Privacy Policy

Effective Date: April 1, 2026 · Last updated: May 13, 2026

1. Introduction

CardOutpost is operated by Arcade Processing LLC ("we," "our," or "us"), a company incorporated under the laws of Delaware, USA. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have in relation to it. Please read this policy carefully. By using CardOutpost (the "Platform"), you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect

We collect information in several ways depending on how you interact with our Platform:

Account Information

  • Email address (required for account creation and communication)
  • Username or display name
  • Password (stored in hashed form — we never store plaintext passwords)
  • Full legal name, date of birth, and residential address (collected at signup and for KYC)

Payment Information

  • Payment processing is handled by Stripe, Inc. using fiat currency (USD) only. We do not store credit card numbers, CVV codes, or full card details on our servers.
  • We may store a tokenised payment method reference (Stripe customer ID and payment method ID) to enable repeat purchases.
  • Billing address or last four digits of a card may be retained for fraud prevention purposes.

KYC & Verification Data

  • For withdrawal eligibility and regulatory compliance, we collect government-issued photo ID, selfie/liveness imagery, and proof of address documents (utility bill or bank statement). This data is processed and stored by Stripe Identity in accordance with their privacy practices and our data processing agreement, and retained for a minimum of 5 years from account closure to comply with AML obligations.

Usage & Activity Data

  • Pages visited, features used, and time spent on the Platform
  • Packs purchased and opened, cards pulled, cards sold
  • Transaction history (deposits, pack purchases, card sales, credit withdrawals)
  • Clicks, scrolls, and interaction events for analytics and UX improvement

Device & Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Device type and screen resolution
  • Referring URL and UTM parameters (for tracking ad campaign performance)

Cookies & Tracking Technologies

  • Session and authentication cookies (Supabase)
  • Analytics cookies (PostHog)
  • Advertising pixels (Meta/Facebook Pixel, TikTok Pixel)

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Account management: Creating and maintaining your account, authenticating your identity, and communicating with you about your account.
  • Transaction processing: Processing your pack purchases, card sales, credit withdrawals, and physical card shipments securely.
  • Platform improvement: Analyzing usage patterns to improve the Platform's features, performance, and user experience.
  • Analytics: Understanding how users interact with the Platform through aggregated and anonymized analytics data.
  • Fraud prevention & security: Detecting and preventing fraudulent activity, abuse, and unauthorized access.
  • Legal compliance: Meeting our legal obligations, including record-keeping for financial transactions.
  • Marketing & advertising: Serving relevant advertisements on third-party platforms (Meta, TikTok) based on your activity and demographics, where you have not opted out.
  • Customer support: Responding to your inquiries and resolving disputes in a timely manner.

4. Third-Party Services

We work with trusted third-party services to operate the Platform. Each has their own privacy practices:

  • Stripe, Inc. — Payment processing and KYC/identity verification. Stripe may collect and process your payment information and KYC documents in accordance with their Privacy Policy (stripe.com/privacy).
  • Supabase, Inc. — Authentication and database services. Your authentication data is processed by Supabase in accordance with their Privacy Policy (supabase.com/privacy).
  • PostHog, Inc. — Product analytics and session recording. PostHog collects usage events and may record screen interactions (posthog.com/privacy).
  • Meta Platforms, Inc. — We use the Meta (Facebook) Pixel to measure the effectiveness of our advertising campaigns. Meta may use this data to serve you relevant ads on Facebook and Instagram (facebook.com/privacy).
  • TikTok — We use the TikTok Pixel to measure advertising campaign performance on TikTok. TikTok may use this data to serve you relevant ads (tiktok.com/legal/privacy-policy).
  • Vercel, Inc. — Hosting and infrastructure provider. Vercel may process request logs and other technical data (vercel.com/legal/privacy-policy).
  • PayPal, Inc. & Wise — For withdrawal processing. We share necessary data (name, email, account identifiers) to facilitate payouts. These transfers are governed by their respective privacy policies.

We are not responsible for the privacy practices of these third-party services and encourage you to review their respective privacy policies.

