Trust and data
Privacy, in plain language.
CardScope is designed to work without an account. Card photos are used for identification, saved collections are private by default, and optional analytics starts only after you allow it.
Effective 10 September 2026
What CardScope handles
Scans and searches
When you scan a card, its image is sent through CardScope to eBay's image-search service to identify likely matches. CardScope uses the image for that request and does not deliberately retain it after the request completes. Search terms, card selections, language, finish, grading company, and grade may be sent to catalogue and market-data providers so CardScope can return the requested result.
Accounts and saved data
Netlify Identity handles account email, password authentication, password resets, and Google sign-in. CardScope does not store your password. CardScope's database stores the Identity user ID and the profile, collection, comp-list, saved market snapshot, quantity, visibility, and note fields you choose to save. Profiles and collections are private unless you publish them; comp lists remain private.
Continuing a save after sign-in
If you choose to save a card before signing in, a temporary draft in this browser tab keeps the identified card details, catalogue artwork link and any displayed sold-value snapshot while you sign in. It does not contain the uploaded photo, your original search, private notes or sign-in credentials, and is never sent to analytics. The draft expires after 30 minutes (checked when it is next used) and is cleared when resumed or cancelled. Returning from sign-in opens the save form; it does not save to your account until you confirm.
Feedback submissions
Feedback is submitted privately through Netlify Forms. The message, category, page area, and an optional reply email are stored so the issue can be reviewed. The message and reply email are not copied into analytics or public planning issues.
Optional analytics and error monitoring
If you allow analytics, CardScope uses Google Analytics and privacy-minimised PostHog events to understand broad journeys such as a scan starting, a result appearing, or a collection item being saved. Fixed categories also distinguish save attempts, failures, sign-in handoffs, profile edits, showcase changes, shares and chosen offer percentages; they do not include profile details, card details, list contents or error messages. Analytics uses an anonymous browser identifier and a coarse page path. Advertising personalisation, session replay, autocapture, person profiles, and precise location enrichment are disabled. You can change this choice from Analytics choices in the footer. Production server errors may be sent to Sentry with request, user, breadcrumb, context, and extra data removed.
Why the data is used
- Identify the card and return catalogue, asking-price, and confirmed-sale evidence.
- Authenticate accounts and provide collections, comp lists, exports, and profiles.
- Protect the service, investigate failures, prevent abuse, and control provider costs.
- Understand aggregate product usage and improve CardScope when analytics is allowed.
- Review feedback and reply only when a user supplies a reply address.
CardScope does not sell personal information or use it to rank market results.
Providers and overseas processing
CardScope relies on service providers for hosting and forms (Netlify), authentication (Netlify Identity and Google when selected), database storage (Neon), encrypted backups (Cloudflare R2), card catalogues and artwork, eBay identification and active listings, specialist sold-market evidence, optional analytics (Google Analytics and PostHog), and scrubbed error monitoring (Sentry). Some providers process data outside Australia, including in the United States, under their own privacy and security terms.
Market-data queries normally describe a card rather than a person. CardScope sends only the information needed for the selected feature and does not give those providers your CardScope password or private collection notes.
Public profiles and your choices
- You can use scanning and search without creating an account.
- Profiles and collections start private; publishing each is a separate choice.
- A spotlight card is public when it is shown on a published profile.
- Public saved values are owner-saved snapshots, not live appraisals or guarantees.
- You can export supported collection and comp-list data as CSV.
- You can delete your account and live CardScope database records from the account page.
- You can deny or withdraw optional analytics from the footer at any time.
Retention and security
Live account and saved product data is kept while your account exists or until you remove it. Account deletion removes live CardScope records and asks Netlify Identity to delete the login. Encrypted disaster-recovery backups roll off under a fixed retention schedule and are not used as a second live database. Feedback, security records, operational totals, and provider data are kept only while reasonably needed for the purpose described above.
CardScope uses access controls, owner-scoped database queries, private-by-default settings, encryption in transit, encrypted backups, request-size checks, origin checks, rate limits, dependency monitoring, and privacy-scrubbed error reporting. No internet service can promise perfect security, so please do not put passwords, payment details, seller/customer details, or sensitive personal information in card notes or feedback.
Young users
CardScope is a general collector tool and is not designed to collect sensitive information from children. If you are not old enough to manage an online account or agree to these terms where you live, use CardScope with a parent or guardian and avoid publishing a profile.
Questions, access, correction, or complaints
Return to the CardScope home page, choose Give feedback, then select Privacy or account data. Add your own reply email only if you want a response. Do not include passwords, payment details, card photos, or another person's information. You can also correct profile fields or delete the account from your account page.
This notice will be updated when CardScope's data practices materially change. A major change will be called out in the product or account experience before it applies where practical.