← Back to Home

Privacy Policy

Last updated: September 15, 2026

Introduction

SlabTracked ("we," "us," or "our") provides a submission-tracking and listing platform for graded collectibles — including comics, trading cards, magazines, video games, and other slabbed items graded by services such as CGC and PSA. This policy explains what information we collect, how we use it, and the choices you have. It covers both the SlabTracked web application and the SlabTracked browser extension. By using SlabTracked, you agree to this policy.

1. Information We Collect

Account information

  • Name and email address
  • Password (hashed; never stored in plain text)
  • Subscription tier and billing details (processed by Stripe)
  • Dealer/business information, if you provide it

Submission & collectible data

  • Invoice and submission details from your grading accounts
  • Cert numbers, grades, and certification data
  • Item titles, issue/set numbers, and variant information
  • Grading status updates and shipment tracking
  • Images of your items and certification pages

Optional SlabTracked AI drafts

Chat with SlabTracked uses your browser's speech recognition, which may process audio through the browser provider. SlabTracked does not upload or store a voice recording. After you consent and choose Build my list, your transcript, selected grading service, service level and expected item count are sent to our configured processor (Gemma 4 through Ollama, or OpenAI) to create editable entries. The original transcript remains in the open form's memory and is not saved by SlabTracked. Generated drafts and hashed request records may be cached for up to 24 hours to recover results and prevent repeat charges. Operational logs contain token counts, timing and estimated cost, not transcript text. Entries you add to the form follow the normal draft and submission storage rules. Item names, printed identifiers, year, set and language are used to search the CGC or PSA catalogue and select the best supported match. Uncertain matches are flagged for review. Review identities and signature requests before submitting.

Optional AI photo and video-frame drafts

When you choose image scan and consent, resized front-photo overviews or still frames selected locally from a short video, plus temporary item crops, are sent through SlabTracked to third-party AI processors to suggest an editable list of collectibles. The initial scan may use multiple bounded analysis calls so each detected item can be read separately. Proposed video identities may be sent to a second processor for independent review; when a photo-scan item remains incomplete, SlabTracked may send only that item's temporary crops to a second processor for enhanced review. Do not include faces, addresses, payment information, or other sensitive details. This beta does not require back photos and does not submit anything to a grader. For video capture, audio is not used, the raw video stays on your device, and up to two selected still frames from each detected item may be sent as one logical entry after you choose Scan. SlabTracked processes scan photos and selected frames temporarily rather than saving them as inventory images. Suggested text and scan-control records are temporarily cached to recover completed scans and limit abuse; rows you add to a form follow the existing draft and submission storage rules. AI suggestions can be inaccurate and must be reviewed before submission.

  • OpenAI — bounded enhanced review of unresolved or disputed photo/video identities after you consent. Clear comic identities that pass the independent issue check do not receive this extra review. API data is not used for model training by default. We disable Responses API application storage; this does not eliminate provider abuse-monitoring retention, which is ordinarily up to 30 days and may be longer when legally required (API data controls)
  • Ollama — initial photo and guided-video still analysis after you consent. One scan may send the resized overview and temporary derived item crops in multiple bounded calls so each detected item can be read separately. Raw video is not sent. Ollama's current cloud service advertises zero data retention; requests remain subject to Ollama's privacy policy

Marketplace data

  • eBay listing drafts and templates
  • Whatnot inventory data (if connected)
  • Shopify store connections (if configured)

Optional grading-account credentials

For hosted CGC submissions, you can enter your login in SlabTracked and have Browserbase sign in on your behalf. We encrypt it using AES-256-GCM with protection tied to your SlabTracked user and chosen CGC account. By default the encrypted password is removed when the sign-in attempt begins, when you close the session, or by cleanup after the session expires (at most 20 minutes, plus the cleanup interval). If you explicitly choose Save encrypted login, we retain it for future hosted drafts until you forget it or disconnect that account in Hosted CGC settings. A failed saved login is paused until you update it. Each Collector or Dealer account has its own private Browserbase context, including login cookies and browser storage. Disconnecting deletes that context and the saved login. Hosted browser recording and session logs are disabled. CGC receives the login; SlabTracked does not collect payment card details for this workflow.

If you choose to enable auto-login in the browser extension, the grading-account email and password you enter are held only for the current browser session in companion version 2.10.5 and are used solely to sign in to your own CGC or PSA account. During the separately labeled regular-account CGC server test, you may instead authorize SlabTracked to store your CGC username and password as one AES-256-GCM encrypted payload for no more than 72 hours so it can request available CGC Comics and CGC Cards CSV exports. That credential becomes unusable at expiry and can be deleted immediately from Connected Accounts.

PSA server sync does not store the password you enter. You sign in directly to PSA inside a temporary Browserbase Live View. With your explicit consent, Browserbase retains the resulting encrypted browser context, including PSA cookies and browser storage, until you disconnect it, PSA invalidates the login, or the connection is otherwise deleted. SlabTracked stores only the opaque Browserbase context identifier. If you separately authorize scheduled access, short-lived server browsers reuse that context about every 30 minutes while a known PSA order is active, and about every six hours otherwise, to request your private order list, exact in-progress stages, return-shipping data, and available completed-order cert data, including PSA's per-order CSV fallback. The browser extension remains an optional companion. See "Browser extension" and "Data storage & security" below.

