CollectorVaultCollectorVault
CollectorVault

Legal Document

Privacy Notice

Last updated: 31 May 2026 · Effective immediately upon global launch

Operator: CollectorVault is operated by Aaron Koh, an individual residing in Singapore. References to "we", "us", or "our" refer to this individual operator. CollectorVault is not an incorporated entity. By using our Services you acknowledge this and agree that your recourse is limited accordingly.

This Privacy Notice describes how and why we collect, store, use, and share ("process") your personal information when you use our Services — including the CollectorVault mobile application (iOS and Android), our website at collectorvault.app, and related features such as AI card scanning, collection management, livestreaming, and price tracking.

If you do not agree with this notice, please do not use our Services. For questions, email [email protected].

1. What Information Do We Collect?

Information You Provide

When you register or use our Services, you may provide:

  • Account details: email address, display name, profile photo
  • Social login data: name, email, profile photo from Google, Apple, Facebook, or X (see Section 8)
  • Collection data: card names, set details, grades, valuations, and collection notes you enter
  • Wishlist data: cards you are seeking, including optional geographic tags
  • Payment information: processed via Stripe and RevenueCat; we do not store raw card numbers
  • Communications: messages or feedback you send us
  • Streamer registration data: handle, social links, streaming preferences

Information Collected Automatically

When you use the app, we automatically collect:

  • Device information: device model, operating system, app version, device identifiers
  • Usage data: features used, screens viewed, session duration, scan events
  • IP address and approximate location (country/region level)
  • Precise location data, where you enable the geo-tagged wishlist feature (see below)
  • Push notification tokens, used to send you in-app alerts and streamer notifications
  • Authentication session tokens, stored locally on your device via Firebase Auth
  • Analytics events, collected via PostHog (see Section 5)

Camera and Image Data

Our core AI scanning feature requires access to your device camera. When you scan a card:

  • Your device camera captures an image of the card
  • The image is transmitted to Google's Gemini API for AI-based card identification
  • We do not permanently store raw card images on our servers after the scan is processed
  • Card scan metadata (card identified, time, result) may be retained in your account history

Google may use submitted data in accordance with its own data governance policies — see Google's Data Governance page.

Location Data

The geo-tagged wishlist feature uses your device location to tag cards you are seeking to specific geographic areas. Location data is collected only when you actively use this feature and is not used for advertising. You can disable location access in your device settings at any time.

Sensitive Information

We do not intentionally collect sensitive personal information such as racial or ethnic origin, health data, political opinions, or financial account credentials. Payment processing is handled entirely by Stripe and RevenueCat.

2. How Do We Process Your Information?

We process your personal information for the following purposes:

  • Account creation and management: to register you, authenticate your identity, and maintain your account
  • Service delivery: to run the AI card scanner, maintain your collection portfolio, and provide price data
  • Payment processing: to handle subscriptions via RevenueCat and Stripe
  • Livestreaming: to facilitate streamer sessions via our LiveKit infrastructure
  • Push notifications: to alert you to streamer events, price changes, and app updates
  • Analytics and improvement: to understand how features are used and improve the app
  • AI scanning: to identify cards via Google Gemini and return valuation data
  • Security and fraud prevention: to detect abuse and protect users
  • Legal compliance: to meet obligations under Singapore PDPA and applicable law
  • Communications: to respond to support requests and send service-related messages
3. Legal Bases for Processing

For users in the EEA, UK, or Switzerland, we rely on the following legal bases under GDPR:

  • Contract performance: processing necessary to deliver the Services you signed up for (account management, scanning, subscriptions)
  • Legitimate interests: analytics, security, fraud prevention, and improving our Services — where our interests do not override your rights
  • Consent: for optional features such as location-tagged wishlists and push notifications; you may withdraw consent at any time
  • Legal obligation: where processing is required to comply with applicable law

For Singapore users, we process your data in accordance with the Personal Data Protection Act 2012 (PDPA) — see Section 14.

