• Features
  • Pricing
  • Testimonials
  • FAQ
Log In
Create Free Account Join Now

Sync My Cards Privacy Policy

Effective date: September 17, 2026
Last updated: September 17, 2026
Version: 2.0

See also the Terms of Service. Prior versions of this document are in the archive.

Sync My Cards, LLC ("Sync My Cards," "we," "us," or "our") operates syncmycards.com, its subdomains, our applications, our API and our Model Context Protocol server (together, the "Service"). We are a California limited liability company located at 5737 Kanan Rd #832, Agoura Hills, CA 91301.

This Privacy Policy explains what personal information we collect, why, who we share it with, how long we keep it, and what rights you have. Our Terms of Service govern your use of the Service.

Sync My Cards is a business tool for card sellers. You must be 18 or older to use it. We do not offer accounts for minors.

Two roles, one policy. We handle two different kinds of data, and the distinction matters for your rights:

  • Your data as our customer. Your account, billing and support data. For this, we are the controller, and this whole policy applies.
  • Data we sync on your behalf. Listings, inventory and orders we access from your eBay, Shopify or other connected store, including your buyers' order details. For this, you are the controller and we act as your processor. We handle it under your instructions and under the Data Processing Addendum in Exhibit A of our Terms. If you are a buyer who purchased from a store that uses Sync My Cards, contact that store first; see Section 12.4.

Contents

  • 1. Notice at collection
  • 2. Information we collect
  • 3. How we use information, and our lawful bases
  • 4. Connected Platform data
  • 5. AI features and the MCP Server
  • 6. How we disclose information
  • 7. We do not sell or share your personal information
  • 8. How long we keep information
  • 9. Security and breach notification
  • 10. International data transfers
  • 11. Cookies and tracking
  • 12. Your rights
  • 13. Children
  • 14. Links to other websites
  • 15. Changes to this policy
  • 16. Contact us

1. Notice at collection

A summary of the categories of personal information we collect, in the terms California law uses. Details are in Section 2.

CCPA category Do we collect it? Purpose Disclosed to
Identifiers (name, email, postal address, IP address, account ID) Yes Account creation, billing, support, security Hosting, email and payment providers
Commercial information (plan, transaction history, listings and orders synced) Yes Providing the Service, billing Hosting and payment providers
Internet or network activity (pages viewed, feature usage, log data) Yes Operating and improving the Service, security Hosting provider
Geolocation (approximate, from IP address) Yes, approximate only Security, fraud prevention, tax determination Hosting and payment providers
Audio, electronic or visual information (product images you upload or that we sync) Yes Providing the Service Hosting provider, Connected Platforms
Professional or employment information (your business name, role) Yes Account setup, support Hosting provider
Sensitive personal information No Not applicable Not applicable
Biometric information No Not applicable Not applicable
Precise geolocation No Not applicable Not applicable
Education information No Not applicable Not applicable
Inferences used to create a profile No Not applicable Not applicable

We do not collect or store full payment card numbers. Our payment processor collects those directly.

We retain each category for the periods in Section 8. We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes that would require offering a right to limit.

Back to top

2. Information we collect

2.1 Information you give us

  • Account data. Name, email address and a password, plus any business name or profile details you add in your account settings.
  • Billing data. Billing address, plan selection, and the last four digits and expiration of your payment card, as returned to us by our payment processor. We never receive or store your full card number, CVV or bank credentials.
  • Support and communications data. The content of emails, support tickets and other messages you send us, and our replies.
  • Configuration data. Your sync rules, price mappings, markup settings, templates and other preferences.
  • Marketing and survey data. Information you provide when you subscribe to our mailing list or respond to a survey.

2.2 Information we collect automatically

  • Log data. IP address, browser type and version, operating system, device type, referring page, pages and screens viewed, timestamps, and actions taken in the Service.
  • API and sync logs. Records of requests made to and by the Service, including which Connected Platform operations were attempted and their outcomes. These are used for support, debugging and abuse prevention.
  • Approximate location, derived from IP address. We do not collect GPS or precise device location.
  • Cookie and similar technology data. See Section 11.

2.3 Information we receive from others

  • Connected Platform data. See Section 4.
  • Payment processor data. Confirmation of successful or failed charges, card brand and last four digits, and fraud signals.

Back to top

3. How we use information, and our lawful bases

If you are in the EEA, the UK or Switzerland, the "lawful basis" column is the legal ground we rely on under GDPR.

