Back to SlabIQ

Privacy Policy

What information SlabIQ collects, why it collects it, who it goes to, and what control you have over it.

Effective Date:
August 25, 2026
Last Updated:
August 25, 2026
Version:
2026-08-25

1. Overview

This policy explains how SlabIQ handles information when you use the Service. It is written to describe what the platform actually does, rather than to cover every hypothetical.

Three things are worth stating up front:

  • Card images you upload are sent to third-party AI and OCR providers when you use identification features. This is how card identification works. Section 6 explains it in detail.
  • SlabIQ never receives your full payment card number. Payment details are handled by the payment processor.
  • SlabIQ does not use third-party advertising or analytics trackers. There is no Google Analytics, no advertising pixel, and no cross-site tracking in the Service.

This policy covers the SlabIQ application and website. It does not cover third-party platforms you connect, which have their own privacy policies.

2. Information You Provide

Account information

  • Email address, and an optional secondary email for notifications
  • Password, stored only as a cryptographic hash — never in readable form
  • Optional profile details: first and last name, display name, avatar, timezone
  • Account role, team membership, and team invitations you send or accept
  • Notification, display, and workflow preferences

Content you upload and create

  • Card images, including front and back scans and photos, and images uploaded from a phone
  • Branding assets such as logos, watermarks, and banner images
  • Inventory, batch, collection, binder, and storage-location records
  • Listing content: titles, descriptions, item specifics, prices, quantities
  • Listing templates and saved presets
  • Purchase, cost, and profitability records you enter
  • Uploaded documents and spreadsheets, such as checklists and import files
  • Notes and other free-text fields
  • Card images and information you submit through catalog contribution features

Subscription information

  • Your plan, subscription status, billing period, and renewal or cancellation state
  • Scan allowance, scans used, add-on credits purchased, and usage history
  • Payment processor customer and subscription identifiers
  • Records of billing events received from the payment processor

SlabIQ does not receive or store full payment card numbers, CVV codes, or bank account numbers. Those are entered with and held by the payment processor. SlabIQ stores identifiers that let it look up your subscription, not your payment instrument.

Support communications

If you contact support, SlabIQ receives your message and any information you include in it.

3. Information Collected Automatically

Operating the Service generates some information automatically:

  • Session data — a session identifier, creation and expiry times, and last-activity time, used to keep you signed in and to enforce session timeouts
  • IP address and browser user-agent — recorded in activity and security logs, used to secure accounts and investigate suspicious activity
  • Activity logs — records of significant actions in the Service, with timestamps, used for audit history and troubleshooting
  • Feature and usage records — such as scans performed, jobs run, and integration calls made, used to enforce plan limits and to operate features
  • Error and diagnostic logs — technical records generated when something fails, used to fix it

This information is collected by SlabIQ itself and is not shared with advertising or analytics companies.

4. Information From Connected Marketplaces

When you connect a third-party marketplace or commerce platform, SlabIQ receives information from it using the permissions you grant. Platforms you can currently connect include eBay, Shopify, TikTok Shop, TCGplayer (via the SlabIQ Marketplace Bridge browser extension), Discord.

Depending on the platform and the permissions granted, this may include:

  • Your seller account identifier, username, and verified identity on that platform
  • Marketplace, store, and account configuration details
  • Authorization credentials — access and refresh tokens, their scopes and expiry
  • Listings, inventory, item details, images, and item specifics
  • Orders, transactions, and sales history
  • Fees, payouts, and financial and earnings information
  • Business policies — shipping, payment, and return policies
  • Inventory locations, store categories, and category metadata
  • Traffic, impression, and performance analytics for your listings

Some of this is stored so features work when the platform is unreachable — your listings, orders, and financial records, for example, persist in SlabIQ. Other information is cached temporarily to reduce API calls and refreshed periodically. Authorization tokens are stored so that SlabIQ can act on your behalf until you disconnect or the authorization expires.

Disconnecting a platform deactivates the connection and stops future synchronization. You can also revoke SlabIQ’s access from the platform’s own account settings. Records already imported into SlabIQ — such as past orders and profitability history — remain unless you delete them or request deletion.

5. Your Buyers' Information

When SlabIQ imports your orders from a connected marketplace, those orders contain information about the people who bought from you:

  • Buyer username and name
  • Shipping address
  • Order, tracking, and shipping details
  • Transaction amounts and fees

SlabIQ stores this so you can fulfill orders, print labels, run pick lists, and track your finances. SlabIQ handles it on your behalf and for no independent purpose — it is not used to market to your buyers, not sold, and not shared with other users.

