This Privacy Policy explains how ValuDex collects, uses, and protects your personal data when you use the ValuDex mobile application and website at valudex.co.uk. By using the Service, you agree to the collection and use of information as described here.
1. Who We Are (Data Controller)
ValuDex is a sole trader business registered in England. ValuDex is the data controller for personal data processed through the ValuDex mobile application and website at valudex.co.uk.
Contact: support@valudex.co.uk
2. Data We Collect
Account Data
When you register, we collect:
- Email address
- Password (stored securely using industry-standard hashing, never in plain text)
- Subscription status and tier
Authentication
ValuDex uses email and password authentication. Email confirmation links are sent via email when you sign up or reset your password. We do not currently offer social login or Apple Sign In.
Portfolio Data
Data you enter into the app:
- Cards added to your portfolio
- Purchase prices and dates you provide
- Portfolio notes or labels
Usage Data
We automatically collect certain technical information:
- App version and device type
- Screens and features used
- Error and crash reports
Camera / Scanner
When you use the card scanner, your device camera captures an image of a card. This image is transmitted to Google's Gemini API for processing to identify the card. ValuDex does not store the image after processing. However, Google may temporarily process or retain the image under their own privacy policies — please refer to Google's Privacy Policy for details.
Website Analytics
- Google Analytics — collects anonymised data about page visits, traffic sources, and user behaviour via cookies. This requires your consent where applicable (see Cookies section).
- Cloudflare — provides security, DNS, and CDN services. Cloudflare may process request metadata including IP addresses as part of normal network operations. See cloudflare.com/privacypolicy for details.
3. How We Use Your Data
- Provide and operate the ValuDex service
- Process and manage your subscription
- Track your card portfolio and calculate valuations
- Improve the app and fix bugs
- Send service-related communications (e.g. email confirmation, account notices)
- Analyse usage trends to improve the product
We do not sell your personal data to third parties.
4. Legal Basis for Processing (UK GDPR)
| Purpose | Legal Basis |
|---|---|
| Providing the service (account, portfolio, scanner) | Contract |
| Security, fraud prevention, abuse prevention | Legitimate interests |
| App analytics and crash reporting | Legitimate interests |
| Website analytics (Google Analytics cookies) | Consent |
| Email service communications | Contract |
5. International Data Transfers
Some of our third-party service providers are based outside the UK. When we transfer your personal data internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR, such as Standard Contractual Clauses or adequacy decisions.
- Supabase — database infrastructure hosted on AWS (EU region where possible)
- Google (Gemini API, Google Analytics) — processes data in Google's global infrastructure
- Cloudflare — operates globally; request data may be processed in various locations
- RevenueCat — US-based subscription management provider
6. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Database and authentication | supabase.com/privacy |
| Google Gemini API | Card image recognition | policies.google.com/privacy |
| Google Analytics | Website analytics | policies.google.com/privacy |
| Cloudflare | Security, CDN, analytics | cloudflare.com/privacypolicy |
| Apple App Store | iOS subscription billing | apple.com/legal/privacy |
| Google Play Store | Android subscription billing | policies.google.com/privacy |
| RevenueCat | Subscription management | revenuecat.com/privacy |
7. Data Retention
We retain your account and portfolio data for as long as your account is active. If you delete your account, your personal data will be deleted within 30 days, except where we are required to retain it for legal or accounting purposes.
Free tier users have access to portfolio history for the past 7 days. Premium users have access to their full history.
8. Your Rights (UK GDPR)
- Access — request a copy of the data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your personal data
- Restriction — ask us to limit how we process your data
- Portability — request your data in a portable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent (e.g. analytics cookies), you may withdraw at any time
To exercise any of these rights, contact us at support@valudex.co.uk. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Deleting Your Account
You can request deletion of your account and associated personal data at any time by contacting support@valudex.co.uk. We will action account deletion requests within 30 days. A self-service account deletion option will be added to the app in a future update.
10. Cookies
- Essential cookies — required for the website to function (no consent required)
- Analytics cookies (Google Analytics) — used to understand how visitors use the website. These cookies are only set with your consent via our cookie banner.
You can manage or withdraw cookie consent at any time through the cookie settings on the website, or by adjusting your browser settings.
11. Children's Privacy
ValuDex is available to users aged 13 and over. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has registered, please contact us at support@valudex.co.uk and we will delete the account promptly.
12. Security
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), secure password hashing, and access controls on our database. No system is completely secure, and we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or email. The latest version will always be available at valudex.co.uk/privacy.html.
14. Contact
For any privacy-related questions or to exercise your rights, contact us at: support@valudex.co.uk