Privacy Policy
Effective date: July 19, 2026 Last updated: July 25, 2026
This Privacy Policy explains how Allstar Interactive LLC (“Allstar,” “we,” “us”) collects, uses, and shares your personal information when you use the Allstar website and services (the “Service”).
By using the Service you agree to the data practices described here. If you do not agree, do not use the Service.
1. Information we collect
We collect only the information needed to operate the Service.
You give us:
- Account info. Email address (required for sign-in). Display name and avatar URL if you set them on your profile.
- Sign in with Google (optional). If you choose to sign in with Google, Google shares your name, email address, and profile picture with us so we can create and secure your account. We never receive your Google password.
- Collection data. Card and sealed-product holdings you add to your portfolio, your binders, your watchlist entries, and any in-app prices, conditions, lots, and cost-basis values you enter.
- Share settings. When you opt in to public share links (portfolio, binder, or collection), the settings that control what’s visible on those links.
- Support requests. Anything you send us by email.
We collect automatically:
- Authentication cookies. A Supabase Auth session cookie that keeps you signed in. We do not use analytics or advertising cookies as of July 19, 2026.
- Server logs. IP address, user-agent, requested URL, and timestamp for each request. Used for security, abuse-prevention, and debugging. Retained for 30 days unless an investigation requires longer.
- Bot protection. When you use the sign-in, sign-up, or password-reset forms, Cloudflare Turnstile performs a bot-detection check. This can involve your IP address and browser signals, processed by Cloudflare to distinguish real users from automated abuse.
- Error reports. Sentry captures uncaught errors, including the URL you were on and a stack trace. Personal data is scrubbed where possible; if a payload leaks into a stack trace it is treated as covered by this policy.
We do not collect: payment information (we do not currently accept payments), precise location, biometric data, contacts, or any data from your device beyond what your browser sends with HTTP requests.
2. How we use your information
We use the information above to:
- Provide the Service: render your portfolio, binders, watchlist, alerts, and share links.
- Authenticate you and keep you signed in.
- Send transactional emails: sign-in confirmations, password resets, and watchlist price alerts you opted into.
- Debug, monitor performance, and prevent abuse.
- Communicate material changes to the Service or to this policy.
We do not sell your personal information, and we do not share it with advertisers.
3. Data we display about cards and prices
The catalog data — card names, set information, current and historical prices — comes from third-party data providers (currently Scrydex). That catalog data is not personal information about you. Your portfolio, binders, and other collection data are linked to your account and are personal information.
4. Sharing your information
We share information only as needed to run the Service:
- Service providers (processors). We use third parties to host data, authenticate users, send email, and operate infrastructure. They process data on our behalf under their own privacy commitments:
- Supabase — database, authentication, and file storage
- Google — “Sign in with Google” authentication; we receive only the profile basics you authorize (name, email address, profile picture)
- Cloudflare — image storage and delivery (R2) and bot protection (Turnstile) on our authentication forms
- Vercel — Next.js application hosting
- Upstash — Redis cache and rate limiting
- Fly.io — background worker hosting
- Sentry — error monitoring
- Scrydex — TCG card catalog and pricing data (we send no personal data to Scrydex)
- Typesense Cloud — full-text search index
- Public share links. When you opt in to a share link for your portfolio, binder, or collection, the data you’ve chosen to expose becomes accessible to anyone who has the link. We do not index these links in search engines unless you choose to.
- Legal requirements. We may disclose information if required by law, court order, or to protect the rights, property, or safety of Allstar, our users, or the public.
- Business transfers. If Allstar is acquired or merged, your information may be transferred to the successor entity, subject to this policy.
We will update this list when we add or drop a processor.
5. Where your data is stored
Data is stored on infrastructure operated by the providers in Section 4. Our primary database (Supabase) is hosted in the United States (region us-west-1). Application hosting (Vercel) runs on a global edge network with origin compute in the United States, and image storage (Cloudflare R2) is globally replicated.
If you are located outside the United States, your data will be transferred to and processed in the United States. By using the Service you consent to this transfer.
6. Your rights
Depending on your location, you may have the following rights:
- Access — request a copy of the personal data we have about you.
- Correction — update inaccurate data. Most fields are editable in the app; for anything you can’t change yourself, email us.
- Deletion — request that we delete your account and associated data. Account deletion permanently removes your profile, portfolio, binders, watchlist, alerts, and share links. Public share links you’ve published will no longer load. Server logs and aggregated metrics may persist for the retention windows in Section 1.
- Portability — request a machine-readable export of your data.
- Objection / restriction — for EU/UK users under GDPR, you may object to or restrict certain processing.
- Withdraw consent — for any processing based on consent (e.g., marketing emails), you may withdraw consent at any time.
- Complaints — you may lodge a complaint with your local data-protection authority.
To exercise any of these rights, email hello@allstar.io. We will respond within 30 days.
7. California residents (CCPA / CPRA)
You have the rights listed in Section 6 plus the right to know the specific pieces and categories of personal information we collect, the right to non-discrimination for exercising your rights, and the right to opt out of any sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising).
8. Children’s privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it. Parents who believe their child has provided us with information may contact us at hello@allstar.io.
9. Data retention
- Account data — retained as long as your account exists, plus a short cooldown after deletion to handle reversals and complete the deletion across all processors.
- Server logs — 30 days.
- Error reports — 30 days.
- Backups — Supabase retains automated backups for the standard window for our plan. Deletion requests are honored on the live database immediately; backups age out on the standard schedule.
10. Security
We use industry-standard measures to protect your information: TLS in transit, encryption at rest on Supabase and Cloudflare R2, row-level security on user data, and separate keys for browser and server contexts. No system is perfectly secure; we cannot guarantee absolute security.
If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
11. Changes to this policy
We may update this policy. The “Last updated” date at the top reflects the most recent revision. For material changes we will provide additional notice (in-app banner or email) before the changes take effect.
12. Contact
For privacy questions, requests, or to exercise your rights:
Allstar Interactive LLC Email: hello@allstar.io
EU/UK users may also contact us at the same address.