Privacy Policy
Learn how Kaiga collects, uses, and protects your personal information, including data accessed through Google Sign-In.
Your privacy is important to us. It is Kaiga's policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, https://kaiga.org, and other sites we own and operate.
Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.
In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.
This policy is effective as of February 10, 2026.
Last updated: February 10, 2026
Google User Data Policy Disclosure
Kaiga uses Google OAuth 2.0 to enable secure authentication via Google Sign-In. This section specifically addresses how we handle data accessed through Google APIs in compliance with the Google API Services User Data Policy.
Data Accessed from Google
When you sign in with Google, we access the following specific types of Google user data:
- Basic Profile Information: Your name, email address, and profile picture URL
- Email Address: Used for account creation, authentication, and communication
- User ID: Google's unique identifier for your account
We only request the minimum scopes necessary to provide our service. Specifically, we access:
openid- For authenticationprofile- For your name and profile pictureemail- For your email address
How We Use Google User Data
Google user data is used exclusively for the following purposes:
-
Account Creation and Authentication: We use your Google email and profile information to create and maintain your KAIGA account, allowing you to sign in securely without creating a separate password.
-
User Identification: Your Google email serves as your unique identifier in our system, enabling you to access your personal collections, sourcing requests, and order history.
-
Communication: We use your email address to send you:
- Order confirmations and shipping notifications
- Account-related notifications (password resets, security alerts)
- Optional marketing communications (only if you opt-in)
-
Profile Display: Your name and profile picture (if provided) are displayed on your collector profile page and used to personalize your experience on the platform.
We do NOT use Google user data for:
- AI/ML model training
- Advertising or ad targeting
- Selling or sharing with third parties for marketing purposes
- Any purpose not explicitly disclosed in this policy
How We Share Google User Data
We do NOT sell, rent, or trade your Google user data to third parties. We only share Google user data in the following limited circumstances:
-
Service Providers: We share data with trusted third-party service providers who help us operate our platform:
- Cloud hosting providers: For secure data storage and infrastructure
- Stripe: For payment processing (only email and name for order fulfillment)
- Email service providers: For transactional email delivery (only email address)
All service providers are contractually bound to protect your data and use it only for the purposes we specify.
-
Legal Requirements: We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent fraud or security threats
-
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, which will be bound by this privacy policy.
We will NEVER share your Google user data with:
- Advertisers or marketing companies
- Data brokers
- Any third party for purposes unrelated to providing our service
Data Storage and Protection
Storage Location: Google user data is securely stored in:
- Encrypted databases hosted in secure data centres (located in Singapore)
- Cloud storage for profile images (if uploaded)
Security Measures: We protect your Google user data using industry-standard security practices:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3
- Encryption at Rest: Database backups and stored files are encrypted using AES-256 encryption
- Access Controls: Access to user data is restricted to authorised personnel only, with role-based access controls
- Authentication Security: We use secure session management with httpOnly cookies and CSRF protection
- Regular Security Updates: We apply security patches and updates promptly
No Unencrypted Storage: We do not store your Google user data in plain text or on unencrypted systems.
Data Retention and Deletion
Retention Period: We retain your Google user data only as long as necessary to provide our services:
- Active Accounts: Data is retained for the duration of your account's active status
- Inactive Accounts: Accounts inactive for 3 years may be subject to deletion after notice
- Deleted Accounts: When you delete your account, all associated Google user data is permanently deleted within 30 days
How to Delete Your Data: You have the right to request deletion of your data at any time:
-
Self-Service Deletion:
- Log into your account
- Go to Account Settings > Privacy
- Click "Delete My Account"
- Confirm deletion
-
Email Request:
- Email us at support@kaiga.org with the subject "Data Deletion Request"
- Include your registered email address
- We will process your request within 30 days
What Gets Deleted: When you delete your account, we permanently remove:
- Your Google profile information (name, email, profile picture)
- Your personal collections, sourcing requests, and bookmarks
- Your order history and shipping addresses
- Your payment methods (we notify Stripe to delete stored payment data)
What We Retain: For legal and regulatory compliance, we may retain:
- Anonymised transaction records (for tax and accounting purposes)
- Order records required by law (7 years for financial records under Singapore law)
- Fraud prevention logs (anonymised identifiers only)
Third-Party Caches: Please note that search engines and third-party services may retain cached versions of public data (such as public collector profiles) even after deletion. We have no control over these external caches.
