Privacy on CardYard
This page describes the current technical setup. A final privacy notice, controller details and retention periods must be established before commercial launch.
Visit statistics
Only with your consent do we count visits, public page categories and listing views. We use a random session code renewed after 30 minutes of inactivity. Statistics do not store IP addresses, email addresses, search terms, order IDs or message contents. Listing views are privately linked to the listing ID. Administrators can view visit records; Premium sellers see only totals for their own listings, without visitor identities. Change your choice through the statistics control. Records older than 90 days are cleaned up at the next measured visit. A session is not a unique person.
Camera and AI
The camera session captures four card photos. The recognition or assessment button sends images to Vercel AI Gateway and the configured AI model, currently Mistral. Verification images and the session code are stored privately in Supabase. Only front and back photos become public listing photos when published. Avoid photographing personal data. Public offers show amounts and status, not bidder identities.
Which data
Your account uses your email address and profile. Listings contain photos and card details. Conversations contain messages. Orders contain the shipping address provided. Do not include sensitive data in public listings or your profile.
Who can see what
Your display name, profile, reviews and active listings are public. Messages are accessible only to conversation participants. Orders are accessible to buyer, seller and authorized staff. Administrators can access reports, helpdesk requests, member details and related listings, offers and orders for support and moderation. Helpdesk requests and replies are visible only to the requester and administrators.
Payments and account emails
Resend sends account and order updates to your verified email address. Stripe processes payment, identity and bank information when you use checkout or seller setup. CardYard does not store full card or bank details, but retains payment references, status and amounts. Sellers enter identity details on Stripe.
Premium and payment disputes
Stripe retains checkout consent, the displayed subscription policy, payment records and activation evidence. When you save Premium selling preferences, we record the first and most recent successful save dates on your Stripe subscription to document service delivery and handle payment disputes. This is not general browsing analytics. Only authorized staff use this evidence; no card numbers or IP addresses are added to these records. Stripe’s retention policy and applicable statutory retention duties apply. For questions or a privacy request: tradecardeu@gmail.com.
Hosting and cookies
The website uses Vercel for hosting and Supabase for accounts, database and photos. Functional cookies store your session and language choice. No advertising trackers have been added in this version.
Request access or deletion
You can edit your profile yourself. To request access, correction or deletion of other account data, email tradecardeu@gmail.com. Do not include passwords in your request.