We collect what an order needs — where the cards go, how to reach you if the shipment is held or short, and proof the payment was real. We do not sell any of it. This page sets out exactly what is held, who else sees it, how long it stays, and how to have it deleted.
What we collect, and why
| What | Why we have it | How long we keep it |
|---|---|---|
| Name, shipping address, email, phone | To pack the order, print the USPS and UPS label, and reach you if the package is held, delayed or arrives short | Seven years, with the order record |
| What you ordered, and your order history | To handle returns, replacements and reorders without asking you for a receipt, and to keep the sale record behind a graded slab | Seven years |
| The result of your payment | The processor tells us the payment cleared, the card brand and the last four digits. That is all we are given and all we need to issue a refund to the same card | Seven years — the card number itself is never held by us at all |
| Checkout fraud signals — IP address, whether billing and shipping match, the device the order came from | Card testing and stolen-card orders follow expensive cards. 143 products here list at $500 or more, up to a $29,999 slab, and those orders get looked at by a person before they ship | With the order record |
| Delivery and signature records | Orders of $500 and up ship signature-required, so the carrier captures a signature and we keep the tracking history as proof of delivery | Seven years, with the order record |
| Your email address, if you subscribe | To send the restock and preorder notices you asked for | Until you unsubscribe, which is one click in any of them |
| Support emails and their attachments | To answer you, and to see what was already said the next time you write about the same order | With the order they relate to |
| Browsing and device data — pages viewed, search terms, referring site, browser, approximate location from your IP address | To see which of 165 collections and 2538 products people actually use and to fix the pages that break | 26 months |
What we never see
Your card number never reaches us. It is entered on the payment processor's own form inside the Shopify checkout, and what comes back to the store is a yes or a no, the card brand and the last four digits. Nobody here can read your full card number, your CVV or your bank login, because those are not in our systems to read.
We also do not ask for a date of birth, a Social Security number, an income bracket, or what else you collect elsewhere. If a field is not on the checkout, we are not collecting it.
Why we use it
- Fulfillment — picking, packing, printing the label, tracking, and arguing with the carrier when a package stops moving.
- Support — answering a question about an order, a return, or the condition of a graded card.
- Fraud prevention — screening at checkout and manual review of high-value orders, which protects the cardholder as much as it protects us.
- Legal obligations — sales tax records, chargeback evidence, and responding to a lawful request from a court or an agency.
- Fixing the store — knowing which collection pages and search terms get used, so the ones that do not work get rebuilt.
Your data is not used to set your price. Every product costs the same whoever is looking at it, from a $1.99 sleeve pack upward.
Who else touches it
Running a store means using other companies, and each of them sees only the slice of your data their job requires:
- Shopify — the platform this store is built on. Shopify hosts the site, runs the checkout and stores order data on our behalf as our processor. Their handling is covered by Shopify's privacy policy.
- The payment processor connected to this checkout — takes the card and tells us the result. We see the result, not the card.
- USPS and UPS — the carriers. They get the delivery name, address, ZIP code and, where you gave one, a phone number or email for the delivery notification.
- Our email provider — order confirmations, shipment notices, and marketing email if you opted in.
- Fraud screening inside the checkout — scores the order before it is released to be packed.
- Courts and agencies — only where a lawful request requires it. Nobody gets an order record because they asked politely.
That is the complete list. There is no data broker in the chain, no ad network, and no list rental.
What we do not do
- We do not sell or share your personal information. The statutory version of that sentence is in the rights section below.
- We do not run third-party advertising pixels on this store, so what you look at here does not follow you to another site.
- We do not build a personalized advertising profile out of your order history, or hand it to anyone who would.
- We do not email you because you browsed something. Marketing goes only to people who asked for it.
The same instinct that stops us weighing, searching, opening or re-wrapping a sealed booster box applies here: what is inside is not ours to go through.
Cookies and analytics
Essential cookies keep your session alive, recognize your cart between pages and let the checkout and its fraud screening work. They cannot be switched off, because without them there is no cart to switch them off from.
