Privacy Policy
How SuperCatch collects, uses, protects, and shares your information across our marketplace and partner integrations.
Key commitments
How we approach your privacy across every part of the platform.
Your Data, Your Control
Access, correct, delete, or export your data at any time through your account settings or by contacting us.
Transparent Sharing
We clearly disclose what data is shared with marketplace partners, payment processors, and shipping providers.
Industry-Standard Security
PCI DSS compliant payment processing, encrypted data transmission, and regular security audits protect your information.
AI with Disclosure
Our AI card recognition processes images for identification purposes. We disclose all automated processing clearly.
Contents
Jump to any section of this policy.
1. Information We Collect
We collect information in several ways to provide and improve our marketplace services. The categories below describe the types of personal information we collect and the sources from which we obtain it.
Information You Provide Directly
- Account registration details, including your name, email address, phone number, and mailing address
- Payment and billing information, including credit or debit card numbers, which are processed by our PCI DSS compliant payment processor (Stripe) and are not stored on our servers
- Identity verification documents submitted during seller onboarding, including government-issued identification
- Listing data, including card descriptions, photographs, condition assessments, and pricing information
- Communications with our support team, other users, and dispute-related correspondence
- Seller business information, including business name, tax identification numbers, and bank account details for payouts
- Profile information, including display name, avatar, and seller bio
- Search queries, saved searches, and wishlist selections
Information Collected Automatically
- Device and browser information, including device type, operating system, browser type and version, screen resolution, and unique device identifiers
- Usage data, including pages viewed, features used, search queries, session duration, click patterns, and referral sources
- Approximate location data derived from your IP address
- Transaction history, including purchases, sales, and payment records
- Log data, including IP addresses, access times, and error logs
- Cookies, local storage, and similar tracking technologies (see Section 5 for details)
Information from Third Parties
- Marketplace partner data when you connect accounts, including product data, order details, and buyer or seller identifiers from TikTok Shop, eBay, Amazon, Walmart, Shopify, WooCommerce, and other integrated platforms
- Payment processor data from Stripe, including transaction status, fraud risk assessments, and billing address verification
- Shipping provider data from USPS, UPS, FedEx, and integrated shipping services such as Shippo and ShipStation, including delivery status and address validation results
- Identity verification results from third-party verification services
- Publicly available data used for fraud prevention and platform integrity
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing, maintaining, and improving the SuperCatch marketplace platform and all associated services
- Processing transactions, payments, refunds, and payouts between buyers and sellers
- AI-powered card recognition, catalog matching, condition assessment, and pricing suggestions to enhance listing accuracy
- Listing management, inventory synchronization, and multi-platform distribution to connected marketplace partners
- Fraud detection, prevention, and investigation, including monitoring for counterfeit items, suspicious activity, and policy violations
- Customer support, dispute resolution, and enforcing our Terms and Conditions
- Personalizing your experience, including recommendations, search results, and content
- Sending transactional communications such as order confirmations, shipping updates, and account alerts
- Marketing communications, including newsletters and promotional offers, which you can opt out of at any time
- Analytics, research, and service improvement, including aggregate usage analysis and A/B testing
- Complying with legal obligations, responding to legal processes, and protecting our rights and the safety of our users
3. AI and Machine Learning Disclosure
SuperCatch uses artificial intelligence and machine learning technologies to enhance our marketplace services. We are committed to transparency about how these technologies process your data.
