1. Who We Are & Our Data Controller
The Card Vault Store is the data controller responsible for your personal data.
- Company Address: 16 Telford St, Inverness, GB IV7F 2CV
- Website: thecardvault-uk.com
- Contact Email: [email protected]
2. The Information We Collect
To provide you with a seamless, secure, and personalised collecting experience, we collect several types of information:
A. Information You Provide Directly:
- Identity & Contact Data: Name, billing and shipping address, email address, and phone number.
- Transaction & Financial Data: Payment information (processed securely via our PCI-DSS compliant partners; we do not store full card details), purchase history, and order details.
- Communication Data: Records of your correspondence with our enthusiast-run support team, including queries about orders, products (like Yu-Gi-Oh! Quarter Century promos or Magic: The Gathering – Aetherdrift boxes), or payment methods.
- Account Data (if applicable): Username, password, and preferences.
B. Information Collected Automatically:
- Technical Data: Internet protocol (IP) address, browser type and version, time zone setting, browser plug-in types, operating system, and device information.
- Usage Data: Information about how you use our website, including pages viewed, products browsed (e.g., in the All Pokémon or Battle Spirit Saga sections), search queries, and navigation paths.
- Cookie & Tracking Data: Data collected via cookies and similar technologies. See Section 7 for full details.
3. How We Use Your Information
We use your data with the same care and precision we apply to packing a booster box. Our legal bases include contract performance, legitimate interests, legal compliance, and your consent.
- To Fulfil Your Order: Process payments, arrange shipping (including customs documentation), and deliver your collectibles to your door, whether you’re a strategic player needing a tournament staple or a passionate collector securing a grail item.
- To Communicate With You: Send order confirmations, shipping updates, and respond to your support enquiries. With your consent, we may send information about new products (like the latest B28 – Ultra-Bout Series set), curated Hot Deals, or collection highlights.
- To Improve Our Vault: Analyse website use to enhance user experience, optimise our product range, and ensure our site is as secure and reliable as our payment gateway.
- To Protect Our Community: Monitor for fraudulent transactions, prevent abuse, and maintain the security of our website and services—a non-negotiable part of our promise to you.
4. Sharing Your Information
We treat your data like a rare card in our vault: with utmost respect and limited access. We only share it where necessary:
- Service Providers: Trusted partners who perform vital functions under strict contracts:
- Payment Processors (e.g., Stripe, PayPal) to handle encrypted transactions.
- Shipping & Logistics Partners (e.g., Royal Mail, DHL) to deliver your packages worldwide.
- IT & Analytics Providers to support website operations and analysis.
- Legal Obligations: If required by law, regulation, or legal process (e.g., customs declarations, fraud investigation).
- Business Transfers: In the unlikely event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
- With Your Consent: We will not share your data with third parties for their own marketing purposes without your explicit consent.
International Transfers: As a global store shipping from Inverness to collectors worldwide, your data may be transferred outside the UK/EEA (e.g., to payment processors). We ensure such transfers are protected by appropriate safeguards, such as Standard Contractual Clauses.
5. Data Security & Storage
Your security is paramount. We implement robust technical and organisational measures inspired by the same principles as our physical Vault:
- Encryption: Industry-standard SSL encryption across our entire website. Payment data is processed via PCI-DSS compliant gateways.
- Access Controls: Strict internal access controls to your personal data.
- Data Retention: We retain your personal data only for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. For example, we retain order information for 7 years for tax and warranty purposes.
- Your Financial Data: We do not store your full credit/debit card details on our servers. This is handled exclusively by our secure payment partners.
6. Your Rights & Choices
You have rights regarding your personal data, and we are committed to honouring them. Depending on your location, these may include:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (‘Right to be Forgotten’): Request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: Request we limit how we use your data.
- Right to Data Portability: Request a transfer of your data to another service.
- Right to Object: Object to processing based on our legitimate interests.
- Marketing Preferences: You can opt-out of marketing communications at any time by clicking the ‘unsubscribe’ link in any email or contacting us.
To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before proceeding.
7. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to ensure proper functionality, analyse trends, and personalise your experience (like remembering your cart or preferred currency).
- Essential Cookies: Necessary for the website to function (e.g., shopping cart, secure checkout). These cannot be switched off.
- Analytical/Performance Cookies: Help us understand how visitors interact with our site (e.g., which All Digimon or Alpha Clash pages are popular), allowing us to improve.
- Functionality Cookies: Remember your preferences (e.g., language, region).
- Targeting Cookies: May be set by advertising partners to build a profile of your interests. We do not allow these partners to use this data for their own independent purposes.
You can manage your cookie preferences via your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
8. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. The updated version will be posted on this page with a revised “Last Updated” date. We encourage you to review this page occasionally.
9. Contact Us & Raising Concerns
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our data protection lead:
Email: [email protected]
Post: The Card Vault Store, 16 Telford St, Inverness, GB IV7F 2CV
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or your local data protection authority.
Last Updated: March 2024
