Privacy Policy
1. Who We Are
CardPitch is a mobile application (iOS and Android) that lets you scan football trading cards with your phone camera, identifies the card and its parallel variant, retrieves European market prices, and maintains your personal card collection.
Data Controller: Sergei Filofeev, individual developer (sole proprietor), Serbia.
Contact: support@cardpitch.app
We are not affiliated with, endorsed by, or connected to any trading card manufacturer. All product names and trademarks are the property of their respective owners.
2. Scope of This Policy
This policy applies to the CardPitch mobile application (iOS and Android) and the website cardpitch.app. It explains what personal data we collect, why we collect it, who we share it with, and what rights you have under the General Data Protection Regulation (GDPR) and other applicable privacy laws.
3. Data We Collect and Why
3.1 Anonymous Account Identifier
When you open CardPitch for the first time, we create an anonymous account using Firebase Anonymous Authentication (provided by Google LLC). This assigns you a random, opaque identifier (Firebase UID). We do not collect your name, email address, phone number, password, or any information that directly identifies you. No sign-up form is presented.
Purpose: To associate your collection and subscription status with a consistent account without requiring registration.
Legal basis: Performance of contract — Art. 6(1)(b) GDPR (necessary to provide the service).
3.2 Card Scan Images
When you scan a card, the photo you take (or select from your camera roll) is sent from your device to our backend server and forwarded to Google Gemini API for automated card recognition. Images are processed in transit only and are not stored permanently. Once recognition is complete, the image is discarded from our systems.
Purpose: To identify the card, set, and parallel variant shown in the photo.
Legal basis: Performance of contract — Art. 6(1)(b) GDPR.
3.3 Collection Data
Cards you save to your collection, the number of scans you have performed, and your subscription tier are stored in our database. This data is linked to your anonymous Firebase UID.
Purpose: To display your collection, enforce usage limits, and determine which features you can access.
Legal basis: Performance of contract — Art. 6(1)(b) GDPR.
3.4 Subscription and Purchase Information
If you subscribe to CardPitch Pro, the purchase receipt or token issued by Apple App Store or Google Play is sent to RevenueCat, Inc. for verification. We receive your subscription status (active/expired/trial) and your Firebase UID is used as the customer identifier in RevenueCat. We do not receive or store your full payment card details — these remain with Apple or Google.
Purpose: To verify that your subscription is valid and unlock Pro features.
Legal basis: Performance of contract — Art. 6(1)(b) GDPR.
3.5 Crash and Diagnostic Reports
If the app crashes or encounters a critical error, anonymized diagnostic information (device type, operating system version, app version, and a crash stack trace) may be sent to Sentry (Functional Software, Inc.). No personally identifying information is intentionally included in crash reports.
Purpose: To identify and fix bugs, maintaining a stable service.
Legal basis: Legitimate interests — Art. 6(1)(f) GDPR (our interest in maintaining a reliable app, balanced against the minimal impact on your privacy given the anonymized nature of the data).
3.6 Market Price Queries
When you view a card's market price, our server queries the eBay Browse API using the card's identity (name, set, parallel) as search terms. No personal data about you is transmitted to eBay.
4. Data We Do Not Collect
We want to be explicit about what we do not do:
- We do not collect your name, email address, phone number, or postal address.
- We do not collect precise or approximate location data.
- We do not collect device advertising identifiers (IDFA/GAID).
- We do not run third-party analytics SDKs. Firebase Analytics is disabled in the app.
- We do not display advertising, and no advertising networks have access to your data.
- We do not sell, rent, or trade your personal data to any third party.
5. Sub-processors and Third Parties
We use the following third-party services to operate CardPitch. Each has its own privacy policy governing their processing of data.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Google LLC (Firebase) | Anonymous authentication | Anonymous Firebase UID | USA (SCC) |
| Google LLC (Gemini API) | Card image recognition | Card scan image (transient) | USA (SCC) |
| eBay Inc. | Market price data retrieval | Card identity only — no personal data | USA |
| RevenueCat, Inc. | Subscription verification | Firebase UID, subscription status, purchase token | USA (SCC) |
| Functional Software, Inc. (Sentry) | Crash and error reporting | Anonymized diagnostic data | USA (SCC) |
| Hetzner Online GmbH | Cloud infrastructure (API server, database) | Collection data, anonymous UID | EU — Finland |
SCC = Standard Contractual Clauses approved by the European Commission, ensuring adequate protection for transfers of personal data outside the European Economic Area.
6. Data Storage and Retention
Primary location: Our database runs on Hetzner infrastructure in Helsinki, Finland (European Union). All data in transit is encrypted using TLS.
Retention periods by data type:
- Anonymous UID and collection data: Retained until you request deletion or we close the service.
- Scan images: Not stored. Discarded immediately after recognition is complete.
- Subscription records: Retained for as long as necessary for subscription management and legal/accounting obligations.
- Crash reports (Sentry): Retained per Sentry's standard retention policy (typically 90 days). See sentry.io/privacy.
7. International Data Transfers
Our primary infrastructure is located in the EU (Finland). However, some of our sub-processors — Google, RevenueCat, and Sentry — are US-based and process data in the United States and potentially other countries outside the European Economic Area (EEA).
For each such transfer we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission as the appropriate safeguard under Art. 46 GDPR.
eBay receives only non-personal card identity data (e.g. "Topps Chrome 2024 Erling Haaland Gold Refractor") and therefore the GDPR transfer rules do not apply to that query.
8. Your Rights Under GDPR
If you are located in the European Economic Area or the United Kingdom, you have the following rights:
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can ask us to correct inaccurate data. Because accounts are anonymous, the main correctable data is your collection contents, which you can edit directly in the app.
- Right to erasure / "right to be forgotten" (Art. 17): You can request deletion of all data associated with your anonymous account. See Section 9 below.
- Right to data portability (Art. 20): You can request your collection data in a structured, machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interests (i.e., crash reporting). If you object, we will stop that processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): Where we rely on consent as a legal basis, you can withdraw it at any time. Note: our core processing is based on contract performance and legitimate interests, not consent.
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.
To exercise any of these rights, please email support@cardpitch.app. We will respond within 30 days.
9. Deleting Your Data
Because CardPitch uses anonymous authentication, there is no username or email address in our system. To request deletion of all data associated with your account:
- Email support@cardpitch.app with the subject line "Delete my data". Include a brief description of your device (e.g. "iOS, iPhone 14") so we can locate your account.
- We will delete your collection data, anonymous account record, and subscription information from our systems within 30 days and confirm by email.
Additionally, uninstalling the app removes locally stored data from your device. However, uninstalling alone does not delete data from our server — please send the email above if you want your server-side data removed.
10. Children
CardPitch is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has used the app, please contact us at support@cardpitch.app and we will delete the relevant data.
11. Advertising
CardPitch does not display advertising. We do not work with advertising networks, and no advertising-related data collection takes place.
12. Security
We use industry-standard measures to protect your data: all communication between the app and our servers is encrypted via TLS/HTTPS; our database server is not publicly exposed; access is restricted to the application layer. No security measure is 100% guaranteed, but we take reasonable precautions.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will provide notice within the app. Continued use of CardPitch after the effective date constitutes acceptance of the updated policy.
14. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Email: support@cardpitch.app
Response time: We aim to respond within 2–3 business days.