Cardstead
ProductSolutionsPricingResources
LoginBook a walkthrough
Privacy PolicyTerms of ServiceAcceptable UseSecurity DisclosureData Requests
Privacy

Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains how Cardstead collects, uses, discloses, retains, and protects information when people visit the public website, join the waitlist, receive support, or use the Cardstead operations platform.

Cardstead is a business operations service for card shops and hobby retailers. Store owners and authorized employees use the service to manage shop records such as customers, trade-ins, store credit, reminders, calendar items, money activity, employee access, reports, billing, and audit history.

Scope and roles

When a store uses Cardstead, the store is responsible for deciding what customer, employee, financial, trade-in, and operational information it enters into the service. For that tenant data, Cardstead acts as a service provider or processor for the store except where Cardstead uses information for its own account administration, security, billing, legal compliance, support, and service improvement purposes.

This policy does not replace a store's own privacy obligations to its customers, employees, vendors, or other people whose information the store enters into Cardstead.

Information we collect

  • Website and waitlist information, including email address, optional store name, website or social link, number of locations, current tools, operational pain points, setup or walkthrough request status, signup source, referrer, IP address, user agent, signup count, and timestamps.
  • Account information, including name, email address, authentication credentials, password reset and invite tokens, tenant membership, role, permissions, assigned locations, profile state, and login/session information.
  • Tenant and store information, including store name, legal or display name, location names, addresses, timezone, approval thresholds, billing status, onboarding state, support status, and product settings.
  • Store customer information entered by a tenant, including customer names, email addresses, phone numbers, favorite categories, notes, store credit balances, trade-in history, reminders, and related operational records.
  • Operational records, including trade-ins, buy records, store credit ledger entries, calendar events, reminders, money movement, register and safe activity, business finance entries, integrations, reports, exports, and audit history.
  • Billing information, including billing email, plan, subscription status, invoice and payment event metadata, and billing history. Payment card details are handled by a payment processor and are not stored by Cardstead.
  • Support information, including messages, issue reports, FreeScout conversation identifiers, screenshots or attachments a user chooses to send, request IDs, troubleshooting notes, and support actions.
  • Security and technical information, including IP address, request IDs, normalized page routes, product interaction events, timestamps, browser and device information, rate-limit events, server logs, error context, and authentication/session events.

Information we do not intend to collect

Cardstead is not designed for social security numbers, driver's license numbers, full payment card numbers, bank account credentials, protected health information, biometric identifiers, children's data, or other highly sensitive personal information. Users must not enter that information into customer notes, trade notes, support messages, exports, or other free-text fields unless Cardstead has expressly approved the use case in writing.

How we use information

  • Provide, secure, operate, maintain, and improve the service.
  • Create and manage tenants, users, roles, locations, sessions, billing status, support links, and onboarding.
  • Process waitlist requests, invite stores, respond to support requests, and communicate about service access.
  • Operate customer, trade-in, store credit, money, calendar, reminder, reporting, employee, billing, settings, audit, and support workflows.
  • Generate reports, exports, audit records, operational alerts, backups, metrics, logs, and troubleshooting records.
  • Process subscriptions, invoices, billing events, payment failures, and billing notices through payment processing and transactional email providers.
  • Prevent fraud, abuse, unauthorized access, tenant data leakage, spam, service disruption, and other security incidents.
  • Comply with legal obligations, enforce agreements, resolve disputes, and protect the rights, safety, and property of Cardstead, customers, users, and others.

Cookies and similar technologies

Cardstead uses essential cookies and local browser storage for authentication, session continuity, location selection, account security, and application behavior. These technologies are required for the service to work.

Cardstead uses Google Analytics to understand aggregate website and product usage, page navigation, and waitlist conversion. Google may receive browser and device information, IP-derived general location, normalized page routes, and limited interaction events and may use cookies or similar identifiers to provide the analytics service.

