Privacy Policy
Last updated: 8 October 2026
This policy explains what personal data JPCardHunt ("we", "us") collects when you use jpcardhunt.com and its alerts, why we collect it, how long we keep it and what your rights are under the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data
The data controller is Anton Kopach, Bulgaria, operating JPCardHunt.
Contact for all privacy questions and requests: [email protected].
We are a small service and are not required to appoint a Data Protection Officer; all requests are handled by the controller personally.
2. What data we collect
- Account data: your e-mail address. If you sign in with Google: your Google account ID, name and e-mail as shared by Google. If you set a password: only a salted, one-way hash of it (scrypt) — we never see or store the password itself.
- Your settings: watched cards and their filters, alert thresholds, language, alert channels and — if you add it — your Discord webhook URL.
- Alert history: which listings we have already sent to you, so you don't receive duplicates.
- Security and technical data: IP address, browser type and request details in server logs; failed sign-in attempts (used to block password guessing).
- Messages you send us: if you write to support, the content of your e-mail and your address.
We do not collect payment card data on this site, we do not use advertising or analytics trackers, we do not build advertising profiles and we do not sell your data.
3. Why we use it and on what legal basis
- Providing the service — creating your account, signing you in, storing your watchlist and sending the alerts you configured (Art. 6(1)(b) GDPR — performance of a contract).
- Security and abuse prevention — rate-limiting sign-in attempts, keeping server logs, protecting the service from attacks (Art. 6(1)(f) — legitimate interest).
- Service e-mails — sign-in links, confirmations and important notices about your account or these terms (Art. 6(1)(b) and (f)). We do not send marketing e-mails without your separate consent.
- Legal obligations — for example keeping records of payments if paid plans are introduced (Art. 6(1)(c)).
We do not use your data for automated decision-making that has legal or similarly significant effects on you.
4. Cookies
We only use cookies that are strictly necessary for the site to work, so no consent banner is required:
jpch_session— keeps you signed in (up to 30 days).g_oauth— protects the "Sign in with Google" step against forgery (10 minutes).lang— remembers your language (1 year).
Our network provider Cloudflare may set a technical security cookie to protect the site from attacks.
5. Who processes data on our behalf
- DigitalOcean — server hosting (data centre in Frankfurt, Germany).
- Brevo (France) — delivery of sign-in links and alert e-mails.
- Cloudflare — domain name service, network security and e-mail forwarding for [email protected].
- Google — only if you choose "Sign in with Google".
- Discord — only if you add a Discord webhook; alerts are then delivered to your Discord channel.
- Payment provider — only if paid plans are introduced; it will be named at checkout and will process payments as an independent controller or reseller.
Some providers may process data outside the European Economic Area. In that case transfers rely on the safeguards required by the GDPR, such as the European Commission's adequacy decisions or Standard Contractual Clauses.
6. How long we keep data
- Account data and settings — until you delete your account.
- Alert history — up to 90 days.
- Server logs and failed sign-in records — up to 90 days, usually much less.
- Sign-in and password-reset links — expire after 20 minutes.
- Support e-mails — as long as needed to handle your request, at most 2 years.
- Payment records (if any) — as long as required by tax law.
7. How we protect it
All traffic is encrypted (HTTPS). Passwords are stored only as strong one-way hashes, sign-in links are single-use and short-lived, secrets are kept only on the server with restricted access, and access to the server is limited to the controller using key-based authentication.
8. Your rights
Under the GDPR you have the right to:
- access the data we hold about you and receive a copy of it;
- have inaccurate data corrected;
- have your data deleted ("right to be forgotten") — you can delete your account yourself in Settings;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable, machine-readable format;
- withdraw any consent you gave, at any time.
To use these rights, write to [email protected]. We answer within one month. You also have the right to lodge a complaint with a supervisory authority — in Bulgaria the Commission for Personal Data Protection (cpdp.bg) — or with the authority in the EU country where you live or work.
9. Children
The service is not intended for children. You must be at least 16 years old to create an account. If we learn that we hold data of a younger child, we delete it.
10. Changes to this policy
We may update this policy when the service changes. The date at the top shows the latest version. If a change matters for you, we will tell registered users by e-mail before it takes effect.