Privacy Policy

App: Card Vault  |  Last updated: March 23, 2026

Summary: Card Vault stores your card collection data securely in the cloud so you can access it across devices. We show ads to keep the app free and offer an optional premium subscription. We do not sell your personal data.

1. Who We Are

Card Vault ("we", "our", "us") is operated by Falco van Dongen. If you have any questions about this policy, contact us at falcovdongen@gmail.com.

2. Data We Collect

Account Data

When you create an account or sign in, we collect:

This data is used solely to identify your account and sync your collection across devices.

Collection Data

The core function of the app is storing your Pokémon card collection. We store:

Device and Advertising Data

To serve ads, our advertising partner (Google AdMob) may collect:

This data is used to show you relevant advertisements. You can reset or opt out of personalised ads in your device settings under Privacy > Ads.

Purchase Data

If you subscribe to Card Vault Premium, our payments partner RevenueCat processes your purchase. We receive your subscription status (active, expired, etc.) but do not store full payment details such as card numbers. All payments are handled by the Google Play Store.

Notification Tokens

If you grant notification permissions, we store a Firebase Cloud Messaging (FCM) token to send you push notifications. You can revoke this at any time in your device settings.

3. How We Use Your Data

4. Third-Party Services

We use the following third-party services, each of which has its own privacy policy:

Supabase

Provides our database and authentication backend. Your account data and collection data are stored on Supabase infrastructure hosted in the EU (Frankfurt). Supabase Privacy Policy

Google Sign-In

Used as an optional sign-in method. Google Privacy Policy

Facebook Login

Used as an optional sign-in method. Meta Privacy Policy

Google AdMob

Serves advertisements within the app. AdMob may use your advertising ID and usage data to show personalised ads. Google Ads Privacy Policy

RevenueCat

Manages in-app subscriptions and purchase verification. RevenueCat Privacy Policy

Firebase (Google)

Used for push notifications (Firebase Cloud Messaging). Firebase Privacy Policy

5. Data Sharing

We do not sell, rent, or trade your personal data. We share data only in the following circumstances:

6. Data Retention

We retain your account and collection data for as long as your account is active. If you request account deletion, we will permanently delete your personal data and collection within 30 days.

Advertising data collected by Google AdMob is retained according to Google's own retention policies.

7. Your Rights

Depending on where you live, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at falcovdongen@gmail.com. We will respond within 30 days.

8. Children's Privacy

Card Vault is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Security

We use industry-standard measures to protect your data, including encrypted connections (TLS) and secure cloud infrastructure. However, no method of transmission over the internet is 100% secure and we cannot guarantee absolute security.

10. Changes to This Policy

We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after changes are posted constitutes your acceptance of the updated policy.

11. Contact

If you have any questions or concerns about this privacy policy or your data, please contact:

Falco van Dongen
falcovdongen@gmail.com