Legal
Privacy Policy
Version: 24 September 2026
1. Controller
The controller for data processing is InSleeve UG (haftungsbeschränkt), Am Fischmarkt 13A, 18439 Stralsund, Germany, email: [email protected].
This policy covers two offerings. Part A describes this website (insleeve.com). Part B describes the InSleeve Manager, our web application for managing trading card inventories, including its API and media CDN. Part C applies to both.
Part A — This website
A.1 Hosting
This website is hosted on Hetzner (servers in Germany) and served via Coolify. When you access the site, technically necessary data (server log files) is processed: IP address, date/time, requested resource, referrer, browser/OS. The legal basis is our legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR).
A.2 Newsletter & beta sign-up (Resend)
We use the processor Resend to send the newsletter and Manager beta information. Sign-up uses a double opt-in procedure: after you register we send a confirmation email, and your address is added to the list only after you click the confirmation link. We process your email address and the time and confirmation of sign-up. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time via the unsubscribe link in every email or by contacting us.
A.3 Spam protection (Cloudflare Turnstile)
To protect our forms from automated abuse we use Cloudflare Turnstile, which may transmit technical information to Cloudflare. The legal basis is our legitimate interest in preventing spam and abuse (Art. 6(1)(f) GDPR).
A.4 Fonts (self-hosted)
All fonts are served locally from our own server. There is no connection to Google Fonts or other third parties, and no personal data is transferred for this purpose.
A.5 Cookies & analytics
This website uses no tracking cookies and no third-party analytics. Technically necessary information (e.g. your language choice) is stored only locally in your browser. Neither Google Analytics nor Google Tag Manager is used.
A.6 Contact form and email contact
You can reach us via the contact form or by email. In the form, we process your email address, your message and — if you provide it — your name. Your name is voluntary; we need your email address and message in order to reply. We also process the technical data set out in A.1 and A.3. The purpose is handling your enquiry.
The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns a contract or pre-contractual steps; otherwise it is our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
The website stores form data in no database: the server forwards it by email through Resend (Plus Five Five, Inc., USA; processor; third-country transfer on the basis of the EU-US Data Privacy Framework, see B.4) to our mailbox. Resend keeps the message for 30 days and then deletes it automatically; backups persist for at most 7 further days.
Our mailbox is operated by Hetzner Online GmbH in Germany as a processor. We delete the enquiry once it has been conclusively handled. Where statutory retention duties apply (for example, six years for commercial and business letters under § 257 HGB), we retain it until they expire.
The same applies when you email us directly, except that Resend is not involved.
Part B — InSleeve Manager
B.1 Scope and roles
The InSleeve Manager is a web application for managing trading card inventories. It is aimed at commercial dealers as well as private sellers. For the data we process about our customers (the users and their accounts) in order to provide the Manager, we are the controller; this Part B describes that processing.
The Manager is not designed to process personal data of third parties. In particular it stores no buyer or order data from connected sales platforms. Under the terms of service users are required not to enter such data into free text fields. We therefore do not act as a processor for our users, and no data processing agreement under Art. 28 GDPR is currently concluded. Should we in future offer functions in which we process personal data on our users' behalf, we will point this out separately and offer a data processing agreement in good time beforehand.
B.2 Hosting principle
The application — web app, API, database (PostgreSQL), cache/queue (Dragonfly) and search index (Meilisearch, self-hosted) — runs on servers of Hetzner Online GmbH in Germany. Deployment is handled by a self-operated Coolify instance, so no additional external processor is involved. A data processing agreement with Hetzner is in place (concluded on 24 September 2026).
B.3 Account & sign-in
A user account is required to use the Manager. We store the email address and technical account and session data; each account belongs to an organisation. We do not collect a password — sign-in is passwordless via magic link (B.4).
After a successful sign-in we set a strictly necessary session cookie (insleeve_rt, httpOnly) holding a refresh token (valid 30 days). The short-lived access token (15 minutes) is kept only in the browser's memory and is stored neither as a cookie nor in localStorage.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). The session cookie is strictly necessary for the requested service (§ 25(2) no. 2 TDDDG — no consent required).
B.4 Magic-link and transactional emails (Resend)
To sign in we send a single-use login link to the registered email address; the link is valid for 15 minutes and is stored on our side only as a cryptographic hash. We send other transactional and notification emails within the contractual relationship via the same service.
We use Resend (Plus Five Five, Inc., USA) as a processor for delivery. Your email address and the message content are transmitted. As Resend is a US provider, a third-country transfer takes place. We base it on the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023, Art. 45 GDPR), under which Resend is certified. A data processing agreement is in place (Data Processing Addendum of 14 January 2026).
Legal basis: Art. 6(1)(b) GDPR.
B.5 Inventory and photo data
Managing the trading card inventory is the core of the application. For this we process the inventory data you create (cards, conditions, quantities, notes, prices) and uploaded card photos together with upload metadata (time, technical file details).
Photos generally show trading cards and therefore typically contain no personal image content; a personal reference arises through the link to your account. Please avoid photographing people or personal objects.
