This Privacy Policy explains how Marbir Digital, LLC ("NDX," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the NDX mobile app, the website at getndx.com, the NDX API, and related services (the "Services").
The short version: we collect what we need to run a card-scanning and collection app — your sign-in identity, the card images you scan, your collection data, and standard device and usage data. We do not sell your personal information. Free tiers are supported by advertising and relevant third-party listings (for example, eBay listings for the card you're viewing); where ad partners collect device data or ads are personalized, you have the consent choices and opt-outs described in Sections 3 and 5. You can delete your account and data from within the app at any time.
1. Information We Collect
Information you provide
- Account information. When you sign in with Apple or Google, we receive your name (if shared), email address, and a provider account identifier. If you use Apple's Hide My Email, we receive the relay address instead of your real email. We also generate a unique NDX account ID and a public username (
@handle), which you can edit. - Card images and scans. Photos you capture or select for card identification. These images are transmitted to our third-party card data provider (see Section 3) for identification, and may be retained and used — by us and by the provider — to improve identification quality and train machine-learning models. Do not include people, identity documents, or other sensitive material in scans — the camera is for trading cards.
- Collection data. The cards you add, collections and lists you create, quantities, conditions, grades, and related notes.
- Preferences and settings. Release reminders, notification settings, appearance settings, and similar choices.
- Communications. Messages you send us (support requests, feedback), including their contents and your contact details.
Information collected automatically
- Device and app data. Device model, OS version, app version, language, time zone, IP address, and unique identifiers needed for sessions and push notifications (e.g., APNs device tokens).
- Usage data. Interactions with app features, crash reports, and performance and diagnostic logs. We use this to fix bugs and improve the app.
- Advertising data. On ad-supported tiers, ad partners may collect device identifiers, IP address, and coarse (city-level) location to serve ads and measure their performance. We will not permit access to your device's advertising identifier (IDFA) for tracking without your consent through Apple's App Tracking Transparency prompt.
- We do not collect precise GPS location, contacts, or microphone audio. We do not use session-replay tools that record your screen or keystrokes.
What we don't collect
We do not collect or derive biometric identifiers from images. Card scans are photos of trading cards, and we do not run face recognition or similar processing.
2. How We Use Information
We use personal information to:
- Provide the Services — authenticate you, identify scanned cards, store and sync your collection across devices, show pricing and release data, and deliver reminders and push notifications you request.
- Maintain safety and security — prevent fraud and abuse, enforce our Terms of Use and Acceptable Use Policy, and protect the Services.
- Improve the Services and train models — debug, analyze aggregate usage, develop features, and use card images and collection data to train, refine, and improve card-identification, pricing, and related machine-learning models, under the license described in our Terms of Use. Card images do not contain information about you personally (see "What we don't collect" above), and we do not use them to identify people.
- Communicate with you — service announcements, security notices, and responses to your inquiries. Marketing messages, if any, will include an opt-out.
- Show advertising and relevant listings — on ad-supported tiers, display ads and third-party marketplace listings (for example, eBay listings related to a card you are viewing). Ads and listings are selected primarily based on the content displayed (contextual), not on a profile of you. If we introduce personalized advertising, it will be subject to your device-level consent (App Tracking Transparency) and the opt-outs in Section 5.
- Comply with law — respond to lawful requests and meet legal obligations.
3. How We Share Information
We share personal information only as follows:
- Card data providers (card identification, pricing, and collection platforms). Card images you scan, and your collection data, are transmitted to and stored with our card data provider under a pseudonymous collector ID that our backend owns and links to your NDX account. The provider does not receive your name or email from us. Under their own terms, these providers may retain submitted images and data and use them to improve their services and train their machine-learning models. When you delete your account, we delete the linked collector data at the provider. We may change providers or use more than one.
- Service providers. Infrastructure and hosting providers (e.g., our backend hosting platform), and Apple/Google for sign-in, push notification delivery, and in-app purchases. Service providers are contractually limited to processing data on our instructions and must protect it consistently with this policy.
- Advertising partners. On ad-supported tiers, ad networks may collect device identifiers, IP address, and ad-interaction data directly from the app to serve and measure ads, as described in Section 1. Depending on the partner and configuration, this collection may be considered a "sale" or "sharing" of personal information under some state laws; you may opt out as described in Section 5.
- Affiliate and marketplace partners. When we show third-party listings (for example, eBay) or affiliate links, the partner may receive standard referral data when you click through — such as the link, your IP address, and device information — and may set its own identifiers on its own properties. We may receive commissions or referral fees from these partners. We do not send partners your name, email, collection contents, or card scans.
- Legal and safety. When required by law or legal process, or when necessary to protect the rights, safety, or property of NDX, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred; we will notify you of any change in ownership or use of your personal information.
We do not sell personal information for money, and we do not license or commercialize datasets derived from your personal information. Some advertising-related disclosures described above may qualify as a "sale" or "sharing" under California law and similar state laws; Section 5 explains how to opt out.
