Privacy Policy

Version 2026.08.26-S  ·  Effective: August 26, 2026  ·  Merkvex, by ChoxxyVerse  ·  Saskatoon, Saskatchewan, Canada
Framework: Canada PIPEDA (primary controller location) · US state privacy (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA) · EU/UK GDPR · COPPA age gate · cross-border transfers.

Short version: We collect account, Bazaar, billing, and security data to run Merkvex. We also keep pseudonymised statistics about what the Pokémon TCG community searches, lists and trades — stripped of your identity, held in a separate database, and used only in aggregate (§3.1). You accept this Policy and the Terms when you create an account, and we record which version you accepted. We do not sell personal information and do not share it for cross-context behavioural advertising. Processors include Supabase, Netlify, Stripe, and Resend. 18+ only; we do not knowingly collect data from children under 13. Canada, US state, and EU/UK rights: email hello@merkvex.com. Full Terms of Service control on conflict with this Policy.

0. Quick map

1. Who we are; contact

Merkvex (“we”, “us”) is operated by Choxxy / ChoxxyVerse, Saskatoon, Saskatchewan, Canada. Contact for privacy requests: hello@merkvex.com (subject “Privacy request”).

For EU/UK purposes, the same Operator is the controller of personal data processed through the Service. We do not currently appoint a separate EU representative; if that changes, we will update this Policy.

2. Scope; relationship to other documents

This Policy covers personal information processed through the Service (websites, apps, emails, and related systems). It pairs with the Terms of Service, Community Guidelines, and Dispute Policy.

Hierarchy: The Terms of Service control if they conflict with this Policy on contractual matters. This Policy describes privacy practices; it does not expand Merkvex liability beyond the Terms.

If you use third-party services (Google sign-in, Stripe checkout, carriers), their policies also apply to data they control as independent controllers or processors under their terms.

3. Categories of personal information

Category Examples Primary purposes
Identifiers & auth Email; auth provider IDs; session tokens Sign-in, account security, notices
Profile / Bazaar identity Handle, display name, bio, optional region/city, cosmetics, badges, XP, public stats Public stall, trust signals, community features
Commercial / account inventory Lists, portfolio/watch data you enter; coin balances; owned cosmetics Provide features you use
Transaction / trade data Listings, offers, trade state, tracking numbers, ratings, dispute text, trade chat, photos Operate Bazaar; fraud; disputes; enforcement
Communications Mailbox messages; support emails; system notices Support, product messages, enforcement
Payment metadata Stripe customer/subscription IDs; purchase events; tax jurisdiction signals (not full card numbers) Billing, entitlements, tax, reconciliation
Technical / security IP, user agent, logs, device/browser metadata Security, abuse prevention, reliability, sanctions screening signals
Product & TCG-culture analytics (pseudonymised, separate store) A fixed list of action types (card search, Price Guide / board view, listing created, trade completed, price alert set, binder view, scan started, counter checkout); the card, set, condition and value attached to that action; a coarse trader-style label (for example scout, flipper, player, vendor, or unknown); a rotating daily key that stands in for identity; a deliberately imprecise time. Not included: email, handle, display name, account ID, age or date of birth, IP, location, photos, notes, chat, or any free text — these are stripped at the gateway before anything is written Aggregate market and community statistics — what the Pokémon TCG community searches, lists, values and trades. Not used to profile, target, score or advertise to you as an individual
Consent & policy records Which version of the Terms and of this Policy you accepted, and when you accepted it Prove and honour consent; know who to re-notify when a document changes; legal compliance

We do not require phone number or home address for registration. If you voluntarily put contact or shipping details in chat or notes, that is User Content you chose to share with counterparties and with us as host.

Sensitive data: We do not seek government ID numbers, precise continuous geolocation, or special-category data (GDPR Art. 9) for core features. Do not upload sensitive documents unless we expressly request them for a dispute or verification and explain why.

3.1 How the culture analytics actually work

We are interested in Pokémon TCG culture — which cards get searched, which sets move, what a fair trade looks like this month — and not in who you are. So the analytics path is built to make individual identification impractical rather than to promise it away in prose. Concretely:

  1. Only listed actions are eligible. An allow-list of event types is enforced at the gateway; anything not on the list is rejected, not stored “just in case”.
  2. Identity is removed and replaced. Your account identifier never reaches the analytics store. It is converted, one way, into a key that is re-salted every day, so the same person is not traceable from one day to the next.
  3. Free text and identifiers are stripped. The gateway deletes a fixed list of fields — email, user ID, handle, username, name, Stripe customer or subscription IDs, latitude/longitude/geo, address, IP, photo, avatar and image paths, URLs, comments, notes, descriptions and messages — before writing. Age and date of birth cannot appear because we never collect them anywhere on Merkvex (see §12).
  4. Timing is blurred. Each event’s timestamp is shifted by a random 5–15 minutes so that a behavioural record cannot be lined up against a public listing, trade or login time.
  5. It lives somewhere else. Analytics are written to a separate database from your account, reachable only by our server-side key. There is no browser-side analytics call, no third-party analytics SDK, and no advertising network anywhere in this path.
  6. Raw becomes aggregate. The raw event buffer is designed to be rolled up into daily per-card and per-market totals and then purged, with the purge verified. What we keep and work from is the aggregate.

