Flipledgr

Privacy policy

What personal information Flipledgr collects, how it is used and disclosed, and the choices available to you.

Last updated 11 August 2026

1. Scope and controller2. Information you provide3. Information collected automatically4. Information we do not collect5. How we use information6. Cookies and local storage7. Disclosure to service providers8. No sale or sharing for advertising9. Administrative access10. Security11. Retention12. Access and portability13. Deletion14. Location of processing15. Children16. Changes to this Policy17. Contact

1. Scope and controller

1.1 This Privacy Policy describes how Bolling Collectibles, LLC, d/b/a Flipledgr ("Company", "we", "us") collects, uses and discloses personal information in connection with flipledgr.com and the Flipledgr application (the "Services"). It forms part of and is incorporated into our Terms of Service.

1.2 Company is the controller of the personal information described in this Policy.

1.3 We do not publish a postal address. All enquiries, including requests concerning your personal information, should be sent to hello@flipledgr.com.

2. Information you provide

2.1 We collect the following categories of information directly from you:

  • Account information: your email address, and a password held in hashed form by our authentication provider. Company does not have access to your password.
  • Access request information: where you request an invitation before holding an account, your email address and any message you submit.
  • Customer content: inventory records including player, set, certificate number, grade, acquisition cost, asking price, storage location and notes; photographs; shows, display cases and packing lists; and ledger entries including amounts, tax rates and descriptions.
  • Settings and preferences, including pricing preferences and your configured tax rate.
  • Change history for your inventory records, comprising the field changed and its prior and new values.

3. Information collected automatically

3.1 We collect the following in the course of providing the Services:

  • Error records generated when an operation fails, comprising the error text, the time, your account identifier or the email address submitted, and your browser user agent string.
  • Usage records of comparable sales lookups and artificial intelligence requests, used to enforce usage limits and to account for costs.
  • On public submission forms, your IP address combined with a secret value and hashed. The stored value is a rate limiting fingerprint and cannot be reversed to an IP address.
  • Standard server request logs maintained by our hosting provider.

4. Information we do not collect

4.1 We do not collect payment card numbers, bank account details or government issued identifiers. No payment processor is presently integrated with the Services.

4.2 We do not use advertising trackers, do not build advertising profiles, and do not collect location data.

5. How we use information

5.1 We use personal information to:

  • provide, operate, maintain and secure the Services;
  • authenticate you and administer your account;
  • enforce usage limits, entitlements and this Policy;
  • diagnose faults and improve reliability;
  • communicate with you regarding your account, including service and administrative messages; and
  • comply with legal obligations and enforce our agreements.

6. Cookies and local storage

6.1 We use a session cookie necessary for authentication, and browser local storage to hold your own records on your device so that the Services function without a network connection.

6.2 We do not use advertising or cross site tracking cookies.

7. Disclosure to service providers

7.1 We disclose personal information to the following categories of service provider, in each case limited to what the provider requires to perform its function:

  • Hosting provider: serves the application and maintains server request logs.
  • Database and authentication provider: stores your account credentials and Customer content.
  • Email provider: transmits invitations, confirmations and administrative notifications, and receives the recipient address.
  • Comparable sales data provider: receives certificate numbers and card descriptions. It does not receive your email address, your acquisition costs or your asking prices.
  • Artificial intelligence provider: receives data only when you invoke an AI feature. A label scan transmits the submitted photograph. A comparable sales summary transmits the card's attributes, its recorded value and the sales records underlying the estimate. Neither transmits your email address or account identifier.
  • Bot detection provider: evaluates requests to our public submission forms.

8. No sale or sharing for advertising

8.1 We do not sell personal information, and we do not share personal information for cross context behavioural advertising.

8.2 We may disclose personal information where required by law or legal process, to enforce our agreements, to protect the rights, property or safety of Company or others, or in connection with a merger, acquisition, financing or sale of all or part of the business.

9. Administrative access

9.1 An administrative console permits Company to view account email addresses, last activity times, records of which inventory items changed and which fields changed on them, error records, and access requests. It does not return your acquisition costs, asking prices, estimate values or ledger entries.

9.2 Separately, the service credential used to operate the Services is capable of direct database access. You should assume that administrative access can reach any information stored in the Services.

10. Security

10.1 We apply access controls that restrict records to the account that owns them, encrypt traffic in transit, and serve stored photographs through links of limited duration.

10.2 No method of transmission or storage is completely secure. Company does not warrant that personal information cannot be accessed, altered, disclosed or lost, and you should retain your own copies of Customer content.

11. Retention

11.1 We retain personal information for as long as your account remains open and thereafter for as long as necessary for the purposes described in this Policy, including to comply with legal obligations, resolve disputes and enforce our agreements.

11.2 Company operates no fixed retention schedule and undertakes no obligation to delete information on any particular timetable.

12. Access and portability

12.1 The Services provide export functions, available to you without request, that produce your inventory records and your ledger entries in CSV format and your uploaded photographs in a zip archive.

13. Deletion

13.1 You may delete your account and its associated records at any time from the account management screen within the Services. On request to hello@flipledgr.com we will perform the deletion for you.

13.2 Residual copies may persist in backups and logs for a period following deletion.

13.3 Accounts not signed in to for twelve consecutive months may be deleted, together with their records, after notice to the account's registered email address (Terms of Service section 15).

14. Location of processing

14.1 Company operates from the United States and personal information is processed there. If you access the Services from outside the United States, you consent to the transfer of your information to the United States.

15. Children

15.1 The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

16. Changes to this Policy

16.1 We may amend this Policy at any time by posting the revised version with an updated date. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.

17. Contact

17.1 Enquiries regarding this Policy may be sent to hello@flipledgr.com.

Also read the terms of service.

HomeTermsPrivacySign in