Privacy Notice
How CardDirector Handles Your Information.
This notice explains what stays on your computer, what may pass through CardDirector services, what third parties process, and what limited records may be retained.
Effective September 4, 2026
1. Scope
This Privacy Notice applies to carddirector.com, Early Access requests, CardDirector desktop services, connected-service features, support communications, and the operational systems used to provide them.
Third-party providers have their own privacy notices and terms. This notice does not replace those provider policies.
2. Website and Early Access Information
When you submit the Early Access form, CardDirector receives the information you provide, such as your name, email address, how you use sports cards, Windows platform, primary workflow need, optional message, submission time, and basic browser user-agent information. The request, its review status, invitation status, and related administrative history are stored in CardDirector’s Cloudflare D1 website database so authorized CardDirector personnel can review and manage the program.
This information is used to review Early Access fit, communicate about the request and invitation process, provide support, prevent abuse, and plan the release. Submitting the free waitlist form does not enroll you in promotional marketing.
Cloudflare may process limited network, browser, request, security, and challenge information when delivering and protecting the website. CardDirector uses Cloudflare Turnstile and transformed rate-limit identifiers to reduce automated abuse. Rate-limit identifiers are salted hashes and are not added to the ordinary Early Access applicant record.
CardDirector uses Cloudflare Web Analytics to understand aggregate website traffic and page performance. Cloudflare provides this through a JavaScript beacon using browser Performance APIs and states that Cloudflare Web Analytics does not collect or use visitors’ personal data. CardDirector does not use this tool for targeted advertising, and the current public pages do not use advertising cookies. Turnstile may use data necessary for its security function. Protected invitation and enrollment routes may use temporary Secure, HttpOnly, SameSite cookies for session and request-integrity purposes.
3. Desktop Records
Core card, workflow, pricing-assumption, notes, follow-up, submission, selling, retained-card, and imported working records are designed to be stored in the local CardDirector database on your Windows computer.
Local storage does not mean every feature is offline. Connected features transmit the information needed to complete the requested service. Users remain responsible for maintaining appropriate backups of local records.
4. Connected Services
Connected services are optional. When you use one, CardDirector may process account identifiers, authorization tokens, search requests, card or listing identifiers, provider responses, order references, shipment information, and technical request details needed to provide, secure, troubleshoot, and limit the connection.
For connected market-data features, CardDirector may process search criteria, card identifiers, pricing or grading context, and the technical request details needed to complete a lookup. Service credentials used by CardDirector are protected and are not exposed as ordinary desktop records.
Application and provider credentials are stored in protected service infrastructure or secure local storage as appropriate. They should not be exposed in public pages or ordinary desktop records.
5. eBay Listing, Order, and Shipment Information
Listing research may send search terms, listing identifiers, buyer location information when supplied for shipping estimates, and related request information through CardDirector’s protected service to eBay.
When a user authorizes their own eBay account, CardDirector may receive account references, purchase and sale order information, listing references, shipment and tracking information, delivery estimates, and authorization status needed for the connected workflow.
Imported working order and shipment records are designed to remain with the desktop program rather than being stored as complete order or shipment histories in CardDirector’s online services. Limited security, compliance, and operational logs may still be retained.
Disconnecting an eBay account ends the authorization process supported by CardDirector. Previously imported local records are controlled separately in the desktop program.
6. Future Payment and Subscription Information
CardDirector is not currently accepting payments, and the free Early Access waitlist does not collect payment-card information or start a subscription or trial.
If paid access opens, the checkout will identify the payment provider and any Merchant of Record before payment information is submitted. That provider may process payment details, taxes, invoices, renewals, cancellations, refunds, fraud checks, and payment-method updates under its own privacy notice and transaction terms.
CardDirector expects to receive only the account, customer, transaction, subscription, product, license, trial, payment-status, paid-through, cancellation, refund, and dispute information needed to provision and maintain access. CardDirector does not intend to receive or store full payment-card numbers or security codes.
7. Service Providers and Disclosures
CardDirector currently uses Cloudflare for website delivery, Cloudflare Workers, D1 database storage, Turnstile, Web Analytics, security, and limited operational logging. CardDirector uses Microsoft 365 for business email and support communications. eBay and licensed market-data providers process the information needed when a user requests their connected features. Each provider processes information under its own terms and privacy notice.
