Privacy policy
Privacy policy
cards.place is owned and operated by Ryan Rood, sole proprietor, of London, Ontario, Canada. This page says what the service collects, what it deliberately does not, who else ever touches it, and how to get it all back or have it deleted.
It is specific rather than general, because a privacy policy that could describe any website tells you nothing about this one.
What we collect
To run your account
- Your email address and name.
- A hash of your password. We never store the password itself and cannot recover it or read it.
- Your second factor. If you use an authenticator app, the shared secret is encrypted at rest with AES-256-GCM. Recovery codes are stored only as hashes, which is why they can be shown to you exactly once.
- A record of sign-in attempts (email, IP address, whether it succeeded) so that repeated guessing can be throttled. Failed attempts are cleared once you sign in successfully.
- The date you last signed in.
To bill you
- A billing name, email, phone number and address, if you enter them. An address is needed because card payments are checked against one.
- Identifiers from Stripe (a customer id and a subscription id), your plan, and when the current period ends.
- No card details. Card numbers go from your browser directly to Stripe and never reach our servers. We could not show you your own card number if you asked.
What you put in
- Your collection: card records, the values and prices you enter, notes, storage locations, saved views, lists, and the players you collect.
- Any photographs you upload. These are stored outside the web root and served only after checking they belong to your account, so there is no URL to guess and no image sitting on the open web.
Technical records
- An activity log of actions taken in your account: what happened, to which item, by which person, and the IP address it came from. This is what lets you see who changed what when more than one person has access, and it is what makes a failed sign-in investigable.
- Server logs recording requests and errors. These include IP addresses and are kept for about 30 days.
- If you send feedback from inside the app: your message, the screen you were on, your browser's user-agent string, and any screenshot you attach.
What we do not do
This part is short because the list of things we are not doing is the useful part:
- There is no analytics on this website. No Google Analytics, no tracking pixel, no session recording, no advertising or marketing cookie. You can check the page source.
- We do not sell or rent your data, or share it with other customers.
- We do not use your collection to train anything.
- We do not advertise to you, or profile you for anyone else.
- Nothing about your collection is public unless you switch it on. The read-only API is off at the server and off per account, and returns nothing at all until both are on.
- We do not read your collection as a matter of course. Access to the database exists because somebody has to keep the service running, and it is used for that: fixing faults, restoring backups, and answering a support question you have asked us about.
If you make an offer on a share link
You do not need an account to make an offer, so the rest of this page is not written to you. This part is.
- What we collect: the name and email address you type, the amount you offer, your message, and the IP address and time the offer came from.
- Why: to email you a link confirming the address is yours, to pass the offer to the owner of that collection, and to stop the form being abused.
- Who sees it: the owner of that collection sees your name, email address, amount and message. That is the point of an offer. We do not sell it, and we do not use it to market anything to you.
- How long: an offer is deleted 90 days after it is declined or expires, and an offer nobody confirmed goes 90 days after it lapses. An offer the seller accepted is their record of a sale and is kept while their account exists. Write to info@cards.place to have one removed sooner.
We are not part of the sale itself: no money passes through cards.place, and what you and the seller agree afterwards is between you.
Cookies and local storage
There are no advertising or analytics cookies. What exists is:
- collector_session – your sign-in token, repeated as a cookie for one reason: a browser cannot attach an authorisation header to an image request, so without it your card photos would not load. It is HttpOnly (script cannot read it), SameSite=Strict, sent only over HTTPS, and accepted only by the image endpoints. Signing out clears it.
- In your browser's local storage: your session token, your chosen light or dark theme, and (for administrators) which plan tier is being previewed. These stay on your device and are cleared when you sign out.
Who else touches it
Three companies are involved in running the service. Nobody else receives anything, and this website makes no third-party requests at all - no fonts, no scripts, no beacons loaded from anyone else's server.
- InMotion Hosting (United States) hosts the application, the database and your photographs.