How We Use AI
- Card recognition via computer vision: when you upload images, our AI analyzes them to identify the card, set, year, and other attributes to assist with listing creation
- Automated catalog matching: AI matches your uploaded cards against our catalog database to suggest accurate product details and market pricing
- Duplicate detection: image hashing and metadata analysis identify potential duplicate listings to maintain catalog quality
- Fraud detection: algorithms analyze listing patterns, pricing anomalies, and user behavior to flag potentially fraudulent activity for human review
- Condition assessment assistance: AI provides preliminary condition suggestions based on image analysis, which sellers can review and adjust
Your Rights Regarding AI Processing
- No automated decision-making produces legal effects or similarly significant outcomes without human review and oversight
- All AI-generated suggestions (card identification, pricing, condition) are presented as recommendations that you can accept, modify, or reject
- You may request human review of any AI-assisted determination by contacting our support team
- You may opt out of certain AI-powered personalization features through your account settings
- Image data uploaded for card recognition is used solely for identification and catalog matching purposes
4. Information Sharing and Disclosure
We do not sell your personal information. We share your information only in the following circumstances and with the following categories of recipients:
Marketplace Partners
- When you connect an external marketplace account (such as TikTok Shop, eBay, Amazon, Walmart, Shopify, or WooCommerce), listing data, inventory levels, pricing, and order information are shared bidirectionally to enable multi-platform selling
- Buyer and seller identifiers necessary to fulfill orders placed through connected platforms
- Each marketplace partner maintains its own privacy policy, and we encourage you to review them
Payment Processors
- Stripe processes all payment transactions and receives payment card data, billing addresses, and transaction amounts
- Payment data is handled under Stripe's PCI DSS Level 1 certification and their own privacy policy
Shipping Providers
- Shipping carriers (USPS, UPS, FedEx) and shipping management services (Shippo, ShipStation) receive recipient name, shipping address, and package details necessary to fulfill orders
Service Providers
- Cloud hosting and infrastructure providers that store and process data on our behalf
- Email service providers for transactional and marketing communications
- Analytics providers that help us understand platform usage and performance
- Identity verification services for seller onboarding
- All service providers are bound by contractual obligations to protect your data and use it only for the purposes we specify
Legal and Safety Disclosures
- To comply with applicable law, regulation, legal process, or enforceable government request
- To enforce our Terms and Conditions (supercatch.com/terms-conditions) and other agreements
- To protect the rights, property, or safety of SuperCatch, our users, or the public
- In connection with a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, with notice provided to affected users
5. Cookies and Tracking Technologies
We use cookies and similar technologies to provide, secure, and improve our services.
Types of Cookies We Use
- Strictly necessary cookies: required for platform functionality, authentication, security, and fraud prevention. These cannot be disabled.
- Functional cookies: remember your preferences, language settings, and display options to enhance your experience
- Analytics cookies: help us understand how users interact with our platform, which features are most used, and where improvements are needed
- Marketing cookies: used to deliver relevant advertisements and measure the effectiveness of our marketing campaigns. These are only set with your consent where required by law.
Managing Your Preferences
- You can control cookies through your browser settings, including blocking or deleting cookies
- Disabling certain cookies may affect platform functionality, particularly authentication and shopping cart features
- We respect Do Not Track (DNT) browser signals where technically feasible
- Third-party analytics providers may set their own cookies, subject to their own privacy policies
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and resolve disputes. Specific retention periods are as follows:
- Active account data: retained for the duration your account remains active, plus 30 days after account deletion to process any pending transactions
- Transaction and financial records: retained for 7 years to comply with tax, accounting, and financial reporting obligations
- Listing data: retained while actively listed, plus 3 years after removal for dispute resolution and audit purposes
- Communication records: retained for 3 years for customer support quality and dispute resolution
- Analytics and usage data: retained in aggregate form for up to 26 months
- Identity verification documents: retained for the duration of your seller account, plus 1 year after account closure
- Server logs: retained for 90 days for security monitoring and incident response
- Upon receiving a valid deletion request, we will delete or anonymize your personal data within 30 days, except where retention is required by law or necessary for legitimate business purposes such as fraud prevention
7. Your Privacy Rights
Depending on your location, you may have specific rights regarding your personal information. We honor these rights regardless of where you reside, to the extent technically feasible.
Rights Available to All Users
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate or incomplete personal information
- Deletion: request that we delete your personal information, subject to legal retention requirements
- Data portability: request a machine-readable copy of your data for transfer to another service
- Opt-out of marketing: unsubscribe from marketing emails using the link in any marketing message or through your account settings
- Account closure: close your account at any time through account settings or by contacting support
California Residents (CCPA/CPRA)
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us and by our service providers
- Right to opt out of the sale or sharing of personal information. SuperCatch does not sell personal information as defined under the CCPA.
