FOUNDER'S HOLIDAY WEEKEND · Subscribe → 0% fees Fri-Sun · Ends in1d 19h 20m
Home

Privacy Policy

Last updated: May 11, 2026

This Privacy Policy explains what personal information PokeBTS collects, how we use it, who we share it with, and the choices you have. It applies to pokebts.net and related services (the “Service”).

Heads-up before you buy or bid:

PokeBTS is not eBay. Bids and orders are binding the moment you submit them. Refunds are reviewed case-by-case and are not guaranteed unless fraud is clear and proven. Every collector is responsible for their own due diligence — zoom the photos, read the description, and ask before you commit. See the full Refunds & Disputes policy for what does and does not qualify.

1. Information We Collect

Information you provide:

  • Account info — email, username, password (hashed), date of birth, optional phone number.
  • Identity verification — selfie photo and government ID image when required for Stripe payouts (processed by Google Gemini for automated verification; not retained long-term).
  • Payment info — handled entirely by Stripe; we never see or store your full card number. Stripe shares with us only the last 4 digits, brand, and a tokenized reference.
  • Biometric credentials (Passkeys) — we store only the public key generated by your device. The biometric data itself (FaceID/TouchID/Windows Hello) never leaves your device.
  • Listings, photos, posts, messages — content you create on the Service.
  • Shipping address — when you ship or receive items.

Information collected automatically:

  • Pageviews and basic analytics (path visited, referrer, device type, country if available, scroll depth).
  • IP address (hashed with a daily-rotated salt — we do not store raw IPs).
  • Session ID (random string stored in your browser's sessionStorage).

Information from third parties:

  • Stripe (transaction status, payout state, identity verification result).
  • Pokemon TCG API (public card metadata and market pricing — no personal info).
  • Twilio (SMS delivery status and opt-out signals when you reply STOP).

2. How We Use Your Information

  • Operate the marketplace, auctions, P2P trades, escrow, and shipping flows.
  • Authenticate you and protect your account from unauthorized access.
  • Process payouts via Stripe Connect.
  • Send transactional notifications (order confirmations, dispute updates, password resets).
  • Send marketing SMS / email when you have opted in.
  • Detect and prevent fraud, abuse, and policy violations (including via AI moderation on Flex).
  • Improve the Service, measure performance, and develop new features.
  • Comply with legal obligations.

3. Who We Share Your Information With

We do not sell your personal information. We share data only with the service providers that make the platform work:

  • Stripe — payments, payouts, and identity verification.
  • Twilio — SMS delivery.
  • Resend / email provider — transactional email delivery.
  • Google (Gemini / Nano Banana) — AI-powered card analysis, ad creative generation, and Flex content moderation. Content sent to Google is governed by Google's API data-use terms (not used to train consumer Gemini models).
  • MongoDB Atlas — database hosting (data stored in U.S. region).
  • Emergent — application hosting infrastructure.
  • Google Ads / Analytics — ad performance and conversion measurement when enabled.
  • PostHog — product analytics and session insights.
  • Law enforcement / legal — if compelled by valid legal process or required to prevent imminent harm.

4. Cookies and Similar Technologies

We use browser localStorage and sessionStorage for authentication tokens, your session ID for analytics, and lightweight preferences (e.g., whether you've dismissed a banner).

Third-party services we use (Google Ads, PostHog) may set their own cookies subject to their own privacy policies. You can block cookies in your browser settings, but core features (login, cart, escrow) may stop working without them.

5. SMS Marketing and TCPA

By providing your phone number and submitting it on a waitlist or notification preferences form, you expressly consent to receive recurring promotional and transactional SMS from PokeBTS at the number provided, including via automated technology. Message frequency varies. Message and data rates may apply. Consent is not a condition of purchase.

You can opt out at any time by texting STOP to any message you receive. We will record the opt-out and stop sending you marketing messages within 24 hours. Transactional messages (e.g., password reset, dispute update) may continue as required to operate your account.

6. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we discover we have collected such data, we will delete it. Parents who believe their child has provided information to us can contact pokebtslivesupport@gmail.com.

Users 13–17 may use the Service with parental consent. Certain features (marketplace selling, Flex social posting) require users to be 18 or older.

7. Security

We protect your information using industry-standard practices: encrypted connections (HTTPS), bcrypt password hashing, hardware-backed biometric authentication (Passkeys/WebAuthn), short-lived JWT session tokens, and AI-driven content moderation. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you as required by law.

8. Data Retention

We retain your account information for as long as your account is active and for a reasonable period afterward to comply with tax, accounting, dispute resolution, and other legal obligations (generally up to 7 years for financial records). Identity verification images are retained only as long as necessary to satisfy Stripe's payout requirements and are deleted thereafter.

You can request deletion of your account at any time — see Section 10.

9. Your Rights

Depending on where you live, you may have the following rights:

  • Access — request a copy of the personal information we hold about you.
  • Correction — update inaccurate information from your profile settings or by contacting us.
  • Deletion — request that we delete your personal information, subject to legal retention obligations.
  • Opt-out of marketing — reply STOP to SMS, unsubscribe from email, or change preferences in your notification settings.
  • Do Not Sell / Share (California) — we do not sell personal information. You may opt out of sharing for cross-context behavioral advertising via your account settings.
  • Non-discrimination — we will not retaliate against you for exercising any of these rights.

To exercise any right, email pokebtslivesupport@gmail.com from the address on your account. We will respond within 30 days.

10. Closing or Deleting Your Account

You can close your account from your profile settings or by emailing pokebtslivesupport@gmail.com. We will delete or anonymize your personal information within 60 days, except for records we are required to retain by law (e.g., transaction history for tax purposes, dispute records).

11. International Users

The Service is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S. PokeBTS is not currently offered to users in the European Economic Area; if you are in the EEA, do not use the Service.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced via email or in-app notification. The “Last updated” date at the top reflects the most recent version.

13. Contact

Questions about this Policy or how we handle your data can be sent to pokebtslivesupport@gmail.com.

See also: Terms of Service.