Legal

Privacy Policy

Last updated: 25 June 2026. This policy explains what personal data Trading Art Game collects, why, and the rights you have over it.

1. Who we are

Trading Art Game (“the app”, “we”, “us”, “our”) is operated by norfstudios OÜ, a company registered in Estonia (registry code 17531670), with its registered office at Järvevana tee 9, Kesklinna linnaosa, Tallinn, Harju maakond, 11314, Estonia.

We are the “data controller” responsible for your personal data under the EU General Data Protection Regulation (GDPR) and the equivalent laws described in this policy. If you have any questions or want to exercise your rights, contact us at privacy@norfstudios.dev.

2. A quick summary

We try to collect as little as possible. We do not use any advertising networks, analytics trackers, or crash-reporting tools, and we never sell your data. Trading Art Game is free to use and contains no real-money purchases. The data we hold is essentially: the email you sign in with, your chosen username, the game progress and social connections you create in the app, and a token that lets us send you notifications.

3. The data we collect

Account & sign-in. You can create an account in one of three ways: with an email address and password, with Google, or with Apple. We store the email address linked to your account and a unique account identifier. If you register with an email and password, the password is stored only in a securely hashed form by our authentication provider — we never see or store it in plain text. If you use “Sign in with Apple” and choose Apple’s private-relay option, we only ever see a relay email address, not your real one.

Profile. A username you choose (this is public to other players and visible in features like friends and trading), a record of your previous username(s) — kept in case you decide to change your username at any point, so we have a history of those changes — and a profile picture that you pick from the artworks inside the game. The username is the only content you can create. We do not collect or store uploaded photos or any other content from you.

Gameplay data. Your in-game progress, including the paintings you own and their history, in-game credits, packs you have opened, login days and streaks, challenges, achievements, and gameplay statistics.

Social data. Your friends and friend requests, the paintings you place on your trade pile, trade requests you send and receive, players you block, and any reports you file about other users (or that others file about you).

What other players can see. Before you are connected as friends, other players can only see your username, your profile picture, and the date you joined. Once you accept a friend request, your friends can additionally see certain in-game information such as your achievements, the paintings you own, the paintings you have placed on your trade pile, and gameplay statistics — for example how many packs you have opened, your number of completed trades, how many friends you have, the number of challenges you have completed, your total days played, and your most recent and longest login streaks. Your profile picture is not an uploaded photo — it is one of the paintings from your in-game collection that you have chosen to represent you. Other players can never see your email address or any contact details, and there is no messaging or chat between players in the app.

Device & technical data. If you enable optional notifications, we store a push-notification token for your device so we can deliver them. Generating that token also involves an installation identifier that Google’s Firebase service creates on your device. Like any online service, our servers automatically process technical information such as IP address and request logs to keep the service running and secure.

Identifiers we do not use or link. The app does not use an advertising identifier and shows no ads. We never link the identifiers described above to persistent hardware or SIM identifiers such as your device’s IMEI, IMSI, MAC address, or SIM serial number — the app does not request or read those at all. We do not use any identifier we hold for advertising, ad measurement, or profiling.

Support. If you contact us (for example by email or through our data-deletion form), we keep the information you provide so we can respond.

At a glance. The table below summarises the same information, grouped the way app stores describe data collection.

Data Why we have it Shared with How long we keep it
Email address and account ID Creating and signing in to your account; account emails such as verification and password reset Supabase; Resend (for the emails only) Until you delete your account (see section 7)
Username, username history, and chosen profile artwork Identifying you to friends and in trading; moderating names Supabase; visible to other players Until you delete your account (see section 7)
Gameplay data (collection, credits, packs, streaks, challenges, achievements, statistics) Saving and running your game Supabase; parts visible to friends Until you delete your account (see section 7)
Social data (friends, trades, blocks, reports) Running the friends and trading features; keeping the app safe Supabase; parts visible to the players involved Until you delete your account (see section 7)
Push-notification token and Firebase installation identifier Delivering the notifications you opted in to Google (Firebase Cloud Messaging); Apple (APNs) Until you turn notifications off or delete your account
IP address and server request logs Running the service, diagnosing faults, and detecting abuse Google Cloud (Cloud Run); Supabase A short period only (see section 7)
Messages, photos, contacts, location, health data Not collected — the app has no chat, no uploads, and asks for none of these — —