You are responsible for how you handle your buyers’ information. You are the merchant in those transactions. If a privacy law applies to your business, your obligations to your buyers are yours, and SlabIQ acts as your service provider in processing that information. If a buyer contacts SlabIQ directly about their information, SlabIQ will generally direct them to you as the seller.

6. AI and Automated Processing

Card identification is the core of the Service, and it works by processing your images. This section explains exactly what that involves.

What gets processed

When you scan or upload a card, SlabIQ may process the card image, text extracted from it, card attributes and metadata, catalog data, and — for listing-generation features — listing information such as titles, descriptions, and item details.

Why

  • To identify the card and match it to a catalog record
  • To extract attributes such as player, set, year, card number, parallel, and condition
  • To read text from card images and uploaded documents
  • To generate suggested listing titles, descriptions, and item specifics
  • To suggest marketplace categories
  • To detect duplicate records
  • To produce pricing and marketplace-health suggestions
  • To diagnose problems when identification fails

Processing that stays inside SlabIQ

Some of this happens without any third-party transfer:

  • Tesseract OCRRuns inside SlabIQ's own servers; images are not sent anywhere.
  • Perceptual hashing and image matchingSlabIQ's own algorithms compare a card image against SlabIQ's catalog. No third party is involved.
  • Ollama (optional self-hosted model)When an administrator selects this option, the model runs on infrastructure SlabIQ controls rather than a third-party API.

Third-party AI and OCR providers

Other processing is performed by third-party providers, which means your card images and related card data are transmitted to them. Which provider handles a given request depends on how the Service is configured at the time. All providers reachable by the Service are listed here:

  • OpenAICard identification from images, and generating listing titles and descriptions. Receives: card images, card text and attributes, listing details.
  • Google (Gemini)Card identification and attribute extraction from images. Receives: card images, card text and attributes.
  • Anthropic (Claude)Card identification and marketplace-health recommendations. Receives: card images, card text and attributes, listing details.
  • CardSightSpecialized trading-card identification. Receives: card images.
  • MistralOptical character recognition on card and checklist images. Receives: card images, document images.
  • OCR.spaceOptical character recognition on card images. Receives: card images.
  • LlamaIndex (LlamaParse)Parsing uploaded checklist and catalog documents. Receives: document uploads.

These providers act as service providers to SlabIQ, processing this information to return a result. SlabIQ sends the image and card context needed for identification; it does not send your password, payment information, or marketplace authorization credentials to them.

Retention and model training by these providers

Each provider applies its own retention and data-use terms to information submitted through its API. Those terms vary between providers and between account tiers, and they change over time.

SlabIQ is not currently in a position to guarantee that content sent to these providers is never retained or never used to improve their models, and this policy will not claim otherwise. If that assurance matters to you, review the terms of the providers listed above, and contact [email protected] before uploading content you consider sensitive.

Pending: provider data-use verification

This wording is deliberately conservative. No zero-retention or no-training configuration exists in the application, and the provider account tiers and contractual terms have not been verified. Rather than making an unverifiable promise, the policy describes the transfer honestly.

Once ownership confirms each provider’s account tier, data-processing terms, and any zero-retention settings, set AI_NO_TRAINING_VERIFIED in src/lib/legal/config.ts and this section will state the confirmed position instead. See docs/legal/OPEN-DECISIONS.md.

Automated results are not decisions about you

SlabIQ’s automated processing analyzes cards and listings. It is not used to make legal or similarly significant decisions about you as a person — no automated credit scoring, employment screening, or profiling of that kind. Automated output is assistive and, as the Terms of Service explain, can be incorrect and should be reviewed.

A note on how SlabIQ is built

The Terms of Service disclose that AI-assisted development tools were used to help write and test SlabIQ’s source code. That is a statement about software development, and is separate from this section. The processing of your information by AI is what this section describes.

7. How Information Is Used

SlabIQ uses information to:

  • operate, maintain, and provide the Service;
  • create and authenticate your account, and keep sessions secure;
  • process subscriptions, track scan usage, and enforce plan limits;
  • identify cards and match them to catalog records;
  • manage inventory, batches, collections, and storage;
  • synchronize with connected marketplaces and publish listings you create;
  • generate listing content, pricing suggestions, and recommendations;
  • display market and pricing information;
  • track orders, sales, fees, and profitability;
  • send transactional email and, where you enable it, notifications;
  • provide customer support and respond to your requests;
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • debug problems and improve reliability and performance;
  • understand aggregate feature usage in order to improve the Service;
  • comply with legal obligations and enforce the Terms of Service.

