Scalpr
Updated 2026-08-10
DRAFT — Owner/legal review required before App Store / Play submission. This document describes actual product behavior; it is not legal advice.
Scalpr is the product name of this software. The legal developer/company entity that operates Scalpr is confirmed separately by the operator (see support contact). Scalpr provides inventory, CRM, restock alerting, and optional financial integrations for trading-card / resale businesses.
We collect email address, authentication identifiers (via Supabase Auth), display name, and subscription/entitlement status. Passwords are handled by the authentication provider and are not stored in Scalpr application tables as plaintext.
Contacts (buyers/sellers/vendors), inventory, lots, sales, deals, notes, tags, capital adjustments, watchlists, notification preferences, and support tickets. This data is private to your Scalpr client account and protected by row-level security.
If you link Discord, we store Discord user ID and display metadata needed for guild membership and role synchronization. OAuth tokens remain server-side when used. We do not post bank or capital details to public Discord channels.
If you connect a bank via Plaid Link, Scalpr does not receive your bank username/password. We store institution/account metadata, balances, and transactions needed for reconciliation, plus server-side access tokens required to sync. Tokens are not exposed to the mobile/web client.
Optional credentials and imported order/purchase history are stored only to power inventory ingestion and reconciliation. We do not store raw payment card numbers.
Product catalog and market prices may be fetched from legitimate pricing providers (e.g. JustTCG) and cached for all subscribers. Provider API keys stay on the server.
If enabled, we store device push tokens, platform, and last-seen metadata to deliver restock and business alerts.
We may retain integration health events and error codes (redacted) to operate the service. We do not intentionally log authorization headers, secrets, or bank access tokens.
You may request account deletion in-app or via the public account deletion page. We delete or anonymize private operational data associated with your client account according to product policy. Active store subscriptions may continue until canceled with Apple/Google/Stripe separately. Legal retention requirements, if any, should be confirmed by counsel.
Data in transit uses HTTPS. Access to private rows is enforced with authenticated sessions and RLS. Secrets are server-side only.
Scalpr is intended for business users and is not directed at children under 13.
We may update this policy; the “Updated” date above will change when published.