4. Why we use your data, and our legal basis

Under the GDPR we must have a “legal basis” for each use of your data. Ours are:

  • To provide the app and your account — creating and authenticating your account, saving your progress, and running social and trading features. Basis: performance of our contract with you.
  • To send push notifications. Notifications are optional and opt-in — you choose whether to enable them. If you opt in, you can also opt out of specific types of notification, or turn them off entirely, at any time in the app or in your device settings. Basis: your consent (which you can withdraw at any time).
  • To operate, secure and troubleshoot our servers — processing technical information such as IP addresses and request logs so we can deliver the service, diagnose faults, and detect attacks and abuse. Basis: our legitimate interests in running a reliable and secure service.
  • To keep the app safe and fair — preventing abuse and cheating, moderating usernames, and handling reports and blocks. Basis: our legitimate interests in protecting our users and our service. We do not use automated decision-making that produces legal or similarly significant effects for you; a person reviews any decision to suspend or restrict an account.
  • To send you transactional emails that are necessary to operate your account — such as verifying your email address, resetting your password, and confirming an account-deletion request. We do not send marketing emails. Basis: performance of our contract and our legitimate interests.
  • To comply with the law and respond to lawful requests. Basis: compliance with a legal obligation.

5. Third-party software and who we share data with

We do not sell your personal data and we do not share it for advertising.

Software included in the app. The app contains the following third-party components (“SDKs”). Each one may process data on your device or send it to its provider so that the feature it powers can work:

  • Firebase Cloud Messaging (Google) — receives push notifications, and generates the device token and installation identifier described in section 3.
  • Google Sign-In (Google) — used only if you choose to sign in with Google.
  • Sign in with Apple (Apple) — used only if you choose to sign in with Apple.
  • Supabase client — connects the app to our database and authentication service.

The app contains no advertising, analytics, attribution, or crash-reporting SDKs.

Service providers behind the app. We share data only with the providers (“processors”) that we rely on to run the service, each under a data-processing agreement and only to the extent needed:

  • Supabase — database and authentication (hosted in the EU, Ireland).
  • Google Cloud (Cloud Run) — our application server (hosted in the EU, Netherlands).
  • Google / Firebase Cloud Messaging and Apple (APNs) — delivery of push notifications, and the Google/Apple sign-in you choose.
  • Resend — sending transactional emails such as email verification, password reset, and account-deletion notices.
  • Formspark and Botpoison — processing and spam-protecting the forms on our website (such as the data-deletion request form).

We may also disclose data if required by law, or to establish, exercise or defend legal claims.

6. International data transfers

Your account and gameplay data are stored within the European Economic Area (EEA). Some of the providers above (for example Google, Apple, and our email provider) are organisations that may process limited data — such as push-notification delivery, sign-in, or sending a transactional email — outside the EEA, including in the United States. Where that happens, the transfer is protected by appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses. You can ask us for more detail using the contact details above.

7. How long we keep your data, and deleting your account

We keep your account data for as long as your account exists.

Deleting your account. You can start the deletion yourself from inside the app, under Profile → Settings → Account Data → Delete Account, or by using our data-deletion request form — you never have to ask us for permission. Deletion is not a freeze, a suspension, or a temporary deactivation: it is scheduled the moment you ask for it and then completes on its own. You are signed out immediately, and the app will not let you back in to play — signing in during the 30 days that follow shows you the deletion notice and nothing else. Your personal data — including your email address, your password and any Apple or Google sign-in, your username and username history, your chosen profile artwork, and your friends, blocks and pending trades — is permanently erased no later than 30 days after the request, and the collection and trade records that remain are irreversibly anonymised. The 30-day window exists only so that you can change your mind: signing in and choosing Cancel Deletion restores the account in full, and until then your profile stays visible to the players you were connected with. If you do nothing, the deletion completes on its own, and once it has, the account cannot be restored.

