cardtracker.io

Privacy Policy | CardTracker
Legal

Privacy Policy

Last updated: 28 June 2026

This policy explains how CardTracker handles your personal data. The data controller is Sink or Swim Inbound Marketing Limited, a company registered in Ireland (company number 5141805), registered office at 70 Charlesland Wood, Greystones, Wicklow, A63 AE79, Ireland ("CardTracker", "we", "us"). We comply with the EU General Data Protection Regulation (GDPR) and Irish data protection law. Contact: info@cardtracker.io.

1. What we collect

  • Account data: your email address and a securely hashed password.
  • Your settings: the Cardmarket cards you choose to track and your notification preferences.
  • Technical data: limited usage and device information (such as IP address and browser type) for security and to keep the Service running.
  • Communications: any messages you send us, for example by email or the contact form.

We do not collect payment card details ourselves; if and when paid plans launch, payments are handled by our payment processor.

2. How and why we use it

We use your data to provide the Service (tracking your cards and sending alerts), to secure and maintain it, to respond to you, and to improve CardTracker. Our legal bases are: performance of our contract with you (providing the Service), our legitimate interests (security and improvement), and your consent where required (for example optional marketing emails, which you can withdraw anytime).

3. Who we share it with (processors)

We share data only with service providers who process it on our behalf, under appropriate agreements:

  • Supabase - database and account authentication (stores your account data and settings).
  • Resend - sending email alerts and messages.
  • ntfy - delivering push notifications.
  • Hostinger - website hosting.
  • (When introduced) a web-app hosting provider for the member dashboard, and a payment processor (such as Stripe) for paid plans.

We do not sell your personal data.

4. International transfers

Some providers may process data outside the EU/EEA. Where that happens, we rely on appropriate safeguards such as EU Standard Contractual Clauses to protect your data.

5. Data retention

We keep your account data for as long as your account is active, and delete or anonymise it within a reasonable period after you close your account, unless we must keep it longer to meet a legal obligation.

6. Your rights

Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your data, and to data portability. You can exercise these by emailing info@cardtracker.io. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).

7. Cookies

We use only the cookies needed to run the site and keep you logged in. If we add analytics or non-essential cookies later, we will ask for your consent first.

8. Security

We take reasonable technical and organisational measures to protect your data, including encryption in transit and hashed passwords. No system is perfectly secure, but we work to keep your data safe.

9. Children

CardTracker is not directed at children under 16, and we do not knowingly collect their data.

10. Changes

We may update this policy from time to time. Material changes will be notified through the Service or by email.