Skip to main content

Privacy Policy

Last updated: August 16, 2026

Introduction​

Trading Card API ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. We are the data controller for the personal information described in this policy.

This policy covers both:

  • Our website — the documentation and marketing site at tradingcardapi.com, including the blog, guides, pricing pages, and the signup, early-access, and newsletter forms.
  • Our API service — the API at api.tradingcardapi.com and the account and billing systems that support it.

It explains what we collect, why we collect it, who else receives it, how long we keep it, and the rights you have over it.

Information We Collect​

Account information​

When you create an account through our signup form, we collect your email address and a password, which we store only as a salted hash — we never store your password in a readable form. If you apply through our early-access form, we also collect the name, company, and project details you choose to provide. Once your account exists, we hold your API keys and their usage statistics.

Billing information​

When you subscribe to a paid plan, we hold your plan, subscription status, and billing history, and the billing name, email, and address associated with the subscription. We never receive or store your card number. Card details are entered directly into payment fields hosted by Stripe and are transmitted to Stripe, not to us. Your use of paid plans is also governed by our Terms of Service.

API usage data​

When you call the API, we record request metadata: the endpoint called, the timestamp, the response status, and the API key used. We maintain rate-limit counters keyed to your API key, and we log IP addresses. This data is used for rate limiting, abuse prevention, billing accuracy, security investigation, and diagnosing errors.

Website analytics data​

When you browse our website in production, we collect pages viewed, referring page, approximate location derived from a truncated IP address, and device and browser type, together with a set of custom interaction events: documentation page views, external link clicks, code-example interactions, blog and guide engagement, site searches, early-access and signup form interactions, and page-load performance timings. This is collected through Google Analytics — see Cookies and Tracking below.

We record the page address without its query string or anchor. The only query parameters we keep are the campaign tags that tell us which link brought you here (utm_source, utm_medium, utm_campaign, utm_term, utm_content, utm_id) and the equivalent advertising click identifiers. Everything else in a page address is discarded before it reaches Google, so codes and tokens that arrive in a link — such as an invite or an email-verification link — are never sent to our analytics provider.

Communications​

We collect the email address you submit to our newsletter, and the contents of any support correspondence you send us.

If you are in the EEA or the UK, we rely on the following legal bases under Article 6 of the GDPR:

PurposeLegal basis
Providing the API and your accountPerformance of a contract
Processing payments and managing subscriptionsPerformance of a contract
Providing customer supportPerformance of a contract
Rate limiting, abuse prevention, fraud prevention, and securityLegitimate interests
Diagnosing errors and improving the serviceLegitimate interests
Website analytics and marketing emailConsent
Retaining tax, accounting, and billing recordsLegal obligation

Where we rely on consent, you can withdraw it at any time — see Your Rights. Withdrawing consent does not affect processing carried out before the withdrawal.

Cookies and Tracking​

Strictly necessary and functional storage​

We use a small amount of browser storage to deliver the site you asked for: remembering your light/dark theme preference on the documentation site, and briefly caching the public statistics shown on some pages so they do not have to be re-fetched on every visit. This storage stays on your device, contains no personal information, is not used to identify or track you, and is set without consent because it is strictly necessary or reflects a preference you expressed. Our website does not sign you in, so it sets no session or authentication storage.

Analytics cookies​

We use Google Analytics 4 to understand how the website is used. It sets the following cookies:

CookiePurposeApproximate lifetime
_gaDistinguishes one visitor from another2 years
_ga_<container-id>Persists the analytics session state2 years

Two things limit what this collects:

  • IP anonymization is enabled, so Google Analytics truncates your IP address before it is stored or used for location.
  • Analytics run only on the production website. Local development and preview builds set no analytics cookies at all.

We do not use advertising cookies, and we do not run cross-site behavioural advertising trackers.

How to opt out of analytics​

You can prevent analytics collection in any of the following ways:

  • Install the Google Analytics opt-out browser add-on, which blocks Google Analytics across all sites.
  • Block or clear cookies for tradingcardapi.com in your browser settings.
  • Enable Global Privacy Control, Do Not Track, or your browser's built-in tracking protection — most modern browsers and privacy extensions block Google Analytics by default.

We want to be straightforward about where we stand: we do not currently present a cookie consent banner, so analytics cookies are set on your first visit to the production site. We are aware that visitors in the EEA and the UK are entitled to give prior consent to non-essential cookies, and implementing a consent mechanism is planned work. Until it ships, the opt-out routes above are the way to prevent analytics collection, and this section exists so that no one is surprised by what is being set.

