Legal
Last updated: May 20, 2026
When you sign in with Google or Discord, we receive your name, email address, and profile picture from that provider. We store this to create and manage your account. We do not receive or store your OAuth passwords.
With your consent, we collect analytics data about how you use the site — pages visited, search queries, time spent — to help us improve the platform. This data is processed by Google Analytics via Google Tag Manager.
When we send you transactional emails (order confirmations, shipping updates, auction alerts), we log that the email was sent. We use Resend to deliver email.
We retain your account data for as long as your account is active. If you delete your account, we remove your personal information within 30 days, except where we are required to retain it for legal or financial compliance (e.g. completed transaction records, which may be kept for up to 7 years).
Anonymised or aggregated analytics data may be retained indefinitely as it cannot be used to identify you.
Depending on your location, you may have the following rights:
To exercise any of these rights, contact us at info@megacardstore.com.
We use industry-standard security measures including encrypted connections (HTTPS), hashed session tokens, and access controls. However, no system is completely secure. We encourage you to use a strong, unique password for your Google or Discord account.
We never store payment card numbers — all payment processing is handled by Stripe.
MegaCardStore is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top. For significant changes we'll notify you by email or by a notice on the site.
Questions about this privacy policy or your data?
Your cart is empty
Browse cards and add them to your cart