Skip to main content

Privacy Policy

Last Updated: 25 August 2026 Effective Date: 23 April 2026

Operating Entity

RetroTechCollector is a service operated by RetroTechCollection.

Operating Entity: RetroTechCollection Service Name: RetroTechCollector Operating Entity Website: https://retrotechcollection.com Service URL: https://retrotechcollector.app

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use RetroTechCollector. In this policy, "we", "us", and "our" refer to RetroTechCollection, the operating company.

RetroTechCollection is based in the United Kingdom and processes data in accordance with UK GDPR and the Data Protection Act 2018. Our infrastructure is located in the United States, as Section 5 explains.

1. Who We Are

RetroTechCollection is the data controller for the personal information you provide when using RetroTechCollector. Our registered office is in the United Kingdom (full address available upon request).

For privacy questions, contact: [email protected] For data protection officer inquiries: [email protected]

2. What Information We Collect

Information you give us

When you register and use RetroTechCollector, we collect:

Account information:

  • Email address
  • Username, and any usernames you have previously used
  • Password (stored only as a bcrypt hash; we never see or store the password itself)
  • First and last name, if you choose to provide them
  • Which version of the Terms you accepted, and when

We do not ask for your date of birth, and we don't collect it anywhere. Age requirements are a term of the service, not something we verify.

Profile information:

  • Display name and biography (optional)
  • Profile photo, banner and custom badge (optional)
  • Location as free text, if you enter one (optional)
  • Preferred display currency and language
  • Privacy and visibility preferences, including whether your profile is public, friends-only or private, and whether it is visible to logged-out visitors

Collection data:

  • Item details you enter (names, descriptions, serial numbers, purchase dates, values, conditions)
  • Photos you upload
  • Storage locations you define
  • Notes, maintenance tasks, play activity, loans and show records
  • Relationships between items

Marketplace activity:

  • Listings you create (prices, descriptions, quantities, options, shipping and returns settings)
  • Offers and bids you make or receive
  • Transactions you complete
  • Postal addresses used for a transaction, and delivery tracking
  • Storefront details, if you set one up
  • Wanted ads, listing questions and answers
  • Ratings and reviews you give or receive

Seller and payout information (only if you sell):

  • Your Stripe Connect account identifier and its status
  • Seller reputation counters, such as completed sales and late shipments
  • If you tell us you sell as a business: business name, business country and VAT number

We do not receive or store your card number, expiry date or security code. Nor do we store your card's brand or last four digits. Card details exist only with our payment provider.

Subscription and purchase data:

  • Plan (Hobbyist, Collector, Enthusiast) and billing interval
  • Subscription status (active, trialing, cancelled, past due)
  • Payment source (Stripe, Apple In-App Purchase or Google Play)
  • For web subscribers: Stripe customer and subscription identifiers (no card details)
  • For iOS and Android subscribers: opaque store-issued transaction identifiers (we never see your Apple or Google account, your name, or your payment details, only that a valid subscription exists and when it renews or expires)
  • Trial eligibility history (whether you've used a free trial before)

Messages:

  • The content of messages you send, encrypted while stored (see Section 8; this is not end-to-end encryption)
  • Participants in conversations
  • Timestamps and read status

AI feature records: When you use one of the AI features we keep a record of the outcome, not the input: what the model suggested, its confidence, how many catalogue candidates we showed you, and technical details such as which model version ran and how long it took. We don't retain the photograph you submitted for AI processing. See AI Features and the EU AI Act.

