Privacy Policy
Last updated: August 2026
Introduction
Cardholdr ("we", "us", "our") is a product of Uniscale GmbH, Zurich, Switzerland. This Privacy Policy describes how we collect, use, and protect your personal information when you use our services.
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
Data Controller
Uniscale GmbH
The Circle 6
8058 Zürich-Flughafen
Switzerland
Email for privacy inquiries: privacy@cardholdr.app
Data We Collect
We collect the following categories of data:
- Account Data: Email address, display name, password (encrypted)
- Profile Data: Bio, location, website, preferred currency, language preference
- Collection Data: Card information, images, PSA certificate numbers, purchase prices, sale prices
- Usage Data: IP address, browser type, access times, page views
How We Use Your Data
- To provide and improve our services
- Account management and authentication
- Communication about your account and our services
- Analytics to improve user experience
- Compliance with legal obligations
Legal Bases for Processing
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR): account creation, providing the collection and portfolio features, handling subscriptions
- Legitimate interests (Art. 6(1)(f) GDPR): security, abuse prevention, error diagnostics, and improving the services
- Consent (Art. 6(1)(a) GDPR): optional communications such as push notifications; withdrawable at any time
- Legal obligation (Art. 6(1)(c) GDPR): in particular commercial and tax record-keeping duties
Data Sharing
We do not sell your personal data. We share data only in the following cases:
- Service Providers: With third-party providers who help us deliver our services (e.g., hosting, payment processing)
- Group Members: In group vaults, certain information is shared with other group members
- Legal Requirements: When required by law or to enforce our rights
Data Storage
Your data is stored on secure servers in the European Union. We employ industry-standard security measures to protect your data from unauthorized access.
International Data Transfers
As a Swiss company we process data in Switzerland. Switzerland benefits from an adequacy decision of the European Commission. Some of our service providers are established in the United States. For such transfers we rely on the EU Standard Contractual Clauses, or on an adequacy decision where one exists for the provider concerned.
Retention Periods
We retain your data for as long as your account exists. After you delete your account, your personal data is removed or anonymized. Excepted is data we are required to keep under statutory retention obligations — in particular invoices and payment records, which Swiss law requires us to retain for ten years.
Also excepted are direct messages that have been reported or deleted by their sender. Deleting a message removes it from the chat for both participants, but a copy is kept for a limited time in a protected log so that we can investigate reports of harassment, fraud or other abuse and respond to lawful requests from authorities. These copies are deleted automatically after 90 days — where a report is open, once it has been resolved, and beyond that only where we are legally required to retain them. You can therefore rely on a deleted message no longer being shown to the other person, but it is not irreversibly destroyed at that moment. The legal basis is our legitimate interest in the safety of the platform (Art. 6(1)(f) GDPR). For the same reason these copies outlive the deletion of an account — otherwise a reported user could dispose of the evidence by closing their account.
Your Rights
You have the following rights regarding your personal data:
- Right of Access: Request access to your data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing of your data
- Right to Withdraw Consent: Withdraw consent at any time with future effect
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority
To exercise these rights, contact us at privacy@cardholdr.app
The competent supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC). Users in the EU may also contact the data protection authority of their country of residence.
Third-Party Services
We use the following third-party services:
- Vercel Inc. (US): Hosting and website delivery
- Neon (EU): Database hosting
- Amazon Web Services (EU): Image storage and email delivery
- Stripe: Payment processing on the web
- Apple, Google: Processing and management of in-app purchases
- Pusher (EU): Realtime notifications in the app
- Sentry: Error diagnostics and stability monitoring
- PSA (Professional Sports Authenticator): Certificate number verification
- eBay: Market price data for card valuations
- Vercel AI Gateway: AI-assisted analysis of uploaded card images
Children's Privacy
Our services are not intended for persons under 16 years of age. We do not knowingly collect data from children under 16.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a notice in our app.
Contact
For questions about this Privacy Policy, please contact us:
Uniscale GmbH
The Circle 6
8058 Zürich-Flughafen
Switzerland
Privacy inquiries: privacy@cardholdr.app
General support: support@cardholdr.app