Skip to content
Crypto-only, prepaid. Top up a balance and we draw from it monthly — nothing is ever charged automatically.
tcggraph

Privacy policy

Last updated 1 August 2026

In short: We collect the minimum needed to run an API business: an email, a payment, and request logs kept for 30 days. We take cryptocurrency only, so there is no card processor holding your name, address and transaction history. We do not sell personal data and we do not run advertising trackers.

Who is responsible

TCGGraph is the data controller for the personal data described here. For anything in this policy, including exercising your rights, contact privacy@tcggraph.com.

What we collect

  • Account data. Email address, and optionally a name and company. Needed to create an account and to contact you about the service.
  • Billing data. We accept cryptocurrency only, so there is no card processor and no card data. We store the invoice amount in USD, the asset and network you settled in, and the transaction hash — enough to prove a payment happened and to satisfy our own tax obligations. We do not require a legal name, a billing address or a tax ID. If you ask us to put those on an invoice for your accountant, we store what you gave us and nothing more.
  • API request logs. Timestamp, endpoint, status code, credits consumed and a truncated IP address. Used for rate limiting, billing accuracy, abuse prevention and debugging.
  • Website analytics. Aggregate, cookie-free page counts. No cross-site tracking, no advertising pixels, no profiles.

We do not collect special category data and we have no reason to. Please do not send it to us.

Why we process it, and on what basis

  • To provide the service — performance of a contract. Account data, request logs.
  • To bill you — performance of a contract and legal obligation. Billing data.
  • To prevent abuse and keep the service up — legitimate interests. Request logs.
  • To send product email — consent, which you can withdraw in one click. Service and billing notices are sent regardless, because you need them.

How long we keep it

  • Account data: for the life of the account, then 30 days.
  • Request logs: 30 days, then deleted. Aggregate usage counters are kept for billing history.
  • Invoices: seven years, because tax law requires it.

Who we share it with

We use a small number of processors, each under a data processing agreement:

  • Vercel — application hosting and edge delivery.
  • Cloudflare — CDN, DDoS protection and image delivery.
  • Postmark — transactional email.

There is no payment processor on this list, and that is deliberate. Taking cards would mean handing a third party your name, billing address and a running history of what you spend and when. Settling in cryptocurrency means the only payment record either of us holds is an amount and a transaction hash.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose data to authorities only where legally compelled, and we will tell you unless we are prohibited from doing so.

International transfers

Data may be processed in the United States. Those transfers rely on the EU Standard Contractual Clauses together with supplementary technical measures, principally encryption in transit and at rest.

Your rights

Depending on where you live you have rights to access, correct, delete, port, restrict and object to the processing of your personal data, and to withdraw consent. California residents additionally have the right not to be discriminated against for exercising those rights.

Email privacy@tcggraph.com and we will respond within thirty days. No account verification hoops beyond confirming you control the address. If you think we have handled your data badly, you can complain to your local supervisory authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

Cookies

The marketing site sets no cookies at all. The dashboard sets one first-party session cookie so you can stay logged in, plus one storing your light or dark theme preference. Neither is used for tracking, which is why you are not being asked to dismiss a banner.

Security

TLS 1.3 in transit, encryption at rest, hashed API keys, least-privilege internal access and audit logging. If a breach affects your personal data we will notify you and the relevant authority within 72 hours of becoming aware.

Children

The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.

Changes

Material changes are announced by email at least thirty days ahead. The date at the top of this page always reflects the current version.