Privacy & data

What we keep.
What we publish.

This register helps people find user reports about missing graded cards. It does not decide ownership, authenticate a card or investigate a crime.

Who operates the register

The data controller is saod, London, UK. For privacy requests or objections, email the operator.

Information you provide

We collect the grading company, certificate number, card description, loss date and category, and your contact email. You can choose to add your own initials for public display. You may also provide a reference number, private notes and whether you offer a reward. Please do not submit other people’s names, seller accounts, addresses or unnecessary personal information.

We record submission and confirmation times, report status, protected confirmation and management tokens, and a salted hash of the connecting IP address for abuse prevention. The application does not store the raw IP address. A hashed IP can still be personal data; it is not treated as anonymous.

Public and private information

A confirmed report makes the grader, certificate number, reporter initials (if provided), loss date and category, report date, status and reward indicator public. A saved PSA certificate lookup may be shown. These pages can be indexed, copied or cached by search engines and others.

The contact email, free-text card description, reference number, private notes, IP hash and management secrets are not included in public pages or APIs. There is no public comment or tip feed. The operator receives enquiries and may forward relevant information to the reporter without publishing their email.

Why we use this information

We rely on your consent to publish your report and any initials you choose to provide. The publication declaration is presented when you submit; public form submissions require a separate email confirmation. At your request, an authorised administrator can record or correct a report and publish it with your permission without sending another confirmation email. You can withdraw publication using your management link.

For the private email and management records, we rely on our legitimate interests in operating the requested service, controlling abuse and responding to objections. Information is not used for marketing, targeted advertising or automated ownership decisions. You may object to processing based on legitimate interests by contacting the operator.

Optional photographs

You may upload up to three card photographs as private supporting material. Each is converted to a separate JPEG of no more than 1 MB; the long edge is limited to 2,400 pixels. The saved copies omit EXIF metadata such as GPS coordinates. Original uploads are temporary processing files and are not retained by the application after the request. Keep your originals separately; compression can reduce fine detail.

Only the number of photos submitted appears on the public report. Photographs are not independently verified and do not establish ownership. They are kept outside the public web directory and can be read by the operator and anyone holding the report’s private management link. Photos are not attached to confirmation emails or sent to PSA. Please avoid faces, names, addresses or payment details visible within an image: removing metadata does not hide photographed text.

Photo retention follows the associated report. After a report is deleted, the daily cleanup task removes its unreferenced photos once the files are at least 24 hours old. Backup retention also applies to photos.

Service providers and transfers

Configured hosting: Krystal, London, United Kingdom.

Email service: Confirmation emails are sent through Krystal-hosted email services..

Human verification: Cloudflare Turnstile is used to prevent automated submissions and processes technical browser and network information for verification.. Turnstile communicates with Cloudflare to check submissions. The application does not add your raw IP address to its server-side verification request, although Cloudflare receives connection information through its widget.

For PSA cards, we may send the certificate number to PSA’s public API. We do not send the report, reporter email or private notes to that API. Its result is a dated snapshot; no live request is made when someone views a report.

Retention and deletion

  • Unconfirmed reports: deleted after 7 days. Confirmation links expire after 72 hours.
  • Published reports: retained while there is an ongoing need to locate the card. The operator reviews records older than 12 months and withdraws entries that are no longer needed. This review is manual.
  • Withdrawn, recovered, disputed, draft, hidden or trashed records: deleted after 6 months without a status update.
  • IP hashes attached to reports: cleared after 7 days. Local rate-limit files are removed after two hours of inactivity.
  • PSA cache: only certificate metadata and lookup time are retained without automatic expiry to avoid repeated API requests. Ask the operator to remove a cache entry when appropriate.
  • Hosting backups: the operator’s configured retention is 30 days. Withdrawn data may remain in protected backups until those expire. Restores must reapply intervening withdrawals and deletions.

Application deletion runs through a daily retention task. Hosting access logs and the operator’s email inbox have separate retention controls; they may contain connection information or correspondence. Ask the operator about these records when making a deletion request.

Administrator access

Authorised administrators can view private report details and photos, correct records, hide reports, restore them or delete them. The administrator audit log records the administrator account, time, action, report identifier and changed field names or statuses; it does not copy report content, email addresses, passwords or private links. Audit records remain until manually reviewed and deleted by the operator. Permanently deleting a report also removes its stored photos; protected backups expire separately.

Cookies

There are no advertising or analytics cookies in this application. Forms use an essential session cookie for CSRF protection and submission state; it expires when the browser session ends. Server-side session files become eligible for cleanup after two hours of inactivity. Public certificate and list pages do not start an application session. Administrator pages use a separate essential session cookie. Administrator login expires after 30 minutes of inactivity or 12 hours in total; server-side administrator session files become eligible for cleanup after 12 hours of inactivity. Cloudflare’s human check may use its own security mechanisms.

Your choices and rights

You can ask to access, correct or erase your personal information, restrict its use or object to processing based on legitimate interests. Where applicable, you can request portability of information processed with consent. Withdrawing consent stops future publication but does not undo earlier lawful processing. We may need to verify that a request comes from the right person without collecting excessive additional information.

Use the private management link to withdraw a report immediately, or contact the operator. The application cannot delete copies already held by other websites. You can also complain to the Information Commissioner’s Office.

Objections to a report

Every certificate page links to the operator. Include the page URL, your reason for objecting and a way to reply. Please send supporting material privately. The operator can hide the report while considering the objection. An email link alone does not establish that a legal notice process has been completed.