Support enquiries:

  • Content of your support requests and feedback
  • Attachments you send us

Information we collect automatically

Usage information:

  • Pages you visit and features you use
  • Listings you view
  • Search queries and saved searches
  • Filters and sort preferences

Device and session information:

  • Browser type and version, operating system, and device type
  • IP address, and an approximate location (city / region / country) derived from it
  • Network operator information derived from your IP address
  • Whether the connection appears to come from a VPN, proxy, hosting provider or Tor
  • For each sign-in session: the device description, the IP it started from, and the last IP and time it was active
  • For push notifications on mobile: a device token, device model, OS version and app version

Security records:

  • Sign-in attempts, whether they succeeded, and why they failed
  • Security events such as password changes, email changes, new device sign-ins and session revocations
  • Marketplace fraud signals and risk assessments

Some of these records exist specifically to protect accounts, and are kept on the retention schedule published in our GDPR statement. Where we keep an IP address for security analytics, we also keep a keyed hash of it so we can continue to recognise patterns after the raw address has been purged.

Cookies and similar technologies:

  • Session cookies (essential for login)
  • Preference cookies (language, theme settings)
  • Analytics cookies

See our Cookie Policy for details.

Information from third parties

Stripe (web subscriptions, marketplace payments and payouts):

  • Payment confirmation
  • Payout status (for sellers)
  • Fraud detection signals

Apple App Store and Google Play (in-app subscriptions, via RevenueCat):

  • The store-issued transaction identifier for your purchase: an opaque reference, not your Apple or Google account
  • The product identifier you purchased (which plan and interval)
  • Subscription status changes from the store: renewal, cancellation, expiration, refund, billing retry, grace period
  • Introductory offer eligibility (whether the store considers you eligible for a free trial on a given product)
  • Environment (sandbox or production), so we don't treat test purchases as real subscriptions

We never receive your Apple or Google account email, your name, your payment method, or any other information those stores hold about you.

RevenueCat: RevenueCat sits between our app and the app stores. When you subscribe on iOS or Android, the store's receipt and renewal notifications go to RevenueCat first. RevenueCat validates them with the store and forwards a normalised record to our server so we can grant or revoke your plan. RevenueCat sees:

  • The store transaction identifier and product identifier described above
  • A pseudonymous "app user ID" which is our internal numeric user id (not your name, email, or any direct identifier)
  • The approximate country inferred from the store account region (so RevenueCat can render prices in the right currency)

RevenueCat's own privacy policy is at revenuecat.com/privacy.

Shippo (postage and tracking): If a postage label is bought through the platform, the delivery and return addresses for that transaction are sent to Shippo and to the chosen carrier so the label can be produced and the parcel tracked.

Catalogue sources (Wikipedia, IGDB, Giant Bomb, PriceCharting, LaunchBox):

  • We fetch public information about hardware and games to enrich catalogue entries
  • These are outbound lookups about equipment. We don't send them any of your personal information.

Google Sign-In and Apple Sign-In (optional):

  • If you choose to sign in with Google or Apple, we receive your email address and basic profile information from that provider
  • Apple may issue you a private relay email address instead of your real one; we accept that and don't try to resolve it
  • You can revoke the connection at any time from your Google or Apple account settings

3. How We Use Your Information

We use your data for these purposes:

Providing the service

  • Creating and maintaining your account
  • Enabling you to catalogue your collection
  • Facilitating marketplace transactions
  • Processing payments and payouts
  • Sending transactional emails (purchase confirmations, shipping updates, etc.)
  • Providing customer support
  • Enforcing our Terms of Service

Legal basis: Contract performance. We need this data to provide the service you've signed up for.

Improving RetroTechCollector

  • Understanding how people use the platform
  • Identifying bugs and fixing them
  • Testing new features
  • Analysing which features are popular or underused
  • Optimising performance

Legal basis: Legitimate interests. Improving our service benefits everyone.

Safety and security

  • Detecting and preventing fraud
  • Identifying suspicious marketplace activity
  • Investigating violations of our Terms
  • Moderating content that has been reported
  • Protecting against account takeovers
  • Complying with legal obligations

Legal basis: Legitimate interests and legal obligations.

AI features

  • Suggesting what an item is from a photo you submit
  • Suggesting a condition grade from a photo you submit
  • Drafting a listing description from details you have already entered

These run only when you invoke them, each has a manual alternative, and none of them decides anything on its own. Legal basis: Consent. Using a feature is how you consent to that processing. Full detail is in AI Features and the EU AI Act.

