Skip to main content
Privacy

Privacy policy

This versioned artifact carries the draft Chase Sets privacy notice for the public policy corpus: what personal information the marketplace collects, why, who receives it, and the choices and rights that apply. Every section requires qualified counsel review, and nothing in it takes effect before counsel approves the final language, launch scope, and external approval reference.

Policy version

Version v1

Effective date pending counsel approval

Locale en

What this notice covers

Counsel-approved language required

This privacy notice describes how Chase Sets Limited (“Chase Sets”) collects, uses, shares, and retains personal information when you visit the Chase Sets website, join the waitlist, create an Account, buy or sell trading cards and related collectibles, set up payouts, or contact support. It applies to the Chase Sets marketplace and its account, developer, and support surfaces. It does not replace the Terms of Service or the other policies that govern your use of the marketplace, and it does not cover the independent practices of other users or of providers acting under their own notices, such as the payment processing described in the Stripe-managed processing section below.

Information Chase Sets collects, and where it comes from

Counsel-approved language required

Chase Sets collects account and profile information you provide when you register, such as your display name, email address, a phone number when you provide one for phone-based sign-in, and your password, passkey, or other sign-in credential. When you choose Google or Facebook social login, Chase Sets receives a mapped profile from that identity provider: the provider's own subject identifier for you, any available email address and whether that provider treats it as verified, your display name, and your given and family names where available. For Google, that mapped profile also includes the hosted domain (the Google Workspace domain claim) when the signing-in account has one. Before launch, the waitlist collects your email address, whether you want to buy or sell, your interests, an email consent timestamp, a separate optional marketing consent timestamp, and, for seller signups, a self-reported inventory-size bucket. Using the marketplace creates activity records: Listings and the evidence images you attach to them, Offers, Orders, reviews, Wallet ledger entries, and payout requests. Fulfilling an order uses the destination address the order is delivered to, which also determines the order's tax jurisdiction. Contacting Chase Sets creates support and feedback records: Support Requests, the evidence you and the other party attach to them, and survey or feedback responses. Your browser also supplies technical information: the first-party cookies and browser storage described in the cookies section below, and bounded analytics events that include the page path, campaign (UTM) parameters, and the referrer of the page you arrived from. Chase Sets collects this information directly from you and your device; from Google or Facebook when you choose that provider for social login; from other users, for example when a buyer or seller opens a Support Request about your order or reports a Listing; and from its payment processor, in the form of provider references and provider-neutral payout-readiness statuses rather than the underlying verification details.

How Chase Sets uses personal information

Counsel-approved language required

Chase Sets uses personal information to operate the marketplace: to create and secure your Account and sign-in sessions; to publish Listings, form Orders, and process purchases, refunds, Wallet activity, and payouts; to verify shipping addresses, buy postage, and deliver orders; to determine the tax jurisdiction of an order from its destination address; to run the Support Request process and resolve order problems; to detect and limit fraud and abuse, including screening registrations while admission is invitation-gated, applying the sale-clearance qualifiers described in the automated-decisions section, and identifying accounts that share payment-instrument or shipping-address risk signals; to send transactional email and text messages about your Account, orders, and payouts; to send early-access updates to waitlist signups and, where you separately opted in, additional product updates; to measure landing-page and campaign funnels with bounded, provider-neutral analytics; and to keep the records Chase Sets needs for legal, tax, audit, and security obligations.

Who receives personal information

Counsel-approved language required

Chase Sets shares personal information with the companies that perform specific functions for the marketplace: Stripe, which processes payments and payout-account onboarding as described in the next section; a postage provider, which verifies shipping addresses and creates shipping labels; an email-delivery provider and a text-messaging provider, which deliver transactional messages; and the cloud infrastructure providers that host the marketplace and store uploaded images. Separately, when you choose Google or Facebook social login, Chase Sets sends that identity provider an authentication request identifying that you are signing in to Chase Sets, and receives that provider's mapped profile in return. Chase Sets also shares information with other users when a transaction requires it — for example, the order and delivery details a sale needs to be fulfilled, and the evidence both parties can see inside a Support Request — and with authorities or other parties where Chase Sets believes in good faith that disclosure is required or permitted by law, including responding to legal process and protecting the marketplace and its users. Chase Sets' public landing pages do not load third-party advertising or analytics scripts.

