Legal
Privacy Policy
How we collect, use, and protect your data on CardHaven.
Our privacy commitment
We do not sell your data. We do not profile you for advertising. We share as little as possible with anyone outside of CardHaven, and only when strictly necessary to operate the service.
This Privacy Policy explains how CardHaven ("we", "our", or "us") handles your information when you use our marketplace.
1. Information we collect
- Account information: email address, username, password hash, and security settings such as MFA enrollment and trusted-device records.
- Marketplace information: listings, orders, dispute records, deposits, withdrawals, and related transaction metadata.
- Security metadata: IP and User-Agent fingerprints for abuse prevention and account protection. These values are stored in a ciphered form — we never see or store them as raw data.
- Communications: account verification, login security messages, password reset emails, and operational notices.
2. How we use information
- Provide and operate the marketplace.
- Authenticate users and protect accounts.
- Process deposits, withdrawals, and dispute workflows.
- Detect fraud, abuse, and policy violations.
3. Payment and blockchain processing
Crypto payments are processed through our payment provider. We track the status of your payment to confirm it and credit your account. No unnecessary data is retained beyond what is needed to complete your transaction.
4. How we share information
We do not sell your personal information. We do not share your data with third parties except as strictly necessary to operate the service. In practice, this means:
- Our payment processor receives only the minimum information required to complete your transaction. We do not share your personal data with them for any other purpose.
We do not share your information with advertisers, data brokers, or any other parties.
5. Data retention and security
We take the security of your data seriously. We use appropriate safeguards to protect your information from unauthorized access, loss, or misuse. We retain data for as long as needed to provide the service, resolve disputes, and maintain financial records. When data is no longer needed, it is removed.
6. Third-party tools
We use Cloudflare Turnstile on certain forms to protect against bots and automated abuse. Turnstile is a privacy-friendly alternative to traditional CAPTCHAs — it does not track you or use your data for advertising. For more information, see Cloudflare's privacy policy.
7. Changes to this policy
We may update this Privacy Policy from time to time. Material updates will be posted on this page with a revised "Last updated" date.
8. Contact
For privacy questions, use live chat on the site or the contact section in the Terms of Service.