CardScout

Privacy Policy

Last Updated: April 23, 2026

Introduction

CardScout ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our sports card collection management platform (collectively, the "Service").

CardScout is built on the Manus AI platform, which provides hosting, authentication, and infrastructure services. Please review this policy carefully. If you do not agree with our policies and practices, please do not use our Service.

1. Information We Collect

1.1 Information You Provide Directly

Account Registration: When you create a CardScout account, we collect your email address, name, password, and profile information. Authentication is handled through Manus OAuth, which may also collect your login credentials from third-party providers (such as Google or Apple) if you choose to use those services.

Collection Data: When you add cards to your collection, we collect detailed information about each card, including card name, player, team, year, condition grade, acquisition price, current market value, grading company (PSA, BGS, SGC, CGC), and any notes or tags you add.

Subscription Information: When you subscribe to CardScout's Rookie or Star tier, we collect subscription type, billing address, and payment information. Payment processing is handled securely by Stripe, and we do not store your full credit card details.

Communications: If you contact us with questions, feedback, or support requests, we collect the content of your messages, your email address, and any attachments you provide.

Gallery and Want List Data: When you create galleries, share want lists, or mark cards for sale, we collect information about those activities, including sharing preferences and visibility settings.

1.2 Information Collected Automatically

Device Information: We collect your device type, operating system, browser type, IP address, and unique device identifiers. This helps us optimize the Service for different devices and detect security threats.

Usage Analytics: We track which pages you visit, how long you spend on each page, which features you use, and your navigation patterns. This information helps us understand user behavior and improve the Service.

Cookies and Tracking Technologies: CardScout uses cookies and similar technologies to remember your preferences, maintain your login session, and analyze usage patterns. The Manus platform may also use cookies for authentication and session management.

Location Data: We may collect general location information (city, state, country) based on your IP address. We do not collect precise GPS location data without your explicit consent.

1.3 Information from Third Parties

Market Data Providers: We integrate with eBay and SportsCardsPro to fetch current market prices and card grading information. These integrations may share card data and market valuations with CardScout.

Manus Platform: As CardScout is hosted on the Manus platform, Manus may collect certain technical and usage data as described in the Manus Privacy Policy.

Payment Processor: Stripe collects and processes payment information on our behalf. For details on how Stripe handles your data, please review Stripe's Privacy Policy.

2. How We Use Your Information

Service Delivery: We use your data to provide, maintain, and improve CardScout, including processing your collection data, calculating portfolio analytics, fetching market prices, and enabling core features like galleries and want lists.

Authentication and Security: We use your account information to authenticate you, prevent fraud, and protect the security of your account and our Service.

Subscription Management: We use your subscription information to process payments, manage your tier level, enforce tier limits (such as card limits for the Rookie tier), and send billing notifications.

Communication: We use your email address to send you important Service announcements, updates, support responses, and billing information. We may also send marketing emails about new features or promotions, which you can opt out of at any time.

Analytics and Improvement: We analyze usage patterns and feedback to understand how users interact with CardScout, identify areas for improvement, and develop new features. This analysis is performed on aggregated, anonymized data whenever possible.

Legal Compliance: We use your information to comply with applicable laws, regulations, and legal processes, including tax and financial reporting requirements.

3. How We Share Your Information

CardScout does not sell your personal information to third parties. However, we may share your information in the following circumstances:

Manus Platform: CardScout is hosted on the Manus platform, which acts as a data processor on our behalf. Manus processes your data according to the Manus Privacy Policy and our Data Processing Agreement.

Payment Processing: We share billing information with Stripe to process subscription payments. Stripe does not use your payment information for marketing purposes.

Market Data Integration: When you use features that fetch market prices, we may share card identifiers with eBay and SportsCardsPro APIs to retrieve current valuations. We do not share your personal account information with these services.

Service Providers: We may share information with third-party service providers who assist us in operating CardScout, such as analytics providers, hosting providers, and customer support tools. These providers are contractually obligated to use your information only as necessary to provide services to CardScout.

