Privacy Policy
Last updated: September 12, 2026
Introduction
This Privacy Policy is maintained by FC Collects, Inc ("we", "us", "our") to explain how we collect, use, and safeguard information when you use our AI-powered platform for photographing, identifying, pricing, and listing trading cards (the "Service").
Information We Collect
- Account information: name, email address, and authentication credentials provided when you sign up or sign in (including via third-party providers such as Google).
- Card content: photos you upload, AI-extracted card metadata (player, team, set, year, grade, condition), pricing data, and notes you add.
- Listings & marketplace data: draft and published listings, marketplace destinations you connect (e.g. eBay), and the responses returned by those marketplaces.
- Billing & credits: subscription plan, credit balance, and transaction records. Payment card details are handled by our payment processor and never stored on our servers.
- Usage data: log data, device information, and basic analytics needed to operate and improve the Service.
How We Use Your Information
- Run the core Service: store your cards, generate AI metadata and pricing, and publish listings on your behalf.
- Manage your account, subscription, and credit balance.
- Communicate service updates, security notices, and (with your consent) product news.
- Detect, prevent, and respond to abuse, fraud, or security incidents.
- Comply with legal obligations.
AI Processing
Card photos you upload are sent to AI providers we contract with to extract card attributes and estimate pricing. We only send the data needed to perform the requested task and do not permit those providers to use your content to train their general-purpose models.
Third-Party Services
We share data with third parties only as needed to deliver the Service:
- Authentication: Google OAuth (if you choose it).
- Marketplaces: eBay and other marketplaces you connect, to publish your listings.
- Shopify: when you connect a Shopify store, we publish products and sync inventory and order data so your listings stay in stock and sales are recorded. See the Shopify data handling details below.
- Payments: our payment processor for subscriptions and credit packs.
- Infrastructure: our hosting, database, and AI inference providers.
Services that process personal data on our behalf
- Supabase — account authentication and database hosting.
- Stripe — payment processing for subscriptions, credit packs, and consultation fees.
- Google — optional sign-in (OAuth) and transactional email delivery.
- Shopify — store, product, and order data for connected merchant stores.
- Cloudflare — application hosting, delivery, and security.
- AI inference providers — card identification and pricing, limited to the images and data needed for the task.
Each of these providers processes personal data only under contract, only for the purpose we engaged them, and with their own security obligations. We update this list as providers change; the date at the top of this policy reflects the latest revision.
Shopify customer data handling
When you connect a Shopify store, FC Collects, Inc acts as a Shopify app and processes a limited set of store and order data strictly to publish and manage your product listings and to record completed sales for accounting and payouts. We request only the minimum scopes required for these purposes and tell merchants, within the app and this policy, what data is processed and why.
- What we process: product and variant details (title, description, price, inventory, images), order line items, order totals, and fulfillment status. We do not request or store customer personal data such as names, email addresses, shipping addresses, or phone numbers.
- Use limitation: Shopify data is used only to deliver the listing, inventory-sync, and sales-accounting features you connect it for. We do not sell Shopify customer data or use it for unrelated purposes.
- Retention: we retain Shopify-derived product and sales data while your store is connected and your account is active. When you disconnect a store or delete your account, we remove the associated Shopify data within 30 days, except where retention is required for legal, accounting, or fraud-prevention purposes.
- Security: Shopify data is transmitted over encrypted connections (TLS) and stored at rest in our managed database, which is protected by row-level security and access controls. Access tokens are stored securely and never exposed to the browser.
- Merchant agreements: merchants connecting a Shopify store agree to this policy and are responsible for any disclosures required of them under their own privacy obligations to their shoppers.
- Disconnect & deletion: you can disconnect a Shopify store at any time from your settings. Disconnection stops all further Shopify data processing and triggers the retention cleanup described above.
Data Retention
We retain your cards, listings, and account data while your account is active. You may delete individual cards or your entire account at any time; after deletion we remove your content within a reasonable period, except where retention is required for legal, accounting, or fraud-prevention purposes.
Security
We use row-level security, encrypted connections, access controls, rate limiting, and automatic session timeouts to protect your data. We also offer two-factor authentication (2FA) on your account — we strongly recommend enabling it from your security settings. No system is perfectly secure; please use a strong unique password and notify us if you suspect account compromise.
If a data breach occurs
If we become aware of a security incident that results in unauthorized access to your personal data, we will investigate promptly, notify affected users without undue delay (and regulators within 72 hours where the law requires), and tell you what happened, what data was involved, what we are doing about it, and what steps you can take to protect yourself.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.
European Economic Area, United Kingdom & Switzerland
If you are in the EEA, UK, or Switzerland, the General Data Protection Regulation (GDPR and its local equivalents) gives you the right to access, rectify, erase, or export your personal data; to restrict or object to processing; and to withdraw consent at any time where processing is based on consent. Where we transfer personal data outside these regions, we rely on recognized safeguards such as standard contractual clauses. You also have the right to lodge a complaint with your local data protection authority.
We respond to verified data requests within 30 days. If we need more time (for complex or numerous requests), we will tell you within that period and may take up to 60 additional days as permitted by law.
California Privacy Rights & Opt-Out Preference Signals
If you are a California resident, the California Consumer Privacy Act (CCPA, as amended by the CPRA) gives you the right to know what personal information we collect, to request deletion or correction, and to opt out of the "sale" or "sharing" of your personal information. We do not sell personal information for money, and we do not knowingly sell or share the personal information of consumers under 16.
- Global Privacy Control (GPC): we honor universal opt-out preference signals. If your browser or extension sends a GPC signal, we automatically treat it as a valid request to stop the sale or sharing of your personal information for that browser — no form to fill out. Advertising and cross-context behavioral advertising signals stay off, and we instruct our advertising and analytics partners to apply restricted data processing.
- Manual opt-out: you can also use the "Do Not Sell My Information" link in our footer, or adjust cookie categories at any time under "Cookie preferences". When a GPC signal is present, the opt-out remains locked on and cannot be reversed by us.
- Scope of the signal: browser-level signals apply to the browser and device sending them. If you use several browsers or devices, send the signal from each, or sign in and set your preference in each browser.
- No discrimination: exercising these rights never changes your pricing, credits, or access to the Service.
- Authorized agents & verification: an authorized agent may submit a request on your behalf; we may ask for proof of authorization and enough information to verify your identity before acting on access, deletion, or correction requests.
- Support declaration: our compliance with the GPC specification is published at
/.well-known/gpc.json.
Children's Privacy
The Service is not directed to anyone under 13 (or under 16 in the EEA/UK, or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal data from children. Everyone creating an account must confirm they are at least 18 years old (or the age of majority where they live). We do not knowingly sell or share the personal information of consumers under 16.
Parents and guardians: if you believe your child has created an account or given us personal information, contact us through our contact page with the subject "Parental request" and the email address used. We will verify your request, delete the account and all related personal information, and confirm deletion to you, typically within 10 business days. We will not use information from such a request for any other purpose.
Changes
We may update this policy from time to time. Material changes will be communicated through the Service or by email.
Contact
Questions about this policy? Reach us via our contact form.