Privacy

Privacy Notice

Version 2026-09-16 · Effective 16 September 2026 · Last updated 16 September 2026

This notice explains what personal information Cardonomics collects, what we do with it, who else handles it, how long we keep it, and the choices you have. We do not sell personal information, we do not show ads, and we do not use advertising trackers or anyone else's analytics: visits are counted by our own server, without cookies (section 2).

1. Who we are

Cardonomics is a DBA of Powerhouse Holdings, LLC, an Alabama limited liability company (“we”, “us”). We decide how and why the personal information described here is used. Questions or requests go to [email protected], or by post to the address in section 16.

2. What we collect

Your account

Payments

Payments are handled by Stripe. Your card details are entered on Stripe's pages and never reach our servers. To set up billing we send Stripe your email address, your name (if we have one) and your Cardonomics account ID. We keep the customer and subscription identifiers Stripe gives back, your plan, its status, when the current period ends and whether it is set to cancel.

Usage, device and IP address

Like any website, our servers receive your IP address and basic request information (such as the page requested and your browser type) with every visit. We use the IP address, in memory only, to limit how many requests and sign-in attempts can come from one address. If something goes wrong on our side we keep an error record for up to 30 days, with email addresses and IP addresses removed from it. Our hosting and network providers also process this request information to deliver and protect the site.

Counting visits

We count page visits ourselves, on our own server. There are no analytics cookies, no local storage, no tracking pixels and no third-party analytics scripts. When a page is requested we add one to that day's totals for:

To estimate how many different people visited on a day, our server combines your IP address and your browser's user-agent string with a random value and turns them into a one-way code. The random value is kept only in the server's memory and is replaced every day (UTC), when the old one is thrown away, so a code cannot be turned back into an address or linked to your visits on another day. The code is held in memory for that day only and is never written to our database. We store only the totals: never your IP address, your user-agent, the code, your location or anything else that identifies you. Requests from known automated programs are not counted. If your browser sends a Do Not Track or Global Privacy Control signal, the page is still counted, but you are not counted as a visitor and your visit is not used to credit a sign-up.

If you create an account, we note on it the campaign tags and referring domain of your first page visit that day, where there were any, so we can tell which links bring people who sign up. If you later buy a subscription, the purchase is added to that day's totals under the same campaign tags and referring domain.

Cookies and local storage

Live-stream data, including usernames

Most of what Cardonomics holds is a record of live sports-card breaks on Whatnot, captured by our own software watching streams through a Whatnot account. It includes stream titles, the handles of the breakers and sellers running them, the products opened, spots and lots, bids and sales with the usernames of bidders and buyers, amounts and times, viewer counts, and announcements made in the stream. This is information shown to viewers of those streams. Our system is able to accept chat messages and notices of people joining a stream, but our capture software does not currently record them. Section 11 explains how we treat this data and how to have your username removed.

When you contact us

If you email us, we keep your message, your email address and our reply.

We also gather product information such as prices, checklists, odds and release dates from manufacturers and online shops and marketplaces. That is information about products, not people.

3. How we use it

We do not use personal information for targeted advertising, and we do not make decisions about you by automated means that have legal or similarly significant effects.

Cardonomics is run from the United States for a US audience. If data protection law in the EU, EEA or UK applies to you, we rely on: contract (running your account and subscription); legitimate interests (security, fraud prevention, improving the Service, counting visits in aggregate, and recording and analysing live-stream market activity, where we limit what is shown and let people ask to be removed); consent (optional news emails, which you can withdraw at any time); and legal obligation (tax, accounting and responding to lawful requests).

5. Who we share it with

We use a small number of service providers who process personal information for us, under their own terms and security commitments:

ProviderWhat they do for usWhat they receive
RenderHosts the application and its databaseEverything stored in the Service, and request information
StripePayment processing and the billing portalEmail, name, account ID, and the payment details you give them
ResendDelivers our emailsYour email address and the content of the email
GoogleSign in with Google, and your profile pictureThe sign-in request, and the image request when your picture is shown
CloudflareDNS and network delivery and protection, and storage of our encrypted backups (R2)Request information, including IP address; encrypted backup files it cannot read

We do not share personal information with advertising networks or data brokers. We may also disclose information when the law requires it or to protect the rights, safety and security of our users, the public or us; to a buyer or successor if our business is sold or reorganised (they would be bound by this notice); or with your permission.

What other customers can see. Buyer and bidder usernames are never shown to customers, never included in exports, and never linked to a Cardonomics account. A breaker's own figures are shown only to that breaker's account after their handle is verified. Breaker and seller handles may appear on pages such as Who to watch, alongside the products they open, without any money figures, and market prices are shown only as aggregates across several sellers.

6. We do not sell or share your personal information

We do not sell personal information, and we do not share it for cross-context behavioural advertising or use it for targeted advertising, and we have not done so in the past 12 months. We do not knowingly sell or share the personal information of anyone under 18. Because there is nothing to opt out of, we have no “Do Not Sell or Share” switch, but we treat a Global Privacy Control signal from your browser as an opt-out request all the same.

