> For the complete documentation index, see [llms.txt](https://gacha-docs.market.cards/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gacha-docs.market.cards/privacy-policy.md).

# Privacy Policy

*Last Update: 16 August 2026*

### 1. Scope and Personal Information Controller

This Privacy Policy explains how Market Cards Limited (a British Virgin Islands company, referred to as "Market.Cards", "we", or "us") collects, uses, discloses, retains, and protects personal information when you use market.cards, applications, accounts, wallet interfaces, Gacha, Vault, marketplaces, Buyback Offers, shipping, promotions, customer service, and related services.

For most platform processing activities, Market.Cards is the personal information controller or responsible organization. Service providers for payments, wallets, identity verification, Vault, logistics, or trading counterparties may act as data processors or independent controllers subject to their own privacy policies. This Policy does not supersede their policies.

### 2. Information We Collect

#### 2.1 Information You Provide

* **Account and Contact Information:** Username, name, email address, phone number, country or region, language, avatar, Privy user identifier (DID), social login profile, and wallet identifiers and authentication information associated with the account.
* **Identity and Compliance Information:** Date of birth, nationality, address, identity documents, selfie/liveness information, sanctions or source of funds information. KYC service providers may retain the original documents; we typically receive verification results and risk indicators.
* **Transaction and Collectibles Information:** Orders, Gacha reveals, DCR and ownership history, listings, bids, trades, Buyback Offers, USDC transactions, refunds, fees, Vault instructions, shipping addresses, customs information, card appeals, and customer service records.
* **Invitation and Referral Information:** Referral codes, relationships between referrers and invitees, and related reward records.
* **Communication and Content:** Customer service messages, complaints, questionnaires, reviews, invitation messages, and content you post.

#### 2.2 Information Collected Automatically

* **Device and Network Information:** IP address, device/browser type, operating system, application version, language, identifiers, time zone, and approximate location.
* **Usage Information:** Visited pages and features, clicks, session events, referring pages, crash/performance logs, and fraud and security events.
* **Cookies, Browser Local Storage, and Similar Technologies:** Login sessions, preferences, analytics, anti-fraud, and advertising technologies used only when enabled and with consent obtained in accordance with the law.
* **Public Blockchain Information:** Wallet addresses, networks, transaction hashes, Token/DCR events, and related public information. Blockchain data may exist publicly long-term and independently of us.

#### 2.3 Information Obtained from Third Parties

* KYC/AML, wallet, payment, anti-fraud, sanctions, and identity service providers.
* Vault, grading agencies, logistics providers, liquidity providers, buyers, sellers, and marketplaces.
* Public card price sources, blockchain explorers, public records, and legitimate data partners.
* Invitation partners or social login service providers that provide information at your direction.

#### 2.4 Inferences and Protection Signals

We may use the above information to generate fraud scores, account risk profiles, valuation inputs, eligibility indicators, and responsible usage signals.

### 3. Purposes of Use and Legal Basis

#### 3.1 Providing Services and Fulfilling Contracts

* Creating and securing accounts/wallets, and verifying operational instructions.
* Processing orders, revealing cards, maintaining DCR and ownership records, storing or shipping cards, operating listings and trades, inquiring/settling Buyback Offers, and providing customer service.
* Displaying transaction records, fees, inventory, card pool probabilities, valuations, and notifications.

#### 3.2 Complying with Laws and Protecting the Platform

* Verifying age and identity, and conducting sanctions, AML, wallet, fraud, tax, and source of funds screenings.
* Identifying manipulation, counterfeit cards, stolen goods, account theft, abuse, and security incidents.
* Responding to lawful requests, enforcing agreements, establishing or defending legal rights, and fulfilling accounting, tax, auditing, and retention obligations.

#### 3.3 Legitimate Interests or Local Equivalent Basis

* Improving features, reliability, pricing data, customer service, and product design.
* Conducting internal analysis, loss prevention, security protection, and understanding service performance.
* Sending non-marketing service messages; sending similar feature information where legally permitted and opt-out methods are provided.

#### 3.4 Consent

When required by law, we will obtain consent for specific Cookies, direct marketing, sensitive information, or cross-border transfers. You may withdraw consent for future processing, but this does not affect lawful processing prior to the withdrawal; certain optional features may become unavailable as a result. We will not make non-essential consent a condition of core services.

