Privacy Policy
Last updated · 21 August 2026
The Hoard is designed to minimize unnecessary identity data while still operating a functional marketplace. This policy explains what the platform processes, why it is needed and what choices users have.
1. Who controls the data?
The operator identified on the Imprint determines the purposes and means of processing personal data for The Hoard and acts as the data controller for platform data. The operator must configure a legal/privacy contact before public launch.
2. Data The Hoard processes
Depending on how you use the service, this can include:
- account data such as username, password hash, role, preferences and account timestamps;
- security data such as registered WebAuthn public credentials, encrypted TOTP secrets, recovery-code hashes, session records and security events;
- an optional notification email address, stored encrypted at rest, plus verification and Email MFA state;
- public profile information, portfolio media, listings, public characters, tags, reviews and other content you choose to publish;
- private Character Vault data, references, direct messages, order conversations, attachments, briefs, revisions and delivery records;
- marketplace records such as bids, favorites, follows, order status, external payment-method selection and transaction-status references;
- platform billing records for Artist Pro, Collector Pro and Featured YCH purchases, including PayPal identifiers, amount, currency, environment and status;
- technical and anti-abuse information such as IP-derived security signals, user agent, rate-limit events, audit logs and error information.
3. Why the data is processed
The main purposes are to provide accounts, security, marketplace discovery, order workspaces, messaging, content hosting, notifications, platform billing, moderation, fraud/abuse prevention and legal or accounting obligations. Depending on the activity, processing is based on performance of the service contract, legitimate interests in operating and securing the platform, consent where the product explicitly asks for it, or compliance with a legal obligation.
4. Email, MFA and notifications
Email is optional at registration and is not your login identifier or a password-recovery mechanism. A verified address can be used for notification emails and, only when you explicitly enable it, Email MFA. Passkeys/FIDO2 and TOTP remain the preferred MFA methods. Notification categories can be changed in Settings.
5. Private messages and order workspaces
Private messages, order conversations, references and private deliveries are not public discovery content and are not automatically added to public galleries or profiles. The service uses authenticated access controls to restrict these areas to the relevant participants and required platform processes.
“Private” does not mean end-to-end encrypted unless the interface explicitly says so. Content stored on the server may still be technically accessible at the infrastructure/database level where necessary to operate, secure or lawfully administer the service. The Hoard does not use private commission content for public discovery or third-party advertising.
6. Public content
Information deliberately published to a public profile, portfolio, listing, public OC gallery, review or other public surface can be viewed by other users and may be indexed by search engines. Removing public visibility reduces future exposure but cannot guarantee removal of copies independently saved or cached by third parties.
7. Payments
Artwork payments between buyers and artists are handled through payment methods configured by the artist. The Hoard does not need or request the buyer's card number or the artist's bank credentials for those transactions.
Payments for The Hoard's own services, including Pro subscriptions and Featured YCH promotion, are processed by PayPal. The Hoard stores the minimum provider identifiers and status information needed to activate, reconcile, cancel or audit those services; PayPal handles the payment credentials themselves.
8. Service providers
The Hoard relies on infrastructure and service providers necessary to operate the site, including web hosting, email delivery, PayPal for platform billing and Cloudflare Turnstile for anti-bot protection where enabled. Data is shared only as needed for those services or where required by law. External artist payment providers are separate services chosen by the artist and/or buyer and are governed by their own privacy terms.
9. Cookies, local storage and first-party analytics
The Hoard uses essential session and security cookies required for authentication, CSRF protection, preferences and marketplace functionality. The service does not use third-party advertising cookies, cross-site tracking or advertising profiles.
To improve discovery and marketplace usability, The Hoard can record first-party product events such as listing views, watches, filters, checkout stages and broad acquisition source. Device information is reduced to a broad category such as mobile, tablet or desktop; precise location and browser fingerprinting are not used. Free-text searches are not retained as an identifiable search history for product analytics: marketplace demand is measured through aggregated dimensions such as listing type, species, style, body type and whether a search returned zero or few results.
Signed-in users can disable first-party product analytics and personalized discovery independently in Settings → Privacy. They can also detach identifiable product analytics history from their account. Aggregated marketplace statistics may remain because they no longer identify the individual account.
10. Retention
Account and content data is generally kept while the account or relevant marketplace record remains active. Identifiable raw product-analytics events are designed for short-term troubleshooting and product analysis and are automatically removed after approximately 90 days once older information can be represented as aggregate statistics. Search-demand aggregates do not contain a user identifier or the original free-text query.
Security, audit, transaction and billing records may be retained longer where necessary for fraud prevention, disputes, accounting, legal obligations or the establishment and defence of legal claims. Data that is no longer needed should be deleted or anonymized according to operational retention rules.
11. Account deletion
You can request account deletion from Settings. Active or pending paid orders can temporarily block deletion so an in-progress transaction is not destroyed. Owned uploads and account data are removed where possible, while minimal records may be retained when a legal obligation, fraud-prevention need, dispute or legal claim requires it.
12. Your privacy rights
Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, portability and objection, plus the right to lodge a complaint with the competent data-protection authority. Some rights depend on the legal basis and context of processing and are not absolute.
For a privacy request, use the legal/privacy contact listed on the Imprint. General product support remains available only through the official Discord ticket system.
13. Security
The Hoard uses security measures such as password hashing, authenticated encryption for selected sensitive secrets, MFA, session revocation, CSRF protection, rate limiting and audit/security logging. No internet service can guarantee absolute security; users should protect their own credentials and report suspected compromise promptly.
14. Changes to this policy
This policy may change as the platform evolves or legal requirements change. Material changes will be communicated where appropriate, and the date at the top of this page will be updated.