What we may keep afterwards. Technical and security logs are kept only for a limited period. We may retain a minimal record where we are legally required to, or to resolve a dispute or enforce our terms.

8. Your rights

Depending on where you live, you have some or all of the following rights over your personal data: to access it, to correct it, to delete it, to export it (data portability), to restrict or object to certain uses, and to withdraw consent at any time.

You can exercise the main rights directly: you can request a copy of your data and delete your account from within the app, under Profile → Settings → Account Data, or use our data-deletion request form. For anything else, email us at privacy@norfstudios.dev. We will respond within the timeframes required by law (generally within one month).

If you are in the EU/EEA, you have the right to lodge a complaint with your local data-protection authority; ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). If you are in the UK, you may complain to the Information Commissioner’s Office (ico.org.uk). We would, of course, appreciate the chance to address your concern first.

9. Children

Trading Art Game is not directed to children. You must be at least 16 years old to create an account and use the app. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. How we protect your data

We host within the EU. All traffic between the app and our servers is encrypted in transit using HTTPS with modern TLS, and we do not accept unencrypted connections. Passwords are never stored in plain text — our authentication provider stores only a salted hash.

Data stored in our database is encrypted at rest by our hosting providers. We restrict database access with row-level security so that users can only reach their own data, we authenticate every request, and administrative access is limited to the people who need it to run the service.

No system can be guaranteed perfectly secure, but we take reasonable technical and organisational measures to protect your information, and we will notify you and the relevant authority of a personal-data breach where the law requires it.

11. Cookies and our website

This website is a simple informational site. It sets no cookies of its own, uses no advertising or analytics cookies, and does not track you across other sites.

Nothing on this site is loaded from a third-party server when a page opens. The fonts, images, styles and scripts are all served from our own domain, so no other company receives your IP address simply because you visited a page here.

Data is processed on the website only when you voluntarily submit a form (such as the data-deletion request), which is handled by the providers named in section 5. Our spam protection (Botpoison) runs from our own site and contacts its provider only at the moment you submit a form.

12. Regional information

California (CCPA/CPRA). In the past 12 months we have collected the categories of “identifiers” (such as email address, account ID and username), “internet or other electronic network activity” (your in-app activity), and “device identifiers” (a push-notification token and installation identifier). We collect these categories from two sources only: directly from you, and automatically from your device as you use the app. We disclose them for business purposes only to the categories of third parties listed in section 5 — our hosting, database, authentication, push-notification, and email providers. We retain each category for the periods described in section 7.

We do not sell or “share” personal information as those terms are defined under California law, we do not use or disclose personal information for cross-context behavioural advertising, and we do not collect sensitive personal information. California residents may exercise the rights to know, delete, correct, and to be free from discrimination for doing so — using the contact details above.

Other US states. If you live in a state with a comprehensive privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect — you have rights to access, correct, delete and obtain a copy of your personal data, and to opt out of targeted advertising, sale, and profiling. We do not carry out any of those three activities. You can exercise your rights using the contact details above. If we decline a request, you may appeal by replying to our decision or emailing privacy@norfstudios.dev with “Appeal” in the subject line; we will respond to the appeal within the time your state’s law allows and will tell you how to contact your state Attorney General if you are still not satisfied.

United Kingdom. We process personal data in line with the UK GDPR and Data Protection Act 2018. UK users have the same core rights described in section 8.

Australia. We handle personal information in accordance with the Australian Privacy Principles, including where we disclose data to overseas service providers as described above. You may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify you in the app. Your continued use of Trading Art Game after an update means you accept the revised policy.

14. Contact us

For any privacy question or to exercise your rights, contact norfstudios OÜ at privacy@norfstudios.dev.

Trading Art Game

norfstudios OÜ

tradingartgame@norfstudios.dev

Instagram

Product

  • Features
  • How it works
  • Download

Support

  • Support request
  • Contact us

Legal

  • Privacy Policy
  • Terms & Conditions
  • Artwork Credits
  • Delete your account

© 2026 norfstudios OÜ