  • Sending you product updates and feature announcements
  • Notifying you about relevant marketplace activity
  • Weekly digest emails (if you've enabled them)

Legal basis: Consent. You can opt out at any time.

  • Responding to law enforcement requests
  • Complying with court orders
  • Meeting tax and accounting requirements
  • Protecting our legal rights

Legal basis: Legal obligation or legitimate interests.

4. How We Share Your Information

We don't sell your personal data. Ever.

We share limited data in these situations:

With other users

Public by default:

  • Your username
  • Items you've marked as public in your collection
  • Marketplace listings, storefronts and wanted ads
  • Questions you ask on a listing, and a seller's answers
  • Ratings and reviews you leave

Your real name is only shown on your public profile if you turn that on; otherwise other people see your username. A separate setting controls whether logged-out visitors and search engines can see your profile, posts and collection at all.

Visible to friends (if you've enabled friend features):

  • Your full collection (if shared with friends)
  • Activity updates

In transactions:

  • Buyers see your username and can message you
  • If a transaction completes, delivery addresses are shared so the item can be sent
  • After delivery, both parties see each other's ratings

You control most of this through privacy settings.

With service providers

We use third parties to help run RetroTechCollector. The complete list, with what each one handles and where it operates, is in our GDPR statement. In summary:

Google Cloud Platform (hosting):

  • Runs our application servers, database and image storage, in the United States
  • Has access to stored data but is contractually bound to process it only on our instructions

Google Cloud Vertex AI:

  • Receives the photo or text you submit to an AI feature
  • Doesn't receive your account identity as part of the request

Stripe (payments):

  • Processes card payments for web subscriptions and marketplace transactions
  • Handles seller payouts and Stripe Connect accounts
  • Holds payment details; we don't

Apple and Google (in-app billing):

  • Process in-app purchases on their own infrastructure
  • Hold the payment relationship with you: your Apple or Google account is billed, not us
  • Send us receipts and renewal notifications via RevenueCat
  • We never transmit your personal data to them for billing; they already have their own relationship with you

RevenueCat (subscription lifecycle):

  • Validates store receipts on our behalf
  • Stores the store transaction identifier and product identifier linked to our internal numeric user id
  • Sends us notifications when your subscription renews, cancels, expires, is refunded, or enters billing retry
  • Doesn't receive your email, name, payment details, or any personal identifier beyond that opaque id

Shippo (postage and tracking):

  • Receives delivery and return addresses for transactions where a label is bought through the platform
  • Passes them to the carrier you choose

Cloudflare:

  • Sits in front of our service to deliver content and block attacks
  • Processes connection metadata, including your IP address

Sentry (error monitoring):

  • Receives diagnostic reports when something goes wrong. While you are signed in, those reports identify the account they came from (your internal user id, username and email address) alongside the page you were on and technical context
  • Hosted in the European Union

Email provider:

  • Sends notification and transactional emails
  • Receives your email address and the content of those messages

Google Analytics:

  • Receives usage events and standard web analytics data, such as pages viewed, device and browser type, and an analytics identifier
  • We don't send it your name, email address or collection contents
  • See the Cookie Policy for the categories and how to control them

All service providers are contractually bound to protect your data.

We may disclose data if:

  • Required by law (court order, subpoena)
  • Necessary to protect rights or safety
  • Part of a business transfer (acquisition, merger)
  • You've given explicit consent

We'll notify you if possible, unless prohibited by law.

5. Where Your Data Is Processed

Our primary infrastructure is in the United States, not the UK or the EU. The application servers, the database and the image storage all run on Google Cloud Platform in the us-central1 region (Iowa, USA).

Sending your personal data there is a restricted transfer under UK GDPR, and we treat it as one. It is covered by a data processing agreement incorporating the Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum, together with the safeguards Google Cloud publishes for its own transfers.

Some processing happens elsewhere: our content delivery and edge protection run on Cloudflare's global network, and our error monitoring is hosted in the European Union. Payment, shipping and subscription providers operate from their own locations.

The full processor list and the safeguards for each are in our GDPR statement. You can request copies of those safeguards: [email protected]

6. How Long We Keep Your Data

We keep different types of data for different periods, and the schedule is enforced automatically.

Active accounts:

  • Your collection, listings, messages and transaction history are kept while your account is open

Closed accounts:

  • Most data is deleted within 30 days
  • Some data is retained longer where the law requires it

Security and operational records are purged on the periods published in our GDPR statement: sign-in attempts after 180 days, security events after 365 days, administrator audit records after 730 days, security email logs after 180 days, IP geolocation cache after 30 days, and marketplace fraud signals after 365 days, among others.

Records we keep longer:

  • Transaction records: retained to meet tax, accounting and anti-money-laundering obligations
  • Marketplace disputes: retained after resolution so a decision can be reviewed
  • Backups: rotated and then deleted

Legal holds:

  • If there's ongoing litigation or an investigation, we keep relevant data until it's resolved

You can request deletion sooner, subject to those legal requirements.

7. Your Rights Under UK GDPR

You have these rights. Our GDPR statement sets each one out in more detail.

Right to access

You can request a copy of your personal data. You can download it yourself at any time from your account settings. It arrives as an archive containing your account information, collection, listings, offers, transactions, ratings and messages. We'll respond to a written request within 30 days.

For your protection, that download is disabled while a support administrator is viewing your account on your behalf.

Right to rectification

If your data is wrong or incomplete, you can update most of it yourself in settings. For things you can't change, contact us.

Right to erasure ("right to be forgotten")

You can request deletion. Closing your account requires you to re-authenticate first, so a stolen session can't delete it. We'll comply unless we need to keep data for:

  • Legal obligations (like tax records)
  • Defending legal claims
  • Completing transactions in progress

Right to restrict processing

You can ask us to limit how we use your data while we resolve a complaint or verify accuracy.

Right to data portability

You can export your collection data at any time from your account, in a structured, machine-readable format.

Right to object

You can object to processing based on legitimate interests. We'll stop unless we have compelling reasons to continue.

For things requiring consent (marketing emails, analytics cookies, the AI features) you can stop at any time. This doesn't affect processing we did before you withdrew consent.

We don't make automated decisions with legal or similarly significant effects. Nothing about your account, your access, your money or your standing is decided by a model or an automated rule alone.

We do use AI to assist you: suggesting what an item is, suggesting a condition grade, and drafting a listing description. Each produces a suggestion you accept, edit or reject before it has any effect. See AI Features and the EU AI Act.

How to exercise your rights

Email [email protected] with your request. We'll:

  • Verify your identity (to protect your data)
  • Respond within 30 days
  • Explain if we can't comply and why

These requests are free. If you make excessive or repetitive requests, we may charge a reasonable fee or refuse.

Right to complain

If you're unhappy with how we handle your data:

  1. Contact us first: [email protected]
  2. If not satisfied, complain to the UK Information Commissioner's Office (ICO):
    • Website: ico.org.uk
    • Phone: 0303 123 1113
    • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

8. Security

Messages: what "encrypted" means here

Direct messages are encrypted at rest with a key that we hold. They are stored as ciphertext, so the message content isn't readable from a database backup or a stolen copy of the data on its own.

This is not end-to-end encryption, and we will not describe it as such. Because we hold the key, we are technically able to read message content, and in defined situations we do:

  • When a message or conversation is reported, our moderators can read the messages involved in order to act on the report. Moderating abuse, harassment and scam attempts depends on this.
  • When a marketplace dispute is opened, the conversation attached to that transaction can be read as evidence.
  • When you export your own data, we decrypt your messages so the export is readable.

Access is restricted to staff whose role requires it, is controlled by named permissions, and administrative actions are recorded in an audit log. If you need a channel we cannot read, don't use in-app messaging for it.

