Privacy Policy
Last updated: 27 August 2026
1. Who we are
ChaseCard.app ("ChaseCard", "we", "us") is operated by Luke MacKay-Morris and Thomas Lee, based in the United Kingdom. For the purposes of UK data protection law, we act as the data controller for the personal data described in this policy.
You can reach us about anything in this policy at hello@chasecard.app.
2. Information we collect
We collect information in three ways: what you give us directly, what's generated by using the service, and what we receive from third parties you choose to connect.
Account information
- Email address and password (stored as a salted hash — we never store or can see your plain-text password).
- First and last name, and the unique @handle you choose.
- Phone number, if you verify one to unlock phone-gated referral rewards.
- Your avatar, generated from your handle via a third-party avatar service (DiceBear) and cached on our own servers.
Subscription & wallet information
- Your subscription tier, billing status, and Stripe customer reference. We never receive or store your full card number — Stripe handles that directly.
- Your Credits/Watch Token/Boost balances and transaction history within ChaseCard.
Watches & alerts
- The cards, search criteria and price thresholds you set up as Watches.
- Your alert history, wins, and archive/loss records.
Discord information
If you choose to connect your Discord account (e.g. to sync a tier role, or to join our community server as part of a beta application), we receive your Discord user ID and username via Discord's own OAuth process, and — only where you've explicitly taken that step — we may add you to our Discord server on your behalf. We never receive your Discord password.
Technical information
- Standard web server logs (IP address, browser/device type, timestamps) generated automatically by normal use of the site.
- A session token stored in your browser's local storage, used to keep you signed in.
Communications
If you contact us (e.g. via hello@chasecard.app or a support ticket in the app), we keep a record of that correspondence to respond to you and improve the service.
3. How we use your information
| What we use it for | Our lawful basis |
|---|---|
| Creating and running your account, processing payments, delivering alerts you've set up | Performance of a contract with you |
| Fraud prevention, keeping the service secure, enforcing our Terms of Service | Legitimate interests |
| Improving the product (e.g. understanding which features are used) | Legitimate interests |
| Sending marketing emails about new features or offers | Consent — you opt in, and can withdraw it any time in Settings |
| Responding to support requests | Performance of a contract / legitimate interests |
| Complying with our legal and tax obligations | Legal obligation |
4. Marketplace data & alerts
ChaseCard's core function is monitoring listings on third-party marketplaces (currently Vinted and eBay, with PokePulse as a pricing data source) and alerting you when something matches your Watches. This listing data is public marketplace data, not your personal data — we do not send your personal information to these marketplaces as part of that monitoring. If you click through an alert to view or buy a listing, you leave ChaseCard and deal with that marketplace and seller directly, under their own terms and privacy practices.
6. International transfers
Our database (Supabase) runs in the EU. Our application server (Railway) is currently hosted in the United States — we plan to move this to the EU once our initial beta period ends. While it remains in the US, personal data processed by ChaseCard is transferred outside the UK/EEA as a normal part of running the service.
This transfer, and any other transfer outside the UK/EEA by a processor we use (such as Stripe, Brevo, or Discord), is covered by that provider's own appropriate safeguards — such as Standard Contractual Clauses — as required under UK GDPR.
7. How long we keep your data
We keep your account data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we're required to keep certain records for longer — for example:
- Transaction and billing records, for our tax and accounting obligations.
- Information reasonably needed to investigate fraud, abuse, or a breach of our Terms of Service.
8. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to the retention exceptions above.
- Restrict or object to certain processing.
- Port your data to another service in a structured, machine-readable format.
- Withdraw consent at any time, where we rely on consent (e.g. marketing emails).
Most of these can be actioned directly from your account Settings. For anything else, email hello@chasecard.app and we'll respond within one month.
10. Age requirement
ChaseCard is only available to individuals aged 18 or over. We don't knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact hello@chasecard.app and we'll remove it.
11. Security
We use industry-standard measures to protect your data — including password hashing, encrypted connections (HTTPS/TLS), and access controls on our infrastructure. No system is 100% secure, but we take reasonable steps to protect your information against unauthorised access, loss, or misuse.
12. Changes to this policy
We may update this policy from time to time — for example, as the product evolves. We'll update the "Last updated" date at the top of this page, and for material changes we'll take reasonable steps to notify you (such as an email or in-app notice).
13. Contact & complaints
Questions about this policy or how we handle your data: hello@chasecard.app.
If you're unhappy with how we've handled your data, you also have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office (ICO). We'd appreciate the chance to address your concern directly first, at the email above.