Privacy Policy

Your Privacy Matters

Last updated: 11 May 2026

Introduction

CardEtra ("we", "our", or "us") is an AI-assisted platform built for football card collectors. We are committed to protecting your privacy and being transparent about how your information is used. This Privacy Policy explains what we collect, why we collect it, and the rights you have over your data. By using CardEtra, you agree to the practices described here.

Information We Collect

We may collect the following categories of information:

  • Account Information — your name, email address, and login credentials when you register.
  • Uploaded Content — card images and collection content you upload to use platform features. We take reasonable technical and organisational measures to store this content securely. CardEtra does not claim ownership over any images or collection data you upload.
  • Subscription & Billing Information — payment details are processed securely via our third-party payment provider (such as Stripe). CardEtra does not store your full card or bank details on our servers.
  • Usage Data — technical information including device type, browser type, IP address, session activity, and platform interactions.
  • Analytics & Cookies — we use analytics tools and cookies to improve platform performance and understand how users engage with CardEtra. You can manage cookie preferences through your browser settings.

How We Use Your Information

We use your information to:

  • Create and manage your account and subscription
  • Deliver AI-assisted collector insights and platform features
  • Maintain security and detect fraudulent activity
  • Monitor and improve platform performance
  • Respond to support requests and develop new features
  • Comply with applicable legal obligations

AI-Assisted Features

CardEtra uses artificial intelligence to provide collector insights, indicative valuation ranges, grading opinions, and market observations. These outputs are informed perspectives based on available data — not exact figures or guaranteed valuations.

Your uploaded content and collection data may be processed by our AI systems to generate insights and display information within the platform. This data is used solely for platform functionality, feature improvement, security, and related operational purposes — it is never sold or shared for commercial gain.

Third-Party Data & External Sources

CardEtra may use third-party data providers to supplement platform features, including market data, population reports, and comparable sales information. We do not guarantee the accuracy, availability, or reliability of any third-party data displayed on the platform.

Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal data on the following grounds:

  • Contract performance: to deliver the services you have subscribed to
  • Legitimate interests: to improve and secure the platform
  • Legal obligation: to comply with applicable laws
  • Consent: where you have explicitly agreed (for example, marketing communications)

Third-Party Service Providers

We use trusted third-party providers to operate CardEtra, covering authentication, payment processing, cloud hosting, analytics, and AI infrastructure. All providers are bound by appropriate data protection agreements and process only the information necessary for their specific function.

International Data Transfers

CardEtra is a global platform. Your data may be transferred to and processed in countries outside your own. Where required under UK or EU GDPR, we ensure appropriate safeguards are in place, including Standard Contractual Clauses.

Data Retention & Security

We implement appropriate technical and organisational measures to protect your information. No online platform can guarantee absolute security, and users are responsible for keeping their credentials confidential.

We retain your data for as long as your account is active. Upon account closure, we will delete or anonymise your data within 90 days, unless retention is required by law.

Your Rights

Depending on your location, you may have the right to access, correct, delete, restrict, or port your personal data, or to withdraw consent at any time. To exercise any of these rights, contact us at hello@cardetra.com.

Children's Privacy

CardEtra is not intended for users under the age of 13. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us and we will remove it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via a platform notice at least 14 days before they take effect. Continued use of CardEtra after changes are posted constitutes acceptance of the updated policy.

Contact

For questions about this Privacy Policy:
hello@cardetra.com | www.cardetra.com