GG.cards

Privacy

Privacy Notice

This beta privacy notice explains how GG.cards handles private collection data and explicitly shared public data. Final legal review is still required before broad public launch.

Private by default

Account data

We use account details such as email, authentication identifiers and setup status to run your account. Email addresses are not shown publicly by GG.cards.

Date of birth and age handling

Date of birth is used to apply age-related account rules and privacy defaults. It is private account data and is not shown on public profiles or shares.

Collection data

Your owned cards, binders, photos, notes, imports, pricing preferences and local backup data are private unless you explicitly share selected views.

Messages

Listing-based Messages are visible only to the conversation participants and are not publicly enumerable.

Explicitly public or shared

Public profile and shares

If you enable public profile, binder, Wishlist or Trade List sharing, the chosen public information can be viewed by people with access to those pages.

Trade and sale listings

Listing status and listing photos are shared only through the public listing surfaces you enable. Private notes, purchase cost, date of birth and email are not included.

Service providers and controls

Supabase

GG.cards uses Supabase for authentication, database storage, private file storage and related account services.

Google OAuth

If you choose Continue with Google, Google provides the authentication result needed to sign you in. GG.cards does not receive your Google password.

Brevo

GG.cards uses Brevo custom SMTP through Supabase Auth to deliver account emails such as confirmations and password reset messages.

Vercel

GG.cards is hosted on Vercel, which processes requests needed to serve the website and API routes.

Vercel Web Analytics

GG.cards uses Vercel Web Analytics for privacy-conscious page-view measurement during beta. Secure share links, profile usernames, query strings and auth tokens are redacted before analytics events are sent.

Google Analytics

With your permission, GG.cards uses Google Analytics 4 to measure privacy-safe page views and improve the service. Google Analytics is optional, advertising storage is disabled, and GG.cards does not attach your account ID or email.

Cookies and local storage

Authentication uses secure cookies. GG.cards also uses browser storage for local collection state, recovery caches, preferences and import/export workflows.

Retention and deletion

You can permanently delete your account at https://gg.cards/account/delete. Account deletion removes your GG.cards profile, cloud collection, binders, Wishlist, shares and user-uploaded images. Local browser data may remain until you clear it. Limited billing, security or legal records may be retained where required for fraud prevention, accounting or compliance.

Children and teen privacy

Independent accounts are currently limited to ages 13 and over. Teen accounts receive privacy-protective defaults.

Analytics preferences

You can accept or reject optional Google Analytics at any time. Necessary authentication and session cookies are unaffected.

Your rights and contact

To delete your account, visit the account deletion page. To ask about privacy or account data, use the Contact page.