Skip to content
PRIVACY & DATA

Your collection.
Clear boundaries.

A practical description of how this beta handles data.

Accounts and collections

The service stores your name, email address, password hash, sign-in sessions and the collection records you choose to add. Private collection and binder actions require a signed-in account. The server operator administers the database, backups and user accounts.

Testing, complimentary access and subscriptions

Existing tester grants remain non-expiring. Administrators can separately assign tiers or complimentary access. These audited access changes do not create or cancel a subscription, and complimentary access does not grant administrator permissions.

When you explicitly request a paid subscription, CardShelf sends your account name, email and an account reference to Stripe. Stripe hosts checkout and billing management and handles recurring payments. CardShelf stores provider references, accepted terms, payment status, dates and verified payment history; it does not collect full card numbers or card security codes. Sandbox customer details are synthetic.

Administrators control new subscription availability and feature enforcement separately. Stopping new subscriptions does not cancel existing renewals. Historical records from a retired payment provider remain read-only for accounting and previously verified access; no new payment requests are sent to that provider.

Referral programme

Referral participation requires administrator approval and your explicit acceptance of the reward terms. An attributed subscriber confirms use of a referral code before subscribing. The service records the attribution, accepted terms, eligible subscription commissions, refunds and manually recorded external payout references. Referrers can see their own totals and ledger, not subscriber identities or payment details. Administrators can see and manage these records. Referral links do not set an advertising cookie; attribution is recorded only when the signed-in subscriber confirms it.

Marketplace

Card listings deliberately share the seller alias, selected card, photographs, description, price and delivery details with signed-in members. Listing enquiries are visible to the participants through the application. Card-sale payments and delivery arrangements remain between collectors; CardShelf does not process them. The database operator has administrative access to stored data and backups.

Account emails and notifications

When email delivery is enabled, CardShelf uses the operator's Postal mail service for password recovery and account security notices. Optional marketplace and membership notifications are controlled under More → Emails. Activity emails link you back to CardShelf without including private conversation text. The mail service processes your email address and the message contents, including a temporary recovery link when you request one. Administrators can inspect delivery status and manage addresses that cannot receive mail. Delivery records and suppression records support retries and prevent repeated sending to failed addresses. Postal's own message retention and backups are managed by the server operator.

Access, support and privacy requests

The request form stores the name, email address, request type and message you submit, with its consent version and review status. Only platform administrators can view the queue. Submitting it does not create an account or subscribe you to a mailing list. Administrators remove requests when no longer required.

Cookies and technical records

CardShelf uses a first-party sign-in cookie and server-side sessions. Rate-limit records, logs and audit events support operation. Stripe webhook processing retains verified routing identifiers and status, not entire raw webhook payloads. This release does not add advertising trackers or third-party analytics cookies.

Images and sharing

Wallpaper and sale-photo uploads are decoded, optimised and re-encoded before storage. Original filenames and image metadata are not retained by those flows. A binder wallpaper is accessible to its owner and, when enabled, through its read-only sharing link. Shared trackers expose their checklist marks. Revoking a link cannot recall screenshots or copies already made.

Catalogue and price providers

Catalogue and market-price requests use TCGdex. Card artwork loads from its image host, which receives ordinary connection information needed to serve images. Currency reference requests use Frankfurter. Full collection databases, private notes and passwords are not sent to these providers.

Stripe subscription payments

When a subscription-ready member explicitly chooses Stripe, CardShelf creates an account-bound hosted checkout. Production customer names and email addresses are sent to Stripe for billing; test mode uses synthetic details. Payment-card entry and saved payment methods remain with Stripe. CardShelf stores provider identifiers, accepted terms, invoice totals, verified paid periods and refund/dispute status, not full card numbers. Administrator credentials are encrypted using the server integration key. Referral rewards use verified production subscription payments and do not disclose subscriber contact details to referrers. Marketplace payments and referral payouts remain external.

Exports and data requests

Ownership exports contain JSON or CSV records, not every account or database record. The administrator manages broader data requests and retention, including billing, referral, marketplace and backup records. No automated retention schedule for those records is included. Contact the operator who invited you or use this form. Do not include a password or payment-card information.

Send a data request

This describes the implemented beta. The operator must review hosting, retention, service terms, subscription/referral disclosures and its wider obligations before a paid public launch.

Free accounts, public card data and sponsor placements

The reference catalogue can be read without signing in. Account email addresses, private quantities, notes and binder contents are not included in its responses. Newly registered Free accounts do not receive protected tester access; subscriptions and explicit administrative grants are separate.

When enabled by the administrator, signed-in Free accounts may see a clearly labelled first-party sponsor placement. CardShelf checks eligibility on the server. Paid accounts, testers, Complimentary users and signed-out visitors do not receive these placements. First-party sponsorship does not add advertising cookies or tracking scripts. Separately enabled Google AdSense, including Auto ads and labelled marketplace placements, on approved public and signed-in content pages may load Google and its advertising partners, use cookies or other identifiers, and process IP addresses, device information, page URLs, rendered page content and advertising/consent signals according to the published privacy messages. Paid and protected accounts are excluded from the CardShelf AdSense loader. Password, billing, account-administration, private-message, private card-editor, binder and battle screens are excluded. Signing out or losing eligibility replaces a document that loaded Google; returning to a private editor first opens an ad-free document. Free users may browse sale listings but need the appropriate membership to start enquiries or sell. Following a sponsor's link opens an external website with its own privacy practices.

CardShelf stores uploaded sponsor artwork locally after re-encoding it. Public card artwork for additional games is likewise cached on this server; existing Pokémon artwork still uses the configured catalogue provider. Ordinary server access logs and essential session cookies continue to apply. Email-based password recovery sends a short-lived one-time link through the configured SMTP provider. Only token hashes are stored; successful redemption revokes old sessions. Queued email metadata is retained briefly for delivery and troubleshooting. Account email verification is not included.

For Google advertising, see how Google uses information from sites that use its services. Use the published Google consent message and its privacy-options link to review or withdraw consent. CardShelf does not treat declining consent as a subscription purchase or removal of account access.