1. Who We Are
MyCoinage Ltd is a UK-registered company. We operate the MyCoinage platform at mycoinage.co.uk. If you have questions about this policy, contact us at hello@mycoinage.co.uk.
2. Data We Collect
- Account data: Email address, username, password (bcrypt hashed). If you sign in with Google, we store your Google ID instead of a password.
- Collection data: The coins you add, grades, purchase prices, and notes you enter.
- Usage data: Pages visited, actions taken (coin added, comment posted). Used only for product improvement.
- Payment data: Handled entirely by Stripe. We never see or store your card details.
- Communications: Emails you send to us via the contact form.
3. How We Use Your Data
- To provide and improve the MyCoinage service
- To process your subscription payments via Stripe
- To send you account-related emails (subscription receipts, password resets)
- To send marketing emails only if you have opted in
- To detect and prevent fraud and abuse
4. Cookies
We use a session cookie to keep you signed in. We do not use advertising or tracking cookies. If you accept optional cookies via the consent banner, we may use analytics to understand how users interact with the site.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Stripe — for payment processing
- Our hosting provider — server infrastructure only
- Law enforcement when legally required
6. Your Rights (UK GDPR)
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your account and data (via Account Settings → Delete Account)
- Object to processing for marketing (unsubscribe at any time)
- Data portability — request an export of your data
To exercise these rights, contact hello@mycoinage.co.uk.
7. Data Retention
We retain your account data for as long as your account is active. If you delete your account, your personal data is removed within 30 days. Coin collection entries are anonymised rather than deleted to preserve community price data.
8. Security
Passwords are hashed using bcrypt. All connections use HTTPS/TLS. We conduct regular security reviews and apply patches promptly.
9. Changes to This Policy
We may update this policy. Material changes will be notified by email to registered users. The "last updated" date at the top of this page will always reflect the most recent version.