Legal basis: Art. 6(1)(b) GDPR.
B.6 AI-assisted card recognition
Uploaded card photos are transmitted to a recognition service and analysed there by machine in order to identify the card shown. We operate the recognition service ourselves; depending on load it runs on our own infrastructure or on GPU capacity of the provider RunPod (RunPod, Inc., USA). We only use data centres within the European Economic Area (currently Iceland, Norway, Sweden and France). RunPod receives nothing but the card image as a re-encoded file stripped of all metadata — including EXIF and location data — without any account, organisation or other identifier. RunPod therefore cannot attribute the image to a person.
The photos are processed there solely for recognition and are not stored permanently. There is no profiling and no automated decision producing legal or similarly significant effects within the meaning of Art. 22 GDPR — the recognition result is a suggestion the user reviews and can change. The photos are not used to train our models.
Legal basis: Art. 6(1)(b) GDPR.
B.7 Media storage & CDN (Cloudflare R2)
Uploaded photos and generated export files are stored in the object storage Cloudflare R2 and delivered via the CDN at cdn.insleeve.com (Cloudflare, Inc., USA). During delivery Cloudflare processes the IP address of the requesting browser. The data processing agreement is part of our contract with Cloudflare (Cloudflare Customer DPA, version 6.4 of 3 April 2026); we base the third-country transfer on the EU-US Data Privacy Framework, under which Cloudflare is certified, and additionally on the EU standard contractual clauses.
Legal basis: Art. 6(1)(b) GDPR for storing and delivering your content; additionally Art. 6(1)(f) GDPR for technical CDN delivery.
B.8 Bot protection (Cloudflare Turnstile)
To protect the sign-in procedure from automated abuse we use Cloudflare Turnstile. Turnstile uses technical signals (including IP address, browser and device characteristics, interaction with the widget) to check whether a request comes from a human. The third-country safeguards under B.7 apply.
Legal basis: Art. 6(1)(f) GDPR (preventing bots, spam and abuse of our login procedure); access to the terminal device is strictly necessary for the expressly requested secure service (§ 25(2) no. 2 TDDDG).
B.9 Payments (Stripe)
We use Stripe for payment processing, checkout and invoices (Stripe Payments Europe, Ltd., Ireland; parent company Stripe, Inc., USA). Name, email address and billing and payment data are transmitted. For the payment processing itself — in particular fraud prevention and payment-law obligations — Stripe acts as an independent controller, and as our processor for supporting services (Stripe Data Processing Agreement, part of the Stripe Services Agreement, version of 18 November 2025). Full card details never reach our servers. The third-country transfer to the USA is based on the EU-US Data Privacy Framework, under which Stripe is certified, and additionally on the EU standard contractual clauses.
Legal bases: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (commercial and tax obligations).
B.10 Sales channels (eBay, Cardmarket, Discord)
The Manager can be connected to third-party platforms at the user's initiative. We transmit only what the user triggers:
- eBay: the connection is made via OAuth. We store the access and refresh tokens encrypted, along with the seller's eBay identifier and eBay username (shown as “connected as”). At the user's initiative we create and maintain listings via the eBay API. If eBay reports an account deletion, we mark the affected records and erase them in a reviewed procedure.
- Cardmarket: the user can export stock data as a CSV file. If they also store their own Cardmarket credentials, we access the Cardmarket API on their behalf (stock and price synchronisation). The credentials are stored encrypted and can be removed at any time.
- Discord: if the user configures a Discord webhook, we send list views to the channel they choose, at their initiative. The user determines the recipient and the content.
The relationship between the user and the respective platform is governed solely by that platform's terms and privacy notices. Legal basis: Art. 6(1)(b) GDPR.
B.11 Feedback and support
If a user sends feedback or a bug report from within the application, we store the text together with the account reference and notify our team by email (sent via Resend, B.4). A user's feedback entries are fully deleted together with their account.
Legal basis: Art. 6(1)(b) and (f) GDPR.
B.12 Error diagnostics (Sentry)
We use Sentry to detect and fix technical errors. When an application error occurs, the error message, stack trace and browser/device context are transmitted; in addition we evaluate a 10 % sample of requests for performance measurement. We have disabled the transmission of default personal data (sendDefaultPii: false): IP address, cookies and user identifier are not transmitted, and our own filters strip remaining details from URLs before an event leaves the device. We do not use session replays and no tracking takes place.
We use Sentry's EU region: the data is stored in Frankfurt am Main. As Sentry (Functional Software, Inc.) is a US provider, access from the USA cannot be ruled out; we base this transfer on the EU-US Data Privacy Framework, under which Sentry is certified, and additionally on the EU standard contractual clauses. Data processing agreement: Sentry Data Processing Addendum, version 5.1.0, concluded on 24 September 2026.
Legal basis: Art. 6(1)(f) GDPR (a stable, error-free service). Retention: at most 90 days, after which Sentry deletes the data automatically.