4. When and With Whom Do We Share Your Information?

Service Providers (Data Processors)

We share data with the following third-party service providers who process it on our behalf:

Firebase Authentication — Google LLC

Authentication session management. Stores tokens locally on your device. Privacy Policy

Google Gemini API — Google LLC

AI card identification. Card images are submitted for processing. Google's data governance applies. Data Governance

PostHog

Product analytics. Anonymised usage events including feature interactions and screen views. No cookies used in mobile app. Privacy Policy

RevenueCat

Subscription and in-app purchase management. Handles subscription state, entitlements, and billing events. Privacy Policy

Stripe

Payment processing for subscriptions. We do not store raw payment card data. Privacy Policy

LiveKit (self-hosted)

Livestreaming infrastructure. Audio/video streams processed via our self-hosted LiveKit server on DigitalOcean (Singapore region).

Backblaze B2

Cloud storage for video clip segments generated from livestream sessions.

DigitalOcean

Cloud infrastructure hosting our backend services in the Singapore region.

Other Disclosures

  • Business transfers: if CollectorVault is sold or transferred, your data may be part of that transaction. We will notify you in advance.
  • Legal obligations: we may disclose data if required by law, court order, or regulatory authority.
  • Protection of rights: to enforce our Terms of Use, or protect the safety of users or others.

We do not sell your personal data to third parties. We do not share data for advertising purposes.

5. Analytics and Tracking Technologies

CollectorVault is a mobile application and does not use browser cookies. We use the following technologies:

  • PostHog: anonymised in-app analytics capturing feature usage, screen views, and session events. No cookies. Data processed on PostHog's servers. You can opt out via app settings.
  • Firebase Auth tokens: stored in your device's local async storage solely to maintain your authenticated session. These are not used for tracking.
  • Push notification tokens: device tokens registered with Apple (APNs) or Google (FCM) to deliver push notifications. You can revoke these in your device notification settings.
6. AI Scanning and Camera Data

The AI card scanning feature is central to CollectorVault. Here is how your data is handled:

  • Camera access is required to capture card images. We only access the camera when you initiate a scan.
  • Captured images are transmitted over an encrypted connection to Google's Gemini API for identification.
  • We do not build a training dataset from your scanned images without your explicit consent.
  • Scan results (card name, set, estimated value) are stored in your account history to populate your collection.
  • Card price valuations are estimates only. Do not rely on them as definitive financial information for insurance, resale, or investment decisions.

Google's handling of submitted data is governed by their terms — we encourage you to review Google's Data Governance documentation.

7. Livestreaming Data

CollectorVault includes a livestreaming feature for trading card sellers and collectors. When you use this feature:

Streamers

  • Your audio and video are processed in real time via our LiveKit server (self-hosted on DigitalOcean, Singapore region)
  • Stream sessions may be recorded as rolling MP4 segments for clip generation and replay features
  • Recordings are stored in Backblaze B2 cloud storage
  • By enabling a stream you consent to audio/video processing and potential recording
  • Streamers must be 18 or older

Viewers

  • We log which streams you viewed and for how long, for analytics purposes
  • Any chat messages you send during streams may be stored as part of the session record
  • Your IP address may be processed by LiveKit infrastructure during stream delivery
8. Social Logins

You may register or log in using Google, Apple, Facebook, or X. When you do, we receive profile information from that provider — typically your name, email address, and profile photo. We use this only to create and manage your CollectorVault account. We do not control how social platforms handle your data, and recommend reviewing their privacy policies separately.

9. International Transfers

Our primary infrastructure is hosted in Singapore (DigitalOcean). Your data may also be transferred to and processed in the United States and other countries by our service providers (Google, PostHog, RevenueCat, Stripe, Backblaze).

If you are located in the EEA, UK, or Switzerland: when we transfer your data outside these regions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (where applicable through our processors) or adequacy decisions. Our processors are contractually bound to handle your data securely.

By using our Services, you acknowledge that your data will be transferred to and processed in Singapore and potentially other countries.

