This Privacy Policy explains how Hobby Smart Case, Inc. (“Slabline,” “we,” “us,” or “our”) collects, uses, and shares information when you use Slabline, a web application that provides a risk index, valuations, and insurance documentation for graded trading-card collections (the “Service”). By using the Service, you agree to this Policy.
1. Information We Collect
We collect the following categories of information:
- Account information. When you sign up, our authentication provider collects your email address, name, and—if you use a social login such as Apple or Google—a unique identifier from that provider. We do not receive or store your social-account password.
- Collection data. Information you enter about your collection, including card details, grades, purchase costs, storage conditions, and self-reported insurance details (such as insurer, policy number, and deductible).
- Usage and device data. Standard technical information such as IP address, browser type, and pages requested, recorded automatically in our hosting provider’s server logs to operate, debug, and secure the Service. We do not use third-party advertising or behavioral-analytics trackers (see “Cookies and Tracking” below).
2. How We Use Information
We use information to:
- Provide, maintain, and improve the Service, including generating your Slabline Score™, valuations, and insurance schedules;
- Authenticate you and secure your account;
- Communicate with you about your account, updates, and support;
- Detect, prevent, and respond to fraud, abuse, or security issues; and
- Comply with legal obligations.
We do not sell your personal information, and we do not use your collection data for advertising.
3. How We Share Information
We share information only as needed to run the Service, with the service providers (“subprocessors”) below, each of which acts on our behalf under contractual confidentiality and security obligations. We share with each only the information needed for its function:
- Clerk — authentication and identity management (your email, name, and login identifiers).
- Netlify — cloud hosting, application delivery, and server logs (technical and usage data).
- Neon — managed PostgreSQL database that stores your account and collection data.
- Stripe — payment processing for paid subscriptions. Card details go directly to Stripe; we do not receive or store your full payment-card number.
- CardHedge — market and comparable-sales data used to identify and value your cards. We send card identifiers (such as certification numbers), not your personal or insurance details.
- An email delivery provider used to send account, transactional, and (for eligible plans) weekly-brief emails.
- A currency exchange-rate provider used to display values in your local currency. No personal information is sent — only the currency codes to convert.
We do not sell your personal information and do not share it with advertising networks or data brokers. We may also disclose information if required by law, to enforce our terms, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honor this Policy).
4. Cookies and Tracking
We use only the storage strictly necessary to run the Service. This includes a session cookie set by our authentication provider to keep you signed in, and first-party browser storage for your own preferences (such as theme, display currency, language, and whether you have seen the product tour). These are not used to track you across other websites.
We do not use Google Analytics, advertising pixels, or other third-party behavioral-tracking technologies. If we introduce analytics in the future, we will update this Policy and, where required by law, request your consent first.
5. Third-Party Authentication
If you sign in with Apple or Google, your use of that login is also governed by that provider’s privacy policy. We receive only the limited profile information necessary to create and secure your account.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data as described below.
7. Security
We use reasonable administrative, technical, and organizational measures designed to protect your information, including encrypted transport and access controls. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at brian@hobbysmartcase.com. We will respond consistent with applicable law (including the CCPA and GDPR where they apply). We will not discriminate against you for exercising these rights.
9. Children’s Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
10. International Users
The Service is operated in the United States. If you access it from outside the U.S., you understand that your information will be processed in the U.S., where data-protection laws may differ from those in your jurisdiction.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will update the “Effective” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
12. Contact
Questions about this Policy or your data? Contact Hobby Smart Case, Inc. at brian@hobbysmartcase.com.