Privacy Policy
How HoloLedger collects, uses and protects personal data.
Last updated: June 2026
1. Who we are
HoloLedger is a web application for Pokémon TCG sellers and collectors who want to manage inventory, operations, market estimates, grading scenarios, profitability and exports.
The controller and contact for privacy matters is:
[LEGAL_NAME] [BUSINESS_ADDRESS] [COUNTRY]
2. Data we collect
Depending on how you use HoloLedger, we may process:
- Account data: email address, user id and authentication metadata.
- Workspace data: inventory items, sealed products, operations, purchase prices, target sale prices, actual sale prices, fees, shipping costs, platform, status, notes, card/product metadata and image URLs where applicable.
- Pricing and market estimate data: pricing queries, external provider quotes, generated estimates, confidence/range data and internal pricing snapshots when a card/product has sufficient identity.
- Billing data: subscription status, plan, Paddle customer id, Paddle subscription id, billing period and cancellation status. Full card payment details are handled by Paddle and are not stored directly by HoloLedger.
- Technical/security data: logs, error information, request metadata and rate-limiting/security data necessary to operate and protect the service.
3. How we use your data
- Provide and operate the service.
- Authenticate users.
- Manage inventory and operations.
- Calculate profitability, margins and dashboard analytics.
- Generate Market Estimates and pricing snapshots.
- Provide premium features.
- Manage subscriptions and plan access.
- Generate CSV/Excel exports.
- Debug issues and improve reliability.
- Protect against abuse and unauthorized access.
- Comply with legal obligations where applicable.
4. Legal bases
Depending on your location and how you use HoloLedger, we rely on one or more of the following legal bases:
- Performance of a contract.
- Legitimate interests.
- Legal obligations.
- Consent where required, for example optional analytics or non-essential cookies if added later.
5. Third-party services
Depending on the features you use, data may be processed by the following providers:
- Supabase for authentication, database and storage-related infrastructure.
- Vercel for hosting and deployment.
- Paddle for billing, subscription and payment processing.
- External pricing providers such as the eBay API, the Pokémon TCG API and other enabled pricing providers.
- Email/support tools if added later.
Not every provider is used for every user; the providers involved depend on the features you actually use.
6. International transfers
Some providers may process data outside your country or region. Where required, we rely on the appropriate safeguards offered by those providers.
7. Data retention
- Account data is retained while your account remains active.
- Inventory and operations data is retained until deleted by you or until account deletion.
- Billing data is retained as required for accounting, legal and security purposes.
- Logs and security records are retained for a limited period where operationally necessary.
8. Your rights
Subject to applicable law, you may have the following rights regarding your personal data:
- Access.
- Rectification.
- Deletion.
- Restriction.
- Portability.
- Objection.
- Withdrawal of consent where applicable.
- Complaint to a supervisory authority where applicable.
9. Account deletion and requests
To exercise your rights or request account deletion, contact support@hololedger.app. Self-service deletion may be added later.
10. Security
HoloLedger uses reasonable technical and organizational measures to protect data, including authentication, access controls and database-level protections where applicable. No online service can be guaranteed to be completely secure.
11. Children
HoloLedger is not intended for children under 16, or under the minimum legal age in their jurisdiction.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.