**Privacy Policy — What Valdar Collects and What Never Leaves**

> What the Valdar sports card scanner collects, what this website collects, why the free calculators transmit nothing at all, and how to access or delete your data.

Source: https://sportscardradar.com/privacy/ · updated: 2026-09-11

Legal

# Privacy policy for the Valdar app and this site

Last updated: September 11, 2026

This Privacy Policy explains how **Vast Flow, LLP (“Vast Flow”, “we”, “us”)** collects, uses and
protects your information when you use the **Sports Card Scanner - Valdar** mobile application (the
“App”) and the website **sportscardradar.com** (the “Site”). By using the App or the Site, you agree
to this Policy.

The App and the Site are not the same thing and they do not collect the same things, which is why they are
separated throughout. The App scans cards, and scanning a card means sending a photograph somewhere that can read
it. The Site publishes reference material and 24 calculators, and those calculators send nothing at all.
Both statements are true at once, and a policy that blurred them would be useless to anybody deciding what to use.

## The short version

- The free calculators on this site run entirely in your browser. Nothing you type into one is transmitted, logged or stored anywhere.
- The Site loads one third-party analytics tool, Microsoft Clarity, and it starts after the page has finished loading rather than during it.
- The Site sets no advertising identifier, runs no ad network and carries no retargeting pixel.
- The open data API is keyless. There is no account, no sign-in and nothing to register.
- The App does send card photographs to be recognised. That is the feature, and it is described in full below.
- We never sell your personal information, and we do not use your card photographs for advertising.

## Why the calculators on this site transmit nothing

Every one of the [24 free calculators](https://sportscardradar.com/tools/) on sportscardradar.com is arithmetic, and
the arithmetic arrives with the page. One small
JavaScript module is downloaded alongside the HTML; the fields you type into are read by that module in your
browser, and the answer is written back into the same page. There is no request in between, because there is
nothing for a request to fetch. The numbers exist only in the tab you have open, and they are gone when you close
it.

This is verifiable rather than promised, which is the point of stating it. Open your browser’s network panel,
type into any tool on this site, and watch nothing happen. Or load a tool page, switch the network off entirely,
and keep using it: the
[centering calculator](https://sportscardradar.com/tools/centering-calculator/) and the
[expected-value calculator](https://sportscardradar.com/tools/grading-worth-it-calculator/) both work with the connection dead,
because there is nothing on the other end of the wire that they need.

Nothing is stored either. The tools set no cookie of their own, write nothing into local storage, and keep no
history between visits. Reloading a page resets it to the worked example that ships in the HTML. The practical
consequence is that a collection valued on this site is not known to this site, and there is nothing on that
surface to export, delete or leak.

***The boundary every claim on this page turns on.** The calculators sit entirely on the left of the dashed line: their inputs, their results and the module that computes them never cross it. What crosses is the page request itself, the analytics tag once it starts, and — in the App, not on this website — the card photographs you choose to scan. The table below says the same thing surface by surface.*

*What each surface transmits, and to whom*

| Surface | What it does | What leaves your device | Who receives it |
| --- | --- | --- | --- |
| The free calculators on this site | All 24 of them: centering, fees, expected value, odds, inflation | Nothing. The inputs are read and the answer written back inside the page | No one |
| The rest of the website | Serving pages, fonts, images and stylesheets | The request itself — address, time, page, browser | The web server, in its ordinary logs |
| Microsoft Clarity | Understanding which parts of a page are used | Clicks, scrolling and a session replay of the page | Microsoft, as a separate controller under its own statement |
| The open JSON API | Publishing the reference data as machine-readable files | The request itself. There is no key, no account and no sign-in | The web server, in its ordinary logs |
| The markdown twins and agent endpoints | Serving the same pages in a form a model can read | The request itself | The web server, in its ordinary logs |
| The Valdar app | Scanning, valuing and keeping a collection | Card photographs, collection entries, device and crash data | The app’s processors, as set out below |

## What the App collects

**Card photos.** When you scan a card, the photo you take is sent to our servers and processed by computer-vision and AI models to identify the card and estimate its condition. Photos are used to provide the scanning service and to improve recognition accuracy. We do not use your photos for advertising and we do not sell them.

**Collection data.** Cards you save, collections you create, favorites and portfolio entries are stored so the App can show your collection and its value across sessions and devices.

**Purchase information.** Subscriptions are processed entirely by Apple App Store or Google Play. We receive anonymized transaction confirmations (e.g., an active-subscription flag) but never your card number, billing address or other payment details.

**Device and usage data.** We collect basic technical data — device model, OS version, app version, crash logs, and anonymized usage events (e.g., which screens are used) — to keep the App stable and improve it.

Each platform also publishes its own summary of this: the App Store privacy label and the Google Play Data safety
section are filled in by us for the App and are the authoritative per-store declaration. Where a store listing and
this page describe the same thing in different words, they are describing the same processing; if you believe one
of them is wrong, that is exactly the kind of report worth [sending](https://sportscardradar.com/contact/).

## What the Site collects

**Site analytics.** The Site uses Microsoft Clarity to understand how visitors interact with pages
(clicks, scrolling, session replays). Clarity may use cookies and similar technologies. See Microsoft’s privacy
statement for details. Clarity is a third party and a separate controller: what it records is held by Microsoft
under Microsoft’s terms, and blocking it in your browser blocks it entirely, with no effect on anything on this
site working.

