1. Introduction
Ace Trainer Rips LLC (“we,” “us,” or “Company”) operates the Ace Trainer Rips platform (“Service”). This Privacy Policy explains what information we collect, how we use it, and your choices regarding that information.
2. Information We Collect
2.1 Information You Provide
- Account data — email address, display name, and password when you register
- Payment data — billing information processed through Stripe; we do not store full credit card numbers on our servers
- Shipping data — name and mailing address if you request physical delivery of cards
- Identity verification data — when identity verification is required (for example, before your first shipment), an image of your government ID and a selfie, which Stripe collects and processes on our behalf. We receive the result and the verified name, not the images (see Section 5)
- Communications — messages you send via live chat or customer support
2.2 Information Collected Automatically
- Usage data — pages visited, features used, Pack openings, and timestamps. When you are signed in, this is linked to your account identifier and email address
- Error data — technical details of errors (page, browser, and the error itself) to help us find and fix problems
- Device data — browser type, operating system, IP address, and device identifiers
- Cookies & similar technologies — session cookies for authentication and analytics cookies to improve the Service (see Section 8)
2.3 Third-Party Sources
If you sign in with a third-party provider (e.g., Google), we receive basic profile information (name, email, avatar) as authorized by you during the OAuth flow.
3. How We Use Your Information
- Operate, maintain, and improve the Service
- Process transactions and manage your wallet balance
- Verify your identity before shipping cards to you, for fraud prevention and legal compliance (see Section 5)
- Send transactional emails (receipts, shipping updates, account alerts)
- Respond to customer support inquiries
- Understand how the Service is used, and produce aggregated statistics for pricing models and business intelligence
- Detect, diagnose, and fix errors
- Enforce our Terms of Service and prevent abuse
4. How We Share Your Information
We do not sell your personal information. We may share data with:
- Payment processors — Stripe receives billing details to process your transactions
- Identity verification — Stripe (Stripe Identity) collects and processes your ID images and selfie to verify your identity (see Section 5)
- Hosting & infrastructure — Vercel (web hosting), Supabase (database & auth), and Railway (background workers) process data on our behalf
- Card intake & OCR — Google Cloud Vision receives images of graded card slabs to read their printed grading labels (optical character recognition) during inventory intake
- Grading verification — the Professional Sports Authenticator (PSA) API receives card certification numbers so we can look up and verify grading details during intake
- Shipping carriers — name and address are shared when you request physical delivery
- Analytics providers — PostHog (product analytics), Google Analytics, and Vercel Web Analytics receive usage and device data. For signed-in users, PostHog also receives your account identifier and email address so that usage can be linked to your account
- Error monitoring — Sentry receives technical details of errors in the Service. It is configured not to receive cookies, request headers, or IP addresses by default
- Embedded video — live streams are embedded using YouTube; when you view an embedded stream, YouTube (Google) may receive your device and usage data under its own privacy policy
- Legal obligations — we may disclose information when required by law, subpoena, or government request, or to protect our rights and safety
5. Identity Verification and Biometric Data
We may ask you to verify your identity before we ship cards to you — normally the first time you request a shipment — and, where we require it, before you add funds. Verification is performed by our service provider, Stripe, through Stripe Identity.
5.1 What is collected
- By Stripe: an image of your government-issued photo ID and a live selfie. To confirm that the selfie matches the photo on your ID, Stripe creates a scan of your face geometry from both images, which is a biometric identifier. It is used only for that match.
- By us: the result of the verification (verified or not), the first and last name on your ID, the date you were verified and when the verification expires, Stripe’s reference for the verification, and the time you gave consent and the version of the notice you agreed to. Stripe’s response can include other details read from your ID, such as your date of birth or address; we do not store them.
We never receive or store images of your ID or your selfie, and we never receive or store your face geometry.
5.2 Why we use it
- To confirm that the person requesting a shipment is the person behind the account, and that the recipient name on the shipping address matches the name on the verified ID
- To prevent fraud, including the use of stolen payment cards and accounts
- To help us meet our legal obligations
5.3 Consent
Before verification starts, we show you a notice describing the biometric data Stripe will collect and ask for your explicit consent. Verification does not begin unless you give it, and we record when you consented and to which version of the notice. If the notice changes, we ask again. You may decline; you can keep using your account, but we will not be able to ship cards to you (or, where verification is required for deposits, accept deposits) until you are verified.
5.4 Who processes it
Stripe collects and processes your ID images, selfie, and biometric data on our behalf, under the Stripe Privacy Policy. We do not sell, lease, trade, or otherwise profit from biometric data, and we do not disclose it to anyone other than Stripe, except where required by law.
5.5 Retention and deletion
ID images, selfies, and biometric data are retained by Stripe in accordance with its policy. We retain the verification result and verified name for as long as your account is open and as required by law. A verification is valid for three years, after which we ask you to verify again. If you ask us to delete your account, we delete the verification result and verified name with it and instruct Stripe to delete (redact) the verification data it holds, subject to anything Stripe is required to keep by law. You can also ask us to do this at any time by contacting us (see Section 9).
5.6 State biometric privacy laws
Some states, including Illinois (the Biometric Information Privacy Act), Texas, and Washington, have laws that give residents specific rights over biometric identifiers, including the right to notice and to give or withhold consent before collection, limits on disclosure and sale, and requirements to destroy the data when it is no longer needed. We handle biometric data as described in this section for all users, wherever they live.
6. Data Retention
We retain your account data for as long as your account is active. Transaction records are kept for at least 7 years to comply with financial reporting obligations. If you delete your account, we remove personal data within 30 days, except where retention is required by law. Aggregated statistics that do not identify you may be retained indefinitely. Identity verification data is covered in Section 5.5.
7. Data Security
We use industry-standard measures to protect your information, including TLS encryption in transit, encrypted storage at rest, row-level security policies in our database, and regular access reviews. No system is perfectly secure, and we cannot guarantee absolute security.
8. Cookies
We use the following types of cookies:
- Essential cookies — required for authentication and core functionality
- Analytics cookies — set by PostHog and Google Analytics to help us understand usage patterns and improve the Service. Vercel Web Analytics does not use cookies
You can disable non-essential cookies through your browser settings. Disabling essential cookies may prevent you from using certain features.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (“right to be forgotten”)
- Object to or restrict certain processing
- Request data portability
- Withdraw consent where processing is based on consent
To exercise any of these rights, email us at privacy@acetrainerrips.com. We will respond within 30 days.
10. Children’s Privacy
The Service is not directed to anyone under 18. We do not knowingly collect personal information from minors. If we learn that we have collected data from a child under 18, we will delete it promptly.
11. International Transfers
Your data may be processed in the United States and other countries where our service providers operate. By using the Service, you consent to the transfer of your information to these jurisdictions, which may have different data protection laws than your country of residence.
12. California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of the sale of personal information. We do not sell personal information. To make a request, contact us at privacy@acetrainerrips.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Service. Your continued use after changes take effect constitutes acceptance of the revised policy.
14. Contact
For privacy-related questions or requests, contact us at privacy@acetrainerrips.com.