Privacy Policy

Last updated: October 1, 2026

The Card Ledger ("we", "our", or "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data. We collect only the personal information that is adequate, relevant, and reasonably necessary for the purposes described in this policy, and we do not use it for materially different purposes without your consent.

1. Information We Collect

We collect information you provide directly and information generated by your use of the app:

2. How We Use Your Information

We do not sell your personal information to third parties.

We may disclose your personal information without further notice only in the limited circumstances necessary to operate lawfully: (i) to comply with applicable law, legal process, or enforceable governmental or regulatory requests; (ii) to enforce our terms of service, or to detect, prevent, or address fraud, security, or technical issues; (iii) to protect the rights, property, or safety of our users, the public, or The Card Ledger; and (iv) in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our assets, in which case we will require the recipient to honor the commitments in this policy and will notify you of any resulting change in control or applicable privacy policy.

3. Third-Party Services

We use the following third-party services to operate the app. Each has its own privacy policy:

Affiliate disclosure. The Card Ledger participates in affiliate programs. Some links in the app and on this website are affiliate links, meaning we may earn a commission if you make a purchase through them — at no additional cost to you. As an Amazon Associate, The Card Ledger earns from qualifying purchases. Affiliate relationships never influence the market values, comparable sales, or pricing data we show you; those are derived from real sold-listing data independently of any commission.

4. Cookies and Tracking Technologies

On our website and within the app, we and our partners use cookies, SDKs, and similar technologies to keep you signed in, remember your preferences, measure product usage through PostHog, and, for affiliate links, attribute qualifying purchases to us through a referral identifier or partner-set cookie. These technologies are limited to the purposes described in this policy. You can control cookies through your browser or device settings, opt out of non-essential analytics where offered, and manage app permissions (such as camera and notifications) at any time in your device settings. Some browsers offer a "Do Not Track" signal; because there is no common industry standard for how to respond to it, we do not currently take action in response to Do Not Track signals, but we honor recognized opt-out preference signals as described in Section 10.

5. eBay Integration

Collector and Pro subscribers may connect their eBay seller account to The Card Ledger to create listings directly from the app. When you connect your eBay account:

We do not share your eBay tokens or seller data with any third party other than eBay's own API services.

6. Data Retention

We retain your account and collection data for as long as your account is active. You may delete your account at any time from the app (Profile → Settings → Delete Account), which permanently removes all your data from our systems within 30 days.

Crash reports are retained for up to 90 days. Usage analytics associated with your account ID are retained for the life of your account and deleted when you delete your account; aggregated usage data that no longer identifies you may be retained for longer.

We keep de-identified card information after you delete a card or your account: a card's identity (such as player, year, set, card number, parallel and grade), its market prices and price history, and corrections to how the app identified it. It does not include anything personal, is not linked to you or your account, and is used only to improve card identification and pricing. We may also keep one photo of the front and back of the card itself, stored separately from your account and not linked to you, to help identify the same card in future scans. A reference photo carries no location, device or date information.

7. Your Rights

Depending on your location, you may have the following rights:

To exercise any of these rights, contact us at contact@thecardledgerapp.com. If we decline your request, you may appeal that decision by replying to our response; we will inform you in writing of the outcome of the appeal and, where applicable, of how to lodge a complaint with your data-protection authority.

8. Children's Privacy

The Card Ledger is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly. We do not knowingly process the personal information of any user under 18 for targeted advertising or for sale.

9. Your Rights in the EEA, UK & Switzerland (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, The Card Ledger, operated by The Card Ledger LLC, a Texas limited liability company, is the data controller of your personal data. Our legal bases for processing are:

In addition to the rights in Section 7, you may restrict or object to processing, withdraw consent at any time, and lodge a complaint with your local data-protection authority. We do not carry out automated decision-making that produces legal effects concerning you.

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, to request its deletion or correction, and not to be discriminated against for exercising these rights.

We do not sell or share your personal information (as "sell" and "share" are defined under the CCPA/CPRA), and we do not use sensitive personal information beyond providing the Service. Your precise geolocation is “sensitive personal information” under the CPRA; we collect and use it only to provide the “card shops/shows near me” feature when you enable it, and not for any other purpose, so no right to limit its use applies beyond that. Because we do not sell or share personal information, there is nothing to opt out of; however, where your browser or device sends a recognized opt-out preference signal (such as Global Privacy Control), we treat it as a valid request and will not sell or share your personal information. The categories we collect (identifiers such as your email; commercial information such as your collection and purchases; photos you upload; precise geolocation when you use the nearby-shops feature; and usage/device data) are described in Section 1 and used for the purposes in Section 2.

To exercise your California rights, contact us at contact@thecardledgerapp.com. You may use an authorized agent to submit a request on your behalf.

11. International Data Transfers

We operate from the United States, and our service providers (including Supabase, Google, and RevenueCat) may process and store your data in the United States and other countries. Where personal data is transferred out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum to those clauses, as applicable. By using the Service, you understand your data may be processed in countries whose data-protection laws differ from those where you live.

12. Data Security

We use industry-standard security measures including encrypted connections (HTTPS/TLS), row-level security on our database, and secure credential management. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach that compromises your personal data, we will notify you and the relevant supervisory or regulatory authorities without undue delay as required by applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page and, where appropriate, by sending an in-app notification. Where a change materially affects your rights or how we use personal data we previously collected, we will provide prominent notice and, where required by law, obtain your consent before applying the change to that data. Your continued use of the app after a change takes effect constitutes acceptance of the updated policy to the extent permitted by law.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: