Privacy Policy

Last updated: 29 June 2026

1. Who We Are

CardPitch is a mobile application (iOS and Android) that lets you scan football trading cards with your phone camera, identifies the card and its parallel variant, retrieves European market prices, and maintains your personal card collection.

Data Controller: Sergei Filofeev, individual developer (sole proprietor), Serbia.
Contact: support@cardpitch.app

We are not affiliated with, endorsed by, or connected to any trading card manufacturer. All product names and trademarks are the property of their respective owners.

2. Scope of This Policy

This policy applies to the CardPitch mobile application (iOS and Android) and the website cardpitch.app. It explains what personal data we collect, why we collect it, who we share it with, and what rights you have under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

3. Data We Collect and Why

3.1 Anonymous Account Identifier

When you open CardPitch for the first time, we create an anonymous account using Firebase Anonymous Authentication (provided by Google LLC). This assigns you a random, opaque identifier (Firebase UID). We do not collect your name, email address, phone number, password, or any information that directly identifies you. No sign-up form is presented.

Purpose: To associate your collection and subscription status with a consistent account without requiring registration.

Legal basis: Performance of contract — Art. 6(1)(b) GDPR (necessary to provide the service).

3.2 Card Scan Images

When you scan a card, the photo you take (or select from your camera roll) is sent from your device to our backend server and forwarded to Google Gemini API for automated card recognition. Images are processed in transit only and are not stored permanently. Once recognition is complete, the image is discarded from our systems.

Purpose: To identify the card, set, and parallel variant shown in the photo.

Legal basis: Performance of contract — Art. 6(1)(b) GDPR.

3.3 Collection Data

Cards you save to your collection, the number of scans you have performed, and your subscription tier are stored in our database. This data is linked to your anonymous Firebase UID.

Purpose: To display your collection, enforce usage limits, and determine which features you can access.

Legal basis: Performance of contract — Art. 6(1)(b) GDPR.

3.4 Subscription and Purchase Information

If you subscribe to CardPitch Pro, the purchase receipt or token issued by Apple App Store or Google Play is sent to RevenueCat, Inc. for verification. We receive your subscription status (active/expired/trial) and your Firebase UID is used as the customer identifier in RevenueCat. We do not receive or store your full payment card details — these remain with Apple or Google.

Purpose: To verify that your subscription is valid and unlock Pro features.

Legal basis: Performance of contract — Art. 6(1)(b) GDPR.

3.5 Crash and Diagnostic Reports

If the app crashes or encounters a critical error, anonymized diagnostic information (device type, operating system version, app version, and a crash stack trace) may be sent to Sentry (Functional Software, Inc.). No personally identifying information is intentionally included in crash reports.

Purpose: To identify and fix bugs, maintaining a stable service.

Legal basis: Legitimate interests — Art. 6(1)(f) GDPR (our interest in maintaining a reliable app, balanced against the minimal impact on your privacy given the anonymized nature of the data).

3.6 Market Price Queries

When you view a card's market price, our server queries the eBay Browse API using the card's identity (name, set, parallel) as search terms. No personal data about you is transmitted to eBay.

4. Data We Do Not Collect

We want to be explicit about what we do not do:

5. Sub-processors and Third Parties

We use the following third-party services to operate CardPitch. Each has its own privacy policy governing their processing of data.

Provider Purpose Data involved Location
Google LLC (Firebase) Anonymous authentication Anonymous Firebase UID USA (SCC)
Google LLC (Gemini API) Card image recognition Card scan image (transient) USA (SCC)
eBay Inc. Market price data retrieval Card identity only — no personal data USA
RevenueCat, Inc. Subscription verification Firebase UID, subscription status, purchase token USA (SCC)
Functional Software, Inc. (Sentry) Crash and error reporting Anonymized diagnostic data USA (SCC)
Hetzner Online GmbH Cloud infrastructure (API server, database) Collection data, anonymous UID EU — Finland

SCC = Standard Contractual Clauses approved by the European Commission, ensuring adequate protection for transfers of personal data outside the European Economic Area.

6. Data Storage and Retention

Primary location: Our database runs on Hetzner infrastructure in Helsinki, Finland (European Union). All data in transit is encrypted using TLS.

Retention periods by data type:

7. International Data Transfers

Our primary infrastructure is located in the EU (Finland). However, some of our sub-processors — Google, RevenueCat, and Sentry — are US-based and process data in the United States and potentially other countries outside the European Economic Area (EEA).

For each such transfer we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission as the appropriate safeguard under Art. 46 GDPR.

eBay receives only non-personal card identity data (e.g. "Topps Chrome 2024 Erling Haaland Gold Refractor") and therefore the GDPR transfer rules do not apply to that query.

8. Your Rights Under GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights:

To exercise any of these rights, please email support@cardpitch.app. We will respond within 30 days.

9. Deleting Your Data

Because CardPitch uses anonymous authentication, there is no username or email address in our system. To request deletion of all data associated with your account:

  1. Email support@cardpitch.app with the subject line "Delete my data". Include a brief description of your device (e.g. "iOS, iPhone 14") so we can locate your account.
  2. We will delete your collection data, anonymous account record, and subscription information from our systems within 30 days and confirm by email.

Additionally, uninstalling the app removes locally stored data from your device. However, uninstalling alone does not delete data from our server — please send the email above if you want your server-side data removed.

Note: We cannot delete data that is already anonymized and impossible to link back to you (e.g., aggregate error counts) or data we are legally required to retain (e.g., subscription billing records for accounting purposes).

10. Children

CardPitch is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has used the app, please contact us at support@cardpitch.app and we will delete the relevant data.

11. Advertising

CardPitch does not display advertising. We do not work with advertising networks, and no advertising-related data collection takes place.

12. Security

We use industry-standard measures to protect your data: all communication between the app and our servers is encrypted via TLS/HTTPS; our database server is not publicly exposed; access is restricted to the application layer. No security measure is 100% guaranteed, but we take reasonable precautions.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will provide notice within the app. Continued use of CardPitch after the effective date constitutes acceptance of the updated policy.

14. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Email: support@cardpitch.app
Response time: We aim to respond within 2–3 business days.