Privacy Policy

Last updated: 2026-05-18

This Privacy Policy describes how Ninebind Inventory Management (“we”, “us”) collects, uses, shares, and retains personal information when you visit, browse, or purchase from this online store, including via Shopify-hosted checkout.

1. Information we collect

  • Account information — name, email address, telephone number, and shipping/billing address you provide when creating a customer account or completing a Shopify checkout.
  • Order history — items purchased, prices paid, shipping addresses, refund history.
  • Buylist submissions — cards you offered to sell, the conditions you reported, payment preference (cash or store credit), and any staff notes attached to the submission.
  • Wishlist — cards you asked to be notified about, and whether we have already emailed you about a previous restock.
  • Browsing data — pages visited, search terms, filters applied, IP address, browser/device fingerprint (collected by us and by Shopify on the checkout surface).
  • Cart contents — items in your cart prior to checkout, stored against your customer record so the cart persists across devices when you are signed in.

2. Why we collect it

  • Order fulfillment — ship the items you bought, issue store credit you earned on a buylist, contact you about the status of an order or submission.
  • Customer support — respond to questions, resolve disputes, process refunds and returns.
  • Fraud prevention — detect and block suspicious orders, chargeback abuse, and inventory-scraping bots.
  • Legal compliance — retain transactional records for tax reporting and audit, respond to lawful requests from regulators or law enforcement.
  • Service improvement — analyze aggregate search and browsing patterns to understand what cards customers are looking for.

3. Who we share it with

  • Shopify — operates our checkout, processes payments, hosts the customer account portal, and provides fraud-prevention services. Shopify’s privacy practices are governed by Shopify’s privacy policy.
  • Our email service — used to send transactional email (order confirmations, buylist updates, restock alerts). Email is sent via our configured SMTP provider; we do not sell addresses to marketing brokers.
  • Backup storage — encrypted database backups are written to off-site object storage on a nightly schedule for disaster recovery.
  • Regulators and law enforcement — when required by valid legal process or to protect our rights.

We do not sell, rent, or trade your personal information to advertisers or data brokers.

4. Retention

We retain customer-account records indefinitely unless you request deletion. Order records are retained for 7 years from the date of sale to satisfy Canada Revenue Agency tax-record requirements (where you are also a customer of the platform’s Canadian deployments); equivalent retention applies in other jurisdictions. When you request deletion, your account record is removed and the personal-information fields on retained order records are pseudonymized (your name and email are replaced with a non-identifying placeholder; the totals, taxes, and line items are retained for accounting purposes).

5. Your rights

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct inaccurate information.
  • Deletion — ask us to delete your account and pseudonymize your order history. Submit a request from your account privacy page. Most requests are completed within 30 days.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — opt out of marketing communications at any time (transactional email about your orders is not subject to opt-out).

6. Cookies and tracking

We use cookies and similar local-storage mechanisms strictly for the operation of the site: keeping you signed in, persisting your cart, and remembering your theme preference. We do not use third-party advertising or tracking cookies.

7. Children

This site is not directed to children under 13. We do not knowingly collect personal information from children. If you believe we may have collected such information, contact us at the address below and we will delete it.

8. Changes to this policy

We may update this policy from time to time. Material changes will be announced on our storefront and, where required, by email to account holders 30 days before they take effect.

9. Contact

Questions about this policy or about your data can be sent to noreply@ninebind.com.

10. Jurisdiction

This policy is governed by the laws of the Province of Ontario, Canada, and is intended to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). Where you are resident in the European Economic Area or the United Kingdom, we additionally comply with the applicable provisions of the General Data Protection Regulation (GDPR / UK GDPR).