To deliver Verdict, we use a small set of third-party service providers (“sub-processors”) that may process user data on our behalf. This page lists each one, what they do for us, what data they receive, where they process it, and a link to their published data-processing terms.
This disclosure is required for users covered by the GDPR (Article 28) and the UK GDPR. We publish it for all users because it’s the right baseline. We’ll update this page before adding, removing, or replacing a sub-processor that touches personal data. If you’d like email notification when this page changes, email support@verdict.cards and we’ll add you to the notice list.
Currently in Use
Vercel, Inc.
- Purpose: Application hosting, edge delivery, performance monitoring (Speed Insights).
- Data processed: IP address (truncated for analytics), request URL, user-agent, response timing. Speed Insights is cookieless.
- Location: United States (primary), global edge network for static assets.
- Terms: Vercel DPA · Privacy Policy
Supabase, Inc.
- Purpose: Authentication (email + password and magic-link sign-in) and database for your Collection, Watchlist, Player Collections, sales-history caches, rate-limit events, and Stripe subscription records.
- Data processed: Email address, salted-and-hashed password (Verdict never sees the plaintext), session cookies, card queries, your saved entries, hashed IP for rate limiting, and Stripe customer/subscription identifiers.
- Location: United States (US-East region).
- Terms: Supabase DPA · Privacy Policy
Functional Software, Inc. (Sentry)
- Purpose: Application error monitoring. Helps us find and fix bugs.
- Data processed: Uncaught exceptions, stack traces, request URL, user-agent. Session Replay is explicitly disabled. The SDK does not set cookies in our configuration.
- Location: United States.
- Terms: Sentry DPA · Privacy Policy
Anthropic PBC
- Purpose: Vision provider for the Grade Tool (grade prediction), Lot Calculator multi-card identification, AI bounds detection, and cert-label OCR / cert scan. Also handles AI Snap photos for any category CardSight doesn’t identify (Yu-Gi-Oh, Lorcana, One Piece, Bo Jackson Battle Arena, non-sport, etc.) and as a fallback when CardSight can’t identify a supported-category card. Also reads messages sent to support@verdict.cards to sort them (bug, wrong price, billing and so on) and draft a reply that a person reviews before it is sent.
- Data processed: Photos you upload to those features and text prompts derived from your inputs. For support, the subject and text of your messages; your email address is not sent. Anthropic does not train on data sent through the commercial API.
- Location: United States.
- Terms: Commercial Terms · Privacy Policy
CardSight, Inc.
- Purpose: Fallback catalog lookup when our own checklist data doesn’t cover a card; sold-comp and grade data for selected categories; and vision provider for AI Snap identification on the search page for supported categories (sports, Magic, Pokémon).
- Data processed: Card query text and, for AI Snap on supported categories, the card photo. AI Snap for other categories routes to Anthropic instead. No Collection, Watchlist, account, or contact information is sent. CardSight is not used for Grade Tool, Lot Calculator bulk identification, or cert scanning — those flows go to Anthropic. CardSight results are used to answer your request in real time; we do not retain them as a stored catalog.
- Location: United States.
- Terms: Privacy Policy
GemRate, Inc.
- Purpose: Population reports for PSA, BGS, SGC, CGC, and CSG.
- Data processed: Card query text and, when used, certification numbers entered by the user. No personal data.
- Location: United States.
- Terms: Privacy Policy
TCGplayer, Inc.
- Purpose: Trading card game raw-market pricing reference.
- Data processed: Card query text only. No personal data.
- Location: United States.
- Terms: Privacy Policy
eBay Inc. (Browse / Marketplace APIs)
- Purpose: Active-listing search and single-item detail/aspect retrieval through the eBay Browse API — used for the active-supply signal and to help identify what is in a lot. Sold-listing comps do not come from this API. Verdict is not affiliated with, endorsed by, or sponsored by eBay.
- Data processed: Card query text. No personal data, no account access, no order history.
- Location: United States.
- Terms: eBay User Privacy Notice
Apify Technologies s.r.o.
- Purpose: Primary source of eBay sold-listing (comp) data for most categories — sold comps for a few categories are served by CardSight instead — and server-side eBay listing retrieval for Lot Calculator URL imports.
- Data processed: The eBay listing URL or card query you submitted. No personal data, no account access.
- Location: European Union (Czech Republic), with global edge infrastructure.
- Terms: Apify DPA · Privacy Policy
Stripe, Inc.
- Purpose: Merchant of record for Pro and Founders subscriptions through Stripe Managed Payments (sold through Link): payment processing, subscription billing, sales tax and VAT collection and remittance, receipts, payment support, fraud screening and disputes, plus the customer portal.
- Data processed: Billing email, name, address, and payment-card information (collected directly by Stripe; never stored on Verdict servers). Stripe uses the billing address to calculate tax.
- Location: United States, with regional sub-processors per Stripe’s DPA for EU/UK card processing.
- Terms: Stripe DPA · Privacy Policy
Resend Inc.
- Purpose: Transactional email delivery — sign-in magic links, password reset emails, and account/billing notifications. Configured as Supabase Auth’s custom SMTP provider. Also receives a copy of mail sent to support@verdict.cards so it can be logged as a support ticket, and sends the automatic acknowledgement.
- Data processed: Recipient email address and message content; for support mail, the sender’s name, email address, message content and attachments.
- Location: United States.
- Terms: Resend DPA · Privacy Policy
GitHub, Inc.
- Purpose: Our private issue tracker. When a support message reports a bug, a wrong price or a missing card, a summary goes there so it can be fixed.
- Data processed: A summary of the report and the card or search it concerns, with names, email addresses and phone numbers removed, and a ticket number. Your identity stays in our own database.
- Location: United States.
- Terms: GitHub DPA · Privacy Statement
ntfy.sh
- Purpose: Push notifications to our own phone when a support message needs a person urgently, such as a billing or data request.
- Data processed: The ticket number, why it needs attention, and a one-line summary, with email addresses and phone numbers removed. ntfy keeps a message on its server for up to 12 hours so it can be delivered.
- Terms: Privacy Policy
Not Yet in Use (Listed Now for Transparency)
We’ll add a provider here when we know its name in advance of a feature shipping. There are no pending sub-processors at this time.
International Data Transfers
Every sub-processor above either operates from the United States or publishes a DPA that incorporates the European Commission’s Standard Contractual Clauses (SCCs) and the corresponding UK and Swiss addenda. For users in the EEA, UK, and Switzerland, those SCCs are the legal basis for transfer of personal data to the United States. See each linked DPA above for the specific clauses and supplementary measures the vendor has in place.
Notification of Changes
We will update this page before engaging a new sub-processor that processes personal data. The “Last updated” date at the top of the page is authoritative. Email support@verdict.cards if you would like to be added to the notification list, or if you object to a new sub-processor — under GDPR Article 28(2), you have the right to do so.
Questions
Anything about how data flows through Verdict: support@verdict.cards, or write to the address on the Contact page.
