Privacy and data handling
Privacy Policy
Effective July 27, 2026
Card Command Center is a personal, single-owner business tool. It is not offered as a public marketplace and does not sell personal information.
1. What this application does
Card Command Center helps its owner manage trading-card inventory, purchases, grading, listings, sales, shipping, expenses, market research, and business reporting. Public visitors can view this policy and the landing page; operational workspaces require approved owner access.
2. Information collected
The application may store owner account details, business preferences, inventory and card data, purchase and sale records, receipts and card images, grading records, shipping and fulfillment references, marketplace identifiers, listing and order facts, fees, and audit history.
When the owner connects eBay, the application uses official eBay APIs to obtain the authorized seller's account identifier, listings, orders, fulfillment status, and available financial transaction details. Imported eBay order snapshots intentionally exclude buyer names, addresses, email addresses, and other delivery details that are not needed for inventory reconciliation.
3. How information is used
Information is used only to operate the owner's card business: reconcile inventory and sales, calculate cost basis and profit, manage grading and fulfillment, generate reports, maintain security, diagnose errors, and satisfy recordkeeping obligations.
4. Sharing and sale of information
Personal information is not sold. Data is shared only when needed to operate the application, such as with the hosting provider, Google for owner authentication, eBay for authorized marketplace access, and other providers the owner deliberately connects. Each provider processes data under its own terms and privacy practices.
5. Storage, security, and credentials
The application uses encrypted transport, owner authentication, authorization checks, secure cookies, input validation, audit logging, and restricted file access. eBay refresh tokens and other sensitive credentials are encrypted or stored outside the source code in protected server configuration. No security method can guarantee absolute protection.
6. Retention and deletion
Operational data is retained while it supports the owner's business and is deleted or anonymized when it is no longer needed. Backups are retained for limited recovery periods and age out through the backup lifecycle.
The application accepts eBay Marketplace Account Deletion notifications through a public HTTPS endpoint. Valid notices are cryptographically verified. Matching account identifiers, stored authorization, and unnecessary personal references are then deleted or anonymized. Limited transaction facts—such as dates, item descriptions, monetary amounts, fees, and order references—may be retained without the notified account identifier when reasonably necessary for bookkeeping, fraud prevention, tax, dispute, or other legal obligations.
7. Cookies and authentication
Secure, essential cookies are used to maintain the approved owner's session and protect the workspace. The application does not use advertising cookies or cross-site behavioral tracking.
8. Data choices
The owner can disconnect marketplace access, export business data, archive records, remove attachments, and request deletion of data that is not subject to a legitimate retention requirement. eBay users' deletion requests are handled through eBay's Marketplace Account Deletion notification process.
9. Changes and contact
This policy may be updated when the application's integrations or data practices change. The effective date above identifies the current version. Questions about this policy can be directed to the Card Command Center site owner through jamesgraham.online.