Usage information

  • Login times and feature usage within the web app
  • Browser and device information
  • Error and diagnostic logs

2. Browser Extension

The SlabTracked browser extension acts on the supported CGC, PSA, Whatnot, and SlabTracked pages declared in its manifest. It reads private grading order and invoice records, statuses, certificate numbers, item details, and grader-provided return tracking numbers to sync them to your SlabTracked account. You can start submission-form assistance and Whatnot inventory workflows from SlabTracked. You review final submissions and marketplace actions. Certification enrichment and carrier delivery updates run through SlabTracked's server integrations; the extension does not open public certification pages, carrier pages, or eBay listings.

Extension version 2.9.0 removes the PSA relay, shared-search proxy, submission-ID pools, and request-header rewriting from the regular companion and drops the declarativeNetRequest permission. Private CGC and PSA sync remains supported, including granular PSA status stages. Sync success is reported after the server acknowledges saved records; failed attempts remain retryable. CGC invoice CSV fallback handles only the exact extension-requested export, removes its completed local file before clearing its download entry, and shows a warning if cleanup cannot finish. Unrelated downloads are ignored. Status propagation and certification enrichment are handled independently on the server.

In companion version 2.9.1, Pause and Sign out keep scheduled grading sync stopped across browser restarts. Manual CGC and PSA sync, sync interval changes, and deferred enrichment timers also respect Pause until you resume. These controls do not delete records already saved to your SlabTracked account.

In companion version 2.9.2, Whatnot CSV uploads stay in memory for the active import and are sent to your Whatnot inventory page. Starting an import clears any older unused CSV upload job from local storage. Import results return to the SlabTracked page that started the upload, and success requires confirmation from Whatnot.

In companion version 2.10.0, convention names/dates, selected creator names and CGC catalog IDs, creator requests, and custom-label requests are saved with your presets and submission drafts. Creator search sends your search text to CGC through SlabTracked; no AI matching is used. The companion stores preparation progress on this device and enters matched choices on your CGC form. You review waivers, shipping, payment, and final submission yourself. When CGC presents its holder-removal waiver, SlabTracked can show the current text and relay your explicit agreement to that exact waiver. We retain its text fingerprint and the times you approved it and it was applied. Shipping and payment open on CGC’s own site using the same account.

Companion version 2.10.1 also carries shared submission services and declared-value defaults. Your most recent applied creator selection is saved to your SlabTracked account for reuse across drafts and devices. Field microphones use your browser’s speech recognition. JSA details, autograph minimum grades, and unavailable choices require review on CGC; payment and legal consent remain under your control.

Companion version 2.10.2 keeps a device-local record of the requested settings and acknowledged book progress to verify its shipping handoff. It can open Shipping after preparing the draft; shipping choices, payment and legal agreements remain yours. This update adds no new permissions or third-party data sharing.

Companion version 2.10.3 verifies convention comic and creator catalog matches directly with CGC and waits for its form to confirm each signer and eligible custom label. It adds no permissions, credential storage, or data sharing with Browserbase. Extension submissions run in your own signed-in CGC browser tab.

Companion version 2.10.4 uses the existing account connection state to show the appropriate sign-in or sign-out actions in the popup. This display update adds no permissions, stored data, or data sharing.

Companion version 2.10.5 stores its SlabTracked token, account email and optional grader credentials in Chrome session storage, restricted to trusted extension contexts. Restarting Chrome, disabling, reloading or updating the extension clears these credentials. Sign out clears them too and pauses the companion; existing website login cookies are separate. Legacy credentials in local and Chrome sync storage are deleted, not migrated. Optional grader passwords are used only for the corresponding grader and are not sent to SlabTracked. PSA credential replies remain restricted to the top-level Collectors sign-in page. Preferences use Chrome sync storage. Order caches, pending jobs, retry state and diagnostic activity remain device-local; this update does not encrypt or remove those workflow records. Broad tabs permission is removed; matching host permissions still allow coordination on the supported sites. Synced records and status reports are sent to SlabTracked over HTTPS. Removing the extension clears its local data; account data can be deleted through SlabTracked's account controls.

The separate PSA Relay developer extension must be installed with Load unpacked and explicitly enabled. It receives shared search requests from SlabTracked, queries PSA using the operator's browser session, and returns matching search results, images, availability, locale, and submission-context metadata to SlabTracked. It keeps pool settings and retry timing locally, including a one-way authentication fingerprint, and uses Chrome sync storage for its SlabTracked login. Optional automatic PSA session recovery stores the operator's PSA email and password only in the developer extension's local storage, never Chrome Sync or SlabTracked. The Collectors host permission lets it submit those credentials only on the Collectors sign-in page in its own maintained relay tab. It reopens or refreshes that tab every 20 minutes while Chrome runs and pauses for verification or login failures. Forget PSA credentials removes the saved PSA login and disables automatic sign-in. It does not copy browser cookies or upload PSA credentials to SlabTracked. Its request-header rules apply only to its own PSA API requests. Disabling it stops relay polling and maintenance; disconnecting also clears its SlabTracked login. Version 1.1.1 changes only relay request timing and adds no data collection or permissions. This developer tool is excluded from the regular companion and its Chrome Web Store package.