- Right to non-discrimination for exercising your privacy rights
- Right to correct inaccurate personal information
- Right to limit use and disclosure of sensitive personal information
- You may designate an authorized agent to submit requests on your behalf with proper verification
- To exercise these rights, contact us at privacy@supercatch.com or submit a request through our contact form under 'Privacy & Data Requests'
EU/EEA/UK Residents (GDPR)
- Legal bases for processing: contract performance (providing marketplace services), legitimate interests (fraud prevention, platform improvement), consent (marketing), and legal obligations (tax, compliance)
- Right to erasure (right to be forgotten) under Article 17
- Right to restriction of processing under Article 18
- Right to object to processing based on legitimate interests under Article 21
- Right to data portability under Article 20
- Rights related to automated decision-making and profiling under Article 22
- Right to lodge a complaint with your local data protection supervisory authority
- To exercise these rights, contact us at privacy@supercatch.com
Other US State Privacy Laws
- Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with consumer privacy laws may exercise analogous rights to access, correct, delete, and opt out of targeted advertising
- To submit a request under your state's privacy law, contact us at privacy@supercatch.com or use the 'Privacy & Data Requests' option on our contact page
8. Data Security
We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
- Encryption in transit using TLS 1.2 or higher for all data transmitted between your device and our servers
- Encryption at rest for sensitive data stored in our databases
- PCI DSS compliant payment processing through Stripe — credit card numbers are never stored on our servers
- Regular security assessments, vulnerability scanning, and penetration testing
- Role-based access controls and the principle of least privilege for employee access to user data
- Employee security training and confidentiality agreements
- Incident response procedures with defined notification timelines: 72 hours for GDPR-regulated incidents, and as required by applicable state breach notification laws
- Continuous monitoring for unauthorized access and suspicious activity
- While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
9. International Data Transfers
SuperCatch is based in the United States, and your personal information is primarily processed and stored in the United States. If you access our platform from outside the United States, your information will be transferred to, stored, and processed in the United States.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on standard contractual clauses approved by the European Commission and other applicable legal mechanisms to ensure that your data receives an adequate level of protection when transferred internationally.
By using our platform, you consent to the transfer of your information to the United States and other countries where our service providers operate, subject to the safeguards described in this policy.
10. Children's Privacy
SuperCatch is not directed at children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children under these age thresholds.
If we become aware that we have collected personal information from a child under the applicable age threshold, we will take steps to delete that information promptly. If you believe a child under 13 (or 16 in the EU) has provided us with personal information, please contact us immediately at privacy@supercatch.com.
Parents or guardians who become aware that their child has provided personal information to SuperCatch without their consent may contact us to request deletion of that information.
11. Third-Party Marketplace Data Handling
When you connect your SuperCatch account to third-party marketplace platforms, data flows bidirectionally between SuperCatch and the connected platform. This section explains how that data is handled.
Data We Receive from Marketplace Partners
- Product and listing data, including titles, descriptions, images, categories, and pricing from your connected marketplace accounts
- Order data, including order identifiers, buyer shipping addresses, item details, and transaction amounts
- Account identifiers and store information necessary to maintain the integration connection
Data We Share with Marketplace Partners
- Listing data, including product titles, descriptions, images, condition information, and pricing that you choose to sync or publish to connected platforms
- Inventory and stock levels to keep availability consistent across platforms
- Order fulfillment data, including shipping carrier, tracking numbers, and delivery status
Authorization and Revocation
- All marketplace connections use OAuth or similar secure authorization protocols. We never store your marketplace account passwords.
- You can review connected marketplace accounts in your SuperCatch account settings at any time
- You may disconnect any marketplace integration at any time, which stops future data synchronization. Data previously synced may be retained per our data retention policy.
- Disconnecting a marketplace does not delete data already transferred to the partner platform. Contact the partner directly to manage data on their platform.
12. Third-Party Links and Services
Our platform may contain links to third-party websites, services, and applications that are not operated by SuperCatch. This privacy policy does not apply to those third-party services.
We are not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third-party service before providing your personal information.
Third-party integrations available through our platform, including payment processing (Stripe), shipping services, and marketplace connections, are governed by their respective privacy policies in addition to this policy.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
For material changes, we will provide at least 30 days' advance notice via email to the address associated with your account and/or through a prominent notice on our platform before the changes take effect.
Your continued use of SuperCatch after the effective date of the updated Privacy Policy constitutes your acceptance of the changes, subject to our Terms and Conditions (supercatch.com/terms-conditions). If you do not agree with the updated policy, you may close your account.
We maintain a version history of this Privacy Policy, which is available upon request by contacting privacy@supercatch.com.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the methods below.
- Privacy-specific inquiries: privacy@supercatch.com
- General support: support@supercatch.com
- Phone: (888) 366-0930
- Online: supercatch.com/contact — select 'Privacy & Data Requests' as the inquiry type
- We will respond to all privacy-related requests within 30 days of receipt. For requests under GDPR, we will respond within one calendar month as required.
- For our full marketplace rules and user agreements, see our Terms and Conditions at supercatch.com/terms-conditions
- If you are not satisfied with our response, you may lodge a complaint with your local data protection authority (for EU/EEA/UK residents) or contact the relevant state Attorney General's office (for US residents).
Privacy FAQ
Answers to common questions about your data and privacy on SuperCatch.
Questions about your privacy?
Contact our team for privacy inquiries, data requests, or questions about this policy. We respond to all privacy requests within 30 days.
For urgent security concerns, email security@supercatch.com or visit our Trust and Safety page.
