Back to home
War Chest

Privacy Policy

Last updated: December 23, 2025

1. Introduction

War Chest, a product of ZEALOUS OÜ ("we," "our," or "the Service"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Data Controller:
ZEALOUS OÜ
Registry Code: 16989036
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name
  • Email address
  • Password (stored securely hashed)
  • Profile information you choose to provide

Collection Data

When you use the Service, you may provide:

  • Item descriptions, provenance, and historical information
  • Images of collection items
  • Serial numbers and valuations (encrypted at rest)
  • Tags and categorizations

Automatically Collected Information

We may automatically collect certain information including:

  • IP address and device information
  • Browser type and settings
  • Usage patterns and feature interactions
  • Error logs for troubleshooting

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Process and complete your requests
  • Send service-related communications
  • Improve and optimize the Service
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption at Rest: Sensitive data including serial numbers, valuations, and purchase prices are encrypted using AES-256 encryption
  • Secure Password Storage: Passwords are hashed using bcrypt with strong salt rounds
  • HTTPS: All data transmission is encrypted using TLS
  • Access Controls: Your data is only accessible to you unless you explicitly make items public

5. Data Sharing

We do not sell your personal information. We may share information with:

  • Service Providers: Third-party services that help us operate (hosting, file storage, analytics)
  • Legal Requirements: When required by law or to protect our rights
  • Public Sharing: Only information you explicitly choose to make public (sensitive fields are never shared publicly)

6. Third-Party Services

The Service uses the following third-party providers:

  • Authentication: Google OAuth (optional)
  • File Storage: UploadThing for image storage
  • Database: Neon (PostgreSQL hosting)
  • Analytics: PostHog (optional, for usage analytics)

These providers have their own privacy policies governing their use of your data.

7. Your Rights

You have the right to:

  • Access: View all data associated with your account
  • Correction: Update or correct your information
  • Deletion: Delete your account and associated data
  • Export: Request a copy of your data
  • Withdraw Consent: Opt out of optional data processing

To exercise these rights, access your account settings or contact us.

8. Data Retention

We retain your data for as long as your account is active. When you delete your account:

  • Your profile and collection data are permanently deleted
  • Uploaded images are removed from storage
  • Backup copies may persist for up to 30 days
  • Anonymized analytics data may be retained

9. Cookies

We use essential cookies required for the Service to function, including:

  • Authentication session cookies
  • Security tokens
  • User preference settings

10. Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal information, please contact us.

11. International Users

If you are accessing the Service from outside the United States, please be aware that your data may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

ZEALOUS OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia

By creating an account, you acknowledge that you have read and agree to this Privacy Policy and our Terms and Conditions.