Legal
Privacy policy
What we collect, why we collect it, and everyone else who touches it.
In effect from 28 August 2026
Draft — not yet in force
This document is awaiting review, and the following details have not been settled: a registered address, a contact address, the governing law. It is published for preparation only and does not yet bind anyone.
This policy covers getnostalgi.com and the service behind it, operated by Nostalgi ("we"). It describes what we do with personal data, and is written to be checked against the software rather than to sound reassuring.
Nostalgi is a marketplace. The sellers here are independent of us — some are businesses, some are private individuals selling their own property — and once a seller receives your delivery details they decide for themselves what they do with them. For that data the seller is a controller in their own right, and their own practices apply alongside this policy. This is worth reading twice for a private sale: your name and address go to a private person, not to a company with a compliance department, and we cannot audit what they do with them.
What we collect
When you open an account
Your email address and a password. The password is hashed by our authentication provider and is not readable by us or stored in our database. We also keep the timestamps of account creation and email confirmation, because an unconfirmed account cannot be allowed to buy.
When you buy something
The lots ordered and the price at the time of the order, whether you chose delivery or collection, and, for delivery, the name and postal address the parcel goes to. We keep the delivery address because the seller cannot post the parcel without it and because it is part of the record of the sale.
When you register as a seller
Your seller name and description, a location, and the payout details you give to Stripe. Those payout details, including any identity documents Stripe asks for, go to Stripe directly — we never see or hold them.
What location means depends on which kind of seller you are, and the difference is enforced in the software, not left to a form:
- A shop gives a full postal address. We hold it and send it to a geocoding service, so that the shop can be placed on a map and found by buyers looking to collect nearby.
- A private seller gives a town and state, and no street address — the field is refused if you try. We geocode the town, which places you at the middle of it and no closer. We never hold your street address, so a mistake, a breach, or a legal demand cannot disclose one.
Only seller locations are geocoded. A buyer's delivery address is never sent to that service.
When you list a lot
The description and facts you enter, and any photographs you upload. Bear in mind that photographs can carry embedded location data from the camera that took them, and that a listing is public.
While you use the site
Our servers keep ordinary request logs — IP address, the page requested, the time, the browser's user-agent string — which we use to keep the service running and to investigate abuse. We also collect aggregate page view counts.
What we never collect
Card numbers. Payment details are entered into fields served by Stripe and go straight to Stripe. They never reach our servers and we could not retrieve them if asked. What we learn is the outcome: that a payment succeeded, and the last four digits and brand of the card as Stripe reports them.
Cookies and tracking
Nostalgi sets no cookies of its own. Keeping you signed in uses your browser's local storage rather than a cookie, which means the session stays on your device and is not transmitted with every request. Clearing site data signs you out.
Our page-view analytics does not use cookies and does not build a profile or follow you between sites. Our fonts are served from our own domain, so loading a page makes no request to a font network. Stripe's scripts load only on the checkout page, and Stripe does set its own cookies there for fraud prevention; that is a condition of taking card payments at all.
Catalogue pictures. The art for anything actually on sale here is served from our own domain. The catalogue also lists hundreds of thousands of entries nobody is currently selling, and on those pages the picture is still loaded from the database we built the entry from — Scryfall for Magic, pokemontcg.io for Pokémon, and IGDB for game cover art. Opening one of those pages lets that database see your IP address and browser, the same as following any link to another site would. Nothing else about you is sent with it. Yu-Gi-Oh! card art is the exception: YGOPRODeck require it to be re-hosted rather than linked, so those images come from our own storage and reach nobody else.
We do not sell personal data, we do not share it for advertising, and there are no advertising or social media trackers on this site.
Who else handles your data
We use a small number of providers, each for one job, and each has access only to what that job needs:
- Stripe — payments, payouts to sellers, and the identity checks the law requires of them. Receives payment and seller payout data.
- Supabase — the database, account sign-in, and storage for listing photographs. Holds most of what is described above.
- Vercel — serves the website, and provides the aggregate page view counts.
- Railway — runs the service that handles orders and escrow.
- Resend — sends account emails, such as confirmation and password reset. Receives your email address.
- IGDB — supplies the cover art shown on game entries, from its own image servers. Receives the IP address and browser of anyone who opens a game page, and nothing else. Reached through a Twitch developer application, which is how their API is licensed.
- OpenStreetMap's Nominatim service — turns a seller's location into coordinates. Receives a shop's full postal address, or a private seller's town and state. Never a buyer's address.
These providers process data on our instructions. Some are outside your country, and transfers rely on the safeguards in our agreements with them. We do not otherwise disclose personal data, except where we are legally required to, or where it is necessary to establish or defend a legal claim.
What the seller sees
A seller you buy from is shown what they need in order to fulfil the order: the lots bought, the order total, whether it is being posted or collected, and, for delivery, the name and address it goes to. They are not shown your account email, your other orders, or anything you have bought elsewhere on Nostalgi. This is the same for a shop and for a private seller: a private seller is given your delivery address because a parcel cannot be posted without one, and nothing beyond it.
How long we keep it
Order records are kept for as long as tax and accounting law requires, which is longer than an account lasts, and they cannot be deleted on request while that obligation stands. Account details are kept until you close the account. Request logs are kept for a short operational period. Listing photographs are kept while the listing exists.
Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, to have it corrected, to have it deleted, to receive a copy in a portable form, and to object to or restrict certain processing. Where we rely on consent you may withdraw it at any time.
Most of it you can act on yourself: your account details and order history are visible when you are signed in. For anything else, write to [CONTACT EMAIL] and we will respond within the period the applicable law allows. We will not charge you for asking, and we will not treat you differently for having asked. If you are in the UK or the EU and you are not satisfied with our answer, you may complain to your data protection authority.
Security
Traffic is encrypted in transit. Access to the database is restricted at the row level, so an account can read its own orders and its own seller records and not another's. Payment credentials are held by Stripe rather than by us, which removes the most valuable target from our systems entirely. No system is perfectly secure, and we make no claim that ours is.
Children
Nostalgi is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will remove it.
Changes
If this policy changes materially we will say so on the site before the change takes effect. The date it came into force is at the top of this page.
Contact
Nostalgi, [REGISTERED ADDRESS]. Privacy requests and questions go to [CONTACT EMAIL].
Questions about this document go to [CONTACT EMAIL].