What we do Lawful basis
Create and operate your account, authenticate you, provide the features you enable Performance of a contract
Sync listings, inventory and orders with your Connected Platforms Performance of a contract
Bill you, collect payment, prevent payment fraud Performance of a contract; legitimate interests
Provide support and respond to your requests Performance of a contract
Send service notices, security alerts, renewal reminders and required auto-renewal notices Performance of a contract; legal obligation
Monitor, debug, secure and improve the Service Legitimate interests
Detect and prevent fraud, abuse and violations of our Terms Legitimate interests
Send marketing emails about our products Consent, where required, otherwise legitimate interests; you can unsubscribe at any time
Analytics on how the Service is used Consent for non-essential cookies; otherwise legitimate interests
Comply with law, respond to lawful requests, establish or defend legal claims Legal obligation; legitimate interests

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.

Back to top

4. Connected Platform data

4.1 Your role and ours

When you connect eBay, Shopify or another platform, we access data from that account at your direction, to provide the features you enable. For that data you are the controller and we are your processor. Our obligations are set out in the Data Processing Addendum in Exhibit A of our Terms, and include using the data only for the Service, not selling or sharing it, not training models on it, security measures, breach notification, and deletion on request.

You are responsible for having a lawful basis and the necessary notices and consents for the data you authorize us to access, and for your own privacy compliance as the merchant of record.

4.2 eBay

When you connect your eBay seller account, we may access:

  • Active and inactive listings, including titles, descriptions, item specifics, categories, conditions, prices and images
  • Inventory quantities and SKU data
  • Orders, including line items, order status, fulfillment status and order-related shipping details
  • Promoted Listings campaign data (read only)
  • Payouts, fees and other financial records for your sales (read only)
  • Traffic and sales analytics for your listings (read only)
  • Your seller account settings and policies, and the account identifiers needed to operate the connection

We also create, update, end and relist items on your behalf when you use those features.

eBay account deletion notifications. As required by the eBay Developers Program, we subscribe to eBay's Marketplace Account Deletion/Closure notification endpoint. When eBay notifies us that an eBay user has requested account closure or data deletion, we delete the data we hold about that user.

4.3 Shopify

Sync My Cards connects to your Shopify store through a custom app set up for your store, which you install and authorize in your Shopify admin. The permissions that app requests are limited to what the sync needs: products and product listings, variants and inventory, locations, orders, publications, metaobjects and purchase options. Through it we may access:

  • Product listings, including titles, descriptions, prices and product images
  • Product variants and inventory levels
  • Orders, including line items, fulfillment status and the recipient's name and shipping address
  • Shop information, including shop name, currency and store domain

We do not request access to your customer list or to customer payment data, and we do not access data unrelated to operating the Sync My Cards connector.

Protected customer data. Order data can include a buyer's name and shipping address. We handle it under Shopify's protected customer data requirements: we use it only to operate the order features you enable, we do not use it for marketing or any other purpose, we do not share it with anyone other than the subprocessors listed in Exhibit B of our Terms, we encrypt it in transit and at rest, and we delete or de-identify it when you disconnect the store, uninstall the app, or ask us to.

Shopify compliance webhooks. We subscribe to and act on the following:

  • customers/data_request: when a customer of your store requests their data, we compile the data we hold about that customer and provide it to you so you can respond, within the time Shopify requires.
  • customers/redact: when a customer requests deletion, we delete or de-identify the data we hold about that customer.
  • shop/redact: 48 hours after you uninstall the app, Shopify notifies us and we delete or de-identify the data we hold for your store.

4.4 Other integrations

Square. When you connect Square we may access your catalog items, inventory, orders (including the recipient name and address on a fulfillment), payments and payouts, customer records, invoices and merchant profile, and we create and update items and inventory on your behalf.

My Card Post. When you connect My Card Post we access your listings, orders (including the buyer's name and shipping address), offers and messages, and we create, update and end listings on your behalf.

4.5 How we use Connected Platform data

Only to:

  • Provide the inventory sync, order sync, listing management and multi-marketplace features within Sync My Cards
  • Display your listings and orders in your account
  • Let you create, update and manage listings across connected platforms from one place
  • Debug and support the connection, and prevent abuse

We do not sell it, rent it, use it for advertising, use it to train machine learning models, or share it with third parties other than the subprocessors listed in Exhibit B of our Terms, or as required by law.

4.6 Retention and deletion

Connected Platform data is retained while the connection is active. When you disconnect a platform, uninstall our app from that platform, or delete your account, we delete the associated platform-derived data within 30 days, except where we must retain it by law.

You may request immediate deletion at any time by emailing privacy@syncmycards.com.

Back to top

5. AI features and the MCP Server

On eligible plans you may connect a third-party AI client to your Sync My Cards account through our Model Context Protocol server.

