Legal

Privacy Policy

Last updated: April 23, 2026

1. Who We Are

SlabCircle ("we", "us", "our") operates the digital pack-opening platform at SlabCircle.com. We take your privacy seriously and are committed to protecting your personal data in compliance with applicable laws including GDPR and CCPA.

2. Data We Collect

  • Account data: Email address, display name, authentication session data, login audit events, and security settings such as authenticator MFA state for admin users.
  • Payment data: Payment method info processed securely by Stripe. We never store full card numbers.
  • Transaction records: Deposit amounts, pack purchases, sellback history, and balance changes stored in our database.
  • Shipping data: Name and address you provide when requesting card delivery.
  • Usage data: Pages visited, session duration, and browser type collected via Vercel Analytics.
  • Cookies: Session cookies for authentication and optional analytics cookies.

3. How We Use Your Data

  • To process deposits, pack purchases, and card shipments.
  • To maintain your account balance and transaction history.
  • To detect fraud and prevent unauthorized access.
  • To improve the platform and user experience.
  • To comply with legal obligations.

4. Data Sharing

We do not sell your personal data. We share data only with:

  • Stripe - Payment processing.
  • Supabase - Secure database hosting.
  • Vercel - Hosting and analytics.
  • SMTP mail provider - Transactional account emails such as verification and password reset messages.
  • Shipping carriers - Only your name and address, when you request card delivery.

5. Data Retention

We retain transaction records for a minimum of 7 years for accounting and legal compliance. Account data is retained until you request deletion. You may contact us at any time to request data deletion, subject to our legal obligations.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data (subject to legal obligations).
  • Opt out of analytics tracking.
  • Withdraw consent at any time.

To exercise any of these rights, email us at privacy@slabcircle.com.

7. Cookies

We use strictly necessary cookies for authentication. With your consent, we also use analytics cookies to understand how users interact with the platform. You can withdraw cookie consent at any time via the cookie banner.

8. Security

All data is transmitted over HTTPS. Payments are handled by Stripe and never pass through our servers. Account passwords are stored using salted, peppered hashing, sensitive MFA secrets are encrypted at rest, and administrative access requires authenticator-based multi-factor verification.

9. Contact Us

For privacy-related questions, contact us at privacy@slabcircle.com.