5. Cookies & Tracking

We use the following types of cookies and tracking technologies on the Platform:

  • Essential cookies: Required for the Platform to function, including session authentication cookies set by Supabase. These cannot be disabled without preventing you from using the Platform.
  • Analytics cookies: Set by PostHog to collect anonymized data about how users interact with the Platform. Used to improve performance and features.
  • Advertising pixels: The Meta Pixel and TikTok Pixel track conversions and enable us to show you relevant advertising on those platforms.

You can disable non-essential cookies through your browser settings. Note that disabling cookies may affect the functionality of the Platform. For advertising pixels specifically, you may also opt out through Meta's and TikTok's ad preference settings in their respective applications.

Global Privacy Control (GPC). We honor the Global Privacy Control signal as a valid opt-out request under the California Consumer Privacy Act (CCPA) and other applicable U.S. state privacy laws. When we detect a GPC signal from your browser, we treat it as a request to opt out of the sale and sharing of your personal information for cross-context behavioral advertising, including the use of the Meta Pixel and TikTok Pixel for that browser and any account linked to it. You do not need to be a verified user for us to honor the signal.

6. Sanctions, PEP & Adverse Media Screening

User names and addresses are screened at onboarding and on an ongoing basis against the OFAC Specially Designated Nationals (SDN) List and consolidated sanctions lists, as well as politically exposed persons (PEP) and adverse media databases. Screening occurs at signup, KYC completion, and continuously thereafter. This screening is performed for AML compliance and fraud prevention. Confirmed sanctions matches result in immediate account suspension and reporting to OFAC where required.

7. Data Retention

We retain your personal information for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal or compliance purposes.

Transaction records, KYC files, sanctions and PEP screening results, and AML escalation logs are retained for a minimum of 5 years from the date of the relevant transaction or account closure, whichever is later, to comply with financial, tax, and AML regulations. Aggregated, anonymized analytics data may be retained indefinitely.

Where a user submits a deletion or erasure request under applicable privacy law (e.g., CCPA, GDPR), we honor the request only to the extent it does not conflict with our regulatory recordkeeping obligations. AML, KYC, and sanctions records are retained for the full statutory period regardless of any deletion request, and the user is informed of this carve-out in writing.

8. Data Security

We take the security of your personal information very seriously and implement appropriate technical and organisational measures to protect it, including:

  • SSL/TLS encryption for all data transmitted between your browser and our servers.
  • Secure, hashed password storage: we never store or have access to your plaintext password.
  • PCI-compliant payment processing through Stripe: your full card details are never transmitted to or stored on our servers.
  • Access controls limiting employee access to user data on a need-to-know basis.
  • Regular security reviews and infrastructure monitoring.

No method of transmission or storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

Breach notification. If we confirm a data breach affecting your personal information, we will notify you and applicable regulators without undue delay and, where feasible, within seventy-two (72) hours of confirming the breach. The notice will describe the categories of personal information affected, the steps we have taken in response, and any actions you can take to protect yourself. Where applicable law requires a shorter notification period or different content, we will comply with that law.

9. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate or incomplete personal data.
  • Deletion: Request deletion of your personal data, subject to legal retention requirements.
  • Opt-out of marketing: Unsubscribe from marketing emails at any time using the unsubscribe link or by contacting us.
  • Data portability: Request your data in a portable format.
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, please contact us at support@cardoutpost.com. We will respond to your request within 30 days.

10. Children's Privacy

CardOutpost is not intended for use by anyone under the age of 18 and we are very strict about our minor policy. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at support@cardoutpost.com and we will take steps to delete that information promptly.

11. International Data Transfers

CardOutpost is operated from the United States. If you are located outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. By using the Platform, you consent to this transfer. Where required by law, we will implement appropriate safeguards for cross-border transfers of personal data.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will update the "Last updated" date at the top of this page when we do so. For material changes, we may notify you by email or by posting a prominent notice on the Platform. Your continued use of the Platform after any changes take effect constitutes your acceptance of the revised Privacy Policy.

13. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: support@cardoutpost.com
Arcade Processing LLC
2810 North Church Street
Wilmington, DE 19802, USA