Lighting the lanterns…
Lighting the lanterns…

The Guildmaster's desk
A question about an order, a product, or something you want us to gather? Tell us which counter and we take it from there.
A person of the guild answers by email, usually within two working days. orders@theguildmaster.eu
The guild keeps a short ledger of names — only what the work requires, and never for sale.
In plain terms: we collect what is needed to take your order, ship it and keep your account safe. Nothing more. Here is the full record.
The Guildmaster (theguildmaster.eu) is operated by The Guildmaster Trading, the sole proprietorship of Marc van Drunen, Koningsweg 99, 6655 AB Puiflijk, the Netherlands. Chamber of Commerce (KvK): 98583840. We are the controller for the personal data described on this page.
Questions, requests or complaints about your data: orders@theguildmaster.eu.
Your account. Email address, an optional name and a password. The password is stored only as a cryptographic hash — we cannot read it. We also briefly hold single-use tokens for email verification and password resets. Legal basis: performing our agreement with you.
Your orders. Your name, delivery address, email address, what you ordered, the order's payment and shipping status, and — if you filled it in — your answer to “how did you find us”. Legal basis: performing the agreement, and legal (tax) obligations for the resulting invoices.
Updates by email (optional). If you tick the box for news and updates, we record your email address and the moment you consented. Legal basis: your consent, which you can withdraw at any time via the unsubscribe link or by emailing us.
Correspondence. Emails you send us, so we can answer and keep track of the conversation. Legal basis: legitimate interest (customer service).
Security. Failed sign-in attempts are counted to temporarily lock an account against password guessing. Legal basis: legitimate interest (keeping accounts safe).
Visitor counts (Spectral Supplies only). On spectralsupplies.theguildmaster.eu we count how many visits our pages get, so the shopkeeper can see whether a shared link reached anyone. Each visit is turned into a one-way code made from your IP address, your browser description and the date — the IP address itself is never stored, and because the date is part of the code, the same visitor gets a different code tomorrow. We keep the code, the page, the country and the website you arrived from; nothing that identifies you, and nothing that lets us follow you from one day to the next. No cookie is involved and the counting is done by us, not by an outside service. Legal basis: legitimate interest (knowing whether the shop is being found).
We collect nothing else. No advertising profiles, no third-party analytics services, and we never sell or rent personal data.
Payments are processed by Rabo Smart Pay (Coöperatieve Rabobank U.A.) (Utrecht, the Netherlands) and Stripe Payments Europe, Ltd. (Dublin, Ireland). Your payment details — card numbers, bank account details — go directly to the payment processor and never reach our systems; we only receive confirmation that a payment succeeded or failed. Each processor is independently responsible for the payment data it processes; see Rabobank's privacy statement and Stripe's privacy statement.
We use a small number of service providers to run the shop. They process data on our instructions and only what is needed:
One note on images: card artwork in the singles search is loaded by your browser directly from the image servers of Scryfall, a card database. Like any server that serves an image to you, Scryfall sees your IP address for that request — nothing more is shared with them.
Your data is stored in the European Union. Some of our providers (such as Vercel and Google) are part of US companies; where any data could be transferred outside the EU, this is covered by EU-approved safeguards (the EU–US Data Privacy Framework and/or standard contractual clauses).
We use one functional cookie: a signed session cookie that keeps you logged in after you sign in to your account. It lives for 30 days, is not readable by scripts and is used for nothing except recognising your session. Functional cookies like this do not require a consent banner — which is why you have not seen one.
Your shopping crate is stored in your own browser (local storage) and only reaches us when you check out. We use no analytics cookies, no advertising cookies and no third-party tracking of any kind. The visitor counting described in section 2 uses no cookie either — it needs nothing stored on your device, which is precisely why it was built that way.
All traffic to the site is encrypted (HTTPS). Passwords are stored only as salted cryptographic hashes. Email verification and password-reset links are single-use and time-limited, and repeated failed sign-ins temporarily lock the account. Access to our systems is limited to the owner.
Under the GDPR (AVG) you can at any time ask us to:
Email orders@theguildmaster.eu and we will respond within one month. If you are not satisfied with how we handle your data, you can lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
The shop is not directed at children. If you are under 16, ask a parent or guardian to place the order or to consent to your account.
If how we handle data changes — a new tool, a new feature — we update this page and the date below. Significant changes that affect you will be pointed out on the site.
Last updated 17 August 2026. Our terms & conditions live in the Charter.