10. How Long Do We Keep Your Information?

We retain your personal data only as long as necessary to provide the Services or as required by law. Specifically:

  • Account data: retained while your account is active. Deleted within 30 days of account deletion request.
  • Scan and collection history: retained while your account is active; deleted with your account.
  • Stream recordings: retained for up to 90 days unless you request earlier deletion.
  • Analytics data: anonymised; may be retained indefinitely in aggregate form.
  • Payment records: retained as required by applicable tax and financial regulations (typically 5–7 years).

When deletion is not immediately possible (e.g. data in backup archives), we will isolate the data from active processing until deletion can be completed.

11. Do We Collect Data From Minors?

We do not knowingly collect, solicit, or market to children under 18 years of age. Streamers must be 18 or older. By using our Services, you represent that you are at least 18, or that a parent or guardian has consented to a minor's use of the Services. If we learn that we have collected data from a user under 18 without parental consent, we will promptly delete that data and deactivate the account. To report such a case, contact us at [email protected].

12. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate or incomplete data
  • Deletion: request deletion of your personal data ("right to be forgotten")
  • Portability: request your data in a portable, machine-readable format
  • Restriction: request that we restrict processing of your data in certain circumstances
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: for any processing based on consent, withdraw it at any time without affecting prior processing

To exercise any of these rights, email us at [email protected] with the subject line "Data Subject Request". We will respond within 30 days.

If you wish to terminate your account, you can do so from within the app's account settings. We will delete your account and associated data within 30 days, subject to legal retention requirements.

13. Do-Not-Track Features

CollectorVault is a mobile application and does not respond to browser Do-Not-Track signals. We do not currently support a standardised opt-out mechanism for mobile analytics beyond the opt-out available in app settings. If a recognised standard is adopted that applies to us, we will update this notice accordingly.

14. Singapore PDPA Compliance

As an operator based in Singapore, we comply with the Personal Data Protection Act 2012 (PDPA). Under the PDPA:

  • We collect, use, and disclose your personal data only with your knowledge and consent, or as permitted by law
  • We take reasonable steps to ensure the accuracy of your personal data
  • We implement reasonable security measures to protect your personal data from unauthorised access, collection, use, disclosure, copying, modification, or disposal
  • We will not retain your personal data longer than necessary
  • You have the right to access and correct your personal data held by us

The data controller for the purposes of Singapore PDPA is: Aaron Koh, contactable at [email protected].

If you have an unresolved concern, you may contact the Personal Data Protection Commission (PDPC) Singapore at pdpc.gov.sg.

15. EEA, UK, and California-Specific Rights

EEA and UK (GDPR / UK GDPR)

If you are located in the European Economic Area or United Kingdom, you have additional rights under GDPR / UK GDPR as described in Section 12. You also have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, or your national DPA in the EU).

As we are not established in the EEA or UK, we are not currently required to appoint a formal EU/UK representative, but may do so as our user base in those regions grows. We commit to honouring all GDPR rights requests regardless.

California Residents (CCPA)

California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of the "sale" of personal information. We do not sell your personal information. To exercise your CCPA rights, contact us at [email protected].

Australia

Australian users have rights under the Privacy Act 1988 (Cth). You may request access to or correction of your personal information at any time by contacting us.

16. Updates to This Notice

We may update this Privacy Notice from time to time. The "Last updated" date at the top of this notice will reflect the most recent version. For material changes, we will notify you via in-app notification or email. We encourage you to review this notice periodically.

17. Contact Us

For questions, data requests, or concerns about this notice, contact:

Aaron Koh, operating as CollectorVault
Singapore
Email: [email protected]
18. How to Review, Update, or Delete Your Data

Based on applicable laws, you may have the right to access, correct, or delete your personal data. To submit a data subject access request, email us at [email protected] with the subject line "Data Subject Request" and describe your request. We will respond within 30 days.

You may also update your account information directly within the CollectorVault app, or delete your account through the account settings menu.

© 2026 CollectorVault · SingaporeTerms of Use