Analytics cookies record which pages and search terms get used. They are set through Shopify's analytics, and where your state requires consent before they are set, they are set only after you give it. We do not run advertising or retargeting cookies on this store.
How to turn analytics off. Use the cookie preferences link in the store footer, or block and clear cookies in your browser settings — every major browser does this in a few clicks and it works whatever we do. We also honor the Global Privacy Control signal, so if your browser or extension sends one, we treat it as an opt-out of analytics cookies without you needing to tell us twice. Blocking the essential cookies as well will stop the cart working, which is a description of how carts work and not a penalty.
Your rights over your data
You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, or ask us to delete it. Email storeprcards@gmail.com and we will action it within 45 days, free of charge. We will not treat you differently for asking — no worse price, no reduced service.
We do not sell or share your personal information, as those terms are defined by the California Consumer Privacy Act, and we have never done so. There is therefore nothing for a "Do Not Sell or Share My Personal Information" link to switch off, which is why you will not find one. If that ever changes, this paragraph changes with it and the link appears in the footer.
California, Colorado, Connecticut, Virginia and a growing list of other states give their residents these rights by statute. We apply them to everybody rather than checking which state you are in first.
To use any of those rights, email storeprcards@gmail.com, ideally from the address the order was placed with. If we cannot match a request to an order we will ask for one more detail — the order number or the shipping ZIP code — before we send anything, because handing an order history to the wrong person is itself a privacy failure. An authorized agent can make the request for you if they send written permission from you along with it.
How long we keep it
The table above gives the period for each kind of data. The short form: order records last seven years because sales tax and chargeback rules require a business to be able to produce them, browsing data lasts 26 months, and marketing consent lasts until you withdraw it.
A deletion request removes your contact details, your marketing subscription and your browsing data. Two things survive it, and we would rather say so than have you find out later: the minimum transaction record — order number, date, amount, sales tax — which we are legally required to keep, and a suppression entry holding your email address so that an unsubscribe stays honored instead of being undone by the next import.
Marketing email
You get marketing email only if you asked for it. Every message carries a working unsubscribe link, unsubscribing takes effect immediately rather than "within ten days", and it has no effect on the transactional emails about an order you have actually placed — you will still get the confirmation and the tracking.
Children
This store is not directed at children under 13 and we do not knowingly collect personal information from them. Plenty of what we sell is bought for children — the Pokémon and Lorcana shelves especially — and that is fine, but the account, the payment method and the shipping address have to belong to an adult.
If you believe a child under 13 has given us personal information, email storeprcards@gmail.com and we will delete it and the account it sits under.
Security
The store runs over HTTPS end to end, including the checkout. Card data is handled entirely on the payment processor's PCI DSS Level 1 infrastructure and never lands in our systems. Access to order records is limited to the people who pack orders and answer support, and it is removed when they no longer do either.
No system is beyond compromise, so here is the commitment that matters: if a breach ever puts your data at risk, we will tell you directly and promptly, and notify the regulators the law requires us to notify. We will not bury it in a policy update.
Contact us about your data
Email storeprcards@gmail.com with "Privacy request" in the subject line and it goes to the right place. You can also write to us:
PrCards
1125 Jupiter Park Drive, Unit 11, Jupiter, FL 33458, United States
We handle data requests in writing so that both sides have a record of what was asked and what was done, but if you would rather talk it through first, (971) 477-0012 is answered Mon–Fri 9:00 AM – 6:00 PM ET. Written requests are answered inside the window set out in the rights section above.
Complaints
If you think we have handled your personal information badly, tell us first — storeprcards@gmail.com — and we will investigate and reply within 30 days.
If you are not satisfied with that reply, you can complain to the consumer protection division of your state Attorney General, or to the Federal Trade Commission at reportfraud.ftc.gov. There is no federal data-protection regulator in the United States, so where you complain depends on where you live.
Changes to this policy
If this policy changes in a way that affects you, we will say so on this page with the date of the change and email anyone on the marketing list. We will not edit it quietly and then rely on you having agreed to a version you never saw.