Understanding Our Commitment to Privacy and Data Protection
This page clearly explains how tradingcardgamestore.co.uk collects, uses, and safeguards your personal information in line with UK GDPR and the Data Protection Act 2018, ensuring transparency and trust.
Committed to Protecting Your Privacy
Discover how our adherence to UK GDPR and the Data Protection Act 2018 safeguards your personal information with transparency and care.
UK GDPR Compliance
Certified in full compliance with UK GDPR, ensuring your data is handled legally and ethically at every step.
Data Security Measures
Implementing robust security protocols to protect your personal information from unauthorized access or breaches.
Transparent Data Usage
Clearly outlining how we collect, use, and store your data to maintain your trust and confidence.
User Rights Protection
Empowering you with control over your data, including access, correction, and deletion rights.

Privacy Policy
Effective Date: May 2026
Last Updated: 10th May 2026
1. Introduction
Welcome to tradingcardgamestore.co.uk. We respect your privacy and are committed to protecting your personal data. This privacy policy informs you how we look after your personal data when you visit our website (regardless of where you visit it from) or purchase our products, including single Pokémon cards, curated bundles, and graded single cards. It also informs you about your privacy rights and how the law protects you.
1.1 Controller Information
Trading Card Game Store is the controller and responsible for your personal data (collectively referred to as “we”, “us”, or “our” in this policy).
Contact Details:
- Full Name of Legal Entity: Trading Card Game Store
- Email Address: privacy@tradingcardgamestore.co.uk
- Postal Address: TBC
- Telephone Number: TBC
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
2. The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:
- Identity Data: First name, last name, username or similar identifier.
- Contact Data: Billing address, delivery address, email address, and telephone numbers.
- Financial Data: Bank account and payment card details (processed securely via our third-party payment gateways; we do not store full card details on our servers).
- Transaction Data: Details about payments to and from you and other details of products (singles, bundles, graded cards) you have purchased from us.
- Technical Data: Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
- Profile Data: Your username and password, purchases or orders made by you, your interests, preferences, feedback, and survey responses.
- Usage Data: Information about how you use our website, products, and services.
- Marketing and Communications Data: Your preferences in receiving marketing from us and our third parties and your communication preferences.
3. How Is Your Personal Data Collected?
We use different methods to collect data from and about you, including:
- Direct Interactions: You may give us your Identity, Contact, and Financial Data by filling in forms or by corresponding with us by post, phone, email, or otherwise. This includes data provided when you create an account, purchase our products, subscribe to our newsletter, or request marketing to be sent to you.
- Automated Technologies or Interactions: As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.
- Third Parties or Publicly Available Sources: We will receive personal data about you from various third parties, such as payment and delivery services (e.g., PayPal, Stripe, Royal Mail) and analytics providers (e.g., Google Analytics).
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of Contract: Where we need to perform the contract we are about to enter into or have entered into with you (e.g., to process and deliver your Pokémon TCG order).
- Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Legal Obligation: Where we need to comply with a legal obligation (e.g., retaining sales records for tax purposes).
- Consent: Generally, we do not rely on consent as a legal basis for processing your personal data, except in relation to sending third-party direct marketing communications to you via email. You have the right to withdraw consent to marketing at any time.
4.1 Purposes for which we will use your personal data
| Purpose/Activity | Type of Data | Lawful Basis for Processing |
| To register you as a new customer | (a) Identity (b) Contact | Performance of a contract with you |
| To process and deliver your order (including managing payments, fees, charges, and shipping graded/single cards) | (a) Identity (b) Contact (c) Financial (d) Transaction (e) Marketing & Comms | (a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us) |
| To manage our relationship with you (notifying you about changes to our terms or privacy policy) | (a) Identity (b) Contact (c) Profile (d) Marketing & Comms | (a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated) |
| To administer and protect our business and website (including troubleshooting, data analysis, testing, system maintenance) | (a) Identity (b) Contact (c) Technical | (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security) (b) Necessary to comply with a legal obligation |
| To deliver relevant website content and advertisements to you | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing & Comms (f) Technical | Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business, and to inform our marketing strategy) |
5. Disclosures of Your Personal Data
We may share your personal data with the parties set out below for the purposes outlined in the table above:
- Service Providers: Acting as processors who provide IT and system administration services (e.g., website hosting platforms like Shopify or WooCommerce).
- Payment Processors: Third-party gateways (e.g., PayPal, Stripe) used to securely process your transactions.
- Logistics Partners: Courier and postal services (e.g., Royal Mail, DPD) required to deliver your physical orders.
- Professional Advisers: Including lawyers, bankers, auditors, and insurers based in the UK who provide consultancy, banking, legal, insurance, and accounting services.
- HM Revenue & Customs, Regulators, and other Authorities: Based in the UK who require reporting of processing activities in certain circumstances.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
6. International Transfers
Some of our external third parties (e.g., software providers, analytics services) may be based outside the UK, meaning their processing of your personal data will involve a transfer of data outside the UK.
Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data.
- Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK (Standard Contractual Clauses/International Data Transfer Agreements).
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. This includes SSL encryption on our website. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
By law, we have to keep basic information about our customers (including Contact, Identity, Financial, and Transaction Data) for six years after they cease being customers for tax purposes.
9. Your Legal Rights
Under certain circumstances, you have rights under UK data protection laws in relation to your personal data:
- Request access to your personal data (commonly known as a “data subject access request”).
- Request correction of the personal data that we hold about you.
- Request erasure of your personal data.
- Object to processing of your personal data where we are relying on a legitimate interest.
- Request restriction of processing of your personal data.
- Request the transfer of your personal data to you or to a third party.
- Withdraw consent at any time where we are relying on consent to process your personal data.
If you wish to exercise any of the rights set out above, please contact us at privacy@tradingcardgamestore.co.uk
9.1 No Fee Usually Required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
9.2 Time Limit to Respond
We try to respond to all legitimate requests within one month. Occasionally, it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
What personal data do we collect?
Find clear explanations about how we handle your personal information to keep it safe and secure.
How do we use your data?
We use your information to process orders and improve your shopping experience.
How is your data protected?
We implement strict security measures to safeguard your details from unauthorized access.
How long do we keep your data?
Your information is retained only as long as necessary for legal and operational purposes.
Can you access your personal data?
Yes, you have the right to view and update your personal information at any time.
What rights do you have under UK GDPR?
You can request data corrections, deletions, or object to processing when applicable.
How do we handle cookies?
We use cookies to enhance site functionality and your browsing experience.
Affiliate Disclosure
tradingcardgamestore.co.uk operates as a commercial enterprise. To offset operational costs and maintain this platform, we participate in various affiliate marketing programs. This means we may earn a commission on qualifying purchases made through outbound links on our website.
Amazon Associates Program: We are a participant in the Amazon Services LLC Associates Program. As an Amazon Associate, we earn from qualifying purchases resulting from links to Amazon.co.uk and affiliated sites.
Third-Party Networks: Our site contains affiliate links to other third-party merchants relevant to the Pokémon TCG market. This includes, but is not limited to, grading authorities (e.g., PSA, CGC, BGS), accessory suppliers, and other trading card retailers. When you click a link and make a purchase on these external sites, a commission may be credited to us.
Editorial Objectivity: Financial compensation does not dictate our assessments. Our curations, market analysis, and product recommendations for Pokémon TCG singles, bundles, and graded cards are conducted independently. The inclusion of an affiliate link does not constitute an uncritical endorsement of a product or service. Items are listed based strictly on technical assessment and market relevance.
Purchasing through these links incurs zero additional cost to the buyer.
