DachCardFAB Price Intelligence

Privacy Policy

Last updated: 4 August 2026

DachCard is run by one person as a side project. This page says exactly what the site collects, who else sees it, and how long it is kept. It is written from the code, not from memory.

Who runs this site

DachCard is operated by an individual, publishing under the site name DachCard rather than a personal or company name. The only contact channel is [email protected].

If you never sign in

You can browse every set, card and price without an account. In that case the site records:

The visitor identifier is not a cookie, is never sent to anyone else, and is not linked to an account. Clearing your browser data, using private browsing, or switching device makes it a new identifier — which means the operator's return-visit numbers are an undercount, and are only meaningful as a trend.

You can remove it at any time by clearing site data for dachcard.com in your browser.

If you sign in

Sign-in is Google OAuth. From Google we receive and store your name, email address, profile picture URL and Google account identifier. We never receive your Google password.

Once you have an account, the site also stores:

The activity log, and the search box

For signed-in accounts the site records these actions, with a timestamp: search, bookmark_add, bookmark_remove, target_price_set, target_price_remove, price_chart_view, price_chart_pick, store_link_click and login.

🔴 Search is recorded with the text you typed. A search for Enlightened Strike is stored as exactly that, together with how many results came back. If you would rather a search not be associated with your account, sign out before making it — browsing and searching work without an account.

These rows are kept for 24 months and then deleted.

Bug reports

If you use the in-app "report a problem" form, the report is sent to the operator's private Telegram and includes your account name, the URL you were on, your description, your screen size, your browser's user-agent string, and a screenshot of the page as you saw it. Do not include anything in that screenshot you would not want the operator to read. The form only appears when you are signed in.

Cookies and local storage

WhatWhenWhy
Session and "remember me" cookiesOnly after you sign in Keeps you signed in for up to 30 days. HttpOnly, SameSite=Lax.
Cloudflare's own cookies (e.g. __cf_bm)Set by Cloudflare, not by us Bot detection in front of the site.
localStorage: display currencyWhen you pick a currency So the site remembers it.
localStorage: visitor identifier + last-sent dateOn first visit The once-a-day visit event described above.

There are no advertising or analytics cookies, because there is no advertising or third-party analytics on this site.

Server logs

The web server keeps an access log containing your IP address (as forwarded by Cloudflare), the URL you requested, the time, and your user-agent. These logs rotate daily and are kept for 10 days, then deleted.

Cloudflare also tells the server which country your request came from. That is used only to pick a sensible default currency for signed-in accounts; it is not stored in the database.

Who else sees your data

Third partyWhat reaches them
Amazon Web Services (EC2 and RDS, Tokyo region) Everything — the site and its database run there.
Cloudflare Every request passes through it: IP, URL, headers.
Google (sign-in) Only if you choose to sign in. Google tells us your name, email and picture.
Google Fonts (fonts.googleapis.com, fonts.gstatic.com) Loading a page fetches fonts from Google, so your IP and browser reach Google even if you never sign in.
jsDelivr (cdn.jsdelivr.net) One stylesheet is loaded from it, so your IP reaches jsDelivr.
Sentry Error reports, plus performance traces on about 5% of requests. Personal data attachment is switched off — but the URL is part of the report, and a search URL contains your search text.
Telegram Operational alerts (aggregate numbers only) and bug reports (name + screenshot, as described above).
Better Stack Uptime checks against /health only. No user data.
A small number of store image hosts Most card images are served from our own server. Around 97 printings still load their image directly from a store's own host, which therefore sees your IP.

Nothing is sold, and there are no advertising networks.

How long things are kept

DataKept for
Account, saved cards, notes, preferencesUntil you delete your account
Activity log (including search text)24 months
Anonymous visit and store-click events24 months
Web server access logs (IP addresses)10 days
Bug reports (including screenshots)Until resolved and deleted by hand

Deleting your account

You can have your account deleted. Deletion is a hard delete: your account row, saved cards, notes, target prices, preferences and activity log rows are removed from the database outright, not anonymised and not archived. It cannot be undone.

If you are signed in, do it yourself here: Delete my account — you will see exactly what would be removed, and have to type a confirmation before anything happens. Otherwise email [email protected] from the address you signed up with.

⚠️ One honest limitation. The database keeps automated backups for 7 days for disaster recovery. A deleted account can still exist inside those backups until they age out. Those backups are only ever used to restore the database after a failure. (The separate off-site backup of this project deliberately excludes every user table, so your data is not in it at all.)

Your rights

You can ask for a copy of what is stored about you, ask for a correction, or ask for deletion, by emailing [email protected]. The site is small enough that this is done by hand.

Changes to this policy

If what the site collects changes, this page changes with it, and the date at the top is updated.

DachCard is an independent project and is not affiliated with Legend Story Studios, TCGplayer, or any of the stores it reads prices from.
Prices · About · Privacy · Terms · Contact