Payment processing and financial data
We do not collect, store, or process your full payment card details or financial credentials on our servers.
- In-app purchases and subscriptions are processed by Apple through the App Store. Apple collects your payment information under its own privacy policy; we receive only confirmation of the transaction and subscription status — never your card details.
- Purchases made through our website, if and when offered, are processed by a third-party payment processor such as Stripe, Inc. Your payment information is collected directly by the processor under its own privacy policy (for Stripe, available at stripe.com/privacy). We receive only limited, non-sensitive transactional data — such as a payment token, transaction confirmation, card brand and last four digits, expiration date, and billing zip code — solely to verify payment status and keep your subscription active.
By using our payment features, you acknowledge that your financial information is handled by these processors, and their use and security of that data is governed by their own policies.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data Retention
- Account and collection data: retained while your account is active.
- Card scan images: used for identification and, where you add a card to your collection, retained with your collection data; raw scan images not associated with a saved card are deleted on a routine schedule.
- Logs and diagnostics: retained for a limited period (typically 90 days or less) and then deleted or aggregated.
- After account deletion: account and collection data (including linked collector data at our card data provider) is deleted promptly; residual copies in our encrypted backups are purged on a rolling basis, no later than 90 days after deletion. Copies in our vendors' archive and backup systems, including our card data providers', persist until purged under those vendors' retention schedules. We may retain limited records where required for legal, security, or dispute-resolution purposes. Deletion does not affect machine-learning models already trained while your data was licensed to us (see the Terms of Use), and such models do not contain your personal information.
5. Your Rights and Choices
Regardless of where you live, we offer everyone the following:
- Access and portability. Request a copy of the personal information we hold about you.
- Correction. Update your profile in the app or ask us to correct inaccurate information.
- Deletion. Delete your account and associated data directly in the app (Profile → Account → Delete Account), or by emailing [email protected].
- Advertising choices. Decline cross-app tracking via Apple's App Tracking Transparency prompt (or in iOS Settings → Privacy & Security → Tracking) at any time. Where the app offers a "Do Not Sell or Share My Personal Information" setting, you can use it to opt out of ad-related disclosures that qualify as sale/sharing under state law. Paid tiers may reduce or remove ads.
- Push notifications. Enable or disable in the app or in iOS Settings at any time.
To exercise rights by email, contact [email protected]. We will verify your request (typically by confirming control of your account email) and respond within the time required by applicable law (generally 45 days). Authorized agents may submit requests with proof of authorization. If we decline a request, you may appeal by replying to our decision; we will respond to appeals as applicable law requires. We will not discriminate against you for exercising your rights.
US state privacy rights
If you live in California or another state with a comprehensive privacy law, you have rights to know/access, correct, delete, and obtain a portable copy of your personal information, and to opt out of sale, sharing, and targeted advertising. To the extent ad-related disclosures described in Section 3 qualify as sale/sharing or targeted advertising, you may opt out using the advertising choices in this Section 5 or by emailing [email protected] with the subject "Opt-Out Request." Our websites honor the Global Privacy Control (GPC) signal where required. California residents: we do not use or disclose sensitive personal information for purposes requiring a right to limit.
EEA, UK, and other international users
If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar laws: we process personal information on the legal bases of contract performance (providing the Services you request), legitimate interests (security, service improvement, communications), consent (where requested, e.g., optional communications), and legal obligation. You additionally have rights to object to or restrict processing and to withdraw consent, and you may lodge a complaint with your local supervisory authority. The Services are operated from the United States, and your information is transferred to and processed in the U.S.; where required, we use appropriate safeguards for such transfers.
6. Children's and Minors' Privacy
The Services are intended for adults and are available only to users 18 and older. We do not knowingly collect personal information from anyone under 18, and we do not knowingly serve personalized advertising to, or sell or share the personal information of, minors. If we learn we have collected personal information from someone under 18, we will delete it and terminate the associated account. Parents or guardians who believe a minor has provided personal information should contact [email protected].
7. Security
We protect personal information with measures including encryption in transit (TLS), encryption at rest for stored data, scoped access controls, and short-lived session tokens with refresh rotation. No system is completely secure; if a breach affecting your personal information occurs, we will notify you as required by law.
8. Third-Party Links and Services
The Services may link to third-party websites and services (for example, a card manufacturer's site or Apple subscription management). Their privacy practices are governed by their own policies, which we encourage you to review.
9. Changes to This Policy
We may update this Privacy Policy. For material changes, we will notify you in the app or by email before the changes take effect and update the dates at the top. If a material change would allow us to use personal information we collected before the change in a materially different way, we will apply the change prospectively only, or ask for your affirmative consent before applying it to previously collected information. For other changes, your continued use of the Services after the effective date constitutes acceptance.
Disputes arising out of or relating to this Privacy Policy are subject to the dispute-resolution, arbitration, governing-law (Wyoming), and venue provisions of our Terms of Use.
10. Contact Us
Marbir Digital, LLC
Privacy inquiries: [email protected]
Legal inquiries: [email protected]