Privacy Policy
What information SlabIQ collects, why it collects it, who it goes to, and what control you have over it.
- Effective Date:
- August 25, 2026
- Last Updated:
- August 25, 2026
- Version:
- 2026-08-25
1. Overview
This policy explains how SlabIQ handles information when you use the Service. It is written to describe what the platform actually does, rather than to cover every hypothetical.
Three things are worth stating up front:
- Card images you upload are sent to third-party AI and OCR providers when you use identification features. This is how card identification works. Section 6 explains it in detail.
- SlabIQ never receives your full payment card number. Payment details are handled by the payment processor.
- SlabIQ does not use third-party advertising or analytics trackers. There is no Google Analytics, no advertising pixel, and no cross-site tracking in the Service.
This policy covers the SlabIQ application and website. It does not cover third-party platforms you connect, which have their own privacy policies.
2. Information You Provide
Account information
- Email address, and an optional secondary email for notifications
- Password, stored only as a cryptographic hash — never in readable form
- Optional profile details: first and last name, display name, avatar, timezone
- Account role, team membership, and team invitations you send or accept
- Notification, display, and workflow preferences
Content you upload and create
- Card images, including front and back scans and photos, and images uploaded from a phone
- Branding assets such as logos, watermarks, and banner images
- Inventory, batch, collection, binder, and storage-location records
- Listing content: titles, descriptions, item specifics, prices, quantities
- Listing templates and saved presets
- Purchase, cost, and profitability records you enter
- Uploaded documents and spreadsheets, such as checklists and import files
- Notes and other free-text fields
- Card images and information you submit through catalog contribution features
Subscription information
- Your plan, subscription status, billing period, and renewal or cancellation state
- Scan allowance, scans used, add-on credits purchased, and usage history
- Payment processor customer and subscription identifiers
- Records of billing events received from the payment processor
SlabIQ does not receive or store full payment card numbers, CVV codes, or bank account numbers. Those are entered with and held by the payment processor. SlabIQ stores identifiers that let it look up your subscription, not your payment instrument.
Support communications
If you contact support, SlabIQ receives your message and any information you include in it.
3. Information Collected Automatically
Operating the Service generates some information automatically:
- Session data — a session identifier, creation and expiry times, and last-activity time, used to keep you signed in and to enforce session timeouts
- IP address and browser user-agent — recorded in activity and security logs, used to secure accounts and investigate suspicious activity
- Activity logs — records of significant actions in the Service, with timestamps, used for audit history and troubleshooting
- Feature and usage records — such as scans performed, jobs run, and integration calls made, used to enforce plan limits and to operate features
- Error and diagnostic logs — technical records generated when something fails, used to fix it
This information is collected by SlabIQ itself and is not shared with advertising or analytics companies.
4. Information From Connected Marketplaces
When you connect a third-party marketplace or commerce platform, SlabIQ receives information from it using the permissions you grant. Platforms you can currently connect include eBay, Shopify, TikTok Shop, TCGplayer (via the SlabIQ Marketplace Bridge browser extension), Discord.
Depending on the platform and the permissions granted, this may include:
- Your seller account identifier, username, and verified identity on that platform
- Marketplace, store, and account configuration details
- Authorization credentials — access and refresh tokens, their scopes and expiry
- Listings, inventory, item details, images, and item specifics
- Orders, transactions, and sales history
- Fees, payouts, and financial and earnings information
- Business policies — shipping, payment, and return policies
- Inventory locations, store categories, and category metadata
- Traffic, impression, and performance analytics for your listings
Some of this is stored so features work when the platform is unreachable — your listings, orders, and financial records, for example, persist in SlabIQ. Other information is cached temporarily to reduce API calls and refreshed periodically. Authorization tokens are stored so that SlabIQ can act on your behalf until you disconnect or the authorization expires.
