Accounts and collections
The service stores your name, email address, password hash, sign-in sessions and the collection records you choose to add. Private collection and binder actions require a signed-in account. The server operator administers the database, backups and user accounts.
Testing, complimentary access and subscriptions
Existing tester grants remain non-expiring. Administrators can separately assign tiers or complimentary access. These audited access changes do not create or cancel a subscription, and complimentary access does not grant administrator permissions.
When you explicitly request a paid subscription, CardShelf sends your account name, email and an account reference to Stripe. Stripe hosts checkout and billing management and handles recurring payments. CardShelf stores provider references, accepted terms, payment status, dates and verified payment history; it does not collect full card numbers or card security codes. Sandbox customer details are synthetic.
Administrators control new subscription availability and feature enforcement separately. Stopping new subscriptions does not cancel existing renewals. Historical records from a retired payment provider remain read-only for accounting and previously verified access; no new payment requests are sent to that provider.
Referral programme
Referral participation requires administrator approval and your explicit acceptance of the reward terms. An attributed subscriber confirms use of a referral code before subscribing. The service records the attribution, accepted terms, eligible subscription commissions, refunds and manually recorded external payout references. Referrers can see their own totals and ledger, not subscriber identities or payment details. Administrators can see and manage these records. Referral links do not set an advertising cookie; attribution is recorded only when the signed-in subscriber confirms it.
Marketplace
Card listings deliberately share the seller alias, selected card, photographs, description, price and delivery details with signed-in members. Listing enquiries are visible to the participants through the application. Card-sale payments and delivery arrangements remain between collectors; CardShelf does not process them. The database operator has administrative access to stored data and backups.
Account emails and notifications
When email delivery is enabled, CardShelf uses the operator's Postal mail service for password recovery and account security notices. Optional marketplace and membership notifications are controlled under More → Emails. Activity emails link you back to CardShelf without including private conversation text. The mail service processes your email address and the message contents, including a temporary recovery link when you request one. Administrators can inspect delivery status and manage addresses that cannot receive mail. Delivery records and suppression records support retries and prevent repeated sending to failed addresses. Postal's own message retention and backups are managed by the server operator.
Access, support and privacy requests
The request form stores the name, email address, request type and message you submit, with its consent version and review status. Only platform administrators can view the queue. Submitting it does not create an account or subscribe you to a mailing list. Administrators remove requests when no longer required.
Cookies and technical records
CardShelf uses a first-party sign-in cookie and server-side sessions. Rate-limit records, logs and audit events support operation. Stripe webhook processing retains verified routing identifiers and status, not entire raw webhook payloads. This release does not add advertising trackers or third-party analytics cookies.
Images and sharing
Wallpaper and sale-photo uploads are decoded, optimised and re-encoded before storage. Original filenames and image metadata are not retained by those flows. A binder wallpaper is accessible to its owner and, when enabled, through its read-only sharing link. Shared trackers expose their checklist marks. Revoking a link cannot recall screenshots or copies already made.
Catalogue and price providers
Catalogue and market-price requests use TCGdex. Card artwork loads from its image host, which receives ordinary connection information needed to serve images. Currency reference requests use Frankfurter. Full collection databases, private notes and passwords are not sent to these providers.
Stripe subscription payments
When a subscription-ready member explicitly chooses Stripe, CardShelf creates an account-bound hosted checkout. Production customer names and email addresses are sent to Stripe for billing; test mode uses synthetic details. Payment-card entry and saved payment methods remain with Stripe. CardShelf stores provider identifiers, accepted terms, invoice totals, verified paid periods and refund/dispute status, not full card numbers. Administrator credentials are encrypted using the server integration key. Referral rewards use verified production subscription payments and do not disclose subscriber contact details to referrers. Marketplace payments and referral payouts remain external.
Exports and data requests
Ownership exports contain JSON or CSV records, not every account or database record. The administrator manages broader data requests and retention, including billing, referral, marketplace and backup records. No automated retention schedule for those records is included. Contact the operator who invited you or use this form. Do not include a password or payment-card information.
Send a data requestThis describes the implemented beta. The operator must review hosting, retention, service terms, subscription/referral disclosures and its wider obligations before a paid public launch.