If you do, your account data leaves our systems at your direction. The data the client requests is transmitted to the AI client and to the AI provider behind it. From that point, that provider's privacy policy and terms govern it, not this policy. We do not control what the provider does with it, how long they keep it, or whether they use it for model training. Read your AI provider's privacy terms before connecting a client, especially if your synced orders include buyer names and addresses.

On our side:

  • We log MCP requests (which tools were called, when, and by which connection) for security, abuse prevention and support.
  • We do not use data exchanged through the MCP Server to train machine learning models.
  • You can pause, change the permissions of, or disconnect an AI connection at any time from the Apps page in your account.

Back to top

6. How we disclose information

We disclose personal information only as described here.

6.1 Service providers and subprocessors. We use vendors to run the Service, including hosting, payment processing, transactional and marketing email, error monitoring, analytics and customer support. They may process personal information only to perform services for us, under contract, and may not use it for their own purposes. The current list is in Exhibit B of our Terms.

6.2 Connected Platforms. When you use the Service, we transmit your listing, inventory and order data to the Connected Platforms you have linked, which is the point of the Service.

6.3 Legal and safety. We may disclose information to comply with law, a subpoena or other lawful request; to enforce our Terms; to establish, exercise or defend legal claims; to prevent fraud or abuse; or to protect the rights, property or safety of Sync My Cards, our users or the public. Where we are legally permitted, we will make reasonable efforts to notify you of a government request for your data before complying.

6.4 Business transfers. If we are involved in a merger, acquisition, financing, reorganization or sale of assets, personal information may be disclosed under confidentiality obligations as part of diligence and transferred as part of the transaction. If your information becomes subject to a different privacy policy, we will notify you.

6.5 With your direction. Including transmission to an AI client you connect under Section 5.

6.6 Aggregated and de-identified data. We may create and disclose aggregated or de-identified information that cannot reasonably be used to identify you, your business or your customers.

Back to top

7. We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We have not done so in the preceding twelve months. We do not sell or share the personal information of minors, and we do not knowingly have any.

Back to top

8. How long we keep information

Data Retention period
Account data For the life of your account, then deleted or de-identified within 30 days of account deletion
Connected Platform data While the connection is active, then deleted within 30 days of disconnection, uninstallation or account deletion
Configuration and sync rules For the life of your account, then deleted within 30 days
Deleted listings Recoverable for 90 days, then permanently deleted
Billing records and invoices 7 years after the transaction, for tax and accounting purposes
Auto-renewal consent records 3 years, or 1 year after your subscription ends, whichever is longer, as required by California law
Support correspondence For as long as we need it to support you and to establish or defend legal claims
Application and API logs For as long as needed to operate, secure and debug the Service, then rotated; marketplace webhook payloads are deleted after 30 days
Account activity log For the life of your account
Marketing list membership Until you unsubscribe, plus a suppression record kept indefinitely so we do not email you again
Aggregated or de-identified data Indefinitely

We may retain information longer where required by law or where necessary to establish, exercise or defend legal claims, and will delete it when that need ends.

Back to top

9. Security and breach notification

We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest
  • Encrypted backups
  • Role-based access control, with access to production data restricted to personnel who need it
  • Logging of account activity and marketplace API calls
  • Separate development, test and production environments
  • Strong password requirements, mandatory two-factor authentication for administrative access, and optional two-factor authentication for your account
  • Use of PCI-compliant third-party payment processors, so that we never hold full card data

No system is perfectly secure. Transmission of data over the internet always carries some risk, and we cannot guarantee absolute security.

Breach notification. If we become aware of a personal data breach affecting your personal information, we will notify you without undue delay, and in any event within 72 hours of becoming aware, with the information reasonably available to us at that time, and will notify regulators and affected individuals where required by law.

Your part. Keep your password confidential, use a unique password, enable multi-factor authentication where available, and tell us immediately at support@syncmycards.com if you suspect unauthorized access.

Back to top

10. International data transfers

We are based in the United States and our infrastructure is located in the United States. If you are outside the United States, using the Service involves transferring your information to the United States, which may have different data protection laws than your country.

Where we transfer personal data from the EEA, the UK or Switzerland to the United States, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum, together with supplementary measures including encryption in transit and at rest and a policy of challenging overbroad government requests. These clauses are incorporated into the Data Processing Addendum in Exhibit A of our Terms, and you may request a copy at privacy@syncmycards.com.

Back to top

11. Cookies and tracking

We use cookies and similar technologies for:

  • Strictly necessary purposes: signing you in, keeping your session, security, and load balancing. These cannot be disabled without breaking the Service.
  • Preferences: remembering your settings.
  • Analytics: we do not currently use a third-party analytics service.
  • Marketing: none. We do not use advertising pixels.

