSON).
- Right to object (Art. 21): applies to processing based on legitimate interest. Contact us with the reason.
- Right to withdraw consent (Art. 7 (3)): where processing is based on consent (push notifications), you can revoke at any time with no effect on past processing.
- Right to lodge a complaint with a supervisory authority (Art. 77): for Germany / NRW: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, https://www.ldi.nrw.de/.
Minors: Riftr's companion features (match tracker, deck builder, collection) may be used by minors only with the consent of a parent or legal guardian (see Early Access Terms § 3). Marketplace purchases require a confirmed age of 18+; selling requires Stripe identity verification. Consent-based processing (push notifications) is not directed at children under 16 (Art. 8 GDPR). Parents or guardians can request deletion of a minor's account at any time via contact@getriftr.app.
9. Automated decision-making
Riftr does NOT use automated individual decision-making or profiling within the meaning of Art. 22 GDPR. The marketplace pricing, listing visibility and seller-tier calculations are deterministic and rule-based, not adaptive profiling.
The sanctions screening described in section 4 (g) is automated matching, but it is not an automated decision: it produces no legal effect and no comparable significant effect on its own. Nothing is blocked, restricted or refused by the match. Any consequence follows only from a decision made by a person at Riftr, and you can contest that decision under section 8.
10. Mandatory provision
Account creation requires email and a display name. Without these we cannot provide an account. Selling on the marketplace additionally requires postal address (for shipping label generation by sellers) and: for private sellers, your date of birth (record-keeping duty of marketplace operators under § 22f (2) of the German VAT Act, never shown to other users); for commercial sellers, VAT identification number (§ 5 DDG / § 14 BGB obligation). Browsing and collecting cards work without seller data.
11. Changes to this policy
We may update this Privacy Policy when we add features, switch providers, or react to legal changes. Substantial changes will be notified in-app at least 30 days before they take effect. The current version is always available under Profile → Legal → Privacy Policy.
