Zardly Privacy Policy
Version: v1.0 Effective date: July 24, 2026
This Privacy Policy explains how [ZARDLY LLC ENTITY NAME] ("Zardly," "we," "us," or "our") collects, uses, and shares information when you use the Zardly platform — our web application (zardly.ai, zardly.vercel.app), our mobile application, and related services (together, the "Service").
Zardly is a business tool for trading-card vendors in the United States. Most of the data in the Service is business inventory and transaction data, but some of it is personal information, and this policy covers both. Plain-language summaries appear throughout; the full text controls.
1. Information We Collect
1.1 Account information
When you sign up, our authentication provider (Clerk) collects your email address, name (if provided), and authentication credentials (passkeys or email-based login). Zardly stores your email address, a display name, and an internal user ID linked to your workspace. We never see or store your passkey private keys or passwords.
1.2 Workspace, inventory, and deal data
The core of the Service is the business data you and your team enter:
- Inventory records — card names, sets, numbers, conditions, grades, prices, quantities, SKUs, notes, and product details;
- Card photos — images you take or upload of your cards. Note: photos are stored in a storage bucket that is publicly readable by anyone who has the image URL (this is required so marketplaces can fetch your listing images), and they are published to marketplaces as part of your listings. Do not photograph anything private alongside your cards.
- Deal records — deals you record (in person or detected from marketplace sales), including items, agreed prices, market-price snapshots, cash amounts, payment method, timestamps, and an optional event tag (for example, the name of a card show);
- Counterparty notes — an optional free-text note on a deal. This field is intended for context like "regular customer, wants Charizards." If you type a person's name or contact details into it, that information will be stored with the deal record. We recommend not entering other people's personal information in free-text fields.
1.3 Marketplace connection data
When you connect a marketplace account:
- eBay: we store OAuth access and refresh tokens (encrypted), your eBay seller account identifier, and listing/offer identifiers.
- Shopify: we store the Admin API access token and webhook secret you provide (encrypted) and your shop domain.
Order data: when a sale happens on a connected marketplace, the marketplace sends us an order notification. Our inventory and deal records built from these notifications store SKUs, item identifiers, sale prices, order IDs, and timestamps — not buyer names or addresses. However, to process each notification reliably (verify it, de-duplicate it, and retry it if processing fails), we retain the raw notification payload in an internal event log, and that raw payload may include buyer information the marketplace sent, such as the buyer's name, shipping address, and contact details. This event log is an internal reliability record: it is not displayed in the app, not used to build profiles, and not included in any data product. See Section 4 (buyers' information) and Section 6 (retention).
1.4 Photos sent for card recognition
When you use the scan feature, the photo you take is sent to our card-recognition provider (CardSight AI) to identify the card, and to our servers to process the result. The photo is also stored with your inventory or deal record if you attach it.
1.5 Device and notification data
If you enable push notifications in the mobile app, we store a push notification token for your device (via Expo's push service) so we can deliver operational alerts (for example, a sale or a failed delisting). We also collect basic device information needed to run the app.
1.6 Usage and log data
Like most online services, our infrastructure providers collect standard technical logs — IP addresses, browser/device type, pages or endpoints accessed, and timestamps — used for security, debugging, and operating the Service. We do not use third-party advertising trackers.
1.7 Billing information
Subscription payments are processed by Stripe. Stripe collects your payment card details directly; Zardly never receives or stores your card number. We store your Stripe customer and subscription identifiers and your subscription status.
2. Where Information Comes From
We collect information: (a) directly from you and your workspace members; (b) automatically from your use of the Service; (c) from marketplaces you connect (eBay, Shopify); and (d) from our data providers (Scrydex catalog and pricing data matched to your inventory; CardSight recognition results for photos you submit).
3. How We Use Information
We use the information described above to:
- Provide and operate the Service — inventory management, listing sync, sale detection, deal recording, search, and notifications;
- Authenticate you and secure your workspace;
- Process subscription billing and seat management;
- Send operational emails (invitations, sale alerts, sync-failure alerts, billing notices) and push notifications;
- Provide support and respond to your requests;
- Monitor, debug, and improve the Service, including diagnosing failures in marketplace sync;
- Create aggregated and de-identified data as described in Section 5; and
- Comply with law and enforce our Terms of Service.
We do not use your data to train third-party AI models, and we do not sell identifiable personal information.
4. Buyers' and Counterparties' Information
When your marketplace buyers' information passes through the Service (as described in Section 1.3), we process it on your behalf as part of operating your workspace — we do not use it for our own purposes, do not build profiles of buyers, do not contact buyers, and do not include it in any data product. If you record information about an in-person counterparty in a deal note, the same applies. Buyers and counterparties who have questions about their information should contact the vendor they transacted with; if a buyer contacts us directly, we will refer the request to the relevant vendor and cooperate reasonably.
5. Aggregated and De-Identified Data
This section describes a commercial use of data and mirrors Section 7 of our Terms of Service.
Zardly creates aggregated and de-identified data sets from data generated through use of the Service — for example, market-level statistics about which cards are trading, at what prices, in what volumes, and when. Zardly may use and commercialize these data sets for any lawful purpose, including selling market-data products.
Our commitments for any such data we publish, sell, or share externally:
- It will never identify you, your store, or your workspace as the source of any data point;
- It will never include your customers' or counterparties' names, addresses, or other identifying details;
- It will be aggregated across vendors and/or de-identified so that an individual store's activity cannot be singled out or re-identified, and we will not attempt to re-identify de-identified data; and
- We do not sell identifiable personal information about anyone.
6. How Long We Keep Information
- Workspace Data (inventory, deals, photos, listings) is kept while your workspace is active. After a workspace closes, we retain it for a wind-down period (at least 30 days, during which you can request an export) and then delete it in the ordinary course of business.
- Marketplace tokens are kept while the connection is active and deleted or invalidated when you disconnect the marketplace or close the workspace.
- The webhook event log (Section 1.3), including raw order payloads, is retained for operational reliability and audit purposes. We are implementing a scheduled purge of raw payloads after they are no longer needed for de-duplication and retry; identifiers needed for duplicate detection are kept longer.
- Billing records are retained as required for tax and accounting purposes.
- Backups and logs roll off on our infrastructure providers' standard schedules.
We honor eBay's marketplace account-deletion notifications: when eBay tells us an eBay user has requested deletion, we delete the eBay user data we hold as required by the eBay Developers Program.
7. Who We Share Information With
We share information only as described here. We use service providers ("subprocessors") to run the Service; each receives only what it needs for its function:
| Provider | Function | What they process | |---|---|---| | Clerk | Authentication | Email, name, credentials, session data | | Supabase | Database, file storage (hosted in the United States) | All Workspace Data, tokens (encrypted), event logs | | Vercel | Web hosting and compute | Traffic to the web app and API, request logs | | Stripe | Payments and billing | Payment card details (collected directly by Stripe), billing contact, subscription status | | Resend | Email delivery | Recipient email addresses and email content (invites, alerts, billing notices) | | Expo | Mobile push notifications | Device push tokens, notification content | | CardSight AI | Card recognition | Photos you submit for scanning, recognition results | | Scrydex | Card catalog and market pricing | Search queries and catalog identifiers (your inventory data is matched against their catalog; we do not send them your customer information) | | eBay | Marketplace you connect | Listing content, photos, prices, inventory quantities, order data for your account | | Shopify | Marketplace you connect | Listing content, photos, prices, inventory quantities, order data for your store |
We may also disclose information: to comply with law, legal process, or enforceable government requests; to protect the rights, safety, or property of Zardly, our customers, or the public; in connection with a merger, acquisition, financing, or sale of assets (in which case this policy continues to apply to previously collected data); and with your direction or consent.
We do not sell identifiable personal information, and we do not share personal information for cross-context behavioral advertising.
8. Security
We take security seriously and apply safeguards appropriate to a business platform:
- Marketplace access tokens and webhook secrets are encrypted at rest with AES-256-GCM before storage;
- Every database record is scoped to a workspace, enforced by row-level security in the database plus server-side permission checks, so one customer's workspace cannot read another's data;
- All traffic between your devices and the Service uses HTTPS/TLS;
- Payment card data never touches our systems (it goes directly to Stripe);
- Webhook messages from Stripe, eBay, and Shopify are cryptographically verified before processing; and
- Access to production systems is limited and credentialed.
No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
9. Your Choices and Rights
Self-serve today: you can view, edit, and delete inventory records, photos, deals (void), and workspace members directly in the Service. Workspace Owners can disconnect marketplaces and cancel the subscription at any time. You can disable push notifications in your device settings.
By request: to access, export, correct, or delete your account or an entire workspace's data, email us at legal@zardly.ai from the email address on the account. We will verify the request and respond within a reasonable time (and within any timeline required by applicable law). Deleting your account removes your access immediately; deletion of stored data follows the retention schedule in Section 6.
Depending on your state of residence, you may have legal rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain uses. We honor such requests as required by applicable law, and we do not discriminate against you for exercising them. Because Zardly does not sell identifiable personal information or use it for targeted advertising, there is nothing to opt out of on that front.
10. Children
The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
11. United States Only
The Service is offered in and operated from the United States, and data is stored in the United States. If you access the Service from outside the United States, you do so on your own initiative and your information will be processed in the United States.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes — including any change to Section 5 — we will notify workspace Owners by email or in-app notice before the changes take effect, and we will update the version number and effective date above.
13. Contact Us
Questions, requests, or concerns:
[ZARDLY LLC ENTITY NAME] Email: legal@zardly.ai Web: https://zardly.ai