Privacy Policy
Last updated: September 18, 2026
This Privacy Policy describes how Abaza Business Services ("we", "us", or "our") collects, uses, and protects information when you use The Vault application and website (collectively, the "Service") available at myvaults.io and app.myvaults.io.
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, and all applicable privacy laws.
1. Data Controller
The data controller for personal data processed through the Service is:
Abaza Business Services
Email: cards@myvaults.io
2. What Data We Collect
We collect only the data necessary to provide and improve the Service:
- Account data: Email address, display name, and profile photo (collected when you register or sign in with Google).
- Card collection data: Images of trading cards you upload, and metadata we derive or you provide (player name, set, condition, estimated value, notes).
- Usage data: Pages visited, features used, error logs, and device/browser type — collected via Firebase Analytics and Vercel Analytics for performance monitoring.
- Public profile data: If, and only if, you choose to publish a profile: the handle you claim, your display name, your bio, and the cards you have chosen to show. See Section 5.
- Reactions: If you react to a card on someone's public profile, we store which reaction you gave and which card you gave it to, linked to your account. The collector who owns that card is told your name. See Section 5.
- Reports: If you report a profile, we store the report, what it refers to, and the account that filed it.
- Referrals: If you sign up through someone's invite or profile link, we store which account referred you, so their reward can be credited.
- Communications: Any messages you send to us via email or support channels.
We do not collect payment information. We do not sell your personal data.
3. Legal Basis for Processing (GDPR)
We process your personal data under the following lawful bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you requested — account creation, card storage, AI analysis, and showing your collection to other collectors, which is what the Service is for. You are told this before you create an account and you can make your collection private at any time.
- Legitimate interests (Art. 6(1)(f)): Analytics and security monitoring to operate and improve the Service.
- Consent (Art. 6(1)(a)): Showing estimated values on your public profile, and any marketing communications. Both are off unless you switch them on, and you may withdraw consent at any time by switching them off again.
- Legal obligation (Art. 6(1)(c)): Where required by law.
4. How We Use Your Data
- To create and manage your account.
- To identify your cards by matching your photo against a card catalogue (processed via Ximilar — see Section 8).
- To describe and assess the condition of your cards using AI (processed via Anthropic's Claude API — see Section 8).
- To fetch pricing estimates relevant to your cards from public market data sources.
- To generate shareable card images on your request.
- To publish your profile page, if you have switched one on, and to show reaction counts on it.
- To diagnose errors and improve the Service.
- To comply with legal obligations.
5. Public Profiles, the Feed and Reactions
Your collection is public by default. The Vault is a place collectors show each other what they own, so when you create an account your collection is visible to other people and you can make it private whenever you want. We tell you this on the sign-up screen, before you create the account, and the switch is in profile settings under Public profile.
Every account is given a web address in the form myvaults.io/u/yourhandle. The handle is generated for you and is never built from your name or your email address; you can change it to anything you like. A public page is public: anyone with the link can open it without an account, and search engines and other people may copy, cache or screenshot what is on it. Please treat anything you publish as permanently out of your hands.
While your collection is public, the page and the collectors' feed show:
- Your handle, your display name and your bio.
- The cards in your collection, including the photographs you uploaded of them and the details recorded against them.
- Estimated values, only if you separately switch that on. It is off by default and we recommend leaving it off. These are physical objects in your home, and what they are worth is nobody else's business.
Your email address is never shown — not on your profile, not in the feed, and not in your handle. If your display name happens to be an email address, we do not publish it; we show your handle instead.
The feed. Cards you add appear in a feed that other collectors see, with your handle and display name attached. Making your collection private removes them from it.
Making it private. Switching your profile off takes the page down and removes your cards from the feed immediately. Copies already made by search engines, caches or other people are outside our control.
Handles. If you change your handle, the old one keeps pointing at your profile for 30 days so that links people have already shared do not break, and is reserved for that period so nobody can immediately take it and inherit your traffic. After 30 days it becomes available again.
