Privacy Policy
Effective date: August 26, 2026
TCGVendr (“the app”, “we”) is a discovery platform for trading-card shows: vendors publish the inventory they’re bringing to upcoming shows, and attendees browse shows, tables, and cards. This policy explains what information the app collects, how it’s used, and the choices you have. The short version: we collect only what the app needs to work, we don’t run ads, we don’t sell your data, and we don’t track you across other apps or websites.
Accounts and sign-in
You can use the app before you sign up for anything. Every install gets an anonymous account on our servers, and the cards you add, the shows you save and the settings you change are stored under it. Publishing a table, RSVPing, marking “Interested”, messaging and reporting all require signing up first.
There are three ways to sign up or sign in:
- Email. You give us an email address and we send you a one-time code. There is no password.
- Sign in with Apple. Apple gives us the email address on your Apple ID, or the private relay address if you choose to hide it, plus your name the first time you authorize the app.
- Sign in with Google. Google gives us the email address and name on the Google account you pick.
Signing up upgrades the anonymous account you are already using, so it keeps the same account and the same cards. Signing in to an account you already have is different: it switches you to that account, and the anonymous account you were using is deleted along with anything you added to it, because you can only be in one account at a time. The app says which of the two you are doing.
Information you provide
- Account details. The email address from whichever sign-in method you used, a display name, and an optional profile photo.
- Content you create. Inventory entries (cards, conditions, grades, prices you set, what you paid, and any card photos you add), published show tables, sales you record, show submissions, RSVPs, “Interested” marks, follows and saved items, chat messages, and any reports you file about other users or their content.
- Card scans. When you scan a card the photo leaves your device: it goes through our servers to Cardsight, which identifies the card and sends back a catalog match. Cardsight is not given your account, and we do not keep the photo or attach it to your profile.
- Subscription details. If you buy TCGVendr Pro, Apple processes the payment and tells RevenueCat whether your subscription is active. We see the subscription status tied to your account. We never see your card number or billing address.
Information collected automatically
The app has no advertising or analytics SDKs, no advertising identifier, and no access to your location. Each session is tied to an account identifier. If you turn on notifications we store a push token for your device so we can deliver them. Supabase, which hosts our database and servers, keeps standard operational logs such as IP addresses and request timestamps to run and secure the service.
We use Sentry for crash and error reporting. It receives the device model, OS version, app version, and stack traces so we can find bugs. It is configured not to attach user identifiers, email addresses are stripped from error text before it leaves the device, and message bodies are dropped outright.
What other users can see
TCGVendr is a discovery app, and some information is visible to others by design:
- Your profile is public inside the app: display name, profile photo, Pro badge if you have one, and the tables you have published.
- Your collection is browsable by anyone using the app, including people who have not signed up. They see card names, images, set, condition or grade, quantity, and an asking price if you set one. They never see what you paid, your purchase history, your recorded sales, or your profit. The app tells you this the first time you add a card.
- Any card can be hidden from your collection with its “hidden” toggle. That is the only opt-out.
- Publishing a table makes that table and the cards on it public, including the prices you put on them.
- RSVP’ing “I’m going” to a show puts you on that show’s public list of people attending.
- Marking “Interested” on someone’s card tells that person. If they mark one of yours, both sides see a Match.
- Messages go to the person you sent them to. We can read a message if someone reports it for moderation.
Blocking someone hides you from each other. They can no longer message you, and you disappear from each other’s collections, Matches and inbox.
How we use information
- To run the service: showing shows and tables, pricing cards, matching interest, delivering messages.
- To keep the app safe: enforcing our terms, reviewing reported content, honoring blocks, and limiting spam.
- To send account email, which means sign-in codes and nothing else. We do not send marketing email.
- To send the notifications you turned on.
Notifications
Notifications are off until you allow them. There are three kinds, and you can turn each one off in Settings → Notifications:
- New messages, when someone messages you.
- Card interest, when someone marks one of your cards.
- Daily market update, one note a day with what your collection is worth, how much it moved and which of your cards moved most. It is computed from card prices and nothing else.
To turn notifications off entirely, use iOS Settings. We store one push token per device to deliver them, and it is deleted with your account.
Service providers
We use a small number of service providers to operate the app. Each one gets only what its job requires and processes it on our behalf:
- Supabase: hosts our database, authentication, file storage, and servers. It holds the data described above.
- Apple: app distribution, Sign in with Apple, and payment for Pro subscriptions.
- Google: Sign in with Google, if you use it.
- RevenueCat: tracks whether your Pro subscription is active, keyed to your account identifier. It receives the receipt from Apple, not your payment details.
- Scrydex: card catalog and market prices. Queries go through our servers, so Scrydex is not given your account or profile.
- Cardsight: card recognition. When you scan a card the photo is relayed through our servers to Cardsight to identify it. Cardsight is not given your account or profile.
- Sentry: crash and error reporting, as described above.
- Expo: delivers push notifications to your device through Apple’s push service.
- Brevo: sends the email carrying your sign-in code. It also sends us an internal notification when someone submits a show, and that notification includes the submitter’s email address.
We do not sell personal information to anyone, and we do not share it with third parties for their own marketing.
Data retention and deletion
Your data is kept while your account exists. You can delete it at any time in Settings → Account → Delete account. Deletion is immediate and permanent. It removes your profile, your inventory and purchase history, your recorded sales, your published tables, your interests, RSVPs, follows and saved items, your conversations and messages, your push tokens and notification settings, your profile photo and any card photos you uploaded, and your RevenueCat subscriber record.
Some things survive on purpose. Shows you submitted stay, because other users rely on them, with your identity removed. Copies of messages that were reported for moderation are kept while we look into the report. Backups expire on a rolling schedule.
Deleting your TCGVendr account does not cancel a Pro subscription, because Apple bills that, not us. Cancel it in iOS Settings → your name → Subscriptions. If you signed in with Apple, deleting your account does not yet revoke the app’s Apple sign-in token. You can remove it yourself in iOS Settings → your name → Sign in with Apple.
Scan photos are only relayed for recognition, so we hold none to delete.
Children
TCGVendr is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us and we will delete it.
Security
Data is encrypted in transit. Sign-in uses one-time codes, Apple or Google, so there is no password to steal. Session tokens are stored in the device keychain. Access controls run on our servers, so an account can only read what the visibility rules above allow.
Changes
If this policy changes materially, we’ll update this page and the effective date above. Continued use of the app after a change means you accept the updated policy.
Contact
Questions or requests (including data deletion): support@tcgvendr.com