PokeTop10
PokeTop10

Privacy Policy

Last updated: April 29, 2026 · Effective date: April 29, 2026

Overview

PokeTop10 ("we", "us", "our", "PokeTop10", or "the platform") operates the website at poketop10.com and the underlying analytics infrastructure that powers it. This privacy policy describes what data we collect, why we collect it, how we use it, who we share it with, how long we retain it, and what rights you have to access, correct, export, or delete your data. It applies to all visitors and registered users of the site, regardless of geographic location.

The short version: we collect very little data. The site does not require an account for most features. If you do create a PokeFolio account, we store a one-way hash of your email address (not the email itself) and the cards or watchlist items you choose to track. Cloudflare provides hosting, CDN, and DDoS protection and processes standard web-traffic data on our behalf. Google AdSense, when active, may serve interest-based or contextual advertising governed by Google's privacy policies. There is no email-list resale, no behavioral data shared with marketers, and no hidden tracking pixels. We're a solo-operated analytics platform, not a data broker.

Data we collect

We collect the minimum data needed to operate the site and improve user experience. Specifically:

Anonymous traffic data (all visitors)

PokeFolio account data (signed-in users only)

What we explicitly do NOT collect

Cookies

PokeTop10's first-party code does NOT set cookies. Authentication uses localStorage tokens (per above). However, third-party services we integrate with may set cookies. The full list:

ProviderCookie purposeType
CloudflareDDoS protection (cf_clearance), bot management, performance routingStrictly necessary
Google AdSense (when ads are served)Ad personalization, frequency capping, fraud preventionAdvertising / analytics
Stripe (Pro/Investor checkout)Fraud prevention during checkout flow, only set on the Stripe-hosted checkout pagePayment processing
Beehiiv (newsletter signup)Form session and confirmationFunctional

You can manage cookie preferences through your browser settings. Disabling all cookies will impair some functionality (e.g. you won't be able to stay signed in to PokeFolio across page reloads).

Third-party services

The site integrates with several third-party services. We disclose them in full so you can make an informed choice about which to opt out of.

Cloudflare (hosting, CDN, DDoS, edge compute, KV, D1)

Cloudflare hosts our website (Cloudflare Pages), runs our backend code (Cloudflare Workers), and stores our data (Cloudflare KV and D1). Cloudflare may collect standard web-traffic data including IP addresses and user agents as part of its service. Refer to Cloudflare's privacy policy for details.

Google AdSense

When AdSense is active on the site, Google may use cookies, web beacons, or similar technologies to serve personalized or contextual advertising. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to PokeTop10 and other sites on the internet. You may opt out of personalized advertising at any time by visiting Google Ads Settings or by visiting aboutads.info (US) or youronlinechoices.com (EU).

For users in the EU/UK, advertising is governed by the IAB Europe Transparency & Consent Framework. Google AdSense provides a consent dialog the first time an EU/UK user views an ad-bearing page. You can revisit and modify your consent at any time via the consent management interface that appears on the site.

Refer to Google's Privacy Policy and Google's partner-sites policy for full details on how Google handles data collected through its advertising network.

Stripe (subscription billing)

Stripe processes Pro and Investor tier subscription payments. When you upgrade, you are redirected to a Stripe-hosted checkout page where you enter payment details. Stripe is the data controller for payment-card data; PokeTop10 never sees, stores, or processes your full card number. We receive only a Stripe customer ID, subscription ID, and status. Refer to Stripe's privacy policy.

Email delivery (Brevo and Resend)

Magic-link sign-in emails and price-alert notifications are delivered through Brevo (primary) and Resend (fallback). These services receive your email address solely to deliver the message. They do not use your email for marketing.

Affiliate networks

PokeTop10 participates in the eBay Partner Network and the TCGPlayer Affiliate Program. When you click an outbound link to eBay or TCGPlayer, the destination URL contains a partner identifier that allows the marketplace to attribute any subsequent purchase back to PokeTop10 for commission purposes. The marketplace's own cookies and tracking apply once you arrive on their site. We earn a commission at no additional cost to you. Refer to eBay Partner Network terms and TCGPlayer Affiliate Program terms.

Pokémon TCG and pricing data sources

The site aggregates price data from JustTCG, the eBay Browse API, PokémonTCG.io, and PokéTrace. These are server-to-server API calls made from our Cloudflare Worker; your browser does not interact with them directly, and they do not receive any data about you.

Data retention

How long we keep different categories of data:

Data categoryRetention
Anonymous page-view events90 days, then aggregated and anonymized further
Cloudflare access logsPer Cloudflare's retention policy (typically <30 days); we don't retain a copy
PokeFolio account data (email hash, plaintext email, portfolio cards, alerts)Until you request deletion; otherwise indefinite while the account is active
Magic-link OTPs15 minutes, then auto-deleted
Session tokens30 days from last use, then auto-deleted
Daily portfolio snapshotsIndefinitely while account is active (powers the value-over-time chart)
Subscription / billing metadataWhile subscription is active + 7 years for tax / accounting compliance

Your rights — GDPR (EU/UK), CCPA (California), and worldwide

Regardless of where you're located, PokeTop10 honors the following rights for any user, signed-in or anonymous:

To exercise any of these rights, email poketop10sean@gmail.com from the email address registered with your account. Anonymous visitors may also email and we'll do our best to assist, though we have very limited data about anonymous visitors to act on. We respond within 30 days, free of charge.

Children's privacy

PokeTop10 is not directed at children under 13 (under 16 in the EU). We do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has provided us with personal data, please contact us and we will delete the affected data immediately, without verification beyond reasonable confirmation that you are the parent/guardian. The sign-up flow for PokeFolio does not request age, but we discourage minors from using the platform without parental permission, given that the content discusses investment decisions involving real money.

International data transfers

PokeTop10 is operated from the United States. Cloudflare's edge network spans 300+ data centers worldwide; your requests are routed to the nearest edge location. Cloudflare Workers and KV/D1 storage may persist data in the EU, US, or other regions depending on Cloudflare's infrastructure. By using the site, you consent to international data transfers governed by Cloudflare's data processing addendum and applicable Standard Contractual Clauses where required. EU/UK users have the right to inquire about the specific safeguards in place; email us for details.

Data security

We take reasonable technical and organizational measures to protect your data:

No system is 100% secure. In the event of a data breach affecting your personal data, we will notify affected users without undue delay and within 72 hours where required by GDPR or other applicable law.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology, regulatory requirements, or our services. Material changes will be reflected in the "Last updated" date at the top of this page and, for signed-in users, communicated via email at least 14 days before they take effect. Your continued use of PokeTop10 after a change constitutes acceptance of the revised policy.

Contact

Questions about this policy, data requests, or privacy-related concerns? Email poketop10sean@gmail.com — read by Sean, the developer who built and operates the platform. For more general inquiries, see the contact page.

← Back to Dashboard