What this is and is not. We describe this data as pseudonymised, not “anonymous”, because a rotating one-way key is a stand-in for identity rather than the absence of one, and honesty here matters more than a stronger-sounding word. Where GDPR or UK GDPR applies we treat it as personal data and process it under legitimate interests (§5.2), you may object under §10.3, and it is never used for cross-context behavioural advertising, individual profiling, or automated decisions about your account.

4. Sources

5. Purposes and legal bases

5.1 Canada (PIPEDA)

Under PIPEDA we collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, including service delivery, security, fraud prevention, billing, and legal compliance.

5.2 EU/UK GDPR. Article 6 legal bases

Where the EU General Data Protection Regulation (GDPR) or UK GDPR applies, we process personal data on one or more of the following bases:

Legal basis (Art. 6) Examples
Contract performance (Art. 6(1)(b)) Create and maintain your account; provide Bazaar and market tools; process Paid Features and Cipher credits; support tickets about your service
Legitimate interests (Art. 6(1)(f)) Fraud/abuse prevention; integrity of ratings and trades; service security; product improvement of a non-intrusive kind; pseudonymised aggregate market and culture analytics (§3.1); defending legal claims: balanced against your rights
Legal obligation (Art. 6(1)(c)) Tax and accounting records; responding to lawful requests; breach notification duties; sanctions compliance
Consent (Art. 6(1)(a)) Optional marketing emails (if offered); non-essential cookies if we introduce them and require consent under ePrivacy/PECR

You may withdraw consent for optional processing at any time without affecting the lawfulness of processing before withdrawal. Core Service functions may still require certain data under contract or legitimate interests.

6. Disclosures; processors; international transfers

We use processors to run Merkvex. They may process data in Canada, the United States, the EEA/UK, and other countries:

We may enable error monitoring later; we will name the vendor here before relying on it for personal data.

Other users see public profile/listing fields you publish and trade/chat content for trades they are party to.

Legal: We may disclose information to comply with law, protect rights and safety, or in a business transfer of the Service.

6.1 Cross-border data transfers (EEA/UK → Canada / US)

When personal data is transferred from the EEA or UK to Canada, the United States, or another third country, we rely on one or more of the following safeguards as applicable:

US-based processors may also participate in frameworks that lawfully support transfers when available. Processors’ own privacy notices describe their sub-processors and locations. Those jurisdictions may have different government access laws; we select established commercial providers and contractual safeguards appropriate for a small Canadian operator.

We do not sell personal information and do not share it for cross-context behavioural advertising.

7. Retention

8. Security

HTTPS in transit; access controls; Supabase RLS for many user tables; privileged operations use server-side secrets. No method is perfect. Report vulnerabilities to hello@merkvex.com (please no public exploit dumps).

9. Breach notification

If a breach creates a real risk of significant harm, we will follow applicable Canadian requirements (including notifying affected individuals and the OPC where required). Where GDPR/UK GDPR applies, we will notify the competent supervisory authority and, where required, data subjects, within the statutory timelines. We will also follow any mandatory US state breach-notification rules that apply.

10. Your rights

10.1 Canada (PIPEDA)

Access, correction, withdrawal of optional consent, and deletion/complaint pathways. Office of the Privacy Commissioner of Canada: priv.gc.ca. We aim to respond within 30 days.