Google API Services User Data Policy Compliance
Kaiga's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit to:
- Using Google user data only for purposes explicitly disclosed in this privacy policy
- Not selling, renting, or trading Google user data
- Not using Google user data for advertising
- Not allowing humans to read Google user data unless:
- We have your explicit consent
- It is necessary for security purposes (e.g., investigating abuse)
- It is required by law or for internal operations (limited to aggregated, anonymised data)
Your Rights Regarding Google User Data
You have the following rights regarding data accessed through Google:
-
Right to Access: You can view all Google user data we have stored by accessing your Account Settings page.
-
Right to Correction: You can update your name and email address in your Account Settings. Note that changing your Google email may require re-authentication.
-
Right to Deletion: You can request deletion of your account and all associated data at any time (see "Data Retention and Deletion" section above).
-
Right to Data Portability: You can export your data in machine-readable format (JSON/CSV) by contacting support@kaiga.org.
-
Right to Revoke Access: You can revoke Kaiga's access to your Google account at any time:
- Visit Google Account Permissions
- Find "Kaiga" in the list
- Click "Remove Access"
- Note: This will log you out and you will need to use a different sign-in method
Changes to Google Data Handling
If we make material changes to how we handle Google user data, we will:
- Update this privacy policy with a new "Last Updated" date
- Notify you via email (at your Google email address)
- For significant changes, request your renewed consent
- Provide you with the option to delete your account if you disagree with the changes
Information We Collect
Information we collect falls into one of two categories: "voluntarily provided" information and "automatically collected" information.
"Voluntarily provided" information refers to any information you knowingly and actively provide us when using or participating in any of our services and promotions.
"Automatically collected" information refers to any information automatically sent by your devices in the course of accessing our products and services.
Log Data
When you visit our website, our servers may automatically log the standard data provided by your web browser. It may include your device's Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit.
Additionally, if you encounter certain errors while using the site, we may automatically collect data about the error and the circumstances surrounding its occurrence. This data may include technical details about your device, what you were trying to do when the error happened, and other technical information relating to the problem. You may or may not receive notice of such errors, even in the moment they occur, that they have occurred, or what the nature of the error is.
Please be aware that while this information may not be personally identifying by itself, it may be possible to combine it with other data to personally identify individual persons.
Device Data
When you visit our website or interact with our services, we may automatically collect data about your device, such as:
-
Device Type
-
Operating System
-
Unique device identifiers
-
Device settings
-
Geo-location data
Data we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.
Personal Information
We may ask for personal information --- for example, when you register for an account, make a purchase, or contact us --- which may include one or more of the following:
-
Name
-
Email
-
Phone/mobile number (if provided)
-
Home/mailing address (for shipping purposes)
User-Generated Content
We consider "user-generated content" to be materials (text, image and/or video content) voluntarily supplied to us by our users for the purpose of publication on our website or re-publishing on our social media channels. All user-generated content is associated with the account or email address used to submit the materials.
Please be aware that any content you submit for the purpose of publication will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy.
Legitimate Reasons for Processing Your Personal Information
We only collect and use your personal information when we have a legitimate reason for doing so. In which instance, we only collect personal information that is reasonably necessary to provide our services to you.
Collection and Use of Information
We may collect personal information from you when you do any of the following on our website:
-
Register for an account
-
Make a purchase or add items to your cart
-
Manage your Pokemon card collection or sourcing requests
-
Sign up to receive updates from us via email
-
Use a mobile device or web browser to access our content
-
Contact us via email or other channels
We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes:
-
to provide you with our platform's core features and services
-
to enable you to customize or personalize your experience of our website
-
to deliver products and/or services to you
-
to contact and communicate with you
-
for analytics and business development, including to operate and improve our website (using aggregated, non-identifying data)
-
to enable you to access and use our website and associated applications
-
for internal record keeping and administrative purposes
-
to comply with our legal obligations and resolve any disputes that we may have
-
to attribute any content (e.g. posts and comments) you submit that we publish on our website
-
for security and fraud prevention, and to ensure that our sites and apps are safe, secure, and used in line with our terms of use
Security of Your Personal Information
When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use, or modification.
Although we will do our best to protect the personal information you provide to us, we advise that no method of electronic transmission or storage is 100% secure, and no one can guarantee absolute data security.
You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services. For example, ensuring any passwords associated with accessing your personal information and accounts are secure and confidential.
