CollectHoloCollectHolo
Explore
Cards
Insights
Sign up
CollectHoloCollectHolo

A Pokemon TCG tracker that brings Cardmarket, TCGPlayer, eBay and more into one app. Compare EU & US prices side by side.

Built for collectors in

Download on the App Store
Get it on Google PlayCard scanner coming soon

Pages

  • Explore
  • Sets
  • Leaderboard
  • Portfolio
  • Wishlist

Resources

  • Blog
  • Changelog
  • Help center
  • Feature Requests
  • Contact

Legal

  • Imprint/Impressum
  • Terms/AGB
  • Revocation/Widerruf
  • Privacy
  • Cancel contract

Any questions?

  • We're always happy to help!

  • Contact

© CollectHolo, 2026

CollectHolo is not affiliated with, sponsored or endorsed by, or in any way associated with Pokémon or The Pokémon Company International Inc. Pokémon and all related names are trademarks of their respective owners.

Privacy Policy

This Privacy Policy explains how CollectHolo GmbH processes personal data when you use CollectHolo or our website.

EnglishDeutsch

1. Controller and privacy contact

The controller for the processing described in this policy is CollectHolo GmbH, Luisantring 1 A, 63477 Maintal, Germany. You can reach us at [email protected] or through our contact form. Further company information is available in our Imprint.

We have not appointed a data protection officer. Please use the contact details above for privacy requests.

2. Data we process

  • Account and login data: email address, password hash for email/password accounts, authentication identifiers, and—where you choose social sign-in—the provider identifier and profile information supplied by Google, Apple, or Discord.
  • Profile and collection data: display name, username, avatar, collections, wishlists, card and sealed-product entries, transactions, purchase and sale details, notes, custom stores, tags, preferences, and exports that you request.
  • Technical and security data: IP address, browser and device information, request and event logs, authentication and rate-limit information, and Cloudflare Turnstile challenge data used to protect forms and the service.
  • Contract and communication data: subscription status, Stripe, Apple App Store, Google Play, or RevenueCat identifiers, invoice and tax information made available to us, PRO contract-confirmation records, support messages, contact requests, newsletter consent, push subscriptions, and notification preferences.
  • Consumer declarations: the information submitted in cancellation or revocation declarations, including the requested contract action, matching information, internal processing notes, and hashed IP and user-agent audit values.

3. Purposes and legal bases

  • Contract performance (Art. 6(1)(b) GDPR): creating and operating your account, providing collection and portfolio features, handling support related to your account, supplying PRO, and administering website subscriptions.
  • Legal obligations (Art. 6(1)(c) GDPR): accounting, tax, consumer-law, and other legally required records, including relevant invoice and contract documentation.
  • Legitimate interests (Art. 6(1)(f) GDPR): maintaining service security and reliability, preventing fraud and abuse, enforcing rate limits, investigating faults, protecting legal claims, and operating our public-sharing features requested by you.
  • Consent (Art. 6(1)(a) GDPR): optional newsletter emails, optional device preferences including remembering campaign offers across visits, optional advertising and analytics technologies, optional push notifications where required, and optional integrations you choose to connect. You can withdraw consent at any time with future effect.
  • End-device storage and access: where required by Section 25(1) TDDDG, we obtain consent before optional storage or access for preferences, analytics, and advertising. Strictly necessary technologies are used only where required to provide the service you request.

4. Required and optional information

An email address and the credentials or social-login information needed for authentication are required to create an account. Without them, we cannot provide an authenticated CollectHolo account. Payment and billing information requested by Stripe, Apple, or Google is required when you purchase PRO; without it, the respective provider cannot complete the purchase.

Display names, avatars, collection content, public sharing, Discord linking, newsletter consent, push consent, and card-scan uploads are optional. If you do not provide them, the corresponding optional feature is unavailable or limited, while the rest of the service remains available where technically possible.

5. PRO subscriptions, cancellations, and revocations

For a website PRO subscription, Stripe processes the payment method directly. We receive and store the customer, subscription, invoice, payment-status, tax, currency, and billing-period information needed to activate, support, document, and account for the subscription. Card details are not processed on our servers.

We store a versioned PRO contract-confirmation record, including the recipient email, billing information, legal-document version and hash, and delivery status. This lets us document the contract confirmation without changing the legal content for an earlier purchase.

If you use our contract cancellation page or revocation page, we process the declaration and matching details you submit in order to handle the request, send a receipt where applicable, comply with legal obligations, and establish, exercise, or defend legal claims. The applicable contractual rules are set out in our Terms of Use. App Store and Google Play purchases are administered through their respective store and are not cancelled or revoked through the CollectHolo website forms.

