GemDelta
Dashboard
Back to dashboard
Effective 2026-08-16

Privacy Policy

This policy explains what GemDelta collects and how GemDelta uses it when you visit the site, create an account, subscribe, use alerts, use referrals, submit feedback, or use the Chrome extension.

Data GemDelta Collects

GemDelta collects the data needed to operate accounts, subscriptions, and product features:

  • account identity data such as name, email address, profile image, provider account identifiers, and email-verification state;
  • authentication data such as database sessions, verification tokens, optional password hashes for email/password users, and OAuth account tokens from connected sign-in providers;
  • saved product data such as watchlists, watchlist notes and thresholds, Supply Watch state, snoozes, alert acknowledgements, hidden-card choices, collection rows, folders, purchase notes, settings, and announcement-read state;
  • alert data such as private ntfy topics, email-alert preference, delivery dedupe records, card or deal references, and alert payload details;
  • feedback data such as your message, page path, page URL, selected element context, viewport size, account identity, and status;
  • referral and marketing-funnel data such as referral codes, first-touch referral cookies, referred-account relationships, buy-list email subscriptions, unsubscribe tokens, UTM fields, referrer, page path, and event metadata;
  • billing mirror data such as Stripe customer IDs, subscription IDs, price IDs, plan tier, quota, status, period end, cancel-at-period-end flag, pass expiration, invoice or charge references, and limited payment-method fingerprint data used for fraud and referral-abuse checks.

Cookies And Sessions

GemDelta uses HTTP-only session cookies for signed-in sessions. Session cookies authenticate your browser to GemDelta and typically expire after about 30 days. GemDelta also uses a first-touch referral cookie when you arrive through a referral link, and an admin-only view-as cookie for operator testing.

Browser storage may also be used for interface preferences, duplicate-call guards, and Chrome extension settings.

Payments

Payments are handled by Stripe. GemDelta sends Stripe the information needed to create checkout and billing-portal sessions, such as your GemDelta user ID, email, name when available, selected plan, referral metadata, and UTM metadata when present.

GemDelta never stores full payment card numbers or payment card security codes. Stripe sends GemDelta subscription and payment events so GemDelta can update account access, billing status, quotas, referral rewards, and fraud checks.

Watchlists, Notifications, And Feedback

Watchlists and collections are tied to your GemDelta user ID. Supply Watch alerts may include card IDs, card names, set names, seller names, quantities, prices, discount references, alert run IDs, and your private ntfy topic or email-alert state.

If you use phone push alerts, GemDelta sends alert content to the ntfy delivery service using your private topic. If you enable email alerts, GemDelta uses your account email address for those alerts. Feedback submitted through the in-app button is stored with page context so GemDelta can diagnose the issue.

Chrome Extension

The GemDelta Chrome extension runs on supported eBay and TCGplayer listing, search, and product pages. It reads the current page URL and title locally so it can recognize supported pages, extract an eBay listing or search-result title, or derive a TCGplayer product ID.

Match requests sent to GemDelta contain the listing title or TCGplayer product ID. When you add a match to your watchlist, the extension sends the matched GemDelta card ID. Requests use your existing GemDelta session cookie when you are signed in and include the Chrome extension origin. The matching work runs on GemDelta servers; GemDelta does not store a separate extension browsing history from match lookups.

The extension is read-only toward marketplace pages. It does not buy, bid, add items to cart, change checkout pages, wrap host-page links, or send marketplace cart or checkout contents to GemDelta.

Analytics And Logs

GemDelta records conversion events and operational logs to understand signups, checkout starts, referral activity, buy-list subscriptions, errors, abuse, and service health. These records may include path, sanitized referrer, UTM fields, timestamps, event type, and limited event metadata.

Hosting, CDN, security, email, and notification providers may also process technical request data such as IP address, user agent, timestamps, and request metadata as part of delivering and protecting the service.

How GemDelta Uses Data

GemDelta uses collected data to:

  • authenticate users and secure accounts;
  • provide watchlists, collection tools, alerts, extension matching, feedback, billing, referrals, and subscriptions;
  • measure feature usage, diagnose errors, prevent abuse, and protect the service;
  • send account, billing, alert, and service communications;
  • comply with legal, tax, accounting, and security obligations.

Sharing And Processors

GemDelta does not sell personal data. GemDelta shares data only as needed to run the service, comply with law, protect rights and security, or complete actions you request.

Processors and infrastructure providers may include payment processing, hosting, database, authentication, email delivery, CDN/security, analytics/logging, and notification-delivery services. Those providers process data for GemDelta or for the transaction you request.

Retention

GemDelta keeps account, subscription, product, alert, referral, feedback, billing, and operational records for as long as needed to provide the service, preserve security, resolve disputes, comply with law, support tax and accounting obligations, and maintain product integrity.

You can request deletion of account data. Some records may be retained if GemDelta needs them for legal, security, billing, abuse-prevention, or accounting reasons.

Your Rights And Choices

You can manage many choices in the app, including subscription cancellation through the billing portal, alert preferences, watchlist contents, extension settings, and email unsubscribe links where provided.

To request access, correction, export, or deletion of personal data, use the in-app Feedback button while signed in. If you are in the UK, European Union, or European Economic Area, you may have additional rights to object, restrict processing, portability, or complain to your local data protection authority, subject to applicable law.

Children

GemDelta is not directed to children under 13, and GemDelta does not knowingly collect personal data from children under 13.

Changes

GemDelta may update this policy as the service changes. The effective date above will change when the posted policy materially changes.

Contact

For privacy questions or requests, use the in-app Feedback button while signed in.