Disconnecting a platform deactivates the connection and stops future synchronization. You can also revoke SlabIQ’s access from the platform’s own account settings. Records already imported into SlabIQ — such as past orders and profitability history — remain unless you delete them or request deletion.
5. Your Buyers' Information
When SlabIQ imports your orders from a connected marketplace, those orders contain information about the people who bought from you:
- Buyer username and name
- Shipping address
- Order, tracking, and shipping details
- Transaction amounts and fees
SlabIQ stores this so you can fulfill orders, print labels, run pick lists, and track your finances. SlabIQ handles it on your behalf and for no independent purpose — it is not used to market to your buyers, not sold, and not shared with other users.
You are responsible for how you handle your buyers’ information. You are the merchant in those transactions. If a privacy law applies to your business, your obligations to your buyers are yours, and SlabIQ acts as your service provider in processing that information. If a buyer contacts SlabIQ directly about their information, SlabIQ will generally direct them to you as the seller.
6. AI and Automated Processing
Card identification is the core of the Service, and it works by processing your images. This section explains exactly what that involves.
What gets processed
When you scan or upload a card, SlabIQ may process the card image, text extracted from it, card attributes and metadata, catalog data, and — for listing-generation features — listing information such as titles, descriptions, and item details.
Why
- To identify the card and match it to a catalog record
- To extract attributes such as player, set, year, card number, parallel, and condition
- To read text from card images and uploaded documents
- To generate suggested listing titles, descriptions, and item specifics
- To suggest marketplace categories
- To detect duplicate records
- To produce pricing and marketplace-health suggestions
- To diagnose problems when identification fails
Processing that stays inside SlabIQ
Some of this happens without any third-party transfer:
- Tesseract OCR — Runs inside SlabIQ's own servers; images are not sent anywhere.
- Perceptual hashing and image matching — SlabIQ's own algorithms compare a card image against SlabIQ's catalog. No third party is involved.
- Ollama (optional self-hosted model) — When an administrator selects this option, the model runs on infrastructure SlabIQ controls rather than a third-party API.
Third-party AI and OCR providers
Other processing is performed by third-party providers, which means your card images and related card data are transmitted to them. Which provider handles a given request depends on how the Service is configured at the time. All providers reachable by the Service are listed here:
- OpenAI — Card identification from images, and generating listing titles and descriptions. Receives: card images, card text and attributes, listing details.
- Google (Gemini) — Card identification and attribute extraction from images. Receives: card images, card text and attributes.
- Anthropic (Claude) — Card identification and marketplace-health recommendations. Receives: card images, card text and attributes, listing details.
- CardSight — Specialized trading-card identification. Receives: card images.
- Mistral — Optical character recognition on card and checklist images. Receives: card images, document images.
- OCR.space — Optical character recognition on card images. Receives: card images.
- LlamaIndex (LlamaParse) — Parsing uploaded checklist and catalog documents. Receives: document uploads.
These providers act as service providers to SlabIQ, processing this information to return a result. SlabIQ sends the image and card context needed for identification; it does not send your password, payment information, or marketplace authorization credentials to them.
Retention and model training by these providers
Each provider applies its own retention and data-use terms to information submitted through its API. Those terms vary between providers and between account tiers, and they change over time.
SlabIQ is not currently in a position to guarantee that content sent to these providers is never retained or never used to improve their models, and this policy will not claim otherwise. If that assurance matters to you, review the terms of the providers listed above, and contact support@slabiq.app before uploading content you consider sensitive.
Pending: provider data-use verification
This wording is deliberately conservative. No zero-retention or no-training configuration exists in the application, and the provider account tiers and contractual terms have not been verified. Rather than making an unverifiable promise, the policy describes the transfer honestly.
Once ownership confirms each provider’s account tier, data-processing terms, and any zero-retention settings, set AI_NO_TRAINING_VERIFIED in src/lib/legal/config.ts and this section will state the confirmed position instead. See docs/legal/OPEN-DECISIONS.md.
