VAM

VAM Privacy Policy

Last updated: September 12, 2026

VAM is made by CrackedPackz, a sole proprietorship in the State of Florida, United States. This policy covers the VAM iPhone app and the servers behind it.

Questions, requests, or complaints: matthewmendes18@gmail.com Abuse and safety reports: abuse@vamcards.app

The short version, because most of this policy is detail:


1. What we collect, and why

1.1 Things you give us

What Why Linked to you?
Email address (or the Apple relay address Sign in with Apple gives us) To create and sign you into your account, send the 6-digit sign-in code, and confirm an account deletion Yes
Business name, handle, display name, avatar, bio Shown to the other vendors at events you join — this is how they know whose table B-14 is Yes, and public to your event roster
Your ledger — sales, buys, trades, prices, quantities, payment method, notes, the event and county each was logged at This is the product. It is yours Yes, and private to you
Your inventory — cards, condition, quantity, cost basis, ask price, your own photos Your stock list Yes. Private by default. Only what you deliberately publish is visible, and cost basis is never published, to anyone, at any tier
Chat messages, direct messages, image attachments, announcements To deliver them to the people you sent them to Yes
Event membership — which events you joined, your table number, check-in time To put you on the roster and scope who can see what Yes
Reports you file and vendors you block To act on abuse, and to keep a block enforced Yes

1.2 Things collected automatically

What Why Linked to you?
Subscription state — which plan you have and whether it is active To unlock what you paid for. Handled by RevenueCat; we never see your card number, and no payment details ever touch our servers Yes
Push notification token To deliver a DM, an @mention, or an organizer’s announcement. Deleted when it stops working Yes
Product analytics — a fixed list of event names like quick_log_opened, event_joined, purchase_completed To know which features are used and which are dead weight. The list is closed and enforced by the type system: no message body, no price, no card name, and no free text you typed can ever enter an analytics payload Yes
Crash reports — stack trace, device model, OS version, app version To fix the bug that just interrupted your Saturday. Sent to Sentry. Identified by your account’s random ID and nothing else; anything resembling an email address or a dollar amount is scrubbed before it leaves your phone Yes
Anonymous price observations See §3 No

1.3 What we deliberately do not collect

Precise or coarse location (there is no location permission in this app — an event’s city is text its organizer typed). Contacts. Health or fitness data. Financial account or card details. Advertising identifiers (IDFA). Browsing history. Biometrics. Your real name, unless you type it in as your business name. Age or date of birth. We do not buy data about you from anyone.


2. Your content, and who can see it

VAM is a shared space, so it matters exactly who sees what.

Private to you, always: your ledger, your cost basis, your notes, your margins, your analytics, your transaction counterparties.

Visible to vendors at an event you joined: your business name, handle, avatar, table number and check-in status; any inventory item you set to “Event only” or “Public”, with its ask price and photo but never its cost basis; anything you post in that event’s channel.

Visible to one person: direct messages.

Publishing is opt-in, per item, and defaults to private. Nothing in your binder appears on a floor because you forgot a setting. An item published to an event stops being visible to that roster when the event archives, when you set it back to private, or if your paid plan lapses — hidden, never deleted.

Event organizers can, within their own event only, delete a message in their channel and remove a vendor from their roster. They cannot see any vendor’s ledger, cost basis, margins, or per-vendor sales. The organizer sales dashboard is hall-wide aggregate only and is suppressed entirely unless at least three vendors have opted in.


3. Realized prices, and how they are kept anonymous

This is the part of VAM that touches other people’s data, so here is exactly how it works.

If you are on a paid plan, price sharing is on by default and explained during the upgrade, with a one-tap switch in Account. On the free plan it is off by default. Either way it is Account → Price sharing, one tap, any time.

When you log a sale and price sharing is on, we write a separate record containing only:

That record contains no vendor identifier of any kind. There is no column for it, no foreign key to it, and no way to add one without a schema change. The hash cannot be reversed into your account.

What other vendors then see is an aggregate: a median, a low-to-high range, and a count. Never a list of individual sales, and never in an order that could be matched to the moment you were seen making one.

Nothing is shown below three independent observations. Under three, the app says “Not enough sales yet today” and returns no numbers at all. This exists for one specific reason: at a small show with two vendors, a single un-floored statistic would tell the other vendor precisely what you sold and for how much.

Deleting a transaction withdraws its observation. Deleting your account leaves observations in place, because by then they contain nothing that was ever connected to you.

These numbers are user-reported and unverified. They are not an appraisal and not a guarantee — see docs/TERMS-EULA.md §6.


4. Who we share data with

We do not sell your data. We do not share it for advertising. We do not share it with data brokers. We have never done any of those things and the business model does not require it.

