Privacy Policy

Version 1.1.0 · Last updated May 16, 2026

1. What We Collect

  • Account info: email, display name, age, parent email (if minor), favorite sports/players.
  • Content you post: card photos, listings, trades, messages, support tickets.
  • Transaction records: amount, fees, currency, parties, Stripe identifiers, shipping address tied to an order, timestamps. Retained for at least 7 years (see Section 6).
  • Identity & tax data collected by Stripe for sellers (KYC, W-9/W-8). Rookie does not store full government ID numbers itself.
  • Technical: IP address, user agent, device info, basic analytics.

2. How We Use It

To operate the marketplace, process payments, match you with other collectors, prevent fraud and money laundering, comply with tax and financial regulations, respond to law enforcement, and improve the Service. We do not sell your personal data and we do not use it for third-party advertising.

3. Sharing

We share data with: Stripe and Stripe Connect (payments, payouts, KYC, tax forms), our cloud hosting and database provider (for storage and delivery), and government authorities when required by subpoena, court order, or applicable law (including IRS reporting and AML obligations).

4. Children (COPPA)

Users under 13 may only use the Service through a parent or legal guardian's account. For users aged 13–17, the parent email on file may receive notifications about purchases and trades, and the parent may request access, correction, or deletion of the minor's account and data at any time by contacting Support.

5. Your Rights

Depending on where you live (e.g., California CCPA/CPRA, Virginia VCDPA, EU/UK GDPR), you may have the right to access, correct, port, or delete your personal data, and to opt out of certain processing. To exercise these rights, contact Support. We will respond within the timeframe required by law. We will not retaliate against you for exercising these rights.

6. Data Retention & the 7-Year Transaction Rule

We keep personal data only as long as needed to provide the Service or as required by law. Specifically:

  • Transaction records (orders, payments, payouts, refunds, disputes, tax documents, Stripe IDs, amounts, parties, timestamps) are retained for a minimum of seven (7) years after the transaction date to satisfy IRS recordkeeping, state sales-tax rules, anti-money-laundering obligations, and payment-network requirements.
  • Card photos and listings are kept until you delete them or close your account.
  • Account profile data is deleted within 30 days of an account-deletion request, except where retention is required by law or by Section 6 above.
  • Support tickets and abuse reports may be retained for up to 3 years for security and quality purposes.

7. Security

Data is encrypted in transit (TLS) and at rest. Database access is restricted via row-level security so users can only see their own private data. Card photos live in a private storage bucket and are served via short-lived signed URLs. No system is perfect — report suspected breaches to Support immediately.

8. Cookies

We use first-party functional cookies and local storage for login sessions. We do not use third-party advertising trackers.

9. International Transfers

Rookie is operated from the United States. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. under appropriate safeguards.

10. Changes

We will record your acceptance of new versions of this policy with a version number, timestamp, IP address, and user-agent string.