Privacy

1. Privacy at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website and use our app. Personal data is all data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy below.

Data Collection on this Website and in the App

Who is responsible for the data collection?
The data processing is carried out by Forestsoft GmbH. You can find their contact details in the "Note on the responsible party" section.

How do we collect your data?
Your data is collected when you provide it to us (e.g., when registering or signing up for the newsletter). Other data is collected automatically by our systems when you visit the website or use the app (e.g., technical data such as operating system or time).

What do we use your data for?
Part of the data is collected to ensure the error-free provision of the website and the app. Other data can be used to analyze your user behavior to optimize our offer.

What rights do you have regarding your data?
You have the right to receive information about the origin, recipient, and purpose of your stored personal data free of charge at any time. You also have a right to request the correction, blocking, or deletion of this data. You can contact us at any time for this purpose.

2. Hosting and Content Delivery Network (CDN)

External Hosting

We host our backend systems on servers within the European Union. The personal data collected on this website or in the app is stored on these servers. This may primarily involve IP addresses, contact requests, meta and communication data, account data, and other data. The hosting is carried out for the purpose of fulfilling the contract (Art. 6 Para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision (Art. 6 Para. 1 lit. f GDPR).

Database Hosting (Cloud Infrastructure)

Our central databases are self-hosted on secure server locations within the European Union. We do not use external Database-as-a-Service providers for the main database. This ensures we have full control over your data. The hosting is in the interest of a secure and reliable provision of our services (Art. 6 Para. 1 lit. f GDPR) and for contract fulfillment (Art. 6 Para. 1 lit. b GDPR).

Content Delivery Network (CDN)

We use a Content Delivery Network (CDN) to deliver the content of our website. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. A CDN is a network of geographically distributed servers that serves to deliver content such as images, scripts, or stylesheets more quickly to the visitors of our website. Technical data such as your IP address is transferred. The legal basis is our legitimate interest (Art. 6 Para. 1 lit. f GDPR) in a secure and fast provision. A Data Processing Agreement (DPA) has been concluded with Cloudflare.

3. General Notes and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

Note on the Responsible Party

The responsible party for data processing is:
Forestsoft GmbH
Schloss-Dyck-Str. 88b
41238 Mönchengladbach
Germany
Phone: +49 (2166) 6782970
Email: [email protected]

Storage Duration

Your personal data will remain with us until the purpose for data processing no longer applies or you revoke your consent or request deletion, provided there are no statutory retention periods to the contrary.

Data Transfer to Third Countries

We sometimes use tools from companies based in the USA (e.g., Google, Cloudflare). The transfer of personal data to the USA is permissible as we have concluded Standard Contractual Clauses (SCCs) with these providers and/or they are certified under the EU-U.S. Data Privacy Framework (DPF).

4. Data Collection on this Website

Cookies

Our websites use cookies. Many cookies are technically necessary. Other cookies are used to evaluate user behavior or to display advertising. Technically necessary cookies are stored on the basis of Art. 6 Para. 1 lit. f GDPR. All other cookies are set exclusively on the basis of your explicit consent (Art. 6 Para. 1 lit. a GDPR). Details can be found on our Cookie Transparency Page.

Server Log Files

The provider automatically collects information in server log files (browser type, operating system, referrer URL, hostname, time, IP address). The legal basis is Art. 6 Para. 1 lit. f GDPR (legitimate interest in an error-free website).

Waitlist and Email Updates

If you register for our waitlist or launch updates, we process your email address and your chosen language (locale) based on your explicit consent (Art. 6 Para. 1 lit. a GDPR). To protect against abuse, we also collect IP-based metadata (rate limiting). You can revoke this consent at any time.

5. Card Scanner App and Collection Data

Local Image Processing (Scans)

Our app uses your device's camera to scan trading cards. The captured images are processed exclusively locally on your smartphone and never leave the device. To identify the card in our database, the app only extracts abstract recognition features (such as recognized texts or mathematical image vectors) and sends these to our servers for querying. These features do not allow any conclusions to be drawn about your environment or privacy.

Data Synchronization (Cloud Sync)

To enable seamless, cross-device use and offline functionality of the app, we use modern end-to-end data synchronization technology. If you are logged in, your collection data is synchronized encrypted between the local database on your device and our cloud database so that it is not lost. The legal basis for this processing is the fulfillment of a contract (Art. 6 Para. 1 lit. b GDPR).

LootLink User Accounts & Google OAuth

We offer you the opportunity to register and log in to the app and the web with Google. Google Ireland Limited is involved here. After your consent, Google transmits your name, email, and profile picture to us. We process this data to manage your user account (Art. 6 Para. 1 lit. a and b GDPR). The connection can be revoked in the Google account.

6. Analytics Tools

Google Tag Manager

If you have consented, we use the Google Tag Manager. The provider is Google Ireland Limited. The Tag Manager itself does not collect any personal data, but only controls other tags that may collect data. Tags are triggered only in accordance with your selection made in the consent banner (Art. 6 Para. 1 lit. a GDPR).

Firebase (Mobile App: Product Analytics and Crash Reports)

In the LootLink mobile app, we may — only if you have explicitly consented — use Google Firebase services to understand how the app is used (e.g., scan, save, and search flows) and to detect and fix crashes. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing may also be carried out by Google's affiliated companies (including Google LLC in the USA). Further information can be found in the Firebase Privacy Notice and the Google Privacy Policy.

We do not send your email address, clear name, or text read via optical character recognition (OCR) from card images. Camera photos of your cards do not leave your device for identification. We do not sell your personal data. The legal basis is your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time in the Settings of the app; after that, no further analytics or crash data will be collected.

New Relic (Mobile App: Performance, Crashes, and Network Telemetry)

In the LootLink mobile app, we may — only if you have explicitly consented to analytics — use the New Relic Mobile agent to measure app performance, detect crashes, and collect limited network/request telemetry that helps us keep the app reliable. The provider is New Relic, Inc. Further information can be found in the New Relic Privacy Notice and New Relic Mobile Agent security documentation.

We do not enable Mobile Session Replay. We do not capture HTTP response bodies from LootLink API calls (so JSON payloads such as auth tokens or collection data are not sent to New Relic). We do not send your email address, clear name, or text read via OCR from card images. Camera photos of your cards do not leave your device for identification. The legal basis is your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time in the Settings of the app; after that, the New Relic agent is shut down for the session and no further telemetry is started.

Account Self-Service & Data Deletion

Logged-in LootLink account holders can export a machine-readable copy of their server-stored personal data, delete their collection and personal user data while keeping their account active, or permanently delete their entire account via /account/privacy or in account settings under /settings (JSON export, self-serve data deletion without account removal, and confirmed account erasure). Alternatively, you can send an informal data deletion request by email to [email protected]. This affects cloud account data — not local database caches in the mobile app. Marketing/analytics cookies are still controlled via the website's consent banner.