SlabIQ does not use your information for third-party advertising, and does not build advertising profiles.

8. How Information Is Shared

SlabIQ does not sell your personal information for money, and does not share it for cross-context behavioral advertising. There is no advertising or tracking infrastructure in the Service.

Information is shared in these circumstances:

Service providers

Providers that process information so SlabIQ can operate, under terms limiting them to that purpose:

  • StripeSubscription payments and billing.
  • Email delivery (SMTP provider configured by SlabIQ)Sending account, verification, sales and notification emails.
  • Google Firebase Cloud MessagingDelivering browser/device push notifications, if you enable them (only if you enable it).
  • Object storage and hosting infrastructureStoring uploaded images and running the service.
  • AI and OCR providers — as described in Section 6.

Platforms you connect

When you connect a marketplace and publish or synchronize through it, SlabIQ sends that platform the information required — listing content, images, inventory quantities, prices, and fulfillment details. This happens because you asked for it, and is governed by that platform’s own privacy policy.

Market data sources

SlabIQ retrieves pricing and catalog data from sources including eBay (sold and active listing data), TCGCSV / TCGplayer, JustTCG, PriceCharting, Pokemon TCG API, Scryfall, YGOPRODeck and similar open card databases, Trading Card Database (TCDB). These are queried about cards and products — not about you — and personal information is not sent to them.

Within your team

If you are part of a team, information in the team’s workspace is visible to other members according to their role and permissions.

Catalog contributions

Card images and information you submit through contribution or bounty features may be added to the shared card catalog and shown to other users, including on publicly accessible card pages. Your ordinary private scans and inventory are not published this way.

Legal and safety

Information may be disclosed where required by law, subpoena, or legal process; to enforce the Terms of Service; or to protect the rights, safety, or property of SlabIQ, its users, or the public.

Business transfers

If SlabIQ is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. You will be notified of any change in who controls your information.

9. Data Retention

SlabIQ retains information for as long as your account is active and as long as needed to provide the Service. In practice:

  • Account and profile information — kept while your account exists.
  • Inventory, listings, orders, and financial records — kept while your account exists, because they are your business records and their value comes from historical continuity. You can delete individual records at any time.
  • Uploaded images — kept while the item they belong to exists. Deleting a card, batch, or listing removes its associated images. Derived versions — thumbnails, resized and marketplace-prepared variants — are removed along with the original.
  • Sessions — expire automatically and are periodically purged.
  • Activity and security logs — retained for audit and abuse investigation. These may outlive the records they describe, because that is what makes an audit trail useful.
  • Marketplace authorization tokens — kept until you disconnect the platform, the authorization expires, or you revoke it at the platform.
  • Billing records — retained as required for financial, tax, and accounting obligations, typically for several years, even after an account closes. The payment processor retains its own records under its own policy.
  • Backups — information may persist in routine backups for a limited period after deletion from the live system, and is overwritten on the ordinary backup cycle.
  • Catalog contributions — card data contributed to the shared catalog may be retained after your account closes, because other users rely on the catalog. It can be disassociated from your account on request.

Why there are no fixed day counts here

This section describes retention by category rather than promising specific windows like “deleted after 30 days.” SlabIQ does not currently run automated time-based deletion for most categories, and stating a schedule the system does not enforce would be inaccurate. Retention windows are an open item — see [email protected] for specific questions.

10. Security

SlabIQ maintains administrative, technical, and organizational measures intended to protect information, including:

  • passwords stored using a modern password-hashing algorithm, never in readable form;
  • encrypted connections for traffic between your browser and the Service;
  • authenticated, expiring sessions with idle and absolute timeouts, and the ability to revoke sessions;
  • role- and permission-based access controls, including for team accounts;
  • scoped marketplace authorization, with verification of the identity behind a connection;
  • audit logging of security-relevant events;
  • restricted internal access to production systems.

No service can promise complete security, and SlabIQ does not claim to be impenetrable. Transmission and storage of information always carry some risk. You play a part too: use a strong, unique password, do not share credentials, and tell SlabIQ promptly at [email protected] if you suspect unauthorized access.

