1. Scope and responsible operator
This draft describes the current development preview. The legal name and contact details of the data controller remain to be completed before production launch. Use test information while the service is in preview.
2. Information we process
Account and transaction information includes your wallet address, session identifiers, signed authentication challenges, listings, offers, pack requests, buyback quotes and redemption records. Blockchain activity also includes public transaction hashes and ownership history.
Deposit submissions include certification information, card descriptions and uploaded card images. Redemption submissions include recipient name, delivery address and phone number. Infrastructure and security services may process IP addresses, request metadata and diagnostic information to operate and protect the service.
3. How information is used
Information is used to authenticate accounts, verify ownership and permissions, operate trading and pack purchases, review deposits, arrange redemption fulfillment, respond to requests and investigate misuse or failures. The production operator must document applicable legal bases and any additional processing before launch.
4. Privy and wallet providers
Privy provides the configured login and embedded-wallet experience. Depending on the method you choose, Privy and connected identity providers may process email, social identity, device and wallet information under their own policies. The current application backend authenticates a signed wallet challenge; it does not require your wallet seed phrase or private key.
External wallet software and RPC providers process information needed to connect and submit transactions. Review their policies and permissions. Never enter a seed phrase or private key into deposit images, support messages or shipping forms.
5. Public records and card images
Wallet addresses, transactions and NFT ownership are public on the blockchain. Card images and NFT metadata may also be publicly served or published through configured IPFS services. Public blockchain records cannot be deleted by the application, and third-party copies of published images or metadata may persist.
Only upload card-related images you have the right to publish. Do not include identification documents, addresses or other private information in card images or public metadata. Shipping addresses are not intended for NFT metadata or public marketplace display.
6. Access and service providers
Account data is limited by account permissions. Delivery details are encrypted in application storage and made available to authorized fulfillment staff. Information needed to fulfill an approved delivery may be shared with the applicable vault, carrier or other service provider when production fulfillment is enabled.
Hosting, storage, authentication, RPC and media providers process information needed for their services. Actual production providers, processing locations and any international-transfer arrangements must be disclosed before launch. Data may also be disclosed where required by applicable law or necessary to investigate abuse.
7. Cookies and browser storage
The application uses an HTTP-only session cookie for authenticated requests. Wallet and authentication providers may use browser storage to maintain sessions and wallet connections. Signing out clears the application session; provider sessions and browser storage may have separate controls.
Third-party login services have their own cookie and telemetry practices. Any future optional analytics or marketing tools must be disclosed, together with the applicable consent controls, before they are enabled.
8. Retention and security
Private records are retained as needed to operate accounts, process custody and fulfillment, resolve incidents and meet applicable obligations. A production retention schedule, including backups and deletion handling, remains to be defined; no automatic deletion period is promised in this preview.
The application uses access controls and encryption for sensitive fulfillment data. These measures do not eliminate all risk. Public blockchain records remain available independently of account closure.
9. Requests and updates
Depending on applicable law, you may have rights to access, correct, delete or restrict use of personal data, or to object to processing. The operator will need to verify the requester’s identity and assess applicable obligations and technical limits, including immutable public records.
The privacy contact and request-handling process must be configured before production launch. This preview does not provide a self-service export or erasure workflow. Changes to this policy will be dated and published here.
Operator & contacts
These placeholders must be replaced with verified information before production launch. No contact address is active here yet.
- Legal entity
- [Operating company name — pending]
- Registered address
- [Registered office address — pending]
- Jurisdiction
- [Jurisdiction and dispute process — pending]
- Customer support
- [Support email — pending]
- Privacy requests
- [Privacy contact email — pending]
Related documents
Read these documents together: Terms of service, Privacy policy and Fees and payments.