Privacy Policy
Version 1.0 · in force since August 31, 2026
This policy says what data CartDisc keeps, why, who it is shared with, and what you can demand about it. It describes the system as it is actually built — when the system changes, this page changes with it.
1.Who the controller is
Data processed by CartDisc is controlled by Renato França, an individual. Any request under this policy — access, correction, deletion, questions — goes to renatofrancarpmf@gmail.com, which is also the contact channel required by art. 41 of the Brazilian data protection law (LGPD).
2.What is collected
What you provide to create and keep an account:
- email address and password — the password is stored only as a bcrypt hash, never as text;
- username, and optionally a display name, bio and profile picture;
- optionally, contact handles (Instagram, Discord, Telegram, X, email, website) — they exist so somebody can ask you about a copy you are selling or trading, so they are public to anyone who can see your collection;
- when you sign in with Google: name, email address and Google profile picture. No Google password ever reaches this service.
What you create by using the service:
- your collection and wishlist, including the fields only you can see — what you paid, your notes, and the tests you recorded;
- copy photos, hauls, haul captions and likes;
- contributions to the catalogue, with their date and moderation outcome;
- who you follow, who follows you, and your notifications.
What is collected automatically:
- technical access and error logs kept by the hosting provider, used to operate and debug the service;
- counts of sign-in and password-recovery attempts, stored under a hash — the IP address and email behind an attempt are never written to that table in the clear;
- usage measurement through Google Analytics, described under Cookies.
No sensitive data as defined by art. 5, II of the LGPD is collected, and no automated decision producing legal effects on you is made.
3.Why, and on what legal basis
Performance of the contract (art. 7, V): keeping your account, storing your collection, sending confirmation and password-recovery email, and delivering the features you use.
Legitimate interest (art. 7, IX): security and abuse prevention — which is what the sign-in attempt limits and the access logs are for — and aggregate usage measurement, which answers how many people use each part of the service.
Your own choice: making a profile public, making it indexable by search engines, publishing a haul, contributing a scan. None of these happen by default.
Compliance with legal obligations (art. 7, II), where they apply to records and to requests from authorities.
4.Who sees what
Profiles start private. Public and indexable are two separate decisions: a public profile is shareable by link, and only appears in search engines if you turn on that second option. The wishlist has its own visibility setting.
Public when you decide so: your profile, collection, wishlist, hauls and statistics.
Always public once approved: the scans you contribute, because they become part of the archive, and the credit to your username for as long as your account exists.
Never public: your email address, what you paid for a copy, your private notes, and the results of your working-condition tests.
5.Photos
Every uploaded image is re-encoded on the server. That drops the original file's EXIF metadata — GPS coordinates, device model and timestamp included — normalises orientation and caps the dimensions. The file that reaches storage is not the one that left your phone.
Copy photos stay pending until moderated, and only then appear in public galleries. Photos can be reported by other users and removed.
6.Cookies
CartDisc uses few, and none for advertising:
- the authentication session — essential, lasts up to 30 days, and is what keeps you signed in;
- cartdisc.locale — stores your chosen language for a year;
- cartdisc.invite — exists for a few minutes during an invited sign-up with Google, then disappears;
- cartdisc.consent — stores your answer about measurement for six months;
- _ga and _ga_* — Google Analytics 4, usage measurement, up to two years, and only with your permission.
Analytics records page views, device type and approximate location. Your email, your username and the contents of your collection are not sent to Google.
Measurement only happens if you allow it. A notice asks on your first visit, and until you answer, Analytics is forbidden from writing any cookie — the denial is declared before the tag loads, not after. Refusing costs the same single click as accepting.
If you refuse, no identifier is written to your browser; Google still receives an anonymous signal that the page was opened, with no cookie and nothing tying that signal to you or to an earlier visit.
Your answer lives in the cartdisc.consent cookie for six months and can be changed whenever you like, through the Cookies link in the footer. The essential and language cookies do not depend on that choice — without them, signing in stops working.
7.Who data is shared with
No data is sold, and nothing is shared with advertisers. Some providers run parts of the service:
- Vercel — application hosting and access logs;
- a managed PostgreSQL provider — the database;
- Amazon Web Services (S3) — storage for photos and avatars;
- Resend — delivery of confirmation and password-recovery email;
- Google — sign-in with Google, when you choose it, and Google Analytics;
- IGDB/Twitch and TheGamesDB — queried to look up game records and artwork. They receive the search term, never your identity or your collection.
Data may also be shared to comply with a legal obligation or a lawful order, and you will be told whenever the law allows it.
8.International transfer
The providers above keep servers outside Brazil, mainly in the United States. The international transfer relies on art. 33 of the LGPD, for the performance of the contract between you and CartDisc, and is limited to what running the service requires.
9.How long
Account data exists for as long as the account does.
Some has a shorter life of its own: email confirmation links expire in 24 hours, password-recovery links in one hour, and sign-in attempt counters disappear at the end of the window they count.
When you delete your account the removal is immediate and permanent — there is no soft delete. Two things remain: your username stays reserved, so old links cannot start pointing at someone else, and contributions already published stay in the archive with no link to you. Infrastructure backups may hold already-deleted data for up to 30 days and are overwritten in the normal cycle.
10.Your rights
Art. 18 of the LGPD gives you, among others, the right to:
- confirm that processing exists and access your data;
- correct incomplete, inaccurate or outdated data;
- ask for anonymisation, blocking or deletion of unnecessary data or data processed unlawfully;
- obtain your data in a portable form;
- know who it has been shared with;
- withdraw consent and object to processing based on legitimate interest.
Most of this is in the product itself: access and correction in Settings, portability in Settings → Account → Download your data, and deletion in Settings → Account. The portability file carries everything you recorded — collection, wishlist, hauls, contributions, former copies, test and play logs, contacts and preferences — in a machine-readable form, and states what it leaves out and why. The spreadsheet and catalogue exports remain on your shelf, for reading.
For anything else, write to renatofrancarpmf@gmail.com. You will get an answer within 15 days. You may also complain to Brazil's National Data Protection Authority (ANPD).
11.Children and teenagers
CartDisc is not intended for anyone under 16 and does not knowingly collect their data. An account found to be below that age will be closed and its data deleted. If you are responsible for someone who created one, write to renatofrancarpmf@gmail.com.
12.Security
What is in place: passwords stored as bcrypt hashes and never as text; all traffic over HTTPS; attempt limits on sign-in, sign-up and password recovery, counted against a hash rather than the original address; sessions that can be revoked all at once when a password changes; and images stripped of their origin metadata.
No system is perfect, and promising otherwise would be false. In a security incident carrying relevant risk, the National Data Protection Authority and the people affected will be notified, as art. 48 of the LGPD requires.
13.Changes to this policy
The version and effective date are at the top of this page. Significant changes — a new category of data, a new provider, a new purpose — will be announced by email or in the app before they take effect.