Legal
Privacy Policy
Last updated 2026-05-25
Foil is built around watching Pokémon TCG card prices and emailing you when one drops to your target. This policy explains in plain language what data we collect to do that, what we never do with it, and how to remove yourself from the list whenever you want. If anything below is unclear, email john.c.craig24@gmail.com — Foil is a solo project and the answer comes from a human.
What we collect
Two things, both supplied by you: your email address, and the cards plus target prices you ask us to watch. Nothing else. We do not collect device fingerprints, behavioural-analytics events, advertising identifiers, or anything you didn't explicitly type into a form. Visiting a page does not by itself put you on any list.
What we use it for
Your email is used only for the things you opted into: (a) wishlist alerts when one of your watched cards drops to your target price, and (b) Foil's weekly deals newsletter if the opt-in checkbox was ticked when you joined. That's the complete list. We do not use your email for product cross-sells, account recovery for a service you didn't sign up for, or any kind of profiling.
What we never do
We never sell, rent, share, or transfer your email or watchlist data to any third party. We do not use your email or your watch history to train AI models or fine-tune content-generation pipelines. We do not store or cache the eBay listing data that surfaces on per-card pages — every listing block is re-fetched live at the moment a page loads and discarded immediately after rendering (this is structurally required by our eBay license; see the public eBay API compliance page).
Where the data lives
Watchlists live in a Supabase Postgres database, accessible only by Foil's service-role credentials. Newsletter subscriptions are stored by Beehiiv (our newsletter platform), which has its own privacy policy. Email is delivered via Resend (transactional alerts) and Beehiiv (newsletter). These three vendors are necessary subprocessors of Foil. We do not use any third-party analytics, advertising, or tracking vendors on the public site.
Unsubscribing + deleting your data
Every email we send carries a one-click unsubscribe link in the email headers (so Gmail, Apple Mail, and other clients can offer a button) AND a visible unsubscribe link in the body. Clicking either removes you from the list immediately. If you want a full data deletion (watchlists too), email john.c.craig24@gmail.com from the address on file and we will remove every row associated with your email within seven days. There is no form for this because Foil is solo-operated and an email request is the lowest-friction path.
Cookies
Foil uses cookies only for the authenticated parts of the site (which V1 visitors never reach — V1 is anonymous-friendly for the public pages). Public pages set no first-party cookies and no third-party cookies. There are no advertising trackers and no analytics-vendor pixels.
Children
Foil is not designed for children under 13 and we do not knowingly collect data from anyone under 13. If you believe a child has subscribed, email john.c.craig24@gmail.com and we will remove the row.
Changes to this policy
If this policy changes materially, the "Last updated" date at the top will move and we will note the change in Foil's next newsletter. Substantive changes (new data collected, new sharing relationships) will be opt-in rather than opt-out. This policy was last updated 2026-05-25.