GrailSniper

Privacy Policy

Last updated 27 July 2026. This policy covers grailsniper.com and the GrailSniper application.

In short

GrailSniper is a private, invitation-only tool for tracking sports card and trading card auctions. Accounts are created by the operator; there is no public sign-up.

We collect what the product needs to work and nothing for advertising. We do not sell personal information, we do not share it with data brokers, we run no advertising trackers, and we use no third-party analytics. You can delete your account and its data from inside the application at any time.

Who is responsible

GrailSniper is operated by its owner as an independent service. It is not affiliated with, endorsed by, or operated by eBay Inc., and it is not affiliated with any card manufacturer or grading company.

For any privacy question, or to exercise any right described below, contact privacy@grailsniper.com.

What we collect

Account details
Your username, email address, role, time zone, and your chosen spending limits and snipe timing preferences. Your password is never stored — only an Argon2 hash of it, which cannot be reversed into the password.
Session and security records
When you sign in we store a hash of your session token, its expiry, and the IP address the session was issued to. Security-relevant actions are written to an audit log recording what happened, when, the IP address, and the browser user-agent string.
Your collection and watchlist data
The cards you track, your vault holdings, cost basis, scanner searches, and any maximum bid you configure. This is the most sensitive data in the system, because a maximum bid states what you are willing to pay for a specific item.
eBay connection
If you link an eBay account, we store the OAuth access and refresh tokens issued to us by eBay, encrypted at rest with AES-256-GCM, along with the eBay account identifier and username, the granted scopes, and connection status. We never receive, request, or store your eBay password — eBay exposes no interface that would accept one, and you authenticate on eBay’s own domain.
Listing and sales data from eBay
Public listing information used to build price comparisons, which can include the seller’s eBay username, feedback statistics, and a written summary of a seller’s record. This is information about eBay members other than you, and we treat it under the same rules as your own data.

We do not collect payment card details, government identifiers, precise location, or any special-category data, and no part of the service asks for them.

Why we use it

To operate your account and keep it secure; to show the auctions, comparables and valuations the product exists to provide; to enforce the spending caps and safety limits you set; and to keep the audit trail that makes administrative access accountable.

We do not use your data for advertising, we do not profile you for marketing, and no automated decision is made about you that produces a legal or similarly significant effect. The product suggests; you decide.

Who we share it with

These are the only third parties that receive any data, and why:

eBay
When you link an account, we call eBay’s APIs on your behalf using the token you authorised. This is the purpose of the connection and is governed by eBay’s own privacy notice.
Anthropic (Claude)
Item and seller summaries are sent to Anthropic’s API to generate written analysis. This can include a listing title and attributes, and a seller’s public eBay username, account age, feedback percentage and transaction counts. Your password, your session tokens, your eBay tokens, your email address, and your maximum bids are never sent. If no API key is configured, this analysis is skipped and the rest of the product continues to work.
Infrastructure
The application runs on servers rented from a hosting provider, which necessarily processes data in transit and at rest on our behalf. It is not permitted to use it for anything else.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it to anyone else except where we are legally required to, or where it is necessary to investigate abuse of the service.

Information about other eBay members

Building price comparisons means holding public information about sellers, including their eBay username. We handle it under two rules.

First, when eBay tells us a member has closed their account and asked to be forgotten, we erase that member’s identifying information from our systems automatically. We remove the username, the credibility grade, and the written analysis, and we delete any stored authorisation for that account.

Second, we keep the transaction facts — what an item sold for, and when — with the identity removed. A sold price is a fact about the market rather than about a person, and deleting those records outright would silently change the valuations every user relies on. Removing the name achieves the erasure; discarding the number would corrupt the product for everyone else.

How long we keep it

Account and collection data is kept for as long as your account exists. Session records expire on their own schedule and are removed once expired.

When you delete your account, your data is deleted with it. Audit entries are the one exception: they are retained, but the link identifying you is severed, so the record that an action occurred survives while the record of who it concerned does not. This is deliberate — allowing deletion to erase the audit trail would turn it into a way to remove evidence of someone else’s actions.

Your rights

You can see and correct your account details in the application at any time. You can disconnect a linked eBay account, which deletes the stored tokens immediately. You can delete individual holdings, watchlist entries, saved searches and comparables.

You can delete your entire account and everything owned by it from your account settings. It asks for your password first, because it cannot be undone.

Depending on where you live, you may also have rights to access a copy of your data, to correct it, to object to or restrict its processing, or to complain to a data protection authority. Write to privacy@grailsniper.com and we will action it. We will never charge you or make you justify the request.

How we protect it

Traffic is encrypted with TLS. Passwords are hashed with Argon2. eBay tokens are encrypted at rest with AES-256-GCM under a key that can be rotated. Every user’s data is isolated at the data-access layer rather than by individual queries, so one account cannot read another’s.

The operator holds an administrative account that can read across accounts for support purposes. Every such access writes an audit record; there is no unaudited path.

Tokens, passwords, session cookies and authorisation codes are never written to logs. No system is perfectly secure, but these are the specific measures in place.

Cookies

We set cookies for one purpose: keeping you signed in and protecting against cross-site request forgery. They are strictly necessary, and there are no advertising, analytics, or tracking cookies to consent to or refuse. Clearing them signs you out.

International transfers

The service is operated from the United States, and the third parties named above process data there. If you use it from elsewhere, your information is transferred to and processed in the United States.

Children

GrailSniper is not intended for anyone under 18, accounts are issued individually by the operator, and we do not knowingly collect information from children. If you believe a child has an account, contact us and it will be removed.

Changes to this policy

If this policy changes materially, the date at the top changes and account holders are notified before the change takes effect. We will not apply a materially different use to information already collected without asking first.