Privacy Policy
Last updated: March 26, 2026
Card Sync ("we," "our," or "us") operates the Card Sync platform. This Privacy Policy explains how we collect, use, and protect your information when you use our services.
1. Information We Collect
We collect the following types of information:
- Account Information: Email address, name, and password when you create an account.
- Inventory Data: Card listings, pricing, descriptions, and images you add to the platform.
- Transaction Data: Buy and sell order details, including customer names and contact information for buylist submissions.
- Third-Party Connections: When you connect services like eBay or Google Sheets, we store authentication tokens to maintain the connection. We do not store your third-party passwords.
- Usage Data: Log data, IP addresses, browser type, and pages visited to improve our services.
2. How We Use Your Information
- To provide and maintain the Card Sync platform
- To manage your account and subscription
- To sync your inventory with connected services (eBay, Google Sheets)
- To process transactions and buylist submissions
- To send important service updates and notifications
- To improve our platform and develop new features
3. Information Sharing
We do not sell your personal information. We share data only in these cases:
- Connected Services: When you connect eBay or Google Sheets, your inventory data is shared with those platforms as directed by you.
- Public Marketplace: Card listings you mark as "available" are visible on your public marketplace page. Buy prices are never shown publicly.
- Service Providers: We use third-party services for hosting (Vercel), database (Supabase), and email (SendGrid) that may process data on our behalf.
- Legal Requirements: We may disclose information if required by law or to protect our rights.
4. Data Security
We implement industry-standard security measures including:
- Encrypted passwords (bcrypt hashing)
- HTTPS/TLS encryption for all data in transit
- JWT-based session management
- Rate limiting to prevent abuse
- Secure storage of third-party authentication tokens
5. Third-Party Services
Card Sync integrates with the following third-party services. Each has their own privacy policy:
- eBay: When you connect your eBay account, we access your seller account to create and manage listings on your behalf. See eBay's Privacy Policy.
- Google Sheets: When you connect a Google Sheet, we read and write inventory data to your specified spreadsheet. See Google's Privacy Policy.
- JustTCG / Scryfall: We query these services for card pricing data. No personal information is shared with them.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal information and inventory data within 30 days. Some data may be retained in backups for up to 90 days.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your inventory data (via Google Sheets sync or CSV)
- Disconnect third-party services at any time
8. Cookies
We use localStorage to maintain your login session. We do not use tracking cookies or third-party analytics cookies.
9. Children's Privacy
Card Sync is not intended for users under 18 years of age. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a new "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: support@cardsync.com