7. How long we keep it

InformationHow long
Account, settings, watchlist, follows, subscription record, alerts sent, daily lookup counts, stream handle claims For as long as the account exists. When you delete the account they are removed from the live database immediately (a handle claim is unlinked).
Copies of the above in our encrypted backups Until the backup rolls off: we keep the 30 most recent nightly backups (about 30 days) and one backup a month for 12 months. Backups are used only to restore the Service; if we ever restore one, we delete again any account that was deleted after it was made.
Sign-in sessionsUntil you sign out or sign out everywhere, and at most 30 days.
Password reset requests (hashed link, times, IP address) The link works once and expires after an hour. The record stays until your next reset request or until the account is deleted.
Account event records (such as account created, password changed, billing events) Kept for security and accounting. They are not removed when an account is deleted and do not currently expire automatically. You can ask us to delete them (section 9).
Error recordsUp to 30 days, with email and IP addresses removed.
Daily visit totals (page, referring domain, campaign tags, phone or computer, and the number of views and visitors) Up to 400 days, then deleted. They are counts and contain no personal information.
The daily visitor code, the random value it is made with, and the campaign tags and referring domain of your first visit that day In server memory only, never in our database; thrown away when the day ends (UTC) and on every restart.
How you found us, noted on your account when it is created (campaign tags and referring domain) For as long as the account exists.
Rate-limit and sign-in attempt countersIn memory only; gone within the hour, and on every restart.
Live-stream data, including usernames Long term, because its value is as a historical price record. A person who asks to be removed has their username replaced as described in section 11.
Emails you send usAs long as needed to deal with them and keep a record of what was agreed.
Information held by Stripe, Google, Resend, Render and CloudflareUnder their own retention policies.

8. How we protect it

No system is perfectly secure, and we cannot guarantee the security of information sent over the internet. If you find a vulnerability, please report it through our security page.

9. Your rights and how to use them

Whichever US state or country you live in, you can ask us to:

We will not treat you differently for using these rights.

How

We will respond within 45 days. If we need longer, we will tell you why and may take up to 45 more days. If we cannot fully meet a request, we will explain why, for example where we must keep billing records by law.

Appeals

If we decline your request, you can appeal by replying to our decision, or by writing to [email protected] with the subject “Privacy appeal”. We will respond in writing within 60 days and explain what we decided. If you are still unhappy, you can contact your state attorney general or, in the EU, EEA or UK, your data protection authority.

Authorised agents

Someone you authorise can make a request for you. We will ask for your signed permission, and may ask you to confirm your identity with us directly, unless the agent holds a valid power of attorney.

10. Children and teens

Cardonomics is not for children under 13, and they may not use it. We do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it and close the account.

People aged 13 to 17 may use Cardonomics only with a parent's or guardian's permission, and only adults may pay for a plan. We do not sell or share teens' information or use it for advertising.

Parents and guardians can ask to see or delete their child's information, or to close the account, by writing to [email protected] with the email address the account uses. We will confirm the request before acting on it.

11. If you appear in a live stream we recorded

If you run, sell in, bid in or buy in a break on Whatnot, our records may include your username and what you bid or bought, for how much and when (section 2).

To be removed, email [email protected] with your Whatnot username. We may ask you to show that the username is yours. We then replace the username with a random-looking code everywhere we store it, including in stream records, sales, error records and anything we capture later. The code cannot be turned back into your username without a secret key we keep separately. The prices and counts stay, without your name.

12. International transfers

We are based in the United States, and your information is stored and processed in the United States. Some of our providers may process it in other countries. If you use Cardonomics from outside the US, your information will be transferred to the US, where the law may differ from yours. Where the law requires, we rely on our providers' approved transfer safeguards, such as standard contractual clauses.

13. If there is a data breach

If personal information we hold is accessed or taken without authorisation, we will investigate promptly, act to contain it, and notify affected people, regulators and others as the law requires, without unreasonable delay. For example, Alabama law generally requires notice to affected residents within 45 days in the cases it covers. We will usually contact you by email and tell you what happened, what information was involved, what we are doing, and what you can do.

14. Changes to this notice

We will update the version and date at the top of this page whenever this notice changes. If a change is material, such as collecting new kinds of information, using it in a new way or sharing it with new kinds of recipients, we will tell you by email or on the Service before it takes effect.

15. Notice for residents of certain US states

Some state laws (for example in California, Colorado, Connecticut, Texas and Virginia) ask businesses to describe personal information by category. In the past 12 months we have collected identifiers (name, email, IP address, account and platform usernames), commercial information (plan and subscription records, and bids and purchases seen in live streams) and internet activity (sign-in sessions, settings and usage counts). We do not draw inferences to build profiles about you. We collected them from you, from Google when you use Google sign-in, from Stripe, and from live streams, for the purposes in section 3. We disclosed them only to the providers in section 5, for business purposes. We do not collect sensitive personal information for inferring characteristics about you.

16. Contact

Powerhouse Holdings, LLC d/b/a Cardonomics
(postal address available from [email protected])
Privacy: [email protected]
Security: [email protected]
Everything else: [email protected]