Last updated July 16, 2026
Privacy Policy
This policy explains what information TradeWave collects, how it is used, and the choices you have. The short version: card recognition runs on your device, your vaults are private unless you share them, and we do not sell personal information.
TradeWave is operated by Dominic LaRocca, an individual doing business as TradeWave. References to “TradeWave”, “we”, “us”, and “our” mean Dominic LaRocca.
1. What we collect
Account information. When you sign in with Apple or Google, we receive provider identifiers and, when the provider supplies and verifies it, your email address. We also store account fields you choose to add, such as a username and bio.
Collection and vault data. The cards, sealed products, grades, quantities, acquisition details, vaults, visibility settings, sync records, and portfolio value snapshots you add or generate in the app.
Friend, profile, and public vault data. Friend and friend-request records, profile information you choose to add, public vault previews, and the timestamps and metadata needed to run those features.
Trade request data. The participants, request status, selected item identifiers, display-safe item and market-price snapshots, counter-request links, and timestamps needed to show and preserve a trade request. Trade requests do not include free-form messages, payment, shipping, or escrow information.
Scanner data. Raw card recognition runs on your device; camera frames are not sent to our servers to identify raw cards. For graded slabs, the app may read the cert number on-device and send the grader and cert number to our server for an optional cert lookup; the full camera frame is not sent for that lookup. If you opt in to contributing scan samples, TradeWave uploads a cropped, EXIF-free card image from confirmed scans, together with text the on-device scanner already read from that image and the card label you confirmed. These uploads are stored without your account identifier, are meant to show only the card — not your surroundings — and are not stored as account-linked personal photos.
Purchase data. For Apple in-app purchases we store subscription entitlement status, product identifiers, transaction-related data, expiration dates, and App Store server notification records needed to validate and maintain subscriptions.
Technical data. Logs, error reports, request metadata, IP-derived rate-limit information, and similar operational data used to secure, debug, and run the service.
2. How we use it
We use this information to create and authenticate accounts, sync your collection across devices, show portfolio values, run friend connections, friend-gated profiles and visibility-controlled vault access, and structured trade requests, validate subscriptions, secure the service and prevent abuse, debug incidents, improve card recognition, communicate service changes, and meet legal obligations.
3. What other people can see
Profile details such as your bio, counts, and shared-vault list are limited to you and accepted friends. Your username remains visible where needed to find you and manage friend requests. Vault visibility works as follows: a Public vault can be viewed by anyone, including people who are not your friends or are not signed in; a Friends vault can be viewed only by you and your accepted friends; and a Private vault can be viewed only by you. The two participants in a trade request can see its selected item snapshots, price comparison, status, and counter-request history.
4. Scan samples
Scan-sample contribution is off unless you turn it on, and you can turn it off at any time to stop future uploads. Contributed samples are stored without an account identifier and without EXIF metadata, so they are not kept as account-linked personal photos. Because those rows are intentionally not linked to your account, already-uploaded cropped card images, recognized text, and labels may remain in use as scanner evaluation data after you opt out.
5. Service providers & data sources
We share information with providers that help operate TradeWave: Cloudflare (hosting, storage, rate limiting, and operational logs), Apple (sign-in and purchases), Google (sign-in), and Sentry only when a Sentry DSN is configured. Sentry receives error-event details such as error type, error message, stack trace, environment, and debugging tags or context. We do not use a separate product analytics SDK or analytics service in the app today, and we do not sell personal information.
Card catalog, price, listing, and image data come from third-party market data providers, including Scrydex and eBay. Requests to these providers are made from our servers and do not include your account information.
6. Security
We protect information with measures including OAuth sign-in, short-lived access tokens, server-side rate limits, database constraints, and secure token storage on your device. No system is perfectly secure, and we cannot guarantee absolute security.
7. Retention
We keep account, collection, subscription, friend/profile, trade-request, and portfolio data while your account is active. When you delete your account, we delete your user record and primary account-linked vault, collection, session, sync, friend, and trade-request records from the live database, except where limited records must be kept for legal, security, or operational reasons.
Refresh-token sessions expire after 30 days. Expired session rows are pruned after an additional 7-day inspection window, and rotated refresh-token replay records are retained for up to 30 days with a per-token-family cap. App Store server notification records used for purchase validation are pruned after 30 days. Listing image override records are pruned after 180 days. Operational logs, error reports, database recovery copies, and provider records may persist after deletion according to our provider settings and legal or security needs. Scan samples stored without account identifiers may be retained as described above.
8. Your choices & rights
In the app you can update your profile, change vault visibility, turn scan-sample contribution on or off, sign out, or delete your account. Subscriptions are managed and cancelled through Apple. You can also contact us to request access, correction, deletion, or other privacy rights available where you live.
9. Children
TradeWave is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us and we will review and take appropriate action.
10. International use
TradeWave is operated from the United States and uses service providers that may process information in the United States and other countries. By using TradeWave, you understand that information may be processed outside your location.
11. Changes to this policy
We may update this policy. If changes are material, we will give notice in a reasonable way, such as an in-app notice or an updated effective date on this page.
12. Contact
Privacy questions or requests: [email protected].