Technical measures

  • Encryption in transit (TLS/HTTPS)
  • Encryption at rest for sensitive data (AES-256-GCM), including message content and two-factor authentication secrets
  • Database backups written to a separate, private storage location that is never publicly readable, encrypted at rest
  • Password hashing (bcrypt with 12 rounds)
  • Two-factor authentication available
  • Passkey / WebAuthn support
  • Rate limiting and IP blocking against automated attacks
  • A check against known breached-password lists when you set a password, so we can warn you

Organisational measures

  • Role-based access controls, so staff only reach what their role requires
  • An audit log of administrative actions, including any support session opened on your account
  • Incident response procedures
  • Review of the third parties we send data to

Limitations

  • No system is completely secure
  • You're responsible for keeping your password safe
  • Don't share your account
  • Enable two-factor authentication or a passkey for additional protection

If we discover a breach affecting your data, we'll:

  • Notify you without undue delay where there is a high risk to your rights
  • Report to the ICO within 72 hours where required
  • Take steps to mitigate harm

Support sessions on your account

A support administrator can open a time-limited session to see your account as you see it, in order to help with a problem. When that happens:

  • The session lasts a maximum of 30 minutes and cannot be extended
  • It appears in your own Active Sessions list, labelled as an administrator support session, and in your security activity
  • It cannot be used to change your password, change your two-factor settings, change your email address, delete your account or download your data

9. Children's Privacy

RetroTechCollector is not intended for children under 13, and we don't knowingly collect data from them. Users aged 13 to 17 need parental consent to use the service, and you must be 18 or over to buy or sell on the marketplace.

We don't collect date of birth, so we can't verify age. If we learn we've collected data from someone under 13, we'll delete it.

Parents can contact [email protected] if they believe their child has created an account.

10. Cookies and Tracking

We use cookies and similar technologies. See our Cookie Policy for full details.

In summary:

  • Essential cookies: required for the site to work (can't be disabled)
  • Functional cookies: remember your preferences
  • Analytics cookies: help us understand how the platform is used
  • Marketing cookies: we don't currently use these

11. Email and Notifications

We send several types of emails:

Transactional (can't opt out):

  • Account creation and email verification
  • Password resets
  • Purchase confirmations
  • Shipping updates
  • Security alerts

Notification (can customise):

  • New messages
  • Offer updates, including counter-offers and accepted offers
  • Transaction and delivery status changes
  • Friend requests, follows and social activity

Marketing (can opt out):

  • Product updates
  • New features
  • Weekly digest

Manage preferences in account settings. Push notifications on mobile are controlled separately, both in the app and in your device settings.

12. Changes to This Policy

We may update this privacy policy. When we do:

  • We'll update the "Last Updated" date
  • For significant changes, we'll email you
  • We'll ask for new consent if required by law
  • Previous versions will be archived

Your continued use after changes means you accept the updated policy.

RetroTechCollector contains links to external sites (like Wikipedia). When you click them:

  • You're subject to their privacy policies
  • We're not responsible for their practices
  • Read their policies before providing data

14. Business Transfers

If RetroTechCollector is acquired or merged:

  • Your data may transfer to the new owner
  • We'll notify you beforehand
  • The new owner must honour this privacy policy (or get your consent for changes)
  • You can close your account before the transfer

15. Your California Privacy Rights (CCPA)

If you're a California resident, you have additional rights under CCPA. We extend the same rights described in Section 7 to everyone, wherever they live.

Key points:

  • We don't sell personal information
  • You can request disclosure of data collected and shared
  • You can request deletion
  • We won't discriminate if you exercise CCPA rights

16. Contact Us

Privacy questions: [email protected] Data Protection Officer: [email protected] General support: [email protected] Security concerns: [email protected]

Mail: RetroTechCollection [Address available upon request] United Kingdom

We aim to respond to privacy enquiries within 5 business days, and resolve requests within 30 days as required by law.


If anything here is unclear, ask us to explain it.