Privacy Policy
Last updated: September 19, 2026
1. Who we are
tradingcardhunt (“the Service”) is operated by [OPERATOR NAME]. This policy explains what personal information we collect, how we use it, and your choices. It applies together with our Terms of Service.
2. What we collect
- Account details: your email address, an optional name, and the time you accepted our Terms and Privacy Policy.
- Your password: we never store it. We keep only a salted, one-way hash of it, which we can’t turn back into your password.
- Session data: when you log in we create a session so you stay logged in (see Cookies below).
- Abuse-prevention data: to limit repeated login, signup and email requests we count them per client. The counter is keyed on a one-way hash of your IP address (and, for logins and password resets, of the email address), not the raw value, and is deleted within about a day.
- Standard technical logs: our hosting provider, Cloudflare, processes requests to the Service and may keep standard request logs (such as IP address and browser type) under its own policies.
We don’t ask for payment details, and we don’t collect information about your card collection.
3. What we don’t do
We don’t run advertising, we don’t use analytics or tracking scripts, and we don’t sell your personal information or share it with third parties for their marketing.
4. Cookies
We use a single, essential cookie (tch_session) that keeps you logged in. It is marked HTTP-only, is sent only to this site, and lasts up to 30 days or until you log out. We don’t use advertising or tracking cookies.
5. How we use information
- to create and secure your account and let you log in;
- to send account emails you need — confirming your email address and resetting your password. We don’t send marketing email;
- to prevent abuse and keep the Service secure and running; and
- to meet legal obligations.
6. Third parties
Hosting and email delivery: the Service runs on Cloudflare, which hosts our application and database and, where enabled, delivers our account emails.
Card data: when you open a card, our servers send the card’s name (not your personal information) to eBay and to a news API to fetch current listings and headlines.
Images and links: your browser loads some card images directly from the Library of Congress and eBay’s image servers, so those services receive your IP address and browser details under their own policies. Links to eBay or news sites take you to services with their own privacy practices.
7. How long we keep it
We keep your account details until you ask us to delete your account. Sessions expire after 30 days. Email confirmation links expire after 24 hours and password-reset links after 1 hour. Abuse-prevention counters are deleted within about a day.
8. Your choices and rights
You can ask us to access, correct or delete the personal information we hold about you, including deleting your account, by emailing [CONTACT EMAIL]. Depending on where you live, you may have additional rights under local law, such as to know what we collect or to object to certain uses. We’ll respond within a reasonable time.
9. Security
We protect your information with measures such as hashed passwords, encrypted connections and limits on repeated login attempts. No system is perfectly secure, so we can’t guarantee absolute security.
10. Children
The Service is for people 18 and older. We don’t knowingly collect information from anyone younger. If you think we have, contact us and we’ll delete it.
11. Where information is processed
Cloudflare runs a global network, so your information may be processed in the United States and other countries where it or its providers operate.
12. Changes to this policy
We may update this policy. We’ll change the “Last updated” date above, and if the change is significant we’ll make reasonable efforts to tell you.
13. Contact
Questions or requests about privacy: [CONTACT EMAIL].