10.2 United States: state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA)

If you are a resident of a US state with a comprehensive consumer privacy law: including California (CCPA as amended by CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA): and that law applies to us for your personal information, you may have some or all of the following rights (wording varies by statute):

Right What it means on Merkvex
Right to Know / Access Request the categories and/or specific pieces of personal information we collected about you, sources, purposes, and categories of third parties with whom we disclose it
Right to Delete Request deletion of personal information we collected from you, subject to legal exceptions (fraud, security, tax, active disputes, free speech of others’ content that mentions you, etc.)
Right to Correct Request correction of inaccurate personal information we maintain about you
Opt-out of Sale / Sharing / Targeted Advertising We do not sell personal information and do not share it for cross-context behavioural advertising. We do not use third-party targeted advertising networks. You may still send an opt-out request; we will confirm our practices
Non-Discrimination We will not deny goods/services, charge different prices, or provide a different quality solely because you exercised a privacy right, except as permitted by law (e.g., a free-tier vs paid difference is not discrimination for exercising a right)
Limit use of sensitive personal information (where applicable, e.g. California) We do not use sensitive personal information for purposes that require a “limit” control under CPRA beyond what is necessary to provide the Service

Authorized Agents (California and other states that allow agents). You may designate an authorized agent to submit a request on your behalf. The agent must provide written proof of authority (for example a signed authorization or power of attorney as applicable). We may still require you to verify your own identity directly with us before we process the request.

Verification. We will verify requests using the account email and other reasonable steps proportional to the sensitivity of the data. We aim to respond within 45 days (or the timeline required by your state’s law), with one extension where permitted.

California “Shine the Light” / notice of financial incentives: We do not sell personal information. Any promotional programs (for example founding rates) are described in-product and in the Terms; they are not exchanged for sale of personal information.

Do Not Track / Global Privacy Control: We do not currently respond to browser DNT signals as a substitute for account-level requests. Because we do not sell/share for behavioural ads, GPC signals do not change a “sale” flag we already keep off. Contact us if you need a recorded opt-out confirmation.

10.3 EU/UK GDPR: data subject rights

Where GDPR or UK GDPR applies, you have the right (subject to conditions and exceptions in the Regulation) to:

You may lodge a complaint with a supervisory authority (for example your local EU DPA or the UK Information Commissioner’s Office). We encourage you to contact us first so we can try to resolve the issue.

10.4 How to exercise any privacy right

Email hello@merkvex.com with subject “Privacy request” and state which right you seek to exercise and your jurisdiction if known. We may need to verify control of the account email. Some data cannot be deleted while required for legal, security, tax, or active dispute reasons: we will explain.

11. Cookies, local storage, analytics

You can clear site data in your browser; you may need to sign in again. If we introduce non-essential analytics cookies that require consent under EU/UK ePrivacy rules, we will update this Policy and present a consent mechanism.

12. Children; COPPA; age gate

The Service is for persons 18 years of age or older. Trading features, Paid Features, and Bazaar use are not available to minors under 18.

We do not collect age. Registration asks for an email address and nothing else — no date of birth, no age field, no identity document. The 18+ requirement is carried by your acceptance of the Terms of Service at sign-up, not by an age question, so no age or birth data exists on Merkvex to be stored, analysed, or lost. It also cannot enter the analytics described in §3.1, because it is never collected in the first place.

Consistent with the US Children’s Online Privacy Protection Act (COPPA) and similar laws, we do not knowingly collect, use, or disclose personal information from children under 13. We do not knowingly process data from anyone under 18 for trading features.

If you believe we have collected personal information from a child under 13 (or from a minor under 18 in violation of this Policy), contact hello@merkvex.com immediately. We will take steps to delete or de-identify that information and close or restrict the account as appropriate.

13. Automated decision-making

We use automated and semi-automated systems for rate limits, spam/abuse signals, fraud scoring, and feature eligibility. Account sanctions that materially affect trading access are subject to human review on appeal as described in the Community Guidelines and Terms. Where GDPR Art. 22 applies, you may request human intervention, express your point of view, and contest the decision via the appeals path or a privacy request.

14. Changes

We will update this Policy and the version/effective date when practices change. Material changes: email or in-Service notice when practicable (target ≥14 days where feasible). Continued use after the effective date means you accept the updated Policy, except where mandatory law requires otherwise.

Acceptance is recorded. Creating an account requires you to actively accept the Terms of Service and this Policy — an unticked box you tick yourself; it is never pre-ticked and never implied by simply continuing. We store the version identifier of each document you accepted and the time you accepted it, against your account. That record is what lets us tell who agreed to which version, and therefore who needs notice when a version changes. You can ask us for a copy of your own acceptance record under §10.

15. Contact

Choxxy / ChoxxyVerse
Merkvex
Saskatoon, Saskatchewan, Canada
hello@merkvex.com

Document control: Privacy v2026.08.26-S · Paired with Terms, Community Guidelines and Dispute Policy v2026.08.02-S (this Policy is the newer document in the family; the others are unchanged).
Change in this version: §3 now names the product/culture analytics and the consent record; new §3.1 describes the analytics pipeline; §7 retention, §11 and §12 updated to match; §14 records that acceptance is version-stamped.
Hierarchy: Terms control over Policies on contractual conflict.