1. Who We Are

GBZone ("we", "us", "our") is operated by GBZone, based in the Netherlands. We operate the website gbzone.zone — a platform for sports card collectors, breakers, and traders.

For privacy-related questions or data requests, contact us at: [email protected]

GBZone is currently operated as a personal business. A formal business registration (BV) is planned. This policy will be updated with the registration number once available.

2. What Data We Collect

DataWhy we collect itLegal basis
Email addressAccount login, security notifications, transactional emailsContract
Password (hashed)Account authentication — never stored in plain textContract
IP addressSecurity, fraud prevention, lockout enforcementLegitimate interest
Device/browser infoSecurity, trusted device recognitionLegitimate interest
Login timestampsSecurity audit log, account protectionLegitimate interest
Consent recordGDPR compliance — proof of your agreementLegal obligation
Account activityService delivery, audit trailContract

3. How Long We Keep Your Data

Data typeRetention period
Account dataWhile account is active + 30 days after deletion
Audit logs12 months, then anonymized
Order history7 years (Dutch tax law requirement)
Failed login attempts30 minutes (auto-deleted)
Analytics data26 months
Consent records3 years
Deleted account emailAnonymized immediately on permanent deletion

4. Who We Share Data With

We do not sell your data. We share data only with the following service providers who process it on our behalf:

We may also disclose data if required by Dutch law or a court order.

5. Cookies We Use

TypePurposeDuration
AuthenticationManage your login session and keep you signed in securelyUp to 7 days
SecurityProtect your account against fraud and unauthorized accessSession to 7 days
PreferencesRemember your settings and choices such as guest mode and login stateUp to 7 days
ConsentRecord your cookie preferences so we do not ask again1 year
Third party — CloudflareSecurity, DDoS protection, and performance optimizationVaries

Authentication and security cookies are strictly necessary and cannot be disabled — the site cannot function without them. Preference and consent cookies can be cleared via your browser settings at any time.

We do not use advertising or tracking cookies. No cookie data is sold or shared with marketing platforms.

6. Your Rights Under GDPR

As a resident of the EU/EEA, you have the following rights regarding your personal data:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl

7. Data Security

We take security seriously. Measures in place include:

8. Children

GBZone is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the version number and date at the top of this page. If changes are significant, we will notify registered users by email.

Your continued use of GBZone after changes are posted constitutes acceptance of the updated policy.

10. Contact

For any privacy-related questions, data requests, or complaints:

Email: [email protected]

Website: gbzone.zone

We aim to respond to all requests within 30 days as required by GDPR.