We use these service providers, and only for the job named:

Provider What it handles Where
Google Cloud (Cloud Run, Cloud SQL, Cloud Storage — our servers, which we operate) Everything in §1.1: accounts, ledgers, inventory, photos, chat, events United States (South Carolina, us-east1)
Apple — Sign in with Apple, in-app purchase, push notification service Authentication if you choose it; all payments; notification delivery Apple’s infrastructure
RevenueCat Subscription state only — which plan, active or not. No card details, no ledger data United States
Sentry Crash and error reports United States
Expo (push notification service) Relays a notification to Apple. Sees the token and the notification text United States
Public trading-card catalog services When you search for a card by name, we ask a public card-identity service for its set, number and rarity. Only the search text is sent, never your identity, your inventory or your prices, and no prices or images come back Various
Our email provider (Resend) Sends your 6-digit sign-in code and your deletion confirmation United States
Ximilar (card recognition) When you scan a card, the photo of the card — and only the photo — is sent to Ximilar to be recognised. No account identifier, no price and none of your ledger goes with it, and the photo is not kept by us for this purpose. If our Ximilar key is not configured the scan is matched locally instead European Union (Czech Republic)
TypeSafe AI (report triage) When someone reports a message or a floor listing, the text of the report and of the reported item is sent to TypeSafe AI’s Jev model, which returns only a category and a severity score so the report can be handled inside our 24-hour moderation window. No identifiers, no prices, no ledger. It is a classifier: it generates no text and its answer is always reviewable and reversible by us United States

We will also disclose data if legally required to — a subpoena, a court order, a valid legal process — or where we believe in good faith it is necessary to prevent imminent harm, investigate fraud, or enforce our Terms. If the law lets us tell you first, we will.

If VAM is ever sold or merged, your data may transfer to the buyer under this same policy, and you will be told before it happens.


5. How long we keep things

Data Retention
Your account, ledger and inventory Until you delete your account
Chat messages Until you delete them, until you delete your account, or until a moderator removes them
Chat and inventory images Same as the message or item they belong to. Stored in private buckets and served only through short-lived signed links (1 hour for chat images, 24 hours for inventory photos)
Event channels Read-only 24 hours after an event ends, then archived; messages remain readable to that event’s roster
Push tokens Until they stop working, or you turn notifications off, or you delete your account
Crash reports Sentry’s default retention (about 90 days)
Database backups Encrypted daily backups of the database roll off after 7 days, so data you delete is gone from backups within a week
Analytics events Aggregated; individual rows are pruned on a rolling basis
Anonymous price observations Indefinitely. They contain no identifier — see §3
Moderation reports and the audit log of actions taken Kept as long as needed to enforce a ban and to show a pattern of abuse

6. Deleting your account

In the app: the account button → Account → Delete account. Three taps. You confirm by typing DELETE. It is not a request, not a deactivation, and not “within 30 days” — it runs immediately, and here is exactly what it does:

  1. Your profile is anonymized in place: handle replaced with a random string, business name replaced with “Deleted vendor”, display name, avatar and bio erased.
  2. Every message you wrote is marked deleted, its text and image links erased, and the uploaded images themselves removed from storage.
  3. Your inventory, push tokens, chat memberships, blocks and staff seats are deleted outright.
  4. Your transactions and their line items are kept, but stripped: reattached to an anonymous tombstone that nobody can sign in as, with counterparty names and notes erased. This is deliberate — a trade has a second vendor on the other side of it, and their ledger has to stay consistent. Nothing left in those rows identifies you.
  5. Your anonymous price observations are untouched, because they never held an identifier (§3).
  6. Your Sign in with Apple token is revoked, and your authentication record is deleted.
  7. The app’s local database on your phone is erased and you are signed out.
  8. A confirmation email is sent.

Deleting your account does not cancel an App Store subscription. Only Apple can do that: Settings → [your name] → Subscriptions. The app says so on the confirmation screen and links you there.

Want your data instead of deleting it? Account → Export produces a CSV of your ledger and inventory. Or email us and we will send you everything we hold.


7. Your rights

Whoever and wherever you are, you can ask us to show you what we hold about you, correct it, delete it, or send it to you in a portable format. Email matthewmendes18@gmail.com. We answer within 30 days and we do not charge for it. Most of it you can do yourself, faster, in the app.

If you are in California (CCPA/CPRA): you have the right to know, delete, correct, and to opt out of sale or sharing — and we make that last one easy by never selling or sharing your personal information for cross-context behavioral advertising. We do not discriminate against anyone who exercises a right.

If you are in the EU or UK (GDPR): our lawful bases are contract (we cannot run your account, your floor or your chat without this data), legitimate interests (security, abuse prevention, fixing crashes, understanding which features are used), and consent where we ask for it (push notifications, price sharing on the free plan). You may object, restrict, or withdraw consent at any time, and you may complain to your supervisory authority. Our servers are in the United States; where we transfer personal data out of the EEA or UK we rely on the European Commission’s Standard Contractual Clauses.

