Privacy Policy

Last updated: September 9, 2026

Who We Are

The Legacy Vault LLC (“The Legacy Vault Cards”, “we”, “us”, “our”) is a United States limited liability company that sells collectible trading cards — Pokémon, One Piece, football and other TCG products, in raw, professionally graded (PSA, BGS) and sealed condition — online, with international shipping.

This Privacy Policy explains what personal data we collect through thelegacyvaultcards.com, why we collect it, who we share it with, and what rights you have over it. We are the data controller (The Legacy Vault LLC, EIN 42-4750545, trading as The Legacy Vault Cards, 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States) for the processing described here.

Questions, requests or complaints about privacy: info@thelegacyvaultcards.com.

Personal Data We Collect

We only collect data that we actually need. Today the website is in pre-launch, so the live collection points are the Early Access list and the contact form. The order-related data below will be collected once the store opens.

  • Early Access list — your email address, plus the date and time you subscribed and the IP address used to submit the form (kept as proof of consent and to prevent abuse).
  • Contact form — your name, your email address and the content of your message, including anything you choose to add to it.
  • Orders (once the store is live) — full name, shipping address, billing address, email address, telephone number (required by international couriers for customs and delivery), order contents, order value and order history.
  • Payment data — we do not receive or store your full card number. Card payments are processed by Stripe, which tokenises the card; we only see a payment reference, the last four digits, the card brand and the authorisation result. For bank transfers we see the payment reference and the details your bank transmits with the transfer. For cryptocurrency payments we see the wallet address the funds came from and the transaction hash.
  • Customer service records — emails you send us, photographs you provide in support of a return or damage claim, and our replies.
  • Technical data — IP address, browser type and version, device type, operating system, referring page and pages viewed. Server access logs are generated automatically by our hosting provider; analytics data is only collected if you consent to it (see our Cookie Policy).

We do not knowingly collect special categories of personal data (health, biometrics, political opinions, and so on). Please do not send us that kind of information.

Why We Use It, and On What Legal Basis

Under the EU and UK GDPR, every use of your data needs a legal basis. Ours are:

  • To send Early Access and marketing emails — your consent, given when you submit the Early Access form. You can withdraw it at any time using the unsubscribe link in any email or by writing to us.
  • To answer your contact form message — our legitimate interest in responding to people who contact us, or the steps taken at your request prior to entering a contract.
  • To process, pack, ship and invoice an orderperformance of the contract between you and us.
  • To handle returns, refunds, disputes and warranty or authenticity claims — performance of the contract and compliance with consumer protection law.
  • To keep accounting, tax and customs records — compliance with our legal obligations.
  • To prevent fraud, chargeback abuse and unauthorised access — our legitimate interest in protecting the business and our customers.
  • To measure how the website is used — your consent, collected through the cookie banner. If you do not consent, no analytics data is collected.

We do not sell your personal data, and we do not use it for automated decision-making or profiling that produces legal effects for you.

Cookies and Analytics

The website uses strictly necessary cookies to function (session and security cookies set by WordPress and Elementor) and, only where you consent, analytics cookies that help us understand which pages are visited. Full detail, including how to refuse or delete cookies, is in our Cookie Policy.

Who We Share Data With

We share personal data only with service providers who need it to do their job for us, and only to the extent needed. Each of them acts as our processor under a written agreement, or as an independent controller where the law makes them one (payment providers and couriers, typically).

  • Web hosting and email hosting — stores the website, form submissions and our mailbox.
  • Email delivery and mailing-list providers — sends Early Access and transactional emails.
  • Stripe — processes card payments and fraud checks. Stripe is an independent controller for the payment data it holds and applies its own privacy policy.
  • Our bank — receives and reconciles bank transfers.
  • Shipping carriers and customs brokers — receive the recipient name, address, telephone number, email and a customs description and value of the goods, which is a legal requirement for international shipments.
  • Grading companies (PSA, BGS) — only if you ask us to submit a card on your behalf.
  • Accountants, auditors and legal advisers — where necessary to run the company lawfully.
  • Public authorities — where we are legally required to disclose, for example customs, tax or law enforcement requests.

We never sell, rent or trade your personal data to third parties for their own marketing.

International Transfers

The Legacy Vault LLC is established in the United States, and some of our providers are located in the United States or process data there. If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal data will be transferred outside your country.

Where that happens we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our contracts with those providers, together with additional technical measures such as encryption in transit and at rest. You may request a copy of the safeguards we rely on by writing to info@thelegacyvaultcards.com.

How Long We Keep It

  • Early Access email addresses — until you unsubscribe, or after 24 months of no interaction with our emails, whichever comes first.
  • Contact form messages — 24 months from the last message in the exchange.
  • Order and customer records — for the duration of the commercial relationship and then for as long as claims can be brought.
  • Accounting, invoicing, tax and customs records — for the retention period required by applicable US tax law and by the customs rules of the destination country, which is generally at least seven years.
  • Server access logs — up to 12 months.
  • Consent records (cookie banner, Early Access) — for as long as the consent is relied on, plus the period in which it may need to be evidenced.

When a retention period ends we delete the data or irreversibly anonymise it.

Your Rights in the EEA and the UK

If the EU or UK GDPR applies to you, you have the right to:

  • access the personal data we hold about you and receive a copy of it;
  • have inaccurate data corrected and incomplete data completed;
  • have your data erased where there is no overriding reason for us to keep it;
  • restrict how we process your data while a dispute about it is resolved;
  • receive the data you gave us in a structured, machine-readable format and have it transmitted to another controller (portability);
  • object to processing based on our legitimate interests, and to object to direct marketing at any time and without giving a reason;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these, write to info@thelegacyvaultcards.com. We reply within one month; if the request is complex we may extend that by a further two months and will tell you why. We may ask you for information to confirm your identity before acting. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

You also have the right to lodge a complaint with your national data protection authority (for the UK, the Information Commissioner’s Office). We would appreciate the chance to address your concern first.

Your Rights in California (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, disclose and (if we did) sell or share; the right to request deletion; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information and of the use of sensitive personal information for certain purposes; and the right not to be discriminated against for exercising any of these rights.

In the past twelve months we have collected the categories of personal information described in “Personal Data We Collect” above, from you directly and from your interaction with our website, for the business purposes described in this policy. We have not sold or shared personal information as those terms are defined by the CCPA/CPRA, and we do not sell or share the personal information of minors.

To submit a request, write to info@thelegacyvaultcards.com with the subject line “California Privacy Request”. You may use an authorised agent; we will ask for proof of their authority. We verify requests by matching the information in the request against the information already in our records.

Children

The website and the store are not directed at children. We do not knowingly collect personal data from anyone under 16 years of age, and you must be at least 18 (or the age of majority where you live) to place an order. If you believe a child has given us personal data, write to us and we will delete it.

Security

The site is served over HTTPS with a valid TLS certificate. Access to the WordPress administration area and to our mailbox is restricted to named accounts with strong, unique credentials. Card data never reaches our servers: it is captured and tokenised directly by Stripe, a PCI-DSS Level 1 certified provider. Backups are taken regularly and stored on the same protected infrastructure.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you directly where the law requires it.

Changes to This Policy

We may update this policy when our processing changes or when the law changes. The current version is always published on this page with the “Last updated” date at the top. If a change materially affects your rights, we will notify Early Access subscribers and customers by email before it takes effect.

Contact

The Legacy Vault LLC
Email: info@thelegacyvaultcards.com
Website: thelegacyvaultcards.com
Instagram: @thelegacyvaultcards

Please use the email address above for all privacy requests; it is the fastest route and it is monitored.