Privacy Policy
Last updated: May 2026
1. Data Controller
LEONIVEYGAMES LTD is the data controller responsible for your personal data when you use PACKRAT at packratt.co.uk or through the PACKRAT iOS app.
- Address: Pandle House, 70 Grange Road East, Wirral, CH41 5FE
- Email: info@leoniveygames.com
2. What Data We Collect
We may collect and process the following personal data:
- Identity and account data: name, email address, password credentials stored in hashed form, account preferences, profile icon, linked sign-in providers and account status.
- Contact and delivery data: postal address, phone number, email address, delivery country and order contact details.
- Transaction data: orders, marketplace transactions, buylist submissions, refunds, wallet/store-credit activity, loyalty rewards and payment references. We do not store full card details. Card payments are processed by Stripe and PayPal where available.
- Seller and marketplace data: seller profile details, verification status, listing details, listing photos, card condition information, messages, feedback, dispute information and payout provider onboarding status.
- Uploaded content: product/listing images, card scan or card identification images, contact-form content, reviews, giveaway entries and other content you choose to submit.
- Authentication data: email/password sign-in data, Google account identifiers and Apple Sign in identifiers, including Apple private relay email addresses where you choose to use them.
- App and device data: push notification tokens, app notification preferences, device type, browser, operating system, IP-derived approximate location, IP hash, referrer and user-agent information.
- Usage and analytics data: pages visited, products or listings viewed and interaction events where analytics are enabled. On the website this depends on your cookie choice. In the iOS app, app usage may be recorded to operate and improve the service.
- Marketing data: newsletter subscription preferences, referral information and communication preferences.
3. How We Use Your Data
We use your personal data for the following purposes:
- To fulfil orders (legal basis: contract performance) , processing payments, arranging delivery, sending order confirmations and handling refunds, returns and customer support.
- To manage your account (legal basis: contract performance), maintaining login, order history, saved addresses, payment-method references, rewards, referrals, wallet/store credit and security settings.
- To operate the marketplace and buylist (legal basis: contract performance and legitimate interests), creating listings, enabling buyer/seller communication, handling disputes, processing seller payouts and preventing abuse.
- To provide app features (legal basis: contract performance and legitimate interests), including push notifications, app inbox notifications, biometric unlock settings, card photo uploads and card identification tools.
- To send marketing communications (legal basis: consent), newsletter emails about new products and offers. You can unsubscribe at any time
- To improve our website (legal basis: legitimate interests and consent where required), analysing usage patterns to improve user experience, stock planning, search, pricing and fraud prevention.
- To comply with legal obligations (legal basis: legal obligation), tax records, accounting, fraud prevention and legal requests.
4. Third Parties
We share your data with the following third parties as necessary:
- Stripe, payment processing (see Stripe's Privacy Policy)
- PayPal, payment processing and marketplace payments where you choose PayPal.
- Vercel, website and app hosting, serverless infrastructure and image/blob storage.
- Neon, database hosting
- Resend, transactional and marketing email delivery.
- Apple and Google, sign-in, device-level app services and push or identity services where you use those features.
- Google Gemini, card image identification where you ask us to identify a card from an uploaded photo.
- eBay, Pokemon TCG API and Scryfall, card and market price lookups where applicable.
- Royal Mail / courier services, order delivery
We do not sell your personal data to any third party.
Third-party providers may process your data according to their own privacy policies when you use their services, such as hosted checkout, sign-in or payment onboarding.
5. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected:
- Account data: retained until you delete your account
- Order data: retained for 6 years for tax and accounting purposes
- Marketplace, seller and dispute records: retained while required to operate the marketplace, handle disputes and meet legal obligations
- Marketing data: retained until you unsubscribe
- Push tokens: retained while active and removed or disabled when no longer valid or when you disable notifications
- Uploaded images: retained while needed for listings, buylist submissions, support, moderation or legal records
6. Your Rights (UK GDPR)
Under the UK GDPR, you have the right to:
- Access, request a copy of the personal data we hold about you
- Rectification, request correction of inaccurate data
- Erasure, request deletion of your personal data (subject to legal retention requirements)
- Restriction, request we limit processing of your data
- Portability, request your data in a structured, machine-readable format
- Object, object to processing based on legitimate interests
- Withdraw consent, where processing is based on consent, you can withdraw at any time
To exercise any of these rights, contact us at info@leoniveygames.com.
7. App Permissions
The PACKRAT iOS app may request permissions only when a feature needs them:
- Camera and photo library: used for marketplace listing photos, card uploads and card identification tools.
- Push notifications: used for order, marketplace, restock, buylist, promotional and system notifications according to your preferences.
- Face ID / Touch ID: used only if you enable biometric unlock on your device. We do not receive or store your biometric data.
8. Cookies
Please see our Cookie Policy for details on how we use cookies on the website. The iOS app may use local device storage for app preferences, such as push and biometric settings.
9. Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.