11. Your Privacy Rights

Privacy laws vary, and which statutory rights apply depends on where you live and on thresholds that may or may not currently apply to SlabIQ. Rather than claim that every regime applies, SlabIQ offers the following to all users regardless of location:

  • Access — ask what information SlabIQ holds about you.
  • Correction — correct inaccurate information. Most account and profile details can be edited directly in your settings.
  • Deletion — request deletion of your account and associated information. See Section 12.
  • Portability — request a copy of information you provided, in a portable format. SlabIQ also offers export tools for inventory and reporting data within the application.
  • Withdraw consent — disconnect a marketplace, turn off notifications, or opt out of non-essential email at any time from your settings or via the unsubscribe link.
  • Object or restrict — object to particular processing, or ask that it be restricted, and SlabIQ will consider the request in good faith.
  • Appeal — if a request is refused, ask for that decision to be reviewed.

To make a request, email [email protected] from the address on your account, or contact support if you cannot. SlabIQ will verify your identity before acting, and aims to respond within 30 days. There is no charge for reasonable requests, and you will not be treated differently for making one.

If you are in a jurisdiction with a supervisory authority for data protection, you may also lodge a complaint with it.

Requests about information SlabIQ processes on behalf of another user — for example, if you were a buyer from a SlabIQ seller — should generally go to that seller, who controls that information. SlabIQ will assist them in responding.

12. Account and Data Deletion

What you can do yourself, today

  • Delete individual cards, batches, listings, inventory items, and their images
  • Delete uploaded branding assets and templates
  • Disconnect any connected marketplace from your integration settings
  • Revoke SlabIQ’s access directly at the marketplace, from that platform’s own account settings
  • Turn off notification categories and unsubscribe from non-essential email
  • Edit or clear most profile information

Account deletion

To delete your entire account, email [email protected] from the address on your account. SlabIQ will verify the request and delete your account and associated records, subject to the retention exceptions in Section 9 — principally billing records kept for tax and accounting purposes, backups on their ordinary cycle, and catalog contributions others rely on.

Cancel any active subscription first, and export anything you want to keep — deletion is not reversible.

Known gap: deletion is request-based, not self-serve

SlabIQ does not yet provide a “delete my account” button in settings. Deletion currently runs through the email request above and is performed by an administrator. This policy states that plainly rather than describing a self-serve control that does not exist.

Building self-serve deletion, and a full downloadable data export, are tracked product gaps — see docs/legal/OPEN-DECISIONS.md.

If you delete your marketplace account

Where a connected marketplace notifies SlabIQ that a user has deleted their account with that marketplace, SlabIQ processes that notification and removes the associated marketplace data it holds.

13. Cookies and Browser Storage

SlabIQ uses only the cookies and browser storage needed to make the Service work. There are no advertising cookies, no third-party analytics cookies, and no cross-site tracking.

  • Session cookie — set when you sign in, to keep you signed in. It is HTTP-only and, in production, transmitted only over secure connections. Strictly necessary; the Service cannot function without it.
  • Browser storagelocalStorage and sessionStorage hold interface preferences and working state, such as your theme, saved view and filter selections, and in-progress workflow state. This stays in your browser.
  • Push notification subscription — created only if you explicitly enable browser or device push notifications, and removable by turning them off.

Because SlabIQ does not set advertising or analytics cookies, there is no cookie consent banner. You can clear cookies and storage in your browser at any time; doing so signs you out and resets interface preferences.

14. Children

SlabIQ is a commercial tool for trading-card sellers and is not directed to children. It is not intended for anyone under 18, and SlabIQ does not knowingly collect information from children.

If you believe a child has provided information to SlabIQ, contact [email protected] and the account and its information will be removed.

15. International Users

SlabIQ is operated from the United States, and information is processed and stored there and in other countries where its service providers operate. Data-protection laws in those countries may differ from those where you live.

By using the Service, you understand that your information will be processed in the United States. Where required, SlabIQ relies on appropriate safeguards for international transfers. If you have questions about transfers relevant to your jurisdiction, contact [email protected].

17. Changes to This Policy

This policy will be updated as the Service changes and as new providers or data flows are added. When it is, the Effective Date, Last Updated date, and Version at the top of this document change.

For material changes — a new category of information collected, a new purpose, a new type of sharing, or a reduction in your rights — SlabIQ will give notice at least 30 days in advance, by email to the address on your account or by prominent notice in the Service.

Clarifications and corrections that do not change how information is handled are reflected in the Last Updated date without advance notice.

18. Contact

For privacy questions or to make a privacy request:

When making a privacy request, email from the address on your account where possible and describe what you are asking for, so it can be handled without unnecessary back-and-forth.

See also the Terms of Service, which govern use of the Service.