B.13 Server logs and audit records
When the app, API and CDN origin are accessed, our servers automatically process technical log data: IP address, timestamp, requested resource, HTTP status, user agent. In addition we keep records of security-relevant events inside the application (e.g. sign-ins, changes to connections and permissions). These records are retained even after an account is deleted, for evidentiary and security reasons (see B.14).
Legal basis: Art. 6(1)(f) GDPR (security, stability, accountability). Retention of server logs: 3 months; security records: 5 years.
B.14 Account deletion and data export
The Manager provides two self-service functions:
- Data export: on request we make the account's data available for download. The download link is valid only briefly.
- Account deletion: the account is deleted or anonymised, together with its sessions, organisation assignment and feedback entries. The deletion runs as a single closed operation — it either succeeds completely or not at all, so no half-deleted account can result. The security records under B.13 are retained; statutory retention obligations (in particular for invoice and accounting data, B.15) remain unaffected.
Use the data export before deleting — afterwards an export is no longer possible, and deletion cannot be undone.
B.15 Retention periods in the Manager
- Account, organisation and inventory data: until the account is deleted; deletion or anonymisation then happens immediately (B.14), in backups, which are overwritten on a rolling basis, after 30 days at the latest.
- Card photos: until the photo, the inventory entry or the account is deleted.
- Sessions / refresh tokens: at most 30 days or until sign-out; magic-link codes 15 minutes.
- eBay / Cardmarket credentials: until the connection is disconnected or the account is deleted.
- Error data (Sentry): at most 90 days.
- Server logs: 3 months; security records 5 years.
- Invoice and accounting data: 8 years (accounting vouchers/invoices) and 10 years (books and financial statements) under § 147 AO / § 257 HGB.
B.16 Cookies and local storage in the Manager
The Manager sets no tracking cookies and uses no analytics tool. Every cookie set is strictly necessary for the expressly requested service (§ 25(2) no. 2 TDDDG):
insleeve_rt— session/refresh token, httpOnly, 30 days.insleeve_theme— chosen colour scheme (light/dark), 1 year.insleeve_sidebar— state of the sidebar, 1 year.insleeve_inv_view,insleeve_catalog_view— remembered view settings for inventory and catalogue, 1 year.
In the browser's local storage the Manager keeps:
insleeve:scan:…(localStorage) and theinsleeve-scandatabase (IndexedDB) — the scan batch in progress including preview images, so an interruption (a call, the lock screen, a tab switch) loses no captures. The entry is bound to the account and deleted on sign-out.insleeve:lastLoginEmail(localStorage) — the email address a sign-in link was last requested for, so that signing in via the link can be completed on the same device.insleeve:intake:captureMode,insleeve:intake:cameraId(localStorage) — the chosen capture mode and camera.insleeve:catalog-trail(sessionStorage) — the navigation path in the catalogue; ends when the tab is closed.
In addition the Turnstile widget accesses the terminal device during sign-in (B.8). The short-lived access token is held in memory only.
B.17 Recipients and processors
- Hetzner Online GmbH — processor, server hosting of the entire platform, Germany; no third-country transfer.
- Cloudflare, Inc. — processor, R2 object storage, CDN and Turnstile, USA; EU-US Data Privacy Framework (certified), additionally EU standard contractual clauses.
- Plus Five Five, Inc. (Resend) — processor, transactional and notification emails, USA; EU-US Data Privacy Framework (certified).
- RunPod, Inc. — service provider, GPU capacity for card recognition, data centres in the EEA (Iceland, Norway, Sweden, France); receives nothing but card images without metadata or personal reference (B.6).
- Functional Software, Inc. (Sentry) — processor, error diagnostics, stored in Frankfurt am Main (EU region); EU-US Data Privacy Framework (certified) for access from the USA, additionally EU standard contractual clauses.
- Stripe Payments Europe, Ltd. — partly an independent controller, partly our processor, payment processing, Ireland/USA.
- eBay, Cardmarket, Discord — not processors: transmission happens at the user's initiative to recipients they choose (B.10).
Meilisearch, PostgreSQL and Dragonfly are operated by us and are therefore not recipients. Data is passed to other third parties only where legally required (Art. 6(1)(c) GDPR).
Part C — For both offerings
C.1 Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw any consent at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.
- Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17)
- Restriction (Art. 18), data portability (Art. 20), objection (Art. 21)
- Withdrawal of consent (Art. 7(3) GDPR)
In the Manager you can exercise access and portability directly via the data export and account deletion functions (B.14). For anything else an informal message to [email protected] is sufficient.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the authority responsible for us: Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern (the data protection commissioner of the state of Mecklenburg-Western Pomerania), Werderstraße 74a, 19055 Schwerin, Germany, phone +49 385 59494-0, email [email protected], www.datenschutz-mv.de.
C.2 Obligation to provide data
Providing an email address is necessary to create an account and sign in to the Manager; without it the service cannot be used. Billing details are contractually required for paid use. All other details are optional. For the newsletter, an email address is sufficient.
C.3 Changes to this policy
We adapt this policy when our processing changes. The version published here applies at any given time; we inform signed-in Manager users about material changes by email to the address they registered with.