### 4. Automated Processing and Human Review

We may use automated tools to identify fraud, sanctions, account theft, suspicious transactions, responsible usage risks, valuation anomalies, or violations, which may result in delaying transactions or escalating them for human review. If a fully automated decision produces legal or similarly significant effects on you, and local laws grant such rights, you may request an explanation, human review, or reconsideration via <privacy@market.cards>.

### 5. Recipients of Information Disclosure

* **Service Providers:** KYC/AML, wallets, payments, Vault/grading, logistics, cloud services, security, analytics, communications, customer service, and professional advisors, subject to appropriate instructions and safeguards.
* **Transaction Counterparties:** Minimum information necessary for Buyback Offers, ownership verification, and settlement. We will not provide unnecessary KYC documents to another user.
* **Competent Authorities and Rights Protection:** Disclosed to regulators, law enforcement agencies, courts, tax/sanction authorities, or affected parties as required by law or to reasonably protect rights, safety, and property.
* **Corporate Transactions:** Disclosed to buyers, investors, lenders, or advisors bound by confidentiality and lawful use constraints during financing, mergers, restructuring, or sales.
* **At Your Direction:** When you request shipping, connect wallets, use social logins, publish content, or make other disclosures.
* **Aggregated or De-identified Information:** Data that cannot reasonably identify you. Except to test safeguards or as permitted by law, we will not attempt to re-identify it.

### 6. Payments, Wallets, and Blockchain

Payment, fiat on/off-ramp, and wallet service providers may independently collect identity, financial, payment, wallet, device, and compliance information. To initiate transactions, verify status, prevent fraud, handle customer service, and fulfill compliance obligations, Market.Cards may receive or retain your Privy user identifier, wallet address, chain ID, buy/sell direction, transaction and service provider identifiers, fiat and digital asset currencies and amounts, payment methods, country or region codes, transaction status, transaction hashes, risk or verification results, and related transaction records returned by the service providers. We typically do not receive full bank card numbers or full payment credentials. Public blockchain transactions can be viewed, copied, and analyzed by anyone. We cannot delete or alter public blockchain records; when necessary, we can unlink them from the frontend account, but the underlying records will persist.

### 7. Cookies, Browser Local Storage, Analytics, and Privacy Choices

We use essential Cookies and browser local storage to log in, remember preferences, prevent fraud, and operate services. We may use analytics tools after obtaining consent where required by law. We will not enable cross-context behavioral advertising or disclose information in a manner that may constitute a "sale/share" without first providing legally required notices and opt-out controls.

* You can stop receiving marketing messages through the unsubscribe link in marketing emails or by contacting <privacy@market.cards>; service, security, and transaction-related messages will not be affected.
* Where applicable, we recognize browser opt-out signals such as Global Privacy Control.
* If advertising tools are enabled, a practically usable "Your Privacy Choices" or equivalent link must be provided by the legal center before deployment.

### 8. Cross-Border Transfers

Market.Cards operates cross-border, and service providers may process information in the British Virgin Islands, Singapore, the United States, and countries listed in cross-border transfer inventories. The level of legal protection may vary by location. We will employ appropriate lawful mechanisms based on the data's origin, including contractual safeguards, equivalent protection obligations, legally obtained consent, or other recognized bases.

* **Singapore Data:** Unless exceptions apply, we require a standard of protection comparable to the Singapore PDPA.
* **South Korea Data:** The Privacy Center will publish recipients, countries, items transferred, purposes, time/method, and retention periods, and will obtain separate consent when required.
* **Malaysia Data:** Comply with the cross-border requirements of Act 709 and applicable mechanisms for equivalent protection, consent, or exceptions.
* **Taiwan Data:** Provide necessary notices and implement lawful safeguards for cross-border processing.

### 9. Retention Period

We retain personal information only for the period reasonably necessary to fulfill the purposes of this Policy, comply with legal obligations, handle disputes, ensure security, and enforce laws. Afterward, it will be deleted, anonymized, or securely isolated, except for backup cycles and immutable blockchain records. Typical targets are as follows:

* **Account and Ownership Records:** During the active account or card relationship, and typically no more than 7 years thereafter.
* **Transaction, Payment, Tax, AML/KYC, and Sanctions Records:** Typically 5–7 years after the transaction or relationship ends; longer when required by law or investigations.
* **Customer Service, Complaints, and Appeals:** Typically 3–7 years depending on the matter.
* **Security, Device, and Access Logs:** Typically 12–24 months; longer when required for investigations.
* **Marketing Preferences:** Until withdrawn, continuing to retain minimum records necessary to enforce the opt-out.

