Legal draft
Privacy Policy
Draft privacy policy for BinderPlug, operated by Wyrdbit LLC. Preview pending final owner and attorney review.
Draft, not yet in effect. This is a preview of BinderPlug's privacy policy pending final owner and attorney review. Nothing here is a live policy yet.
Version: privacy-policy-draft-2026-07-18
Effective date: To be set at publication
Operated by: Wyrdbit LLC ("Wyrdbit", "we", "us")
Contents
Summary
This summary is here to help you read the policy. It is not a substitute for the full text below.
- BinderPlug is a mobile app for discovering and coordinating local trading card game trades. It is operated by Wyrdbit LLC.
- We collect what the app needs to work: your email address, a display name, a password (stored only as a hash), your approximate location if you grant permission, your card lists, and your trade activity.
- BinderPlug's core features, finding and matching with nearby traders and suggesting public meetup spots, use your approximate location and require it. You can still build your Wishlist and Offer Binders without granting location, and you can turn the permission off at any time in your device settings.
- The app does not request navigation-grade GPS, and we reduce the precision of your location to an approximate area before storing it. We keep it for a limited time (see Section 3.2).
- We do not sell personal data, we do not show ads, and the app has no private-message system to read.
- Analytics and crash reporting are configured to avoid personal information: no advertising identifiers, no location lookup from your network address, and no email addresses or names in events. You can turn analytics off in Settings.
- Deleting your account anonymizes your personal information. Some anonymized records (like trade and feedback history) are kept so other traders' history stays intact and to prevent abuse.
- Questions or requests: [email protected].
1. Who we are
BinderPlug is operated by Wyrdbit LLC, a California limited liability company. Our mailing address is 31441 Santa Margarita Pkwy, Ste A #8099, Rancho Santa Margarita, CA 92688, USA. You can reach us at:
- General support and privacy requests: [email protected]
- Account deletion requests: [email protected]
- Account access issues: [email protected]
- Security vulnerability reports: [email protected] (see also https://binderplug.app/.well-known/security.txt)
2. What BinderPlug does
BinderPlug helps trading card game collectors discover possible local card trades by comparing wanted cards with cards people are willing to trade, and helps them coordinate a meetup. Trades happen in person, between users, outside the app. This shapes what data we handle: the app works with card lists, approximate proximity, and trade coordination records. The app does not handle payments, shipping addresses, or private conversations.
3. Information we collect
3.1 Account information
When you create an account we collect:
- Email address: used to sign in, verify your account with a one-time code, and send account-related email (verification codes, password resets).
- Display name: shown to other users. Display names are checked against a content filter at creation.
- Password: stored only as a cryptographic hash (Argon2). We cannot read your password.
When you accept the registration notice and the age/guardian attestation, we record the version of each that you accepted and the time of acceptance, as evidence of account creation.
3.2 Location (approximate; required for nearby features)
BinderPlug's core features, finding and matching with nearby traders and suggesting public meetup spots, use your approximate location and require it. You can still build your Wishlist and Offer Binders, share your binder, and manage trades you already have without granting location. You control this permission and can turn it off at any time in your device settings.
- The app does not request navigation-grade GPS. On Android, the app declares only the coarse-location permission and blocks the precise-location permission at the manifest level.
- Before storing your location, we reduce its precision to an approximate area (about a two-kilometer grid) rather than an exact point. This applies to every device. We store only your most recent approximate location point, the time it was updated, and your chosen search radius (default 25 km).
- Other users never see your stored location. They see derived information such as distance ranking ("nearby") in discovery surfaces.
- Retention: we keep your approximate location for up to 30 days after your most recent update, and sooner when you turn the permission off. If you stop using nearby features, the stored point ages out and is deleted, and after that you no longer appear to nearby traders. When the app detects that you have turned location off, we clear the stored point.
3.3 Cards, trades, and community activity
- Card lists: the cards you add to your Offer and Wishlist Binders, including printing, condition, and treatment details you select. Card catalog data itself comes from public card databases (see Section 6).
- Trade records: proposals, responses, schedule and meetup-location negotiation, status changes, and a history log of trade actions.
- Feedback: per-trade ratings you exchange with trade partners, and aggregate reputation derived from them.
- Reports: if you report another user (for example for a no-show, harassment, or a suspected scam), we store the report, its category, and its resolution. Reports are visible to us for review, not to other users.
- Blocks: the accounts you block, used to keep blocked users out of your discovery and trade surfaces.
- Share Binder links and saved traders: share codes you generate, and the traders you save.
- Avatar: a selection from the app's built-in icon set. The app does not upload your photos.
- Preferences: search radius, distance units, notification preferences, and whether to share usage analytics.
3.4 Device and technical data
- Camera (QR scanning only): if you use "Scan Binder," the app asks for camera permission to read another trader's Share Binder QR code. Scanning happens on your device; the app does not record, store, or upload photos or video.
- Push notification tokens: if you enable push notifications, we store the token needed to deliver them (via Expo's push service), per device. You can disable push in settings; the tokens are cleared when you delete your account.
