Privacy Policy for TheHobbyNetwork

Last Updated: May 13, 2026

Welcome to TheHobbyNetwork. This Privacy Policy explains how TheHobbyNetwork (operated by GFYGaming, Inc.) collects, uses, discloses, and protects your personal data when you visit our website (TheHobbyNetwork.com) or use our mobile application.

TheHobbyNetwork is operated by GFYGaming, Inc. in the United States. If you are a resident of the European Economic Area (EEA) or the United Kingdom, see the dedicated section below for your additional rights under the General Data Protection Regulation (GDPR) and UK GDPR.


1. What Personal Data We Collect

We collect the following categories of personal data:

  • Identity & contact data — name, screen name, email address, phone number, mailing addresses.
  • Financial data — wallet balance, transaction history, invoices, withdrawal records. We do not store payment-card details; those are handled by Stripe under their privacy policy.
  • Account & activity data — listings, bids, offers, messages, collection items, vault items, gameplay records.
  • Technical & security data — IP address, device type, browser, operating system, language, time-zone, and anti-fraud fingerprint data. Used to detect and prevent abuse.
  • Mobile-app data (with your permission) — camera and photo library access (only when you initiate it), push notification tokens. Biometric authentication (Face ID, fingerprint) is processed entirely by your device's operating system; we never receive or store biometric data.

2. How We Use Your Personal Data

We use your data to:

  • Create and manage your account, including authentication.
  • Process your payments, manage your wallet balance and vault.
  • Operate the marketplace, auctions, messaging, and in-game features.
  • Send transactional emails about your account, orders, and platform activity.
  • Send SMS verification codes to US phone numbers only via Twilio. Non-US phone numbers are stored as contact information but are not used to send SMS.
  • Send push notifications via Expo / Apple APNs / Google FCM.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with our legal and regulatory obligations.

Where GDPR or UK GDPR applies, we rely on these legal bases:

  • Performance of a contract — operating your account, processing your transactions, fulfilling orders.
  • Legitimate interests — fraud prevention, anti-abuse logging, platform integrity, business operations and analytics. We balance these interests against your rights and freedoms.
  • Legal obligation — tax records, financial-services compliance, responding to lawful requests.
  • Consent — for camera/photo-library access, push notifications, and any marketing communications. You can withdraw consent at any time.

We do not process special-category data (Article 9 GDPR), and we do not engage in any automated decision-making or profiling that produces legal or similarly significant effects on you.

4. Who We Share Your Data With

We share your data with the third-party service providers ("subprocessors") that help us operate the platform. A current, maintained list lives on our Subprocessors page.

We may also share data:

  • By law or to protect rights — when required to respond to legal process or to protect TheHobbyNetwork, our users, or the public.
  • In a business transfer — in connection with a merger, sale, or acquisition. We will notify you in advance of any change in controller.

5. International Transfers

TheHobbyNetwork is operated from the United States. If you are located in the EEA or UK, your data is transferred to the US. Where required, we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK International Data Transfer Agreements (IDTAs) with our subprocessors to provide an adequate level of protection.

6. Data We Keep, and For How Long

We keep your personal data only as long as is necessary for the purposes set out above, or as required by law:

  • Account data — until you close your account, plus any retention period legally required by tax/accounting law.
  • Financial / transaction records — retained for the applicable tax and accounting retention periods (typically 7 years in the US).
  • Security access logs (IP, device fingerprint) — retained 90 days by default, then permanently deleted by an automated nightly task.
  • Messaging history — retained for the lifetime of your account; deleted when your account is deleted (subject to legal-hold exceptions).
  • Marketing data (if you opt in) — until you opt out or your account is closed.

7. Your Rights (EEA / UK residents)

Under GDPR and UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you. You can self-serve this through Privacy Controls → Download My Data.
  • Rectification — correct inaccurate or incomplete data. Edit your profile or contact us.
  • Erasure ("right to be forgotten") — request deletion of your account. Self-serve through Privacy Controls → Delete My Account. A 14-day grace window lets you cancel. Some records may be retained for legal reasons (see Section 6); these are itemised in your data export.
  • Restriction of processing — ask us to limit how we use your data in specific cases.
  • Data portability — receive your data in a structured, machine-readable format (JSON). Same self-serve flow as Access.
  • Object — to processing based on legitimate interests, including direct marketing.
  • Withdraw consent — at any time, for processing based on consent.
  • Lodge a complaint — with your local supervisory authority. A directory is at edpb.europa.eu. UK residents may contact the Information Commissioner's Office.

We respond to data-subject requests within 30 days. Contact privacy@thehobbynetwork.com or use the self-serve flows above.

8. EU Representative (Article 27 GDPR)

TheHobbyNetwork's processing of EU residents' personal data is currently occasional within the meaning of GDPR Article 27(2). We do not currently appoint an EU representative on that basis. This position is reviewed if our EU user base, the nature of our processing, or our risk profile changes. We will update this section if we appoint a representative.

9. Cookies

TheHobbyNetwork uses only strictly necessary first-party cookies — specifically, the login/session cookie and the CSRF token cookie. These are required for the site to function and do not require consent under GDPR or the EU ePrivacy Directive. We do not use analytics, marketing, advertising, or cross-site tracking cookies, web beacons, or tracking pixels.

10. How We Protect Your Data

We use administrative, technical, and physical security measures to protect your data. Personally identifiable address fields are encrypted at rest. Passwords are stored only as one-way hashes. While we take reasonable steps, no system is impenetrable; if you suspect unauthorised access to your account, contact us immediately.

In the event of a personal-data breach affecting EU/UK residents, we notify the appropriate supervisory authority within 72 hours where required, and notify affected users where the breach is likely to result in a high risk to their rights and freedoms.

11. Children's Privacy

We do not knowingly solicit personal data from or market to children under the age of 13. If you become aware of any data we have collected from children under age 13, please contact us using the contact information below.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page, updating the "Last Updated" date, and (where appropriate) sending you a notice in the platform.

13. Contact Us

For any privacy questions or to exercise your rights, contact us at privacy@thehobbynetwork.com. We aim to respond within 30 days.

Controller: GFYGaming, Inc., operating TheHobbyNetwork.com and the TheHobbyNetwork mobile app.

Zoomed image
Scroll to zoom · Drag to pan · Double-click to reset
Offer Cart — [[ items.length ]] item[[ items.length === 1 ? '' : 's' ]]

Your offer cart is empty.

Browse the marketplace and click Add to Cart or Make Offer on a card to start an offer.

Browse Marketplace

You'll send these as one combined offer to the seller — set your prices on the next page.

Seller: [[ sellerLabel ]]

Items from different sellers can't go in the same offer.

  • [[ it.title ]]
    List: $[[ formatCurrency(it.sale_price) ]]