CardDirector may use additional service providers for support, error handling, and payment processing if paid access opens. Information may also be disclosed when reasonably necessary to comply with law, protect users or CardDirector, investigate abuse or security issues, enforce applicable terms, or complete a transaction or connected feature that you request.
8. Waitlist, Service, and Marketing Communications
CardDirector may send communications needed to administer a waitlist request, invitation, access, account, security issue, support request, connected service, or future billing relationship. These operational and service communications may be necessary to complete a request or provide the service and are separate from promotional marketing.
The current free waitlist form does not enroll you in promotional marketing. If CardDirector later offers newsletters, promotions, or other marketing emails, it will request separate optional consent where required, identify the marketing purpose, and provide a way to unsubscribe. Declining or withdrawing marketing consent will not prevent necessary waitlist, account, security, billing, or support communications.
9. Sale, Sharing, and Targeted Advertising
CardDirector does not sell personal information. CardDirector does not currently share personal information for cross-context behavioral advertising or use personal information for third-party targeted advertising.
Disclosures to service providers and connected services described in this notice are made to operate CardDirector, secure the service, process billing when enabled, or complete features you request; they are not intended as sales of personal information.
If CardDirector’s practices change in a way that creates additional privacy choices under applicable law, this notice will be updated and the required choices will be provided.
10. Retention
CardDirector applies the following current retention schedule to the free Early Access website and waitlist:
- New, reviewing, waitlisted, or invited requests are retained for up to 24 months after the most recent submission, status activity, or meaningful contact.
- Direct identifiers and free-form content for declined requests are removed after 12 months. Minimal status and audit records may remain for up to 24 months after the final decision.
- Expired or revoked unused invitation records are retained for up to 12 months after expiration or revocation. Accepted invitation records and related website audit history are retained for up to 24 months after acceptance.
- Temporary website enrollment-session records are retained for up to 90 days after expiration or completion. This does not delete separate account, entitlement, activation, or trial-use records needed to prevent duplicate trials and maintain access history.
- Basic browser user-agent information submitted with a waitlist request is retained for up to 90 days unless it is needed for a documented security investigation.
- Transformed rate-limit identifiers are retained for no more than 24 hours.
- Ordinary support correspondence is retained for up to 24 months after resolution. A minimal record showing that a privacy or deletion request was handled may be retained for up to three years.
If you withdraw a waitlist request or make a valid deletion request, CardDirector aims to remove the ordinary waitlist record within 30 days. Limited information may be retained when reasonably necessary to honor an opt-out, document completion of the request, protect security, comply with law or provider obligations, or resolve a dispute. A minimal marketing-suppression record may be kept for as long as needed to avoid contacting a person who opted out.
Future customer, billing, tax, refund, dispute, account, entitlement, activation, and connected-service records will follow the final paid-service policy published before payments open. Local desktop records remain on the user’s computer until the user deletes or restores them. eBay compliance records may be retained as required by eBay’s policies and applicable obligations.
11. Security
CardDirector uses reasonable administrative and technical safeguards, including protected service credentials, authorization checks, signed provider requests where required, rate limits, restricted routes, and secure transport. No system can guarantee absolute security.
12. Your Choices
You may choose not to submit an Early Access request or connect an optional service. Supported connected accounts can be disconnected. Local imported records can be managed separately in the desktop program.
You may contact CardDirector to request access, correction, withdrawal, or deletion of personal information where applicable. Some information may need to be retained for security, legal, compliance, billing, provider, opt-out, or dispute purposes.
13. Children’s Privacy
CardDirector is not directed to children under 13, and the service is not intended to knowingly collect personal information from children under 13.
If you believe a child under 13 has provided personal information to CardDirector, contact privacy@carddirector.com so the issue can be reviewed.
14. Changes to This Notice
This notice may be updated as CardDirector, connected services, billing, and legal requirements change. The effective date will be revised when material changes are published.
15. Contact
Privacy questions and requests, including waitlist withdrawal, access, correction, and deletion requests, can be sent to privacy@carddirector.com.