Privacy Policy
Last updated: May 2026
This Privacy Policy explains how SnapSlab ("we", "us") collects, uses, and protects your personal data when you use snapslab.uk. We are committed to your privacy and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
SnapSlab operates the website snapslab.uk. For data protection purposes, SnapSlab is the data controller. You can contact us at snapslab.uk/contact with any privacy-related questions.
2. Data we collect
We collect the following categories of personal data: (a) Account data — your email address and name, collected when you register via Clerk; (b) Card library data — the trading card details you save (card name, set, rarity, condition, estimated value, scan date), stored in our database; (c) Card images — photographs you take of trading cards, stored in Vercel Blob storage; (d) Subscription data — your plan status (Free or Pro), monthly scan count, and subscription timestamps, stored in our database; (e) Payment data — Stripe handles payment processing and stores your card details. We only receive a Stripe customer ID and subscription status — we never see or store your full payment card number; (f) Usage data — basic request logs (IP address, browser type, pages visited) retained by our hosting provider Vercel for security and performance purposes.
3. How we use your data
We use your data to: (a) provide and operate the Service, including authenticating you, running AI card identification, and displaying your library; (b) process subscription payments and enforce plan limits; (c) send transactional emails (e.g. receipt of subscription) via Clerk or Stripe; (d) prevent fraud and abuse. Our lawful basis for processing is performance of a contract (providing the Service you signed up for) and, where applicable, our legitimate interests in operating a secure and functional service.
4. AI processing
When you scan a card, the image is sent to Anthropic's Claude API for identification. Anthropic processes the image solely to return an identification result. Anthropic's data usage policies apply to this processing. We do not use your card images to train AI models, and Anthropic's API usage under zero data retention terms means images are not retained by Anthropic after the API call completes.
5. Third-party services
We use the following third-party processors: Clerk (authentication and user management — clerkjs.com), Stripe (payment processing — stripe.com), Anthropic (AI card identification — anthropic.com), Vercel (hosting and image storage — vercel.com), Neon (database hosting — neon.tech), PokéTCG API / Scryfall / YGOPRODeck (live price lookups — no personal data is sent to these services). Each processor operates under their own privacy policy and data processing terms.
6. International data transfers
Some of our third-party processors (including Vercel, Neon, Anthropic, and Stripe) are based in the United States. Data transferred to the US is protected by the processor's compliance with UK GDPR Standard Contractual Clauses or equivalent safeguards.
7. Data retention
We retain your account and library data for as long as your account is active. If you delete your account, your personal data is removed within 30 days, except where we are required to retain certain records for legal or tax purposes (such as payment records, which Stripe retains per their policy). Card images in Blob storage are deleted promptly upon account deletion.
8. Your rights
Under UK GDPR you have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data (the right to erasure); request restriction of processing; receive your data in a portable format; object to processing based on legitimate interests. To exercise any of these rights, email snapslab.uk/contact. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.
9. Cookies
SnapSlab uses two categories of cookies: (a) Essential cookies — set by Clerk to maintain your signed-in session. These are strictly necessary to provide the Service and do not require your consent; (b) Analytics cookies — set by Vercel Analytics to measure aggregate site usage (pages visited, device type). No personal identifiers are stored. We ask for your consent before setting analytics cookies via the banner shown on your first visit. You can change your preference at any time by clearing your browser's local storage for snapslab.uk. We do not use advertising or tracking cookies.
10. Children's privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us at snapslab.uk/contact and we will delete it.
11. California residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights in addition to those listed above: (a) Right to know — you may request details about the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the third parties we share it with; (b) Right to delete — you may request deletion of your personal information, subject to certain exceptions; (c) Right to correct — you may request correction of inaccurate personal information; (d) Right to opt out of sale or sharing — SnapSlab does not sell your personal information and does not share it for cross-context behavioural advertising; (e) Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights. To submit a CCPA/CPRA request, email snapslab.uk/contact with the subject line 'California Privacy Request'. We will respond within 45 days.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or by a notice on the Service. The date at the top of this page reflects when the policy was last revised.
13. Contact
For privacy-related questions or to exercise your rights, contact us at snapslab.uk/contact.