Last updated 3 September 2026.
This notice explains what Cambridge TCG does with personal data on this website, including account, marketplace, community, optional verification, testnet-wallet, PRISM Signals closed-beta-interest, Stripe-sandbox and Telegram-preview features. It also explains which choices make information public.
Cambridge TCG Limited (company number 15680297) is the controller for the processing described here. Our registered office is 60 Tottenham Court Road, Suite 4583a, Fitzrovia, London, United Kingdom, W1T 2EW.
For a privacy question, rights request, public-data correction or removal request, email [email protected]. Please put “privacy” in the subject where practical.
prism-signals, one or both bounded preferences of web and Telegram, the exact beta-contact wording version, and request, update and expiry times. The beta table stores no new copy of your email address; Cambridge TCG may use the email already held on your account only for a PRISM beta invitation or status update you requested. A Telegram preference does not supply a Telegram identity, authorise Telegram outreach or link an account. Presence of the row is not general marketing consent, a purchase, an invitation, a queue position, product access or an entitlement. You can inspect the exact owner-scoped state and delete the complete row without penalty from the same signed-in page.Most data comes from you. We also receive transaction and status data from Stripe, fulfilment or dispute information from a trading counterparty, optional account/profile and OAuth data from Google when you choose configured Google sign-in, public facts from a marketplace profile you ask us to check, wallet-verification results from the configured RPC service where needed, an optional Telegram update when you choose the configured PRISM preview bot, an optional account-scoped PRISM beta request when you choose to make one, and records created by our own service.
| Purpose | UK GDPR lawful basis |
|---|---|
| Create an account, authenticate, communicate and provide requested account tools. | Contract, including steps you request before entering one. |
| Receive and answer an optional PRISM Signals Telegram synthetic-preview command and protect the webhook from unauthorised submissions. | Legitimate interests in responding to the low-impact voluntary preview interaction you initiate and in authenticating, bounding and securing the test route. The necessity and balancing safeguards are recorded in the PRISM product-flow methodology. No payment or entitlement contract is formed. |
| Store a signed-in PRISM Signals closed-beta request and, if relevant, use the account email only for the requested PRISM beta invitation or status contact. | Consent through the separate affirmative beta-contact checkbox and versioned wording. Withdrawal deletes the request immediately and stops future contact based on it, without affecting prior lawful processing. It is not consent to general marketing. |
| At your request, operate the optional PRISM Stripe billing sandbox, mirror its test subscription lifecycle, provide owner status and cancellation, and secure or repair signed provider events. | Legitimate interests in providing the low-impact voluntary test you initiate, preventing misuse, enforcing idempotency, securing and repairing the test, and proving that no sandbox callback becomes live access by mistake. The sandbox takes no real payment and is not a live purchase contract. |
| Operate orders, trades, auctions, swaps, shipping, escrow, refunds and payouts. | Contract; and legal obligation where payment, tax, accounting or regulatory rules apply. |
| Publish any bid or ask that remains open so collectors can discover its terms, respond and see market depth. | Contract, including the open-order service you request; and legitimate interests in operating a transparent peer-to-peer order book where contract is not the applicable basis. This necessary order-book publication is not treated as consent to the separate profile, activity or directory features. |
| Keep tax, company and transaction records and respond to lawful requests. | Legal obligation. |
| Prevent abuse, secure sign-in, rate-limit, investigate replay, fraud, disputes and legal claims, moderate, and maintain service reliability. | Legitimate interests in protecting users, transactions, Cambridge TCG and the service; and legal obligation where applicable. |
| Publish a profile, review, milestone activity or collective-directory listing you separately switch on. | Consent, recorded per purpose and notice version. You can withdraw it for future Cambridge publication. |
| Save a private deck or owner-only collector observation; publish a deck; or record permission for a possible future collector-observation projector. | Contract for the requested private save/notebook; consent for public deck publication or future-projector eligibility. No collector-observation projector is active now. |
| Perform optional Cambridge identity verification or a nominated external-reputation check. | Consent for an enabled optional submission/check; legitimate interests in reviewing authenticity and preventing fraud for review and audit records. |
| Link and verify a Base Sepolia testnet wallet. | Consent for the optional link; legitimate interests for bounded attempts, replay investigation and proof audit. |
| Remember functional preferences and keep the application working. | Contract and legitimate interests in a usable, secure service; cookies are used only where necessary or requested. |
Our legitimate interests are service and transaction security, fraud and abuse prevention, dispute handling, moderation, reliability, record integrity and the defence of legal claims. We consider whether those interests can be achieved with less data and the likely effect on people. You can object; we will reassess the balance unless the law requires the processing or compelling grounds override the objection.