Cardstead does not send Google Analytics customer names, customer record identifiers, tenant identifiers, user identifiers, email addresses, form contents, authentication tokens, or URL query strings. Dynamic record routes are normalized before collection, and Google advertising signals and ad personalization are disabled. Cardstead does not use third-party advertising cookies or cross-site behavioral advertising.

How we disclose information

  • To service providers that help us host, operate, secure, monitor, support, email, bill, and maintain the service.
  • To payment processing providers for subscription checkout, billing portal, invoices, tax calculation, payment method handling, payment status, and billing event processing.
  • To Resend or another configured transactional email provider to send password reset, employee invite, billing, alert, and operational emails.
  • To FreeScout or another configured support system when waitlist leads or support requests are synced for customer support.
  • To Google Analytics for aggregate website and product usage measurement configured without advertising signals or raw tenant, user, or customer identifiers.
  • To authorized users within a tenant according to that tenant's roles, permissions, and location access settings.
  • To comply with law, subpoenas, court orders, legal process, regulatory requests, or enforceable government requests.
  • To protect the service, investigate abuse, prevent harm, enforce terms, collect amounts owed, or respond to security incidents.
  • In connection with a merger, financing, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and continuity protections.

Subprocessors and infrastructure

Cardstead uses third-party infrastructure and service providers to operate the service. Current categories include hosting, data storage, backups, billing, email, support, domain, security, and deployment services.

We require service providers to process information only for authorized business purposes and to maintain appropriate security controls for the nature of the information they handle.

Security

We use administrative, technical, and organizational safeguards intended to protect information against unauthorized access, loss, misuse, alteration, and disclosure. Safeguards include tenant scoping, authentication, role-based permissions, audit logs for sensitive actions, rate limits, security headers, production backups, deployment controls, monitoring, and restricted operational access.

No internet service can guarantee absolute security. Users are responsible for protecting their credentials, assigning appropriate roles, limiting access to authorized employees, and promptly reporting suspected unauthorized access.

Retention

We retain information for as long as needed to provide the service, maintain accurate operational and billing records, comply with legal obligations, resolve disputes, enforce agreements, preserve security, and support backups and disaster recovery.

Certain records, such as audit logs, store credit ledger entries, money records, report export history, billing records, and security logs, may be retained for longer periods because they protect operational integrity, accounting accuracy, fraud prevention, legal compliance, and customer accountability. Generated export files may expire before the audit record of the export request.

Deletion, access, and correction

Store owners may request tenant data exports, account correction, account closure, or deletion by contacting support. Some information may be retained where required or permitted for billing, tax, accounting, audit, security, backup, dispute, legal, or legitimate operational reasons.

People whose information was entered by a store should contact that store first. Because the store controls its tenant data, Cardstead may direct requests about a store's customer or employee records back to the store unless applicable law requires a direct response from Cardstead.

Regional privacy rights

Depending on where a person lives, they may have rights to request access, deletion, correction, portability, limitation, objection, or information about certain disclosures. Requests can be sent to support@cardstead.com. We may need to verify identity and authority before acting on a request.

Cardstead does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are commonly used in U.S. state privacy laws. If that changes, we will update this policy and provide any required choices before doing so.

International use

Cardstead is operated from the United States. If information is accessed from outside the United States, it may be processed in the United States and other locations where our service providers operate. Users are responsible for ensuring their use of the service complies with laws that apply to their store and their data subjects.

Children

The service is intended for business use by adults and authorized employees of stores. It is not directed to children under 13, and users must not knowingly submit children's personal information except where legally permitted and necessary for the store's own lawful business records.

Changes

We may update this policy as the service, law, vendors, or business practices change. Material changes will be posted on this page and, when appropriate, communicated through the service or email.

Contact

Privacy, data, account, and security reports can be sent to support@cardstead.com.

Cardstead

Daily operations software for card shops.

support@cardstead.com
ProductProduct overviewSolutionsPricingResourcesAboutCustomer login
SupportContact usSecurity and dataBook a walkthroughReport a security issue
SocialFacebookDiscord
LegalPrivacyTermsAcceptable UseData Requests
© 2026 Cardstead. All rights reserved.Built for the work behind the counter.