6. Public collections and wishlists

Collections and wishlists are private by default. If you choose to make one public, it is available through its direct public link. The public view can show the collection or wishlist name, included items and quantities, and the public profile information associated with it, such as your username and avatar. Do not make a collection public if it contains information you do not want to disclose.

You can turn public sharing off in the relevant collection or wishlist settings. This prevents future access through the public view, subject to copies or cached material outside our control.

7. Communications, newsletter, and notifications

We send service and contract emails, including account, security, billing, cancellation, revocation, and PRO contract-confirmation messages, where necessary to provide the service or comply with our obligations. These are not marketing emails.

The weekly portfolio digest and occasional product news are sent only if you opt in. We retain an audit trail of the consent wording, version, source, time, and related account information. You can withdraw newsletter consent through the unsubscribe link in the relevant email or in the available account settings.

Web push and Apple Push Notification service (APNs) notifications are optional. We process the browser push endpoint or Apple-issued device token and the notification payload until you unsubscribe, disable notifications, or the subscription becomes invalid.

8. Card Scan and AI processing

When you use the optional Card Scan feature, the card image you capture or select is sent over an encrypted connection to CollectHolo's Card Scan endpoint. The endpoint processes the image in memory and forwards it, together with limited technical request context, to the Google Gemini API in order to identify the card. CollectHolo does not save the original Card Scan image to its database or object storage after the recognition request has completed.

We retain only the quota, security, and diagnostic metadata needed to operate and protect the feature. Do not use Card Scan for photographs containing personal, sensitive, or unrelated information.

9. Recipients and service providers

We use providers to operate CollectHolo. They process data on our instructions where they act as processors; some providers also process data under their own terms for payment, platform, authentication, or communication services. We use written data-processing agreements where required.

Provider or servicePurpose and data involvedWhen used
Supabase and database infrastructureAuthentication, account, profile, collection, wishlist, transaction, preference, and service metadata.Operating an account and the service.
Amazon Web Services / Amazon SESRecipient email addresses and transactional message content.Sending account, support, security, billing, and contract emails.
VercelIP address, request, and delivery logs.Hosting and delivering the website and APIs.
Cloudflare, Turnstile, and R2IP address, user agent, security challenge data, request data, and stored object data such as avatars where applicable.CDN, DDoS and bot protection, and object storage.
StripeCustomer, subscription, invoice, tax, payment-status, and payment-method data handled by Stripe.Website PRO subscriptions.
Apple App Store, Google Play, and RevenueCatStore purchase identifiers, store identity, entitlement, and subscription status.iOS and Android PRO purchases and restoration.
Sentry (Functional Software, Inc.)Pseudonymous account identifier, runtime/platform tag, error type and message, stack trace, and limited diagnostic request context after local scrubbing. We do not intentionally send email addresses, usernames, request bodies, cookies, authentication headers, or IP addresses.Security, reliability, fault investigation, and limited performance tracing. Data is stored in Sentry's EU region.
Google Analytics 4 and Google Tag ManagerPseudonymous online identifiers, page views, interaction and conversion events.Only for the Analytics category after consent, subject to the GTM configuration described below.
Meta Pixel and Reddit PixelAdvertising identifiers and conversion events.Only for the Advertising category after consent.
Google Gemini APIThe card image submitted for Card Scan and limited request context.Only when you use Card Scan.
Google, Apple, and Discord sign-inProvider identifier and the profile data released by the provider, such as email or name.Only when you choose that sign-in method.
Discord PRO integrationDiscord user ID and the OAuth token needed to link or maintain the optional PRO role.Only when you connect Discord.
APNs and browser push providersDevice token or push endpoint and notification payload.Only when you enable push notifications.
Connected MCP/AI clientsThe portfolio data permitted by the scopes you authorise for the connected client.Only when you actively authorise a connection, for example with ChatGPT, Claude, Codex, Gemini, or another compatible client.

10. Cookies, local storage, analytics, and advertising

We use cookies and similar local storage to run the service and to remember your choices. You can open Cookie Settings at any time from the website footer or, in the iOS or Android app, from More → Cookie Settings. Withdrawing consent does not affect processing that took place before withdrawal.