Third-Party Processors​

The companies below process personal data on our instructions as our processors. They are not permitted to use your data for their own independent purposes, and we do not sell your data to any of them.

ProviderWhat it doesWhat it receives
StripePayment processing for paid subscriptionsBilling name, email, billing address, and card details entered directly into Stripe's hosted payment fields
BrevoMarketing email — newsletters and early-access updatesYour email address, plus any name and company you supplied on the early-access or newsletter forms
LoopsTransactional email — account verification, welcome, and trial lifecycle messagesYour email address
Google AnalyticsWebsite usage analyticsTruncated IP address, page views, and the interaction events listed above
DigitalOceanHosting for the website, the API, and our serverless functionsAll data processed by the service, in its capacity as our infrastructure provider

Each provider publishes its own privacy policy describing how it handles the data it receives. If we add a processor that receives your personal data, we will update this table.

Data Sharing​

Beyond the processors listed above, we do not sell, trade, or share your personal information with third parties except:

  • With your explicit consent
  • To comply with legal obligations, including valid legal process
  • To protect our rights, our users, and the security of the service
  • In connection with a merger, acquisition, or sale of assets, where you will be notified before your data becomes subject to a different privacy policy

We do not "sell" your personal information, and we do not "share" it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We have not sold or shared personal information in the preceding twelve months.

International Data Transfers​

Our service is hosted in the United States. If you access the service from the EEA, the UK, or elsewhere outside the United States, your personal data is transferred to and processed in the United States.

Where we transfer personal data out of the EEA or the UK, we rely on the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable) in our agreements with our processors, together with each provider's own certification or transfer framework participation where they maintain one. You can request a copy of the safeguards we rely on using the contact details below.

Data Retention​

We keep personal data only as long as we need it for the purposes described in this policy. Concretely:

DataRetention period
Account recordsFor the life of the account, then deleted within 30 days of account closure
API request logs90 days
Rate-limit countersRolling 24 hours
Billing, invoice, and tax records7 years, as required by tax and accounting law
Marketing contactsUntil you unsubscribe, then removed from our mailing lists
Support correspondence2 years from the close of the conversation

Where we are required to retain billing or tax records beyond the deletion of your account, we retain only those records and not the rest of your account data.

Your Rights​

If you are in the EEA or the UK​

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — have your personal data deleted, subject to our legal retention obligations
  • Restriction — ask us to limit how we process your data
  • Portability — receive your data in a structured, machine-readable format, or have it transmitted to another controller
  • Object — object to processing we carry out on the basis of legitimate interests, and to direct marketing at any time
  • Withdraw consent — withdraw consent for analytics or marketing email at any time

If you are in California​

Under the CCPA/CPRA you have the right to know what personal information we collect and disclose, to delete it, to correct it, to opt out of any sale or sharing (we do neither), to limit the use of sensitive personal information (we do not collect any), and to be free from discrimination for exercising any of these rights. You may use an authorized agent to submit a request on your behalf.

How to exercise your rights​

Email [email protected] — or [email protected] if you prefer — with the request you want to make. We will respond within 30 days, and will tell you if we need longer for a complex request. Because these requests concern your data, we may need to verify your identity, usually by confirming that you control the email address on the account. There is no charge for exercising your rights.

You can unsubscribe from marketing email at any time using the unsubscribe link in any message we send, without contacting us.

If you are in the EEA or the UK and you are not satisfied with how we have handled your request, you have the right to lodge a complaint with your local data protection supervisory authority.

Data Security​

We implement appropriate technical and organizational measures to protect your information:

  • Encrypted data transmission (HTTPS/TLS) across the website and the API
  • Passwords stored as salted hashes, never in a readable form
  • API keys stored in a non-reversible form, so they cannot be recovered from our systems after issuance
  • Secure API key management, rotation, and revocation
  • Regular security review of our infrastructure and dependencies
  • Access controls and monitoring limiting who can reach production data

No system is perfectly secure, but we work to protect your data using measures appropriate to its sensitivity.

Children's Privacy​

Our service is not directed to children. We do not knowingly collect personal data from anyone under 13, or under 16 in the EEA. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.

Changes to This Policy​

We may update this privacy policy periodically. We will revise the "Last updated" date at the top of this page, and we will notify users of significant changes through our documentation site or by email before those changes take effect.

Contact Us​

For privacy-related questions or requests: