Last updated: 1 January 2025
1. Introduction
Centrifyx ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
2. Information We Collect
2.1 Personal Information
We collect the following personal information:
- Account Information: Email address, display name
- Payment Information: Processed securely by Stripe (we do not store card details)
- Authentication Data: Google account information if you sign in with Google
2.2 Usage Information
We automatically collect:
- Analysis history and results
- Usage statistics and feature interactions
- Device information and IP address
- Browser type and operating system
2.3 Images and Content
- Trading card images you upload for analysis
- eBay listing URLs you provide
- Manual adjustments you make to analysis results
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process your card analyses
- Manage your subscription and billing
- Send you service updates and notifications
- Improve our algorithms and features
- Respond to your support requests
- Comply with legal obligations
4. Data Storage and Security
4.1 Storage
Your data is stored using:
- Firebase: User accounts, analysis data, and metadata
- Google Cloud Storage: Uploaded card images
- Stripe: Payment and subscription information
4.2 Security Measures
- Data encryption in transit (HTTPS/TLS)
- Encrypted storage at rest
- Regular security audits
- Access controls and authentication
- Secure payment processing via Stripe
5. Data Retention
- Free Tier: Analysis data retained for 30 days
- Paid Tiers: Analysis data retained permanently while subscription is active
- After Cancellation: Account data retained for 90 days, then deleted
- Legal Requirements: Some data may be retained longer if required by law
6. Third-Party Services
We use the following third-party services that may collect data:
6.1 Analytics and Monitoring
- Firebase Analytics: Usage patterns and feature adoption
- Microsoft Clarity: User interaction heatmaps and session recordings
6.2 Payment Processing
- Stripe: Payment processing and subscription management. See Stripe's Privacy Policy
6.3 Advertising
- Google AdSense: Displays ads to free tier users. See Google's Privacy Policy
6.4 External APIs
- eBay API: Fetches listing data when you provide an eBay URL
- Google Gemini: Validates uploaded images
7. Cookies and Tracking
We use cookies and similar technologies for:
- Authentication and session management
- Remembering your preferences
- Analytics and performance monitoring
- Advertising (free tier only)
You can control cookies through your browser settings. Note that disabling cookies may affect Service functionality.
8. Your Rights
Under GDPR and UK data protection laws, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data
- Portability: Receive your data in a machine-readable format
- Object: Object to processing of your data
- Withdraw Consent: Withdraw consent for data processing
To exercise these rights, email us at privacy@centrifyx.com
9. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected data from a child, please contact us immediately.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice on the Service.
12. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@centrifyx.com
Data Protection Officer: dpo@centrifyx.com
13. Complaints
If you have concerns about how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or your local data protection authority.