SlabTracked's use of information received from the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data is used to provide and improve the disclosed grading and inventory features, not for advertising or sale. We do not collect general browsing history.

Permissions and why they are used

PermissionPurpose
storageStore preferences and the SlabTracked login in Chrome sync storage; keep order state and optional grader logins locally
scriptingRead private grader submission/order data and assist with grading submission forms and Whatnot inventory
tabs, tabGroupsCoordinate grader workflows and keep one reusable CGC tracking tab visibly contained in the SlabTracked group
cookiesDetect grader sessions, authenticate with SlabTracked, and reset only a staged CGC form draft; grader cookies are not uploaded to SlabTracked
downloadsIntercept a requested CGC CSV for import and cancel the duplicate browser download
notificationsAlert you when a tracked submission changes status
alarmsSchedule periodic background syncs

Sites the extension works with

  • CGC (cgccomics.com, cgccards.com) — discover and sync your private-account submissions and assist with submission forms
  • PSA (psacard.com, collectors.com) — discover and sync your private-account orders and assist with submission forms
  • Whatnot (whatnot.com) — help you add and edit your inventory
  • SlabTracked (slabtracked.com) — sign you in and sync data to your account

3. How We Use Your Data

  • Sync and display your grading submissions and statuses
  • Send status notifications by email and, if you opt in, Telegram or Discord
  • Help you pre-fill marketplace listings with your item data and images
  • Track shipments
  • Provide analytics such as turnaround times and grade distribution
  • Process subscription billing
  • Maintain, secure, and improve the service

4. Data Storage & Security

  • In transit — data between your browser and our servers is encrypted with TLS
  • At rest — our database is hosted on Supabase with encryption at rest
  • SlabTracked account passwords — hashed and never stored in plain text
  • Temporary grader credentials — regular-account CGC/CCG credentials are encrypted at the application layer using AES-256-GCM, access-controlled to server code, automatically expired after 72 hours, and physically deleted by an hourly cleanup
  • Browser sessions — worker sessions are temporary. Hosted CGC submissions and explicitly authorized PSA connections reuse private Browserbase contexts containing login cookies and browser storage until disconnected, invalidated by the grader, or deleted.
  • Companion auto-login credentials — version 2.10.5 keeps optional grader credentials in trusted-context Chrome session storage, not persistent local or sync storage. They are used only for the corresponding grader and clear on browser restart, extension disable/reload/update or popup sign-out. The separately installed developer relay has its own disclosed storage behavior.
  • Companion workflow data — private order caches, queued form details and operational logs may remain in device-local extension storage until replaced, cleared by their workflow or removed with the extension. There is no single automatic expiry for all these records. Popup sign-out clears authentication and pauses work, but does not erase all cached records, website sessions or server account data. Remove the extension to clear its local data; contact support to request account-data deletion.
  • Payment data — we never store full card numbers; payments are handled by Stripe

5. Data Sharing

We do not sell, rent, or share your personal data with third parties for advertising or marketing, and your synced collectible data is associated only with your own SlabTracked account. We share data with service providers only as needed to operate SlabTracked:

  • Stripe — subscription payments (privacy policy)
  • Supabase — database hosting (privacy policy)
  • Vercel — application hosting (privacy policy)
  • Browserbase — isolated browser hosting for hosted CGC draft preparation and optional immediate and authorized scheduled CGC/CCG CSV and PSA private-order syncs. Hosted submissions send your chosen CGC login and draft selections to CGC through this browser (privacy policy)
  • OpenAI — photo analysis and Chat with SlabTracked transcript processing only when you consent. API data is not used for model training by default. We disable Responses API application storage; this does not eliminate provider abuse-monitoring retention, which is ordinarily up to 30 days and may be longer when legally required (API data controls)
  • Telegram / Discord — only if you opt in and provide your own credentials, to deliver notifications to yourself

6. Your Rights

  • Access — view your data through your dashboard or request a copy
  • Correction — update inaccurate information
  • Deletion — request deletion of your account and associated data
  • Export — download your submission data in a portable format
  • Opt out — disable notifications or data sync at any time

To exercise these rights, email privacy@slabtracked.com.

7. Data Retention

  • Active accounts — data retained while your account is active
  • Cancelled subscriptions — data retained on the free tier per your plan
  • Deleted accounts — data deleted within 30 days of your request
  • Backups — encrypted backups retained for up to 90 days for disaster recovery

8. Cookies & Local Storage

We use session cookies for authentication and browser/extension storage to remember your preferences and keep synced data available locally. The extension stores data locally on your device and communicates with our servers only to sync your own data. You can clear this data at any time through your browser settings.

9. Children's Privacy

SlabTracked is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact privacy@slabtracked.com and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of SlabTracked after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this policy or our data practices? Email privacy@slabtracked.com.