Brickonomy

Privacy policy

Last updated 24 August 2026

Brickonomy is a LEGO collection tracker. This policy explains what personal data we collect, why we collect it, and the rights you have under the UK GDPR and EU GDPR. Brickonomy is the data controller for the data described below.

Data we collect

  • Account data — your email address, authentication identifiers, and (if you sign in with Google) the basic profile Google returns.
  • Collection data — the sets and minifigures you add, their status (owned or wishlist), price alerts you create, and barcodes you scan.
  • Usage and diagnostics — anonymous onboarding and error events used to find broken sign-up steps, plus standard server logs (IP address, user agent).
  • Payment data — purchases are processed by Stripe, or by Apple or Google when you buy inside the mobile app. We never see or store your card details; we only store whether your account has Pro access and a payment reference.
  • Optional API keys — if you add your own marketplace API key, it is encrypted at rest (AES-256-GCM) and only ever used to price your own items.

Camera use

Barcode scanning runs on your device. Camera frames are processed locally to read the barcode; images are never uploaded or stored. Only the resulting barcode number and the set or minifigure it matched are saved to your scan history.

Why we use your data (lawful bases)

  • Contract — to create your account, store your collection, and provide Pro features you paid for.
  • Legitimate interests — to keep the service secure, prevent abuse, and fix faults using aggregated diagnostics.
  • Legal obligation — to keep records of purchases for tax and accounting.
  • Consent — for optional email notifications and any marketing, which you can withdraw at any time.

Sharing and processors

We do not sell your personal data. We share the minimum necessary with service providers who process data on our behalf: our hosting, database and authentication provider; Stripe, Apple and Google for payments; and LEGO catalogue and marketplace pricing APIs (BrickLink, BrickOwl, Rebrickable, Brickset, eBay), which receive set or minifigure numbers only — never your identity.

Some providers are located outside the UK/EEA. Where that happens, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

How long we keep it

Account and collection data is kept while your account is open, and deleted within 30 days of you deleting your account. Diagnostic events are kept for up to 12 months. Purchase records are kept for 7 years where tax law requires it.

Your rights

You can request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You can also withdraw consent at any time. To exercise any right, email privacy@brickonomy.co.uk — we respond within one month. You can also delete your collection items and scan history yourself from inside the app.

If you are unhappy with how we handled your data, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.

Cookies and local storage

We use strictly necessary storage only: a session token to keep you signed in, and cached prices and preferences held on your device to make the app faster. We do not use advertising or third-party tracking cookies.

Children

Brickonomy is not directed at children under 13. If you believe a child has created an account, contact us and we will delete it.

Contact

Questions about this policy: privacy@brickonomy.co.uk. Brickonomy is an independent app and is not affiliated with, authorised or endorsed by the LEGO Group.

Back to Brickonomy