Automated results are not decisions about you
SlabIQ’s automated processing analyzes cards and listings. It is not used to make legal or similarly significant decisions about you as a person — no automated credit scoring, employment screening, or profiling of that kind. Automated output is assistive and, as the Terms of Service explain, can be incorrect and should be reviewed.
A note on how SlabIQ is built
The Terms of Service disclose that AI-assisted development tools were used to help write and test SlabIQ’s source code. That is a statement about software development, and is separate from this section. The processing of your information by AI is what this section describes.
7. How Information Is Used
SlabIQ uses information to:
- operate, maintain, and provide the Service;
- create and authenticate your account, and keep sessions secure;
- process subscriptions, track scan usage, and enforce plan limits;
- identify cards and match them to catalog records;
- manage inventory, batches, collections, and storage;
- synchronize with connected marketplaces and publish listings you create;
- generate listing content, pricing suggestions, and recommendations;
- display market and pricing information;
- track orders, sales, fees, and profitability;
- send transactional email and, where you enable it, notifications;
- provide customer support and respond to your requests;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- debug problems and improve reliability and performance;
- understand aggregate feature usage in order to improve the Service;
- comply with legal obligations and enforce the Terms of Service.
SlabIQ does not use your information for third-party advertising, and does not build advertising profiles.
9. Data Retention
SlabIQ retains information for as long as your account is active and as long as needed to provide the Service. In practice:
- Account and profile information — kept while your account exists.
- Inventory, listings, orders, and financial records — kept while your account exists, because they are your business records and their value comes from historical continuity. You can delete individual records at any time.
- Uploaded images — kept while the item they belong to exists. Deleting a card, batch, or listing removes its associated images. Derived versions — thumbnails, resized and marketplace-prepared variants — are removed along with the original.
- Sessions — expire automatically and are periodically purged.
- Activity and security logs — retained for audit and abuse investigation. These may outlive the records they describe, because that is what makes an audit trail useful.
- Marketplace authorization tokens — kept until you disconnect the platform, the authorization expires, or you revoke it at the platform.
- Billing records — retained as required for financial, tax, and accounting obligations, typically for several years, even after an account closes. The payment processor retains its own records under its own policy.
- Backups — information may persist in routine backups for a limited period after deletion from the live system, and is overwritten on the ordinary backup cycle.
- Catalog contributions — card data contributed to the shared catalog may be retained after your account closes, because other users rely on the catalog. It can be disassociated from your account on request.
Why there are no fixed day counts here
This section describes retention by category rather than promising specific windows like “deleted after 30 days.” SlabIQ does not currently run automated time-based deletion for most categories, and stating a schedule the system does not enforce would be inaccurate. Retention windows are an open item — see support@slabiq.app for specific questions.
10. Security
SlabIQ maintains administrative, technical, and organizational measures intended to protect information, including:
- passwords stored using a modern password-hashing algorithm, never in readable form;
- encrypted connections for traffic between your browser and the Service;
- authenticated, expiring sessions with idle and absolute timeouts, and the ability to revoke sessions;
- role- and permission-based access controls, including for team accounts;
- scoped marketplace authorization, with verification of the identity behind a connection;
- audit logging of security-relevant events;
- restricted internal access to production systems.
No service can promise complete security, and SlabIQ does not claim to be impenetrable. Transmission and storage of information always carry some risk. You play a part too: use a strong, unique password, do not share credentials, and tell SlabIQ promptly at support@slabiq.app if you suspect unauthorized access.
11. Your Privacy Rights
Privacy laws vary, and which statutory rights apply depends on where you live and on thresholds that may or may not currently apply to SlabIQ. Rather than claim that every regime applies, SlabIQ offers the following to all users regardless of location:
- Access — ask what information SlabIQ holds about you.
- Correction — correct inaccurate information. Most account and profile details can be edited directly in your settings.