How Long We Keep Your Personal Information
We keep your personal information only for as long as we need to. This time period may depend on what we are using your information for, in accordance with this privacy policy. For example, if you have provided us with personal information as part of creating an account with us, we may retain this information for the duration your account exists on our system. If your personal information is no longer required for this purpose, we will delete it or make it anonymous by removing all details that identify you.
However, if necessary, we may retain your personal information for our compliance with a legal, accounting, or reporting obligation or for archiving purposes in the public interest, scientific, or historical research purposes or statistical purposes.
Children's Privacy
We do not aim any of our products or services directly at children under the age of 13, and we do not knowingly collect personal information about children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.
Disclosure of Personal Information to Third Parties
We may disclose personal information to:
-
a parent, subsidiary, or affiliate of our company
-
third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, error loggers, maintenance or problem-solving providers, professional advisors, and payment systems operators
-
our employees, contractors, and/or related entities
-
credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you
-
courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
-
an entity that buys, or to which we transfer all or substantially all of our assets and business
Third parties we currently use include:
- Cloud hosting providers: Secure hosting and file storage
- Stripe: Payment processing
- Email service providers: Transactional email delivery (order confirmations, notifications)
- SingPost: Order delivery and shipping
We do NOT use:
- Google Analytics or other analytics platforms that sell data to advertisers
- Advertising networks or ad tracking services
- Data brokers or third-party marketing platforms
International Transfers of Personal Information
The personal information we collect is stored and/or processed in:
- Singapore (primary database hosting)
- United States (cloud file storage and content delivery)
If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law, including the PDPA's Transfer Limitation Obligation; and (ii) we will protect the transferred personal information in accordance with this privacy policy.
Your Rights and Controlling Your Personal Information
Your choice: By providing personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this privacy policy. You do not have to provide personal information to us, however, if you do not, it may affect your use of our website or the products and/or services offered on or through it.
Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person's consent to provide the personal information to us.
Marketing permission: If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below.
Access: You may request details of the personal information that we hold about you.
Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details provided in this privacy policy. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or out of date.
Non-discrimination: We will not discriminate against you for exercising any of your rights over your personal information. Unless your personal information is required to provide you with a particular service or offer (for example providing user support), we will not deny you goods or services and/or charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties, or provide you with a different level or quality of goods or services.
Downloading of Personal Information: We provide a means for you to download the personal information you have shared through our site. Please contact us for more information.
Notification of data breaches: We will comply with laws applicable to us in respect of any data breach, including notifying the Personal Data Protection Commission (PDPC) and affected individuals as required under the PDPA.
Complaints: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg in relation to your complaint.
Unsubscribe: To unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details provided in this privacy policy, or opt-out using the opt-out facilities provided in the communication. We may need to request specific information from you to help us confirm your identity.
Use of Cookies
We use "cookies" to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified.
Please refer to our Cookie Policy for more information.
Business Transfers
If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data, including your personal information, among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may, to the extent permitted by applicable law, continue to use your personal information according to this policy, which they will be required to assume as it is the basis for any ownership or use rights we have over such information.
Limits of Our Policy
Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.
Changes to This Policy
At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.
If the changes are significant, or if required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy.
If required by law, we will get your permission or give you the opportunity to opt in to or opt out of, as applicable, any new uses of your personal information.
Trademark and Intellectual Property Disclaimer
KAIGA is an independent platform and is not affiliated with, endorsed by, or sponsored by The Pokémon Company, Nintendo, Game Freak, or Creatures Inc.
All Pokémon characters, names, images, card designs, and related trademarks are the exclusive property of The Pokémon Company and its affiliates. Pokémon © 2002-2026 Pokémon. © 1995-2026 Nintendo/Creatures Inc./GAME FREAK inc. TM, ®Nintendo.
When you use our platform to manage your Pokémon card collection, sourcing requests, or make purchases, you acknowledge that:
- The Pokémon card data, images, and information displayed on our platform are used for identification and reference purposes only
- We collect data about your Pokémon card collections solely to provide our collection management and shop services
- We do not claim any ownership rights to Pokémon intellectual property
- Your collection data relating to Pokémon cards is your personal information, not owned by The Pokémon Company
This disclaimer applies to all personal information collected in connection with Pokémon trading cards and related products.
Contact Us
For any questions or concerns regarding your privacy, you may contact us using the following details:
Email: support@kaiga.org
Website: https://kaiga.org
For data deletion requests specifically, please email: support@kaiga.org with "Data Deletion Request" in the subject line.