Reactions. Reacting to someone's card records that your account gave that reaction, so that you can take it back and so the same reaction cannot be counted twice.
The collector you react to sees your name. They receive a notification naming you and the card, and if your own collection is public they can open it from there. Everyone else sees only the total for each reaction: we do not publish a list of who reacted to what, and the counts shown on a public page are never attributed. If you would rather not be seen, do not react.
Reactions given before 17 September 2026 were given while reactions were anonymous, and they notify nobody. Only reactions from that date onward carry your name.
Reports. You can report a profile, a card in the feed, or a comment. We store the report and which account filed it, so that we can act on it and so that the reporting tool cannot be abused. Reports are readable only by us.
6. Data Retention and Account Deletion
We retain your account and collection data for as long as your account is active.
If you delete your account, then within 30 days, except where we are required to keep something by law:
- Your account, your card collection and the images you uploaded are deleted.
- Your public profile is taken down, your cards are removed from the feed, and your handle is released.
- Reactions you gave to other people's cards are kept, but anonymised. The link to your account is severed so the reaction can no longer be traced back to you. The count stays on the other collector's card. We do this because those counts belong to their page, and removing them would silently rewrite something that matters to somebody else. Once anonymised a reaction cannot be traced to you or attributed to you, and we cannot restore the link.
- Reports you filed are retained in anonymised form where an outcome depends on them.
Server logs are retained for up to 90 days for security and debugging purposes.
To delete your account, see Delete your account.
7. Cookies and Tracking
The website uses minimal cookies:
- Strictly necessary: Firebase Authentication session tokens — required for you to stay logged in.
- Analytics: Vercel Analytics and Firebase Analytics collect anonymised usage data. No advertising trackers are used.
You can disable analytics cookies in your browser settings at any time without affecting core functionality.
8. Third-Party Services
We use the following third-party services to operate the Service. Each acts as a data processor under appropriate agreements:
- Google Firebase (Google LLC) — authentication, Firestore database, and file storage. Data may be processed in the US. Google is certified under the EU-US Data Privacy Framework. See Firebase Privacy.
- Anthropic — AI card analysis. Card images and metadata are sent to Anthropic's API for processing. Anthropic's data processing is governed by their Privacy Policy. We do not send personally identifiable information to Anthropic beyond what is strictly necessary.
- Vercel — web hosting and serverless API functions. See Vercel Privacy Policy.
- Ximilar (Czech Republic) — card recognition. The photograph you take of a card is sent to Ximilar and matched against a card catalogue. No account details are sent with it. See Ximilar Privacy Policy.
- eBay — public sales data used to estimate card values. No personal data is sent for pricing. Separately, if you ever connect your own eBay account to list a card, you authorise that through eBay directly and the resulting listing is made in your name; we never see your eBay password.
- PriceCharting, SportsCardsPro and CardTrader — public market price data used to estimate card values. We send the card's details, never yours.
- Google Programmable Search — used to look up card and set information. No personal data is sent.
- Pexels — royalty-free images used in articles. No personal data is sent to Pexels.
9. International Transfers
Some of our third-party providers are based in the United States. Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including reliance on Standard Contractual Clauses (SCCs) or certification schemes such as the EU-US Data Privacy Framework.
10. Your Rights (GDPR)
Under the GDPR and UK GDPR, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data.
- Right to restriction: Ask us to limit how we use your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at cards@myvaults.io. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK, or your national supervisory authority in the EU).
11. Data Security
We implement industry-standard security measures including HTTPS encryption in transit, Firebase Security Rules restricting data access to authenticated owners, and regular review of access controls. Collections are private to their owner by default, and only the cards on a profile you have switched on are readable without signing in. No method of transmission over the internet is 100% secure, but we take reasonable steps to protect your data.
12. Children's Privacy
The Service is not directed at children under the age of 13 (or 16 where applicable under local law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes your acceptance of the updated policy.