Legal Requirements: We may disclose your information if required by law, court order, or government request. We will attempt to notify you of such requests unless legally prohibited.

Business Transfers: If CardScout is acquired, merged, or sold, your information may be transferred as part of that transaction. We will provide notice of any such change and any choices you may have regarding your information.

With Your Consent: We may share your information with third parties when you explicitly consent to such sharing, such as when you authorize a third-party integration or share your gallery with other users.

4. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:

Active Account Data: While your account is active, we retain your collection data, profile information, and usage history to provide the Service.

Deleted Account Data: If you delete your account, we will delete your personal information within 30 days, except where we are required to retain it for legal, tax, or business purposes.

Transaction Records: We retain subscription and payment records for seven years to comply with tax and financial reporting requirements.

Aggregated Data: We may retain aggregated, anonymized data indefinitely for analytics and service improvement purposes.

5. Your Privacy Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

Access: You can request a copy of the personal information we hold about you. You can download your collection data at any time through the Settings page.

Correction: You can update or correct your profile information and collection data directly through the CardScout interface.

Deletion: You can request deletion of your account and associated data. We will delete your information within 30 days, except where retention is required by law.

Portability: You can request your data in a portable format suitable for transfer to another service.

Opt-Out of Marketing: You can opt out of marketing emails by clicking the unsubscribe link in any email or adjusting your preferences in the Settings page.

Opt-Out of Cookies: You can control cookie preferences through your browser settings. However, disabling certain cookies may affect the functionality of CardScout.

GDPR Rights (European Users): If you are located in the European Economic Area or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority.

CCPA Rights (California Users): If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know, delete, and opt-out of the sale of personal information.

To exercise any of these rights, please contact us at [email protected] or through the Settings page.

6. Data Security

CardScout implements industry-standard security measures to protect your information from unauthorized access, alteration, and destruction:

Encryption: We use SSL/TLS encryption to protect data transmitted between your device and our servers. Sensitive data is encrypted at rest in our database.

Access Controls: Only authorized CardScout personnel and Manus infrastructure staff have access to your personal information, and access is limited to what is necessary to provide the Service.

Security Monitoring: We continuously monitor our systems for security threats and vulnerabilities.

Secure Authentication: We use OAuth for authentication, which does not require us to store your passwords directly.

While we implement strong security measures, no system is completely secure. We encourage you to use strong passwords and enable two-factor authentication if available.

7. Third-Party Links and Services

CardScout may contain links to third-party websites and services, such as eBay, SportsCardsPro, and market data providers. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services before providing your information.

8. Children's Privacy

CardScout is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13, we will delete such information promptly. Parents or guardians who believe their child has provided information to CardScout should contact us immediately at [email protected].

9. International Data Transfers

CardScout is hosted on the Manus platform, which may store your data in multiple geographic locations. If you are located outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries. By using CardScout, you consent to such transfers. We implement appropriate safeguards, such as Standard Contractual Clauses, to protect your information during international transfers.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last Updated" date at the top of this policy and, in some cases, by sending you an email notification. Your continued use of CardScout after such changes constitutes your acceptance of the updated Privacy Policy.

11. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our privacy practices, please contact us:

Email: [email protected]

Response Time: We will respond to privacy inquiries within 30 days.

For questions about how Manus processes your data, please refer to the Manus Privacy Policy or contact Manus directly at [email protected].

12. References

[1] Manus Privacy Policy - https://manus.im/privacy

[2] Stripe Privacy Policy - https://stripe.com/us/privacy

[3] eBay API Terms - https://developer.ebay.com/

[4] General Data Protection Regulation (GDPR) - https://gdpr-info.eu/

[5] California Consumer Privacy Act (CCPA) - https://oag.ca.gov/privacy/ccpa

Acknowledgment: This Privacy Policy was created with reference to industry best practices and the Manus platform's privacy framework. CardScout is committed to transparency and compliance with applicable data protection laws worldwide.