Machete Cards

Legal

Privacy Policy

Last updated

This policy describes how Machete Cards handles personal information — what we collect through this site and the software card shops subscribe to, what we do with it, who else receives it, and how to get it corrected or deleted.

Who this policy is from

Shipyard Labs LLC, doing business as Machete Cards, operates this site, the Machete Cards shop, and the software that card shops subscribe to. Where this policy says "we", it means Shipyard Labs LLC. We are based in Ponte Vedra, Florida, and you can reach us about anything in this policy at sales@machetecards.com.

What we collect

Contact details, collection information, photos you upload, and campaign attribution (such as UTM parameters) submitted through our forms — plus standard technical logs, including IP address and browser information, needed to run the site securely. If you create an account, we also store your name, email address, a hashed password (or your Google account identifier if you sign in with Google), and which workspaces you belong to.

How we use it

To evaluate your collection, respond to your submission, arrange appointments or mail-in logistics, operate and secure the service, and understand how our marketing performs. We send marketing email only to people who have opted into it, and every marketing email includes a way to opt out. Service email — receipts, security notices, billing — is separate and comes with the account.

Photos, and the software that reads them

Seller photos are stored privately, used only for evaluation, and are never published or made publicly accessible. Card photos uploaded for identification are sent to Anthropic's API, which reads the image to name the card and estimate its condition, and are stored in Cloudflare R2. They are sent for that identification and for nothing else — we do not use your photos to train AI models.

If your shop subscribes to our software

A subscribing shop gets a workspace, and we store what running it requires: the shop's members and their roles, its inventory, photos and scan history, its pricing and offer records, its orders and customer contact details, its subscription and usage counters, and access tokens for any service it connects, such as eBay or Stripe. Workspace data is scoped to that shop — other shops on the platform cannot see it. For the shop's own customer data, the shop decides what is collected and why; we process it on the shop's behalf and on its instructions. We access workspace data only to operate, support, secure and bill the service.

Who else receives data

We do not sell personal information, and we do not share it for cross-context behavioral advertising. These are the service providers that receive data in the course of running the product:

  • Stripe — payments, subscription billing and payouts to shops. Receives your email, order amount and the card details you enter on Stripe's own payment page.
  • Anthropic — reading a card photo to identify the card and estimate condition. Receives the card photo and the text of the identification request.
  • Cloudflare R2 — storing uploaded photos. Receives the image files themselves.
  • Resend and ZeptoMail — sending transactional email such as receipts and invitations. Receives the recipient address and the contents of that message.
  • eBay — listing a connected shop's inventory and importing its orders (only if a shop connects it). Receives listing details and order information for that shop's own eBay account.
  • Railway — hosting the application and its database. Receives everything the application stores, as its infrastructure provider.

Cookies and device storage

We set one cookie: the session cookie that keeps you signed in. There are no advertising cookies and no third-party analytics or tracking scripts on this site. Your browser's local storage holds convenience state — a shopping cart, an in-progress scan batch, which onboarding notices you have dismissed — and session storage briefly holds the campaign parameters a link arrived with. All of it stays in your browser except what you submit.

How long we keep it

Seller submissions and their photos are kept while we are evaluating and discussing your collection, and deleted on request at any time. For accounts and workspaces:

  • A closed workspace is kept for 30 days, during which the deletion can be cancelled, then permanently purged.
  • Web sign-in sessions expire after 14 days; mobile app sign-ins can refresh for up to 60 days before requiring a new login.
  • Workspace export bundles are available through an expiring link and are then removed from storage.
  • Completed order, payment and tax-relevant records are kept as long as accounting and legal obligations require, even after a workspace closes.
  • When we honor an erasure request, the log of that request stores only a one-way hash and a masked form of the email — the record proves the erasure happened without re-creating the identifier.

Your rights and choices

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, by writing to sales@machetecards.com. A workspace owner can do this self-service from Settings → Your data: a full workspace export is immediate, a per-customer erasure tool honors a buyer's request, and closing the workspace deletes it after the 30-day grace period, during which the deletion can be cancelled. Depending on where you live, laws such as the California Consumer Privacy Act or the EU and UK GDPR may give you these rights by statute; we honor the requests regardless of where you live, we do not discriminate against you for making one, and if we deny a request we will tell you why. If you bought a card from a shop that runs on our software, that shop controls your order data — send your request to the shop, and we will help it comply.

Children

This site and the software are for adults running or transacting with a card business. They are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us and we will delete it.

Security

Traffic is encrypted in transit. Passwords are stored only as salted hashes. Access tokens for connected services are encrypted at rest with keys held outside the database. Workspace access is role-based, and erasure logs store hashes rather than the erased identifiers. We do not yet hold a formal certification such as SOC 2. No system is perfectly secure — if a breach affects your personal information, we will notify you as the law requires.

Changes to this policy

When this policy changes, the date at the top changes with it, and the version published on this page is the one in effect. If a change meaningfully reduces your rights under it, we will notify account holders by email before it takes effect.

Contact

Write to sales@machetecards.com, or use the contact link at the foot of this page. Privacy requests are handled by a person.

Questions about this page?

Reach us through the contact page, or see the FAQ for how safety, authenticity, privacy, and payment work in practice.