Cambridge TCG uses rules to calculate and present trust scores and tiers; set transaction limits, escrow routes, physical-inspection requirements, trust-based commission rates and payout holds; enforce auction, payment and trade states; match only explicit card-level trade intent; apply rate limits; and raise security, fraud or moderation flags. Inputs can include account age and state, completed or cancelled transactions, trading volume, trust-weighted reviews, verified external reputation, returns, disputes and chargebacks, transaction value, card category, explicit listing/wishlist choices and risk signals.
Fraud signals have a specific automatic downstream effect. Each unresolved signal at medium, high or critical severity subtracts 20 points the next time the trust score is calculated. A lower result can reduce per-transaction and daily limits, change the displayed tier or trust-based commission rate, route a future trade through stricter escrow or inspection, and lengthen a hold on a future seller payout. The signal row’s stored auto_actionlabel is not itself executed: current detection does not directly suspend the account or stop an already-earned payout. An operator can resolve or dismiss a signal; recalculating the score then removes that signal’s 20-point deduction.
A rule can reject or limit an action, change the route or terms of a trade, require inspection or escrow, delay a payout, change trust presentation, or affect whether a listing/account is discoverable. Whether an outcome has a legal or similarly significant effect depends on its real context and impact; Cambridge TCG does not treat this list as a conclusion that the statutory safeguards for solely automated decisions can never apply. If a rule blocks or materially changes a service, email the privacy contact to request an explanation and human review, express your view, or challenge inaccurate input data. Where those statutory safeguards apply, the review must be capable of correcting inputs and changing the outcome rather than merely repeating the automated result.
There is not yet a durable in-product decision-review case queue, assigned reviewer or published service level. Email is the current request channel, but a support link alone is not evidence that human intervention is operational. For that reason, production rejects new orders, offers and acceptances, auction commitments, swaps, lot commitments and automatic pricing-rule commitments by default. The pause does not block payment, shipping, receipt, cancellation, return, dispute, refund, payout, evidence or revocation steps for an existing obligation.
Any part of a bid or ask that remains open is published without sign-in because public discovery is the service requested when an open order is placed. The aggregate order book identifies the card/SKU and side and, at each price, the total remaining quantity and number of orders. It also exposes best-bid, best-ask and derived book values such as spread. Aggregate price levels do not include individual order IDs or account identity.
Bids are not returned as individual public rows; only aggregate bid values are public. To support negotiation, the individual- ask response returns the SKU and, for each ask, its listing ID, price, remaining quantity, condition, offer setting, return setting and return window, creation time and a listing-scoped contact-availability flag. A signed-in viewer can also be told whether an ask is their own. The response does not return the seller’s account/user ID, username, name, profile, email, trust dossier, private notes, payment details or delivery address.
Once an order is cancelled, completely filled or expired, Cambridge TCG stops serving it in future open-order responses. Cambridge TCG cannot recall copies already fetched, cached, indexed or redistributed by someone else. Do not place an open order if you do not want its terms published in this way.
Saved decks are private unless their owner selects “Publish to community”. A public deck is listed at /decks and available through unauthenticated list and full-deck APIs. Anyone can read and copy it. The public list includes the deck identifier and slug, name, leader/card summary, tags, view count and update time. The full public response includes its card identities and quantities, notes, tags, view count and update time. Stored catalog price and image snapshot values are withheld from these public responses, and the author account ID is not returned.
Opening a full public-deck API response increments its aggregate view count; the current counter is not deduplicated by session. Unpublishing stops Cambridge TCG serving the deck through the public page and APIs but cannot recall a copy already fetched. Delete the deck to remove its saved row. Do not put another person’s personal data in a deck name, note or tag.
A public collective profile and inclusion in the organisation directory are separate choices. A public profile is available at its /c/… address. The directory adds searchable HTML and a public JSON API containing the slug, display name, kind, region, languages, description, house rules, and platform-record creation and update times. Names and descriptions are searchable; kind, region and language are filters. Existing public profiles are not listed automatically.
Anyone can view directory material. Search engines, AI crawlers and other third parties may index, copy or redistribute it. Turning the listing off stops future directory responses but leaves the public profile visible; making the profile private also clears the listing. Cambridge TCG cannot recall copies already fetched. Do not include personal data about another person in directory fields. For correction or removal, turn the listing off or email the privacy contact. Read the directory publication contract.
