CardSniprOpen app →
Legal & privacy

Privacy Policy

Effective: August 20, 2026

CardSnipr uses the minimum information needed to operate accounts, watchlists, alerts, portfolios and subscriptions. We do not sell personal data.

1. Who controls your data

CardSnipr is the controller of personal data processed through cardsnipr.com. Privacy and data-rights requests can be sent to privacy@cardsnipr.com. General support is available at support@cardsnipr.com.

2. Information we process

  • Account details, including email address, password hash, verification status and subscription plan.
  • Watchlists, card criteria, alert preferences, portfolio entries, uploaded card images and feedback you submit.
  • Payment and subscription identifiers supplied by Stripe. CardSnipr does not receive or store full payment-card details.
  • Technical and security information such as IP address, timestamps, request logs, device/browser information and authentication events.
  • Delivery configuration you choose to provide, such as a Discord webhook or Telegram chat details.

3. Why and on what basis we use it

  • Contract: creating your account, operating watchlists, delivering alerts, maintaining portfolios and administering subscriptions.
  • Legitimate interests: securing the service, preventing abuse, diagnosing failures, measuring capacity and improving listing-match quality.
  • Consent: optional communications or integrations where consent is the appropriate basis. You may withdraw consent through settings or by contacting us.
  • Legal obligations: accounting, fraud prevention and responding to lawful requests.

Automated matching compares listings with criteria you configure. It produces recommendations and alerts, but no decisions that create legal or similarly significant effects.

4. Service providers and recipients

We disclose data only as needed to operate CardSnipr. Providers may include Hetzner for hosting and encrypted backups, Resend for email delivery, Stripe for billing, and alert destinations you enable, including Discord or Telegram. Marketplace search information may be processed when CardSnipr communicates with supported providers such as eBay, CardTrader, Tradera and CardNexus.

5. International transfers

Some providers may process information outside the European Economic Area. Where required, transfers are protected through an adequacy decision, Standard Contractual Clauses or another lawful mechanism.

6. Retention

Account content is generally retained while your account is active. After deletion, active records are removed or anonymised unless needed for security, billing, disputes or law. Encrypted backups follow a rotating operational retention schedule and are used only for disaster recovery. Security logs and failed-delivery records are retained only as long as reasonably necessary. Anonymous public-site conversion events are retained for no more than 180 days.

7. Cookies, local storage and service analytics

CardSnipr uses essential authentication and security storage needed to keep you signed in and protect your session. The public website also records limited first-party conversion events such as a landing-page view, proof-feed load or registration-button click. These events contain an anonymous session identifier, page, placement and campaign source; they do not contain card searches, account content or advertising identifiers. The anonymous browser identifier is kept in session storage and expires with the browser session, while the corresponding anonymous event records are retained for aggregate funnel measurement under the retention period above. Network addresses may be processed briefly in memory for abuse prevention but are not written into the conversion event. We do not use third-party advertising cookies. Optional third-party analytics or marketing cookies will require updated information and consent controls before introduction.

8. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may complain to your local supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman. We may verify your identity before completing a request.

9. Security and children

We use access controls, encrypted transport, password hashing, restricted production access and encrypted backups. No online service can guarantee absolute security. CardSnipr is not directed to children under 16; younger users must have valid parental or guardian authorisation where required.

10. Changes

Material changes will be communicated through the service or by email when appropriate. The effective date above identifies the current version.

Terms of ServiceContactHome