Last updated: April 29, 2026 · Effective date: April 29, 2026
PokeTop10 ("we", "us", "our", "PokeTop10", or "the platform") operates the website at poketop10.com and the underlying analytics infrastructure that powers it. This privacy policy describes what data we collect, why we collect it, how we use it, who we share it with, how long we retain it, and what rights you have to access, correct, export, or delete your data. It applies to all visitors and registered users of the site, regardless of geographic location.
The short version: we collect very little data. The site does not require an account for most features. If you do create a PokeFolio account, we store a one-way hash of your email address (not the email itself) and the cards or watchlist items you choose to track. Cloudflare provides hosting, CDN, and DDoS protection and processes standard web-traffic data on our behalf. Google AdSense, when active, may serve interest-based or contextual advertising governed by Google's privacy policies. There is no email-list resale, no behavioral data shared with marketers, and no hidden tracking pixels. We're a solo-operated analytics platform, not a data broker.
We collect the minimum data needed to operate the site and improve user experience. Specifically:
PokeTop10's first-party code does NOT set cookies. Authentication uses localStorage tokens (per above). However, third-party services we integrate with may set cookies. The full list:
| Provider | Cookie purpose | Type |
|---|---|---|
| Cloudflare | DDoS protection (cf_clearance), bot management, performance routing | Strictly necessary |
| Google AdSense (when ads are served) | Ad personalization, frequency capping, fraud prevention | Advertising / analytics |
| Stripe (Pro/Investor checkout) | Fraud prevention during checkout flow, only set on the Stripe-hosted checkout page | Payment processing |
| Beehiiv (newsletter signup) | Form session and confirmation | Functional |
You can manage cookie preferences through your browser settings. Disabling all cookies will impair some functionality (e.g. you won't be able to stay signed in to PokeFolio across page reloads).
The site integrates with several third-party services. We disclose them in full so you can make an informed choice about which to opt out of.
Cloudflare hosts our website (Cloudflare Pages), runs our backend code (Cloudflare Workers), and stores our data (Cloudflare KV and D1). Cloudflare may collect standard web-traffic data including IP addresses and user agents as part of its service. Refer to Cloudflare's privacy policy for details.
When AdSense is active on the site, Google may use cookies, web beacons, or similar technologies to serve personalized or contextual advertising. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to PokeTop10 and other sites on the internet. You may opt out of personalized advertising at any time by visiting Google Ads Settings or by visiting aboutads.info (US) or youronlinechoices.com (EU).
For users in the EU/UK, advertising is governed by the IAB Europe Transparency & Consent Framework. Google AdSense provides a consent dialog the first time an EU/UK user views an ad-bearing page. You can revisit and modify your consent at any time via the consent management interface that appears on the site.
Refer to Google's Privacy Policy and Google's partner-sites policy for full details on how Google handles data collected through its advertising network.
Stripe processes Pro and Investor tier subscription payments. When you upgrade, you are redirected to a Stripe-hosted checkout page where you enter payment details. Stripe is the data controller for payment-card data; PokeTop10 never sees, stores, or processes your full card number. We receive only a Stripe customer ID, subscription ID, and status. Refer to Stripe's privacy policy.
Magic-link sign-in emails and price-alert notifications are delivered through Brevo (primary) and Resend (fallback). These services receive your email address solely to deliver the message. They do not use your email for marketing.
PokeTop10 participates in the eBay Partner Network and the TCGPlayer Affiliate Program. When you click an outbound link to eBay or TCGPlayer, the destination URL contains a partner identifier that allows the marketplace to attribute any subsequent purchase back to PokeTop10 for commission purposes. The marketplace's own cookies and tracking apply once you arrive on their site. We earn a commission at no additional cost to you. Refer to eBay Partner Network terms and TCGPlayer Affiliate Program terms.
The site aggregates price data from JustTCG, the eBay Browse API, PokémonTCG.io, and PokéTrace. These are server-to-server API calls made from our Cloudflare Worker; your browser does not interact with them directly, and they do not receive any data about you.
How long we keep different categories of data:
| Data category | Retention |
|---|---|
| Anonymous page-view events | 90 days, then aggregated and anonymized further |
| Cloudflare access logs | Per Cloudflare's retention policy (typically <30 days); we don't retain a copy |
| PokeFolio account data (email hash, plaintext email, portfolio cards, alerts) | Until you request deletion; otherwise indefinite while the account is active |
| Magic-link OTPs | 15 minutes, then auto-deleted |
| Session tokens | 30 days from last use, then auto-deleted |
| Daily portfolio snapshots | Indefinitely while account is active (powers the value-over-time chart) |
| Subscription / billing metadata | While subscription is active + 7 years for tax / accounting compliance |
Regardless of where you're located, PokeTop10 honors the following rights for any user, signed-in or anonymous:
To exercise any of these rights, email poketop10sean@gmail.com from the email address registered with your account. Anonymous visitors may also email and we'll do our best to assist, though we have very limited data about anonymous visitors to act on. We respond within 30 days, free of charge.
PokeTop10 is not directed at children under 13 (under 16 in the EU). We do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has provided us with personal data, please contact us and we will delete the affected data immediately, without verification beyond reasonable confirmation that you are the parent/guardian. The sign-up flow for PokeFolio does not request age, but we discourage minors from using the platform without parental permission, given that the content discusses investment decisions involving real money.
PokeTop10 is operated from the United States. Cloudflare's edge network spans 300+ data centers worldwide; your requests are routed to the nearest edge location. Cloudflare Workers and KV/D1 storage may persist data in the EU, US, or other regions depending on Cloudflare's infrastructure. By using the site, you consent to international data transfers governed by Cloudflare's data processing addendum and applicable Standard Contractual Clauses where required. EU/UK users have the right to inquire about the specific safeguards in place; email us for details.
We take reasonable technical and organizational measures to protect your data:
No system is 100% secure. In the event of a data breach affecting your personal data, we will notify affected users without undue delay and within 72 hours where required by GDPR or other applicable law.
We may update this policy from time to time to reflect changes in our practices, technology, regulatory requirements, or our services. Material changes will be reflected in the "Last updated" date at the top of this page and, for signed-in users, communicated via email at least 14 days before they take effect. Your continued use of PokeTop10 after a change constitutes acceptance of the revised policy.
Questions about this policy, data requests, or privacy-related concerns? Email poketop10sean@gmail.com — read by Sean, the developer who built and operates the platform. For more general inquiries, see the contact page.
← Back to Dashboard