### 10. Security and Incident Response

We implement administrative, technical, and physical safeguards appropriate to the nature of the data, including access controls, encryption in transit and appropriate encryption at rest, logging, service provider vetting, isolation, backups, incident response, and employee confidentiality. No system can guarantee absolute security. In the event of an incident, we will conduct an assessment and notify affected individuals and competent authorities in accordance with applicable laws.

### 11. Your Rights and Requests

Depending on your local laws, you may have the right to know, access, obtain copies, correct, delete, restrict or stop processing, withdraw consent, object to direct marketing, port data, opt-out of sales/sharing/targeted advertising, limit sensitive information, learn about automated decisions, request human review, and appeal denied decisions. These rights may be subject to statutory exceptions.

* Please submit privacy requests via email to <privacy@market.cards>. We may require reasonably necessary information to verify your identity and the scope of the request.
* We only conduct reasonably necessary identity verification; we will not require you to create an account or provide excessive information for an opt-out request where prohibited by law.
* Where permitted by law and verifiable, requests may be submitted by an authorized agent.
* We will respond within the timeframes mandated by applicable law and explain the reasons for any refusal and the avenues for appeal.
* You will not be discriminated against for exercising privacy rights; however, if data essential to providing a feature cannot be processed, that feature may become unavailable.

### 12. Minors

The Services are intended only for individuals who are at least 18 years old and have reached the age of majority. We do not knowingly collect children's information for the Services. If you believe a child has provided information to us, please contact <privacy@market.cards>, and we will investigate and delete it in accordance with the law.

### 13. Regional Supplementary Terms

#### 13.1 Taiwan

Individuals in the Taiwan region may lawfully request to inquire/review, copy, supplement or correct, stop collection/processing/use, and delete data; rights that cannot be waived in advance by law are not limited by this Policy. The collection notice and this Policy will specify the controller, purposes, categories, period, territory, recipients/methods, rights, and potential impacts of not providing data.

#### 13.2 South Korea

For South Korean users, this Policy and the South Korean Privacy Center inventory will specify statutory collection items, purposes, retention/destruction, trustees, overseas transfers, rights procedures, the personal information protection officer, and the domestic representative. Necessary and optional consents shall be obtained separately. Users may lawfully request access, correction/deletion, suspension of processing, data portability, and review of eligible automated decisions. The South Korean services shall not launch until the real-name service provider, overseas transfer inventory, and representative information are completed.

#### 13.3 Malaysia

Malaysian users may request access and correction, withdraw consent, prevent processing likely to cause damage or distress, and opt-out of direct marketing in accordance with the Personal Data Protection Act 2010 and its amendments. When statutory thresholds or local rules demand, we will appoint and register a Data Protection Officer or local representative.

#### 13.4 Singapore

Singapore users may request access to personal information and its use/disclosure, and request correction in accordance with the PDPA. We comply with obligations regarding purpose, notification, accuracy, protection, retention, cross-border transfers, and data breach notification, and will provide a data protection contact.

#### 13.5 United States

Residents of applicable US states may have the right to access/know, delete, correct, port data, opt-out of sales/sharing/targeted advertising or specific profiling, restrict certain uses of sensitive information, use authorized agents, and submit appeals. California users also have the right to non-discrimination and to submit recognized browser opt-out signals. We do not sell personal information for monetary consideration; if enabled advertising technologies legally constitute a sale or sharing, we will provide an opt-out link and recognize applicable signals.

### 14. Policy Updates

We may update this Policy due to changes in laws, technologies, service providers, or services, and update the effective date; material changes will be separately notified in accordance with the law. If new purposes require consent, we will obtain consent again rather than merely relying on your continued use.

### 15. Contact and Complaints

* Privacy requests and inquiries: <privacy@market.cards>
* General customer service: <hello@market.cards>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://gacha-docs.market.cards/privacy-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
