GBZone ("we", "us", "our") is operated by GBZone, based in the Netherlands. We operate the website gbzone.zone — a platform for sports card collectors, breakers, and traders.
For privacy-related questions or data requests, contact us at: [email protected]
GBZone is currently operated as a personal business. A formal business registration (BV) is planned. This policy will be updated with the registration number once available.
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address | Account login, security notifications, transactional emails | Contract |
| Password (hashed) | Account authentication — never stored in plain text | Contract |
| IP address | Security, fraud prevention, lockout enforcement | Legitimate interest |
| Device/browser info | Security, trusted device recognition | Legitimate interest |
| Login timestamps | Security audit log, account protection | Legitimate interest |
| Consent record | GDPR compliance — proof of your agreement | Legal obligation |
| Account activity | Service delivery, audit trail | Contract |
| Data type | Retention period |
|---|---|
| Account data | While account is active + 30 days after deletion |
| Audit logs | 12 months, then anonymized |
| Order history | 7 years (Dutch tax law requirement) |
| Failed login attempts | 30 minutes (auto-deleted) |
| Analytics data | 26 months |
| Consent records | 3 years |
| Deleted account email | Anonymized immediately on permanent deletion |
We do not sell your data. We share data only with the following service providers who process it on our behalf:
We may also disclose data if required by Dutch law or a court order.
| Type | Purpose | Duration |
|---|---|---|
| Authentication | Manage your login session and keep you signed in securely | Up to 7 days |
| Security | Protect your account against fraud and unauthorized access | Session to 7 days |
| Preferences | Remember your settings and choices such as guest mode and login state | Up to 7 days |
| Consent | Record your cookie preferences so we do not ask again | 1 year |
| Third party — Cloudflare | Security, DDoS protection, and performance optimization | Varies |
Authentication and security cookies are strictly necessary and cannot be disabled — the site cannot function without them. Preference and consent cookies can be cleared via your browser settings at any time.
We do not use advertising or tracking cookies. No cookie data is sold or shared with marketing platforms.
As a resident of the EU/EEA, you have the following rights regarding your personal data:
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl
We take security seriously. Measures in place include:
GBZone is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we do, we will update the version number and date at the top of this page. If changes are significant, we will notify registered users by email.
Your continued use of GBZone after changes are posted constitutes acceptance of the updated policy.
For any privacy-related questions, data requests, or complaints:
Email: [email protected]
Website: gbzone.zone
We aim to respond to all requests within 30 days as required by GDPR.