- Stripe processes payments and holds your card details.
- Resend sends transactional email: sign-in codes, account recovery, invitations, and replies to feedback you have sent.
Where your data is held
We are in Canada. The servers are in the United States. Your data is therefore stored and processed outside Canada, and while it is there it is subject to the laws of that country, including lawful access requests made under them. Stripe and Resend also process data outside Canada.
We would rather tell you this plainly than bury it. If it is not acceptable to you, please do not use the service.
How it is protected
- Two-factor authentication is mandatory and cannot be switched off.
- Accounts are separated at the query level. Every request for data is scoped to one account, and a record belonging to somebody else reads as “not found” rather than “not allowed”, so its existence cannot be probed.
- Everything is served over HTTPS.
- Passwords and recovery codes are hashed; authenticator secrets are encrypted.
- Photographs sit outside the web root and are only ever handed over by the application after an ownership check.
- Uploaded images are fully re-encoded, which strips anything hidden inside a file that is pretending to be a picture.
No system is perfect and we will not pretend otherwise. If a breach affects you, we will tell you and the Office of the Privacy Commissioner of Canada as the law requires, and we will tell you what we know rather than what sounds best.
How long we keep it
- Your collection and account: for as long as your account exists. If an account is unpaid and dormant we will give you at least 30 days' notice by email before deleting its contents, so you can export first.
- Things you delete inside the application: a card, saved view or collection you delete goes to a recycle bin and is kept for 30 days, with its photographs, so you can put it back. A daily job then deletes it permanently, files and all. Closing your whole account is separate and is immediate — it does not go through the bin.
- Server logs: about 30 days.
- Offers on share links: 90 days after they are declined, expire or lapse unconfirmed. Accepted offers stay while the seller's account does.
- Activity log: for the life of the account. It is the record of who did what, so pruning it would defeat its purpose. It goes when the account goes.
- Billing records: kept as long as tax and accounting law requires, which is longer than the account itself.
- Feedback and replies: for the life of the account. Anything you report to us, and any screenshots attached to it, is tied to your account and is deleted with it. It is not kept after you go.
Your rights
Under Canadian privacy law (PIPEDA) and comparable law elsewhere, you can:
- See what we hold. Most of it you can already see, and the export button gives you the whole collection as an Excel workbook or CSV at any time, including while an account is locked. Ask us for anything the export does not cover and we will send it.
- Correct anything wrong. Most of it you can edit yourself.
- Have it deleted. You can do this yourself, from Settings in the application, without asking us. It needs your password and a fresh two-factor code, and then it is immediate and permanent: the account, the cards, the photographs and the saved views all go, and the image files are removed from disk rather than just unlinked from a record. Billing records Stripe is required to keep are the only exception. Please export first, because deletion is meant to be real. Email us if you would rather we did it for you.
- Change your mind for 30 days. Deleting a single card, saved view or collection inside the application is not the same as closing your account. Those go to a recycle bin, where you can see them and put them back — with their photographs — for 30 days. After that they are permanently deleted on a daily schedule and cannot be recovered by you or by us. Closing the whole account, described above, skips the bin and is immediate.
- Withdraw consent and stop using the service, at any time.
- Complain. To us first, please, at info@cards.place. If we do not put it right you can complain to the Office of the Privacy Commissioner of Canada.
We will answer a request within 30 days. There is no charge, and we do not need a reason.
Children
The service is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child has an account, tell us and we will remove it.
Changes
If this policy changes in a way that materially affects you, we will email you and change the date at the top. We will not quietly start doing something this page says we do not do.
Contact
Ryan Rood, sole proprietor
London, Ontario, Canada
info@cards.place
For privacy questions, that address reaches a person rather than a queue.
Written in plain language on purpose. It is accurate to how the service works today and it is not legal advice; it has not been reviewed by a lawyer. It sits alongside the terms of service and the refund policy.