CategoryStorage or providerPurposeDuration and choice
NecessaryAuthentication and session storage; CookieConsent; current-tab campaign-offer session storageSecure login, session handling, remembering your consent selection, and keeping an offer requested through a campaign landing page available in the current tab.CookieConsent is stored for 365 days. Authentication/session duration follows the configured authentication session. The campaign-offer session marker ends with the browser tab. Necessary storage cannot be switched off while using the service.
PreferencesBrowser local storage, optional preference storage, and the ch_campaign_offer cookieTheme, currency and display choices; optional saved Explore filters and searches; remembering an eligible campaign offer across browser sessions.The campaign-offer cookie is stored for no more than 14 days. Preference storage is used only if you enable Preferences and is removed where applicable when you withdraw this choice in Cookie Settings.
AnalyticsGoogle Tag Manager, Google Analytics 4, ch_first_touch and ch_last_touch attribution cookiesMeasure use of CollectHolo, understand entry sources, and improve the service.Attribution cookies are retained for 90 days. GA4 is configured for 14 months. Used only if you enable Analytics.
AdvertisingMeta Pixel and Reddit Pixel through Google Tag ManagerMeasure advertising conversions and campaign performance.Used only if you enable Advertising; you can withdraw the choice in Cookie Settings.

On the website, the Google Tag Manager container is loaded with Google Consent Mode set to deny analytics and advertising storage by default. Analytics and advertising tags must respect the category choice you make in Cookie Settings. In the iOS and Android apps, optional analytics starts only after you allow Analytics; no advertising tag is currently active in either mobile app.

11. International data transfers

Some providers listed above operate globally or may process data outside the European Economic Area, including in the United States. Before a transfer for which the GDPR requires a safeguard, we use the applicable lawful transfer mechanism, such as an adequacy decision where the recipient is eligible or the European Commission's Standard Contractual Clauses together with supplementary measures where required.

We maintain a current provider and transfer inventory for the services we use. You may request information about the safeguards applicable to a particular recipient by contacting us at [email protected].

12. Retention

DataRetention period or criterion
Account, profile, collection, wishlist, transaction, and preference dataFor the life of the account. Following completed account deletion, data is removed from active systems and encrypted backups are cleared within 30 days, except where a legal retention duty applies.
Server, security, and email-delivery logsUp to 14 days, unless a longer period is necessary to investigate a concrete security incident or enforce legal claims.
Invoice, tax, and accounting recordsFor the applicable statutory commercial and tax retention period, currently up to 10 years under German law.
PRO contract-confirmation recordsFor the contract term and thereafter for the applicable statutory retention and limitation periods; records containing accounting information follow the longer accounting retention period.
Cancellation and revocation declarationsFor the time needed to process the request and thereafter for the applicable statutory retention and limitation periods, generally three calendar years after the end of the year in which the matter is closed unless a longer legal duty applies.
Newsletter consent recordsFor the duration of consent and generally three calendar years after withdrawal or the end of the relevant consent record, unless a longer legal duty applies.
Push subscriptionsUntil you unsubscribe, disable notifications, the endpoint/token becomes invalid, or we no longer need it to provide notifications.
Card Scan imagesProcessed for the recognition request and not persistently stored by CollectHolo after it completes. Related quota and security metadata follow the relevant log-retention period.
Sentry error and performance eventsUp to 90 days under the active Sentry plan; shorter where the plan or our configuration provides less. Test events are resolved after verification but may remain until expiry.
Google Analytics 4 data14 months, according to the configured GA4 retention setting.

13. Your rights and supervisory authority

Subject to the legal requirements, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. You may withdraw consent at any time with future effect. To exercise a right, contact us at [email protected].

You also have the right to lodge a complaint with a data protection supervisory authority. For CollectHolo GmbH, the competent authority is the Hessian Commissioner for Data Protection and Freedom of Information. You may also contact the authority in your habitual residence, place of work, or place of the alleged infringement.

14. Minors and automated decisions

CollectHolo is not intended for persons under 16. We do not knowingly collect personal data from persons under 16. If you believe that this has happened, please contact us so that we can review and delete the data where appropriate.

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Card Scan and product or portfolio calculations are assistance features and do not make such decisions.

15. Security and changes to this policy

We use appropriate technical and organisational measures, including encryption in transit, access controls, authentication protections, and restricted administrative access. No system can be completely secure; please keep your credentials confidential and use a strong password.

We may update this policy when our processing changes or legal requirements require it. We will publish the updated version here and change the effective date. Where required by law, we will provide an additional notice.

Last updated: 08/29/2026

We use cookies

We use cookies and local storage to remember choices and, with your consent, for analytics and advertising.

Read our Privacy Policy