Privacy
1. What we collect
- Your account: your email address. If you sign in with Google or Apple, the email and name they share with us.
- Your collection: the cards you add, and what you choose to record about them (condition, grade, serial number, what you paid, your own value, notes, sales), your wishlist, and your settings (display name, currency, market, theme).
- Your photos: card photos you upload or scan.
- Reports you send us about missing or wrong cards.
- Technical data: the cookies that keep you signed in and remember your theme, and the connection data our hosting and anti-bot providers need to serve pages and block abuse (IP address, browser).
We don't use advertising or analytics cookies, and we don't track you across other sites.
2. Why we use it
- To run the service you signed up for (your account, collection, scans, values, exports).
- To keep it safe: anti-bot checks, limits on sign-in emails and scans, fixing errors.
- To price cards for everyone: what collectors paid and sold for is combined into anonymous prices, shown only when three collectors or more have reported one. Nobody can see your own prices or sales.
- To show catalogue pictures, only if you opt in: with “Share my card photos” on in your settings, the front photo of a card may become that version's picture for everyone, after review, without your name. Back photos are never shared.
In GDPR terms: running the service is the performance of our contract with you; security and anonymous prices are our legitimate interest; photo sharing relies on your consent, which you can withdraw in your settings.
3. Scanning
When you scan a card, its photos are sent to a cloud artificial-intelligence service located in Frankfurt (European Union), which reads the text printed on the card. It acts as our processor, under contract, and doesn't use the photos for anything else. Your photos are stored in Cloudflare R2 (European Union), in a private bucket: only you can see them, through short-lived links.
4. Who helps us run it
- Supabase — database and sign-in (United States).
- Netlify — hosting of the site (United States).
- Cloudflare — photo storage (European Union), anti-bot check (Turnstile) and DNS.
- A cloud AI service — reading scanned cards (Frankfurt, European Union).
- Brevo — sending sign-in emails (European Union).
- Google, Apple — only if you choose to sign in with them.
- eBay — listings shown on card pages come from eBay; we send eBay the card being looked at, never your identity. When you follow an eBay link, eBay's own privacy policy applies, and eBay may tell us a purchase happened through our link (see how we make money), without telling us who you are.
Where data leaves the European Union (Supabase, Netlify), it is covered by the European Commission's standard contractual clauses in these providers' data processing agreements. The full list of our processors is available on request at contact@iony-systems.com.
5. How long we keep it
Your data stays as long as your account exists. When you delete your account, your collection, photos, scans, wishlist, sales and reports are deleted immediately. Catalogue pictures you chose to share stay, without your name. Our providers may keep technical logs for a short time for security.
6. Your rights
- Export your whole collection at any time, from your collection or settings.
- Delete your account and everything in it from settings (Danger zone).
- Access, correct, object or ask a question about your data: write to contact@iony-systems.com.
- Complain to your data protection authority (in France, the CNIL).
7. Children
Smeshr Cards isn't meant for children under 16, and we don't knowingly collect their data. If you think a child has an account, tell us at contact@iony-systems.com.
8. Changes and contact
If this policy changes in a way that matters, we'll say so in the app before it applies. Questions: contact@iony-systems.com.