Privacy Policy

Last updated: June 2025

Who we are

BrickOdex is a LEGO® collection tracker. The data controller is BrickOdex (contact: privacy@brickodex.com).

What data we collect

Data Why Legal basis
Email address & username Account creation and login Contract (Art. 6(1)(b))
Hashed password Authentication (never stored in plain text) Contract (Art. 6(1)(b))
LEGO® collection data (set numbers, quantities, notes, purchase price/date/location) Core service functionality Contract (Art. 6(1)(b))
Wishlist items Core service functionality Contract (Art. 6(1)(b))
IP address (request logs) Security, abuse prevention, affiliate link geo-targeting Legitimate interest (Art. 6(1)(f))

We do not use advertising networks, sell your data, or run third-party analytics (e.g. Google Analytics).

Third-party services

  • Google OAuth — if you choose to sign in with Google, Google processes your Google account data under their own privacy policy.
  • Amazon affiliate links — clicking a product link takes you to Amazon, which may set tracking cookies. See our Affiliate Disclosure.
  • Rebrickable & BrickLink APIs — used to enrich set data (image, piece count, theme). Only set numbers are shared; no personal data is sent.
  • YouTube — set detail pages may embed YouTube videos via youtube-nocookie.com.

How long we keep your data

Your data is kept for as long as your account is active. Deleting your account removes all personal data immediately (including collection, wishlist, and login credentials). Server request logs are retained for up to 30 days.

Your rights under GDPR

If you are in the EEA or UK you have the following rights:

You also have the right to lodge a complaint with your national data protection authority (e.g. the ICO in the UK).

Contact

Email: privacy@brickodex.com