It is also started late, on purpose. The tag is not loaded while the page is rendering; it waits for your first
interaction with the page, or for 2.5 seconds after the page has finished loading, whichever comes first. That
change was made for performance — a tool that walks the whole document delays the first paint on a slow phone —
and it has a privacy consequence worth stating: a visitor who lands on a page and leaves immediately is generally
gone before the tag has started.

**No advertising.** The Site sets no advertising identifier, loads no advertising network, and
carries no retargeting or conversion pixel. Clarity is the only third-party script on it. Nothing on this website
is used to build an advertising profile, and there is no mechanism here that could be.

**The open data API.** The 7 datasets published at
[sportscardradar.com/api/](https://sportscardradar.com/api/) are keyless and CORS-open: there is no account to create, no token to
apply for and nothing to identify a caller with. Requests to them are logged the way any web server logs a request
— address, timestamp, path, user agent — and those logs exist to keep the service running and to see what is being
used, not to profile anybody. The same applies to the markdown copies of each page and to the agent endpoints.

## How we use information

- To identify cards, estimate market values and generate AI condition grades;
- To store and sync your collections and portfolio;
- To operate subscriptions and enable Premium features;
- To fix crashes, improve recognition models and develop new features;
- To respond to your support requests;
- To send optional notifications you enable (e.g., price alerts for followed players).

## Who else receives anything

We rely on a small number of processors to run the service. Each receives only the data required to perform its
function and is bound by its own privacy obligations. We never sell your personal information.

*Third parties, what each does and what each receives*

| Processor | What it does | What it receives | Governed by |
| --- | --- | --- | --- |
| Apple App Store and Google Play | Selling and managing the subscription | The transaction. An anonymised confirmation comes back — never a card number, billing address or payment detail | Apple and Google |
| AI and cloud infrastructure providers | Card recognition, grade estimation and the Card Advisor chat | The photograph you scanned and the request made of it | Each provider’s own terms |
| Market data providers | Pricing built from public marketplace data such as eBay sold listings | A query about a card. No personal data is required to answer one | Each provider’s own terms |
| Microsoft Clarity | Website analytics and session replay | Page interactions on this website only. It is not present in the app | Microsoft |
| Crash reporting and analytics tools | Keeping the app stable | Crash traces, device model, OS and app version, anonymised usage events | Each provider’s own terms |

Note the asymmetry: every row in this table is a consequence of the App, except Clarity, which is a consequence of
the website. No processor receives anything from the free calculators, because the calculators produce nothing to
receive.

## How long is any of it kept?

Collection data is kept while your account or on-device library exists. Scanned photos are retained only as long
as needed to provide and improve the recognition service. Analytics data is stored in aggregated or anonymized
form. You can request deletion of your data at any time, and the section below sets out how.

## How it is protected

Data is transmitted over encrypted connections (HTTPS/TLS) and stored on access-controlled infrastructure. No
method of transmission or storage is 100% secure, but we apply industry-standard measures appropriate to the type
of data we process. The strongest protection available to any system is not to hold the data in the first place,
which is the reason the calculators are built the way they are.

## What rights do you have, and how do you use them?

Depending on your jurisdiction (including GDPR for EEA residents and CCPA/CPRA for California residents), you may
have the right to access, correct, export or delete your personal data, and to object to or restrict certain
processing. To exercise any of these rights, email us at
[support@vastflow.kz](mailto:support@vastflow.kz). We respond within 30 days.

To delete your data from within the App, you can also use the account deletion option in Settings, where
available. Naming the account email or the device your collection sits on makes a request faster to act on,
because that is what identifies the records in question.

*Your rights, and what each one means here*

| Right | What it means in practice | How to use it |
| --- | --- | --- |
| Access | A copy of what is held about you — collection entries, scans, account record | Email the address below from the account email |
| Portability | That copy in a machine-readable form | Ask for an export in the same message |
| Correction | Fixing something recorded wrongly | Name the record and what it should say |
| Deletion | Removing the account and what is attached to it | The Settings screen in the app where available, or by email |
| Objection and restriction | Stopping or narrowing a particular processing | Say which processing; analytics can be declined by blocking the tag |
| Complaint | Raising it with a supervisory authority instead | Your local data protection authority, directly |

## Children

The App is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not
knowingly collect personal information from them. If you believe a child has provided us personal information,
contact us and we will delete it.

## Where the data is processed

We are based in Kazakhstan and use cloud infrastructure that may process data in other countries. Where required,
we rely on appropriate safeguards such as standard contractual clauses. Because the free calculators transmit
nothing, no cross-border transfer arises from using them, wherever you are reading from.

## How you will know if this Policy changes

We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above
and, where appropriate, announced in the App. Continued use after changes take effect constitutes acceptance. The
practical advice is to read the date: this version is September 11, 2026, and a change that matters will move it.

## Contact

Vast Flow, LLP
Email: [support@vastflow.kz](mailto:support@vastflow.kz)

The [contact page](https://sportscardradar.com/contact/) sets out what to include in a data request so it can be acted on in one
round rather than two. The [terms of service](https://sportscardradar.com/terms/) cover the other half of the relationship: what
the estimates are, what the published data may be used for, and the limits on both.
[Who publishes this](https://sportscardradar.com/story/) names the people behind both documents and the method the site is run
by.

---

HTML version: https://sportscardradar.com/privacy/
Structured data for this site: https://sportscardradar.com/api/v1/openapi.json · https://sportscardradar.com/llms.txt
Free to quote and reuse with a link back to the source URL above (CC BY 4.0).
