BRISCARDPrivacy
Privacy Policy
How personal data is handled on briscard.com. This page gathers the parts of the veax Privacy Policy (Document 04) that apply to BRISCARD, in accordance with the General Data Protection Regulation (GDPR).
Data controller
The data controller is the publisher of veax (see Legal notice), reachable at contact@veax.lol. Their full identity may be provided on legitimate request, in particular when exercising your rights or upon a request from the competent authority.
Briscard — what happens today
briscard.com is a static site, with no third-party resource, no cookie and no analytics. Like any website, it is served by a host, Cloudflare, which processes visitors' IP addresses in its technical logs in order to deliver the pages and keep the service secure. veax does not read, store or exploit those logs.
Everything else stays in your own browser (local storage) and is never sent to a server: your cart, the size you select, the measurement you type into the size guide and the plan you pick. This is storage strictly necessary to the service you asked for, which is why no cookie banner is shown.
Account creation is in maintenance: no account can be created and no personal data is collected.
When accounts open, and this policy will say so from that day: accounts and saved carts will be hosted by Supabase in the European Union (Frankfurt). The data will be your email address, username, password (hashed by Supabase Auth, never readable by veax), saved cart, creation and update dates, and the technical connection logs kept by Supabase. Each player sees only their own data, and can delete their account from the site: the account, the profile and the cart are erased immediately.
Representative in the European Union. veax is established outside the Union. Because the shop will offer goods to people in the European Union, a representative established in a Member State will be designated in writing and named in this document before orders open, as Article 27 of the GDPR requires. Until then, no order can be placed and no customer data is collected.
Processors
veax uses technical providers acting on its behalf, in compliance with the GDPR:
- Our hosts — Vercel for the veax sites, Cloudflare for briscard.com (see Legal notice).
- A database hosting provider — storage of veax.lol data.
- Stripe — secure payment processing (where applicable).
- Discord — optional authentication on veax.lol.
- An email provider — transactional sending and forwarding (including ImprovMX for veax.tr).
- Supabase — database and authentication for Briscard accounts, hosted in the European Union (Frankfurt). Will apply when accounts open.
- iyzico — secure payment processing for Briscard. Will apply when orders open.
The full named list can be obtained on request at contact@veax.lol.
Transfers outside the European Union
Some providers (Vercel, Cloudflare, Stripe, Discord) are established in the United States. The corresponding transfers are covered by appropriate safeguards (standard contractual clauses and/or the EU–US data protection framework).
veax is established in Türkiye, and so is iyzico, the payment provider that will apply to Briscard when orders open. Running the shop therefore involves processing from Türkiye, a country without a European adequacy decision. The appropriate safeguards used, and the way to obtain a copy of them, will be stated here before any such transfer takes place.
Your rights
In accordance with the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data. You can exercise them at contact@veax.lol, and lodge a complaint with the competent data-protection authority.
Security
Passwords are stored hashed, data access is restricted on the server side, and all exchanges with the sites are encrypted (HTTPS).