TrackCollectibles · Effective date: June 9, 2026 · Last updated: June 9, 2026
TrackCollectibles is an iOS app that helps collectors track, value, and list their items. It is developed and operated by TrackCollectibles, based in Canada.
This policy explains what personal information we collect, why we collect it, who we share it with, and what rights you have over it. It applies to anyone who downloads or uses the TrackCollectibles app, whether you are located in Canada, the United States, or elsewhere.
If you have questions about this policy or want to exercise your privacy rights, see Section 14 – Contact Us.
When you create an account, we collect your email address and a hashed password. Authentication is handled by Supabase Auth — we never see your password in plain text.
When you add items to your collection, you provide information like item names, descriptions, photos, purchase price, current value, condition, grading details, and dates. This data is stored on Supabase servers on your behalf and is not sold or used for advertising.
When you use the AI scan feature to identify an item, the photo you submit is sent through our Supabase Edge Functions to Anthropic's Claude API for analysis. Scan photos are not permanently stored — they are processed and discarded once the scan completes. Anthropic's handling of this data is governed by Anthropic's Privacy Policy.
We track how many scans and listing generations you have used (lifetime total for free users, monthly total for paid subscribers). This is stored on our servers solely to enforce your plan's usage quota.
Your currency setting (USD or CAD) and enabled item categories are stored both on your device (in iOS local storage) and in your Supabase account so your preferences sync across reinstalls.
We use the information we collect only for the following purposes:
We do not use your personal information to serve you targeted advertising, and we do not sell your data to third parties.
This disclosure is made in accordance with the U.S. Federal Trade Commission (FTC) guidelines on endorsements and testimonials, and the eBay Partner Network agreement. We only surface eBay pricing because it provides useful market data for collectors — not because of the affiliate relationship.
When you tap a pricing link in the app, no personal information about you is sent to eBay. Only the search query (e.g., item name or category) is included in the request.
TrackCollectibles relies on the following third-party services to function. Each service has its own privacy policy governing its data practices.
We use Supabase for user authentication, our database, and serverless processing functions. Your account data and collection data are stored on Supabase infrastructure. Supabase operates servers primarily in the United States. Supabase Privacy Policy →
Scan photos are routed through our Supabase functions to Anthropic's Claude API for AI-powered item identification. Photos are not sent directly from your device to Anthropic — they go through our servers. Anthropic processes the image to return identification results and does not retain images beyond the scope of the API request under our data processing agreement. Anthropic Privacy Policy →
We query eBay's APIs to show you current market pricing for your items. Only search terms (item names, categories) are sent — no personal information about you is included. eBay Privacy Policy →
For certain item categories (such as vinyl records), we query third-party collectibles databases to assist with identification. Only search terms are sent — no personal information about you is included in these requests.
We plan to add grading certificate lookups for trading card verification. When this feature launches, this policy will be updated to describe what data is sent and to which service.
All subscription billing — Free, Premium, Dealer Pro, and Lifetime Founder plans — is processed entirely by Apple through StoreKit. We never see your payment card details or billing information. Apple's handling of payment data is governed by Apple's Privacy Policy →
TrackCollectibles is developed in Canada. Your data is stored on Supabase infrastructure, which operates primarily in the United States. By using the app, you acknowledge that your personal information may be transferred to and processed in a country outside your province or country of residence, including the United States, which may have different privacy laws than Canada.
We take steps to ensure that any service provider handling your data provides an adequate level of protection, consistent with our obligations under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).
We keep your account data and collection data for as long as your account is active.
You can permanently delete your account at any time from within the app: go to Profile → Delete Account. This deletes all of your personal information and collection data from our Supabase database immediately and cannot be undone.
Usage counters (scan counts) and any cached preferences may persist briefly in system logs before being purged as part of our routine log-rotation schedule (typically within 30 days).
Depending on where you live, you have the following rights regarding your personal information:
In addition to the rights above, Quebec residents have the right to:
You can also file a complaint with the Commission d'accès à l'information du Québec (CAI) at cai.gouv.qc.ca.
To exercise any of these rights, contact us using the information in Section 14. We will respond within 30 days.
TrackCollectibles is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you are under 14 and located in Quebec, you must have parental or guardian consent before creating an account, as required by Quebec Law 25.
If you believe a child has provided us with personal information without appropriate consent, please contact us and we will delete it promptly.
We plan to add optional rewarded video ads (watch an ad to earn a bonus scan). Google AdMob collects advertising identifiers and usage data. This policy will be updated — and the App Store privacy nutrition label will be revised — before AdMob is enabled. We will not enable AdMob without giving users adequate notice.
When PSA grading lookups are activated, this policy will be updated to describe what data (cert numbers) are sent and how they are handled.
We use industry-standard safeguards to protect your personal information, including encrypted connections (TLS) for all data in transit, and Supabase's built-in security controls for data at rest. Passwords are hashed and salted by Supabase Auth — we never store passwords in plain text.
No method of electronic storage or transmission is 100% secure. If you believe your account has been compromised, contact us immediately.
Some browsers and devices send "Do Not Track" (DNT) signals. TrackCollectibles does not track users across third-party websites or apps for advertising purposes, and we do not currently respond to DNT signals — not because we ignore your preferences, but because the app does not engage in the kind of cross-site tracking DNT signals are designed to address.
We may update this privacy policy from time to time. If we make material changes — for example, adding a new third-party service or new data collection — we will notify you via an in-app notice or email at least 14 days before the changes take effect. The updated effective date will always be shown at the top of this page.
Continuing to use the app after a policy change takes effect means you accept the updated policy.
For any privacy-related questions, requests to access or delete your data, or complaints, please contact our privacy officer:
We will respond to all privacy requests within 30 days. Requests relating to access, correction, or deletion of personal information are free of charge.