On our website we use, as far as possible, secure transmission technologies. However, data transfer on the Internet, especially the communication via e-mail, may involve security gaps. A complete data protection against access of third parties is not possible.
Personal data, i.e. specific data about the personal or factual circumstances of a particular or identifiable natural person, are only collected as far as necessary for the performance of the contract and for the provision of contractual services. The collection of data is carried out exclusively to the extent provided by you. The processing of personal data may consist in saving, changing, transmitting, blocking and deleting of these data. Any personal data are only saved by us as long as this is necessary for the respective specified purpose or we are obligated by law to save this information.
Already when visiting our website, your information may also be saved to the server when having access (e.g. date, time, pages visited). This data is not considered personal data, but they are anonymised, for example name of the Internet provider, type of Internet browser, pages visited on the website. These data are used for statistical purposes only and to improve our services. By accessing the site, data may also be saved on your computer. These data are called “cookies” and they facilitate the use of the website. However, you have the option to deactivate this function in your web browser. This may result in limitations when using our website.
The user’s personal data will not be transmitted to any third party. Exempt from this are only the service partners of the CCGCastle, LLC needed for the completion of the contractual relationship, e.g. providers of payment services (such as e.g. Stripe, PayPal) as well as a transmission of data to authorities within our legal obligations.
You shall be entitled to the right of withdrawal of the consent with effect for the future at all times and without limitations. You have the right to information free of charge on your stored personal data.
The data controller of your personal data is Shift4Shop, LLC and doing business as "Shift4Shop". Shift4Shop, LLC is registered at 6691 Nob Hill Road, Tamarac, FL 33321, United States of America (USA).
SECTION 1 - TRANSACTIONAL INFORMATIONWhat do we do with your information?
(1) When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address, and email address.
(2) When you browse our store, we also automatically receive your computer Internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system. More information on cookies we use on our website is available at the following link: https://www.ptcgostore.com/cookie-policy.
(3) Your personal data are processed for the following purposes:
- to complete a transaction, verify your credit card, place an order, and arrange for delivery. Provision of personal data is a requirement necessary to enter into a contract or a contractual requirement,
- with your permission, we may send you emails about our store, new products, and other updates,
- for purposes of calculating overall usage statistics, for internal marketing and promotional purposes, product development, content improvement, performing data analytics; and performing accounting, auditing as well as other internal functions;
- to contact you and provide you with the information you have requested,
- to protect against, identify, and prevent fraud and other criminal activity, claims, and other liabilities; and
- to comply with and enforce applicable legal requirements, relevant industry standards, and our policies.
SECTION 2 - CONSENTHow do we get your consent?
(1) When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
(2) If we ask for your personal information for a secondary reason, such as marketing, we will either ask you directly for your expressed consent or provide you with an opportunity to say no.
How do you withdraw your consent?
After you opt-in, if you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use, or disclosure of your information, at any time, by contacting us at [email protected] or you can request for accessing your data "Data Page" here: https://www.ptcgostore.com/gdpr_request.asp or you can request for automatic removal "Data Removal" here: https://www.ptcgostore.com/gdpr_deleteme.asp (you will receive the confirmation email).
SECTION 3 - DISCLOSUREDo we disclose your information?
(1) Limited members of our team may access and otherwise process personal data in connection with their job responsibilities or contractual obligations. We may share your personal information with our subsidiaries and affiliates and with service providers who perform services for us. We do not authorize our service providers to use or disclose the information except as necessary to perform services on our behalf or to comply with legal requirements.
(2) We may disclose your personal information if we are required by law to do so.
SECTION 4 - ONLINE STOREOur online store is hosted by Shift4Shop. They provide us with an online e-commerce platform that allows us to sell our products and services to you. You can read more about how Shift4Shop uses your Personal Information here https://www.shift4.com/privacypolicy/.
(1) If you choose a direct payment gateway to complete your purchase, the online store transmits your credit card data. The store data is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
(2) All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Master Card, American Express, and Discover.
(3) PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
(4) Please note that additional measures of protection of your personal data may be in place as provided by PayPal, your bank, or other institution involved in transactions based on your choice of payment method.
SECTION 5 - THIRD-PARTY SERVICES(1) In general, the third-party providers we use will only collect, use, and disclose your information to the extent necessary to allow them to perform the services they provide to us.
(2) However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
(3) For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
(4) In particular, remember that certain providers may be located in or have facilities that are located in a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
(5) As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
LINKS / URL's
When you click on links on our store, they may direct you away from our site. We are not responsible for the content or privacy practices of other sites and encourage you to read their privacy statements.
SECTION 6 - SECURITY(1) To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered, or destroyed.
(2) If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 7 - YOUR RIGHTSGDPR - EUROPE
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted, to limit processing, to data portability, and to object to the processing of personal data. When the processing is based on your consent, you may at any time withdraw / remove your consent. Withdrawal of consent does not affect the lawfulness of processing on the basis of consent prior to its withdrawal. If you would like to exercise this right, please contact us through the contact information below. You also have the right to lodge a complaint with a supervisory authority.
LGPD - BRAZIL
If you are a Brazilian resident, you have the following rights:
- The right to confirmation of the existence of the processing;
- The right to access the data;
- The right to correct incomplete, inaccurate, or out-of-date data;
- The right to anonymise, block, or delete unnecessary or excessive data or data that is not being processed in compliance with the LGPD;
- The right to the portability of data to another service or product provider, by means of an express request;
- The right to delete personal data processed with the consent of the data subject;
- The right to information about public and private entities with which the controller has shared data;
- The right to information about the possibility of denying consent and the consequences of such denial; and
- The right to revoke consent.
CCPA - CALIFORNIA
If you are a consumer and resident of California, you have a right to request disclosure of your personal information, to receive additional details regarding the personal information we collect and its use purposes, including any third parties with which it shares information, right to data portability, right to deletion of erasure under certain restrictions, and other rights as may be granted based on CCPA.
(2) If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
SECTION 10 - QUESTIONS AND CONTACT INFORMATIONIf you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information you have the following options:
- Email us: [email protected];
- Access your data "Data Page": https://www.ptcgostore.com/gdpr_request.asp;
- Remove your data "Removal Data": https://www.ptcgostore.com/gdpr_deleteme.asp;
- Contact us via contact form;
- For EU residents send us a letter to: POTCG d.o.o., Železna cesta 10C, 1000 Ljubljana, Slovenia, Europe