Payments and payout onboarding handled by Stripe

Counsel-approved language required

Payments and payout accounts run on Stripe. When you pay, Stripe collects and processes your payment method details, and Stripe charges your selected payment method as part of completing the purchase; Chase Sets holds the purchase funds on its own platform account until seller payout. When you set up payouts as a seller, Stripe collects the onboarding and verification information it requires — identity details, verification documents, and your payout bank details — directly through Stripe-rendered components embedded in the Chase Sets account area, and Stripe presents its own terms as part of that onboarding. Chase Sets stores provider references, provider-neutral payout-readiness statuses, missing-requirement identifiers, timestamps, and user-safe failure reasons; Chase Sets does not store your bank account numbers, tax identity values, verification documents, or raw provider payloads.

Cookies, browser storage, and analytics

Counsel-approved language required

Chase Sets sets first-party cookies for sign-in sessions (chase_sets_session), selecting which Account to act as (chase_sets_account_selection), guest checkout (chase_sets_guest_checkout), a signed-out cart (chase_sets_anonymous_cart), a signed-out sell list (chase_sets_anonymous_sell_list), signed-out saved lists (chase_sets_anonymous_saved_lists), signed-out product alerts (chase_sets_anonymous_product_alerts), signed-out Listing drafts (chase_sets_anonymous_listing_drafts), signed-out Listing reports (chase_sets_anonymous_reports), and your colour-mode preference (chase_sets_color_mode). This section names the cookies the marketplace sets today rather than asserting a fixed total; it is re-derived from the shipped source whenever that set changes. The sign-in session, account-selection, and guest-checkout lifetimes are deployment settings rather than values an administrator can change from inside the app, and the signed-in session default is fourteen days. Your browser also stores information for the marketplace itself. In local storage, chase-sets:marketplace:recent-searches holds your recent search terms and chase-sets-theme holds your light, dark, or system theme preference. In session storage, keys in the chase-sets:review-draft: family hold an unfinished review's rating, feedback text, and problem categories for a specific order; discovery.search.restoration.v2 holds the identity of the search result set you last viewed — the search text, category, tag, language, market activity, price bounds, in-stock filter, sort, and dynamic filters — together with your scroll position and a bounded number of already-fetched result pages; and discovery.search.loader-cache.v1 holds a bounded, time-limited set of search responses keyed by the search URL that produced them. The search page is public, so this browser-side search state can exist before you sign in or create an Account. Some pages load a payment provider's own browser script. Stripe.js loads on /checkout/buy/session/:sessionId, /account/payments/:paymentId, /checkout/payments/:paymentId, and /account/payment-methods; Stripe Connect.js loads on /account/desk/settings. Those scripts are controlled by Stripe and may use provider-controlled client-side storage in your browser. Chase Sets' own source establishes only that the scripts load on those pages; which storage each provider script uses, how long it lasts, and what it is for are described by that provider rather than by Chase Sets. In production builds the marketplace also registers a service worker served from /service-worker.js. It keeps a browser cache named chase-sets-marketplace-pwa-v1 holding static assets and an offline page. That cache skips requests carrying credentials, and it excludes /guest-checkout/exit, /sign-in, /sign-out, and /register as well as anything under /api/, /account, /checkout, /payment, /payments, and /orders. Chase Sets' landing-page and campaign analytics are first-party and provider-neutral: no third-party analytics SDK, vendor cookie, or third-party script is added to the page. Analytics events carry bounded properties such as the page path, section, and status, together with the campaign parameters utm_source, utm_medium, utm_campaign, utm_content, and utm_term, and the referrer of the page you arrived from, so Chase Sets can measure which campaigns and referring pages bring visitors to the marketplace. These events are kept free of email addresses, account identifiers, and raw URLs.