- Device integrity attestation: the app uses Apple App Attest and Google Play Integrity checks during registration to limit automated abuse. We receive and store attestation results, hashed device identifiers, and a device-to-account link record. We do not receive device contents.
- Server logs: our API keeps operational logs (request metadata, including network addresses) for reliability and abuse prevention. Log fields are designed to mask email addresses and never record passwords or tokens in plain form.
- Website forms: when you submit a request or bug report on binderplug.app, we store the form contents together with technical metadata (a hashed network address, browser user-agent, and language header) for abuse prevention and follow-up, and we use Cloudflare Turnstile to filter bots.
- Local storage on your device: the app stores session tokens, cached data, and settings on your device. This data stays on the device and is removed by uninstalling the app or clearing its storage.
3.5 Analytics and crash reporting
We use two narrowly configured tools, and you can turn product analytics off at any time in Settings → "Share Usage Data."
- PostHog (product analytics), hosted in the EU. We record named product events (for example: account created, trade proposed, share link opened) and screen views, tied to your account's internal identifier, which is a pseudonymous ID rather than your name or email. Configuration: automatic capture is off, session replay is off, location lookup from your network address is disabled, and events must not contain email addresses, names, coordinates, or card values. If you turn "Share Usage Data" off, the app stops sending analytics entirely, including at app start.
- Sentry (crash and error reporting). Reports contain technical error context. Personal information is disabled in the Sentry configuration; our telemetry layer sends presence flags (for example "a trade id was present") instead of raw ids, and never sends emails, tokens, or passwords. We can disable it entirely.
3.6 What we do not collect
- No payment information (the app has no purchases).
- No contacts, no photo-library access, and no microphone access. Camera access is requested only for QR scanning, as described in 3.4, and nothing from the camera is stored or transmitted.
- No navigation-grade GPS location.
- No advertising identifiers, and no third-party advertising or tracking SDKs.
- No private messages. BinderPlug has no direct-message or chat system. (Trade coordination fields, like schedule notes, are part of the trade record.)
4. How we use information
We use the data above to:
- create and secure your account, and sign you in;
- match Wishlists with Offer Binders and rank nearby traders;
- coordinate trades: proposals, schedules, and meetup-location suggestions;
- deliver notifications you enable;
- show trade partners the reputation signals the community produces (feedback scores, trade counts);
- review reports, enforce our Terms of Service, and prevent fraud, spam, and abuse (including re-registration abuse after bans);
- diagnose crashes and errors, and understand aggregate product usage;
- comply with legal obligations.
We do not sell personal data, rent it, or share it with advertisers or data brokers. We do not use your data to train AI models.
5. What other users can see
BinderPlug is a trading community, so some information is visible to other users by design:
- your display name, avatar, and trust/reputation level;
- your Offer Binder and Wishlist contents in discovery and trade surfaces, and in any Share Binder link you generate (share links can be revoked, and web share pages are excluded from search-engine indexing);
- your feedback scores and trade statistics on completed trades;
- approximate proximity, for example that you are within a chosen radius; your stored location itself is never shown.
6. Service providers
We share data with providers only as needed to run BinderPlug:
| Provider | What it does | What it handles |
|---|---|---|
| Render | Hosts our API and database | All server-side data described above |
| Postmark | Sends transactional email | Your email address and message content (codes, resets) |
| Expo (EAS) | App builds and push delivery | Push tokens and notification payloads |
| Sentry | Crash and error reporting | Technical error data as scoped in 3.5 |
| PostHog (EU) | Product analytics | Event data as scoped in 3.5 |
| Cloudflare | DNS, bot protection (Turnstile) on our website forms, and encrypted database-backup storage | Web request metadata on binderplug.app and encrypted backups |
| Google Workspace | Our support mailboxes | Email you send to our addresses |
| Google Maps / Places | Meetup-location suggestions | Place queries the server makes; suggestions are "powered by Google" |
| Apple / Google | Device integrity attestation | Attestation tokens and verdicts |
Card catalog data comes from public card databases (Scryfall for Magic: The Gathering, the Pokémon TCG API for Pokémon cards). Requests for catalog data go through our servers; these providers do not receive your account information.
7. Retention and deletion
Your data is retained while your account exists, except where this policy states a shorter period:
| Data | Retention |
|---|---|
| Approximate location | Up to 30 days after your most recent update, and sooner when you turn the permission off (Section 3.2) |
| Sign-in sessions / refresh tokens | Until logout, expiry, or account deletion |
| Website form submissions | Up to 24 months after the request is resolved, then deleted |
| Everything else | Life of the account, then the deletion treatment below |
When you delete your account (in the app, or via [email protected] after we verify control of the account email):
- your display name, email, avatar, location, and push tokens are anonymized or cleared;
- your password hash is replaced so the account can never be signed into;
- your sign-in sessions are revoked and Share Binder links are deactivated;
- your card lists are removed from matching and discovery;
- in-progress trades are cancelled and your trade partners keep an anonymized record that the trade was cancelled;
- completed trade records, feedback ratings, and report records are retained in anonymized form ("Deleted User") to keep other users' trade and reputation history accurate and to prevent abuse;
- to prevent ban evasion and abuse, we keep a one-way hash of the deleted account's email for 30 days; during that time the same email cannot be used to register a new account. The hash is cleared after 30 days.