Our cookies are the session cookie that keeps you signed in, the token cookie that protects forms against forgery, and Google reCAPTCHA on our sign-in, registration and contact forms.

You can control cookies through your browser settings. Blocking strictly necessary cookies will prevent the Service from working.

Do Not Track and Global Privacy Control. We do not respond to browser Do Not Track signals, because there is no common industry standard for them. Because we do not sell or share personal information, there is nothing to opt out of.

Back to top

12. Your rights

12.1 Everyone

Regardless of where you live, you can:

  • Access and update your account and profile data in your account settings.
  • Export your receipts and sales reports from the Service as CSV files.
  • Delete your account by emailing privacy@syncmycards.com from the email address on your account.
  • Disconnect any Connected Platform at any time from your account settings, which triggers deletion of that platform's data within 30 days.
  • Unsubscribe from marketing email using the link in any marketing message. We will still send service notices, billing notices and required legal notices while you have an account.

To submit a request, email privacy@syncmycards.com. We may need to verify your identity before acting, usually by confirming control of the email address on the account. If we cannot verify you, we cannot complete the request. We will not discriminate against you for exercising your rights.

12.2 California residents

Under the California Consumer Privacy Act as amended, you have the right to:

  • Know the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes, and the categories of third parties to whom we disclosed it. Section 1 and Section 6 provide this at the category level; you may also request the specific pieces.
  • Correct inaccurate personal information.
  • Delete personal information we hold about you, subject to legal exceptions such as our obligation to keep billing records.
  • Opt out of the sale or sharing of personal information. We do not sell or share it, so there is nothing to opt out of. See Section 7.
  • Limit the use of sensitive personal information. We do not collect sensitive personal information as CCPA defines it.
  • Non-discrimination for exercising any of these rights.

How to submit. Email privacy@syncmycards.com, or write to the address in Section 16. We will confirm receipt within 10 business days and respond within 45 calendar days, which we may extend once by an additional 45 days with notice to you.

Authorized agents. You may use an authorized agent. We will require written proof of authorization and may require you to verify your identity directly.

Shine the Light. California Civil Code Section 1798.83 also permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures. Requests may be sent to privacy@syncmycards.com.

12.3 EEA, UK and Switzerland

Where GDPR or the UK GDPR applies to our processing as a controller, you have the right to:

  • Access your personal data and receive a copy
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to legal exceptions
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interests, and to object to direct marketing at any time
  • Data portability, to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible
  • Withdraw consent at any time, where we rely on consent. Withdrawal does not affect processing already carried out.
  • Lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner's Office. In the EEA, a list is maintained by the European Data Protection Board. We would appreciate the chance to address your concern first.

We will respond within one month, extendable by two further months for complex requests, with notice to you.

Our lawful bases are in Section 3. International transfers are in Section 10.

12.4 If you are a buyer, not a Sync My Cards customer

If you bought a card from a seller who uses Sync My Cards, we process your order details, including your shipping address, as that seller's processor, on their instructions. Contact the seller first, because they control that data and can act on your request directly.

You may also email privacy@syncmycards.com and we will either forward your request to the relevant seller or act on it as their processor. If you shopped on a Shopify store, you can also submit a data request or deletion request through Shopify, and their mandatory webhooks will reach us automatically. See Section 4.3.

Back to top

13. Children

The Service is a business tool for people 18 and over. We do not knowingly collect personal information from anyone under 18, and we do not offer parent-managed or minor accounts. If you believe a person under 18 has provided us personal information, contact privacy@syncmycards.com and we will investigate and delete it.

Back to top

14. Links to other websites

The Service links to third-party websites, including Connected Platforms, that we do not own or operate. Their terms and privacy policies govern your use of them. A link is not an endorsement, and we are not responsible for their practices. Review their policies before using them.

Back to top

15. Changes to this policy

We may update this Privacy Policy. We will post the updated version here with a new effective date. For material changes we will notify you by email or in-app notice before they take effect, and will obtain your consent where required by law. Archived versions are available at syncmycards.com/privacy/archive. Your continued use of the Service after the effective date means you accept the updated policy.

Back to top

16. Contact us

Sync My Cards, LLC
5737 Kanan Rd #832
Agoura Hills, CA 91301
United States

  • Privacy questions, data requests and account deletion: privacy@syncmycards.com
  • General support: support@syncmycards.com

Back to top

Terms of Service | Archived versions of the Privacy Policy | syncmycards.com

Contact

Terms

Privacy

Login

Contact Us