Do Not Track / Global Privacy Control: we do no tracking, so there is nothing for these signals to turn off.


8. Children

VAM is for people running a business at trading-card events. You must be at least 16 to create an account, and under 18 only with a parent or guardian’s consent (see the Terms). We do not knowingly collect anything from a child under 13. If you believe a child has created an account, email matthewmendes18@gmail.com and we will delete it.


9. Security

Every table in our database is protected by row-level security, enabled without exception: what you can read is decided by the database itself, not by the app, so a bug in the app cannot expose another vendor’s ledger. Image storage buckets are private and served only through expiring signed links. Your sign-in token is held in the iPhone’s secure keychain. Privileged operations run on the server; the app itself holds only a public key that can do nothing RLS does not allow. All traffic is over HTTPS.

No system is perfect. If you find a hole, email matthewmendes18@gmail.com — we would much rather hear it from you.


10. Where this policy is governed

This policy and the handling of your data are governed by the laws of the State of Florida, United States, and the applicable federal laws of the United States, without regard to conflict-of-laws rules. Our servers and providers are in the United States; using VAM means your data is processed there. Nothing in this section takes away a right you have under the mandatory law of the country you live in.


11. Trading-card names, publisher trademarks, and card art

VAM is a tool for tracking physical cards that you own. To do that it has to be able to say which card you mean.

Card names, set names, set codes, collector numbers and game names are used nominatively — purely to identify a physical object — and they are the trademarks of their respective owners. VAM is not affiliated with, endorsed by, sponsored by, or licensed by any game publisher or trading-card marketplace.

We ship no publisher card art. None. Where another app would show a picture of the card, VAM draws a typographic plate instead. The only image ever attached to an inventory item is a photograph a vendor took of a card they physically have, and uploading publisher artwork is a breach of our Terms.

We display no third-party market price data. There is no price feed in this app. Every number shown is either a vendor’s own ask price or an aggregate of what VAM’s own users reported selling for (§3).

Riot Games — Riftbound

Where VAM supports Riftbound, Riot Games’ trading card game, the following notices apply and are displayed in the app under Account → Legal & Safety.

Riot’s Riftbound developer policy requires that an app include the statement from Section 6 of Riot’s “Legal Jibber Jabber” policy “in a place that’s clear and easy to find” (https://developer.riotgames.com/policies/riftbound). That statement, exactly as Riot specifies it:

VAM was created under Riot Games’ “Legal Jibber Jabber” policy using assets owned by Riot Games. Riot Games does not endorse or sponsor this project.

Riot’s General Developer Policies separately require the following boilerplate “in a location that is readily visible to players” (https://developer.riotgames.com/policies/general):

VAM isn’t endorsed by Riot Games and doesn’t reflect the views or opinions of Riot Games or anyone officially involved in producing or managing Riot Games properties. Riot Games, and all associated properties are trademarks or registered trademarks of Riot Games, Inc.

Both are displayed, because the Riftbound policy instructs developers to read and comply with the General policies as well.

⚠️ Engineering note — remove this box before publishing

Do not ship any Riftbound surface until Riot developer registration is approved. Riot’s Legal Jibber Jabber §3 is unambiguous (https://www.riotgames.com/en/legal):

“we do not allow any Projects on the Apple Store or Google Play Store unless they have either a written license agreement from us or a valid Riot API key and comply with our API Terms and Policies”

Registration is mandatory “regardless of whether or not your product uses official documented APIs”, so sourcing Riftbound card names from Riftcodex instead of Riot’s API does not exempt us — it makes it worse, because the Riftbound policy also says “Your App may only use Riftbound assets (including cards) provided by the Riot API. No external or unofficial materials.”

Until the registration in docs/PLAN.md § 4 is approved with a production API key, the correct v1 behaviour is no Riftbound game option at all — not “catalog names only”. Once approved: source Riftbound card data from Riot’s API, display official English text, show both disclaimers above, and keep the app framed as a card library and inventory tool — “card libraries” is a listed approved use case and “metagame-defining statistics” is a listed rejection ground. Our realized-price pulse must never be extended to Riftbound win rates, play rates or matchup data.

Also note: Guideline 5.2.2 says “Authorization must be provided upon request.” Have the Riot portal approval on hand at submission.


12. Changes to this policy

If we change anything that affects how your data is handled, we will update this page and the date at the top, and we will tell you in the app before the change takes effect. If the change is material, we will ask you to accept it. The App Store privacy labels are updated at the same time, never after.


13. Contact

CrackedPackz State of Florida, United States General and privacy: matthewmendes18@gmail.com Abuse and safety: abuse@vamcards.app

We are one person and a card table. Email actually reaches us.