We keep some records where required for safety, fraud prevention, security, or legal obligations. Encrypted database backups may retain deleted data for up to about 35 days before rotating out. Deletion is not reversible.
8. Your choices and rights
- Access, export, correction: request them at https://binderplug.app/account/data or by emailing [email protected]. We verify account control before sharing account-specific information. Some requests are handled manually until self-service tools exist.
- Deletion: delete your account in the app (Settings → Delete Account) or request it at https://binderplug.app/account/delete.
- Location: grant or revoke location permission in your device settings at any time. Revoking stops new collection; the stored point is removed as described in Section 3.2.
- Analytics: turn product analytics on or off in the app (Settings → "Share Usage Data"); off means no analytics events at all.
- Push notifications: turn them off in the app or in device settings.
United States
Depending on where you live (for example California under the CCPA, or other U.S. states with comprehensive privacy laws), you may have statutory rights to access, correct, delete, or export your personal data, and to opt out of the sale or sharing of personal data or targeted advertising. We do not sell or share personal data as those terms are defined by the CCPA, and we do not use it for targeted advertising, so there is nothing to opt out of. We honor access, correction, deletion, and export requests for all users through the mechanisms above regardless of region.
Canada (PIPEDA and Quebec Law 25)
We serve Canadian users, and your information is stored and processed in the United States (see Section 11). Canadian federal law (PIPEDA) and provincial laws, including Quebec's Law 25, apply to how we handle your personal information.
- Consent. We collect and use your personal information for the purposes described in this policy, and we ask for it in plain language at the point it matters. For example, the app requests location permission only for the nearby features that need it, with an education screen explaining what the permission does. We do not use your personal information for a new, unrelated purpose without asking you first.
- Withdrawing consent. You can withdraw consent, subject to legal or contractual limits. In practice this means you can turn off location, analytics, and push notifications at any time, or delete your account. When you turn location off, we stop using your stored location and clear it as described in Section 3.2, and we retain personal information only as long as it is needed for the purposes described here before anonymizing or deleting it.
- Access and correction. You can request access to, or correction of, your personal information through the mechanisms above.
- Person responsible. The person responsible for the protection of personal information at Wyrdbit LLC can be reached at [email protected].
- Complaints. If you are not satisfied with how we handle your personal information, you can complain to the Office of the Privacy Commissioner of Canada or to your provincial regulator, such as the Commission d'accès à l'information du Québec.
Quebec and younger players. Quebec's Law 25 requires a parent or guardian's consent to collect personal information from a person under 14. BinderPlug's minimum age for creating your own account is 13, and younger players may only take part through an account created, held, and supervised by a parent or legal guardian (see Section 9). This means a 13-year-old in Quebec can currently self-register even though Law 25's parental-consent line sits at under 14. We describe the app's current posture plainly here; reconciling it for Quebec is a legal question we are working through.
9. Children and parents
You must be at least 13 years old to create a BinderPlug account. Younger players may participate in trades only through an account created, held, and supervised by a parent or legal guardian; the account holder is responsible for all activity on the account. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact [email protected] and we will delete it.
10. Security
Passwords are stored only as Argon2 hashes. Connections to our servers use TLS. Sign-in uses short-lived tokens with revocable refresh tokens. Email verification uses expiring one-time codes with rate limits. We design our logging, analytics, and crash reporting to exclude personal identifiers, and we accept vulnerability reports at [email protected]. No system is perfectly secure, and we cannot guarantee absolute security.
11. Where data is processed
Our servers and database are hosted by Render in the United States. Analytics data is hosted by PostHog in the EU. Encrypted database backups are stored with Cloudflare. If you use BinderPlug from outside those regions, including from Canada, your data will be transferred to and processed in them.
12. Changes to this policy
We version this policy and record the date of each change in the changelog below. If we make a material change, we will notify you before it takes effect. Notice appears in the app and, for significant changes, by email to your account address. We will post the new effective date here.
Where a change introduces a new purpose or a new sharing of personal information, we will ask affected users to agree before it takes effect, rather than relying on continued use. This is consistent with the renewed-consent standard under PIPEDA and Quebec's Law 25 for material changes affecting Canadian users.
Changelog
- privacy-policy-draft-2026-07-18: draft reflecting the shipped location-privacy changes (approximate-only location, precision reduced before storage, and up-to-30-day retention with clearing on revoke), push-token deletion on account deletion, and the append-only consent record for registration acceptances. Not in effect.
- privacy-policy-draft-2026-07-05: initial draft for owner review. Not in effect.
13. Contact
Wyrdbit LLC
31441 Santa Margarita Pkwy, Ste A #8099
Rancho Santa Margarita, CA 92688, USA
[email protected]