Selling, sharing, and Global Privacy Control

Counsel-approved language required

Chase Sets' shipped analytics are first-party and provider-neutral, and Chase Sets' public landing pages do not load third-party advertising trackers or cross-context behavioural-advertising scripts. [SALE-SHARE-AND-GPC-STATEMENT: counsel's conclusion on whether any Chase Sets practice is a “sale” or “sharing” of personal information under applicable state law, and the operative description of how Chase Sets responds to Global Privacy Control and other opt-out preference signals, will be stated here before this notice takes effect.]

Your privacy rights and how to make a request

Counsel-approved language required

Depending on where you live, you may have rights over your personal information, such as the right to know what Chase Sets has collected about you, to access a copy of it, to correct it, to delete it, and to exercise those rights without being treated worse for doing so. You can submit a privacy request from your Account through a Support Request, or by writing to Chase Sets Limited, PO Box 164, Maize, KS 67101-0164, US, or to [NOTICE-EMAIL]. Chase Sets needs to confirm that a request comes from you, or from an agent you have authorized, before acting on it. [RIGHTS-VERIFICATION-AND-RESPONSE: counsel's operative description of the verification method, authorized-agent handling, response timing, and any appeal process will be stated here before this notice takes effect.] Independent of any request, your Wallet history, orders, and account records remain visible to you in your account area.

How long Chase Sets keeps personal information

Counsel-approved language required

Chase Sets keeps personal information for as long as it is needed for the purposes described in this notice and for legal, tax, audit, dispute, and security obligations, and then deletes, redacts, or de-identifies it. Where a shipped, versioned retention schedule exists, that schedule controls. Today that is true for customer feedback: survey response content and its direct identifiers are redacted 365 days after submission, invitation diagnostics after 90 days, and operator case notes 365 days after the case closes; follow-up delivery artifacts are deleted after 30 days and generated exports after 24 hours; and content-free structural audit facts are kept for 2,555 days (about seven years) to support security and compliance investigations. Marketplace money records work differently: Wallet ledger entries, including Wallet Adjustments, are permanent records that are never edited or deleted — a correction is posted as a new, linked, opposite-direction entry, so both the original and the correction stay visible in your history.

Children

Counsel-approved language required

The Chase Sets marketplace is for adults. Under the Terms of Service you must be at least 18 years old to create an Account, and Chase Sets does not offer services directed to children. Chase Sets does not ask for a date of birth at registration; the age requirement is a condition of the Terms of Service that Chase Sets relies on you to meet. [CHILDREN-STATEMENT: counsel's operative children's-privacy language, including any COPPA conclusion and the commitment Chase Sets makes if it learns it holds a child's personal information, will be stated here before this notice takes effect.]

State-specific information

Counsel-approved language required

Some U.S. states give their residents additional privacy rights and require additional, state-specific disclosures. The rights section above describes how to submit a request wherever you live. [STATE-SUPPLEMENTS: counsel's state-specific supplements — including any California notice-at-collection presentation of categories, sources, purposes, and recipients, and equivalent disclosures for the other states in the approved launch scope — will be stated here before this notice takes effect.]

Automated decisions and human review

Counsel-approved language required

Chase Sets uses a small set of automated rules to run the marketplace today. Registration screening can require an invitation while admission is invitation-gated and can screen disposable email domains. Sale-clearance rules decide whether a seller's sale credit matures on the base or the extended clearance schedule using qualifiers such as trusted-seller standing, manual review, zero reviews, high order value, and linked-risk clusters. Risk signals group accounts that share the same payment instrument or shipping address. People stay in the loop for consequential actions: a Wallet Adjustment must be requested by one authorized operator and approved by a different one, and a Support Request resolution can rest on an operator's finding as well as on deterministic policy. Stripe, not Chase Sets, decides payout-account verification outcomes under Stripe's own rules. Chase Sets does not currently use card-scanning or image-recognition technology to make decisions about you. The California Consumer Privacy Act regulations addressing automated decisionmaking technology became effective on January 1, 2026, and the relevant compliance obligation begins on January 1, 2027 for businesses whose use of automated decisionmaking technology is in scope. [ADMT-APPLICABILITY: counsel's conclusion on whether and how those regulations apply to Chase Sets, and any resulting pre-use notice, opt-out, or access rights, will be stated here before this notice takes effect.]