- Deletion — request deletion of your account and associated information. See Section 12.
- Portability — request a copy of information you provided, in a portable format. SlabIQ also offers export tools for inventory and reporting data within the application.
- Withdraw consent — disconnect a marketplace, turn off notifications, or opt out of non-essential email at any time from your settings or via the unsubscribe link.
- Object or restrict — object to particular processing, or ask that it be restricted, and SlabIQ will consider the request in good faith.
- Appeal — if a request is refused, ask for that decision to be reviewed.
To make a request, email support@slabiq.app from the address on your account, or contact support if you cannot. SlabIQ will verify your identity before acting, and aims to respond within 30 days. There is no charge for reasonable requests, and you will not be treated differently for making one.
If you are in a jurisdiction with a supervisory authority for data protection, you may also lodge a complaint with it.
Requests about information SlabIQ processes on behalf of another user — for example, if you were a buyer from a SlabIQ seller — should generally go to that seller, who controls that information. SlabIQ will assist them in responding.
12. Account and Data Deletion
What you can do yourself, today
- Delete individual cards, batches, listings, inventory items, and their images
- Delete uploaded branding assets and templates
- Disconnect any connected marketplace from your integration settings
- Revoke SlabIQ’s access directly at the marketplace, from that platform’s own account settings
- Turn off notification categories and unsubscribe from non-essential email
- Edit or clear most profile information
Account deletion
To delete your entire account, email support@slabiq.app from the address on your account. SlabIQ will verify the request and delete your account and associated records, subject to the retention exceptions in Section 9 — principally billing records kept for tax and accounting purposes, backups on their ordinary cycle, and catalog contributions others rely on.
Cancel any active subscription first, and export anything you want to keep — deletion is not reversible.
Known gap: deletion is request-based, not self-serve
SlabIQ does not yet provide a “delete my account” button in settings. Deletion currently runs through the email request above and is performed by an administrator. This policy states that plainly rather than describing a self-serve control that does not exist.
Building self-serve deletion, and a full downloadable data export, are tracked product gaps — see docs/legal/OPEN-DECISIONS.md.
If you delete your marketplace account
Where a connected marketplace notifies SlabIQ that a user has deleted their account with that marketplace, SlabIQ processes that notification and removes the associated marketplace data it holds.
14. Children
SlabIQ is a commercial tool for trading-card sellers and is not directed to children. It is not intended for anyone under 18, and SlabIQ does not knowingly collect information from children.
If you believe a child has provided information to SlabIQ, contact support@slabiq.app and the account and its information will be removed.
15. International Users
SlabIQ is operated from the United States, and information is processed and stored there and in other countries where its service providers operate. Data-protection laws in those countries may differ from those where you live.
By using the Service, you understand that your information will be processed in the United States. Where required, SlabIQ relies on appropriate safeguards for international transfers. If you have questions about transfers relevant to your jurisdiction, contact support@slabiq.app.
16. Third-Party Links
The Service links to third-party sites — marketplaces, card databases, pricing sources, grading companies, and others. SlabIQ does not control them and is not responsible for their content or privacy practices. Their policies govern what they do with your information once you are on their site.
17. Changes to This Policy
This policy will be updated as the Service changes and as new providers or data flows are added. When it is, the Effective Date, Last Updated date, and Version at the top of this document change.
For material changes — a new category of information collected, a new purpose, a new type of sharing, or a reduction in your rights — SlabIQ will give notice at least 30 days in advance, by email to the address on your account or by prominent notice in the Service.
Clarifications and corrections that do not change how information is handled are reflected in the Last Updated date without advance notice.
18. Contact
For privacy questions or to make a privacy request:
- Privacy: support@slabiq.app
- General support: support@slabiq.app
When making a privacy request, email from the address on your account where possible and describe what you are asking for, so it can be handled without unnecessary back-and-forth.
See also the Terms of Service, which govern use of the Service.