For versioned person, activity and directory choices, Cambridge TCG stores the current notice version and acceptance time while the choice is on. Deck publication currently stores an unversioned public/private flag and deck update time, not a separate notice receipt. Withdrawal stops future publication by Cambridge TCG and clears an active receipt where the feature is designed that way; it cannot make someone else forget, return or delete a copy they already obtained.
Wallet linking is optional and currently limited to Base Sepolia; Cambridge TCG does not accept assets through this feature. We keep the public Base Sepolia address, chain, proof method, verification times, signature fingerprint, and the exact five-minute standard wallet-signing message (EIP-4361), including its one-use code and random request identifier. We also keep the bounded verification-attempt count and attempt times. A separate one-way digest binds the challenge to the Cambridge sign-in session; that digest is not placed in the wallet-visible message. The raw session token and wallet signature are not retained. This proof is not identity, KYC, asset ownership, or permission to move funds; it shows only control of the address at that time.
A public blockchain address and its public activity may be correlated with the Cambridge account that links it. Cambridge TCG first checks an ordinary wallet signature locally. Only after that fails does the configured Base Sepolia network service receive the public address to check whether it belongs to a smart wallet. It receives the exact challenge message and submitted signature only when the address has deployed smart-wallet code or the signature contains a locally recognised smart-wallet marker (ERC-6492). Cambridge first checks that the service reports Base Sepolia. Cambridge TCG will not enable remote smart-wallet verification unless the wallet screen identifies the configured RPC provider and links its privacy information before a submission can call it. If no provider is explicitly and validly configured, smart-wallet verification stops instead of using an unnamed default. The wallet feature may remain disabled until these conditions are met.
Suppliers and infrastructure may process data outside the United Kingdom. In particular, some Cambridge database and object storage currently uses AWS in the United States, while Google, AWS, Vercel and Stripe operate international services and subprocessors. Their provider terms state that a recognised mechanism applies where UK restricted-transfer rules require one, such as UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum to standard contractual clauses, as applicable, together with contractual and security measures. Cambridge TCG relies on those terms for these services. The applicable route can vary by provider and subprocessor. Provider information is available in the AWS GDPR centre, Vercel DPA, Telegram privacy policy and Stripe privacy centre. Contact us for the current safeguard relevant to your data.
closed-beta-v1 mode is only a switch for new request intake and its public invitation; pausing or losing that setting does not disable authenticated owner status, withdrawal, or the retention sweep.Public catalogue and methodology pages can be viewed by anyone and may be accessed by children. Account, messaging, social publication, trading, payment, collective-directory publication, Cambridge identity-verification and wallet-linking features are not designed for people under 18. Cambridge TCG does not currently run general age assurance or record a site-wide, versioned age-and-terms assent at account creation or before all social tools. Production now defaults new account admission and new P2P commitments to paused unless an operator selects the exact reviewed release mode. That reversible release control is not age assurance, so the service still cannot claim that every account holder is an adult. When the optional identity-verification form is enabled, it rejects a declared date of birth under 18; that is not site-wide age verification. A person under 18 should not submit personal data to or use those account features. A parent or guardian can email the privacy contact to ask us to locate and remove a child’s data, subject to legal retention duties.
/api/tradein/status, /api/tradein/submit, /api/tradein/quote, /api/market/sell-for-credit and /api/quotes paths return HTTP 410 before reading submitted content or trade-in database records, so they collect no new trade-in submission content. Ordinary infrastructure request logs described above can still exist. Legacy database schemas remain; this notice does not infer from source code alone whether a historical row exists. Any historical transaction record, if present, follows the transaction-retention and rights rules in this notice.Depending on the circumstances, UK data-protection law gives you the right to:
Email [email protected] to exercise a right. We may ask for proportionate information to verify identity and scope. Rights are not absolute: tax/company records, another person’s rights, fraud/safety records, legal claims and other statutory exceptions can limit a request. We normally respond within one month, subject to the extensions the law permits for a complex or repeated request.
You can make a complaint about Cambridge TCG’s handling of personal data through the same privacy email address. Put “data protection complaint” in the subject and explain what happened, which data or feature is involved and the outcome you seek. Cambridge TCG will acknowledge a data-protection complaint within 30 days, make appropriate enquiries, keep you informed where the investigation remains open, and communicate the outcome without undue delay. A complaint can include a rights request; the applicable rights-request time limit remains separate.
You can also complain to the UK Information Commissioner’s Office. See the ICO’s complaint service. We would welcome the chance to address the issue first, but you do not have to contact us before contacting the ICO.