← Back to BEAUZAAR

Privacy policy

Last updated: September 24, 2026

BEAUZAAR ("we," "us") operates https://thebeauzaar.com and related websites and apps. This policy describes how we collect, use, and share information across our services.

Bulk card inquiries

When you submit a bulk card inquiry, we use your name, email address, collection details, and any photos or CSV files you attach to review your request and reply. Inquiries and attachments are delivered through Resend to our email inbox. Attachments are not published on the website. Please do not include payment information or other sensitive details. We do not use these inquiries for unrelated marketing. You can request deletion by contacting contact.beauzaar@gmail.com.

Sign-in with Google

Some BEAUZAAR services (including TCGzaar, Tagzaar, and future BEAUZAAR apps) let you sign in with Google. When you do, we receive information from your Google account such as your name, email address, and profile picture, as permitted by your Google account settings. We use this to create and manage your account, authenticate you, and provide our services.

Google's use of your data is governed by Google's Privacy Policy. Authentication is handled through Supabase on our behalf.

https://thebeauzaar.com waitlists

When you join a product waitlist on https://thebeauzaar.com, we collect your email address and which product you are interested in (TCGzaar or Tagzaar). We use this to send you a one-time email when that product launches. We do not use waitlist emails for unrelated marketing.

Waitlist signups are stored in a Supabase database (hosted in the United States). We keep your email until we send the launch notification for that product, or until you ask us to delete it — whichever comes first. Waitlist email addresses are not sent to PostHog.

TCGzaar

TCGzaar (tcgzaar.com) is inventory and fulfillment software for TCGplayer sellers, operated by BEAUZAAR. If you use TCGzaar, we also collect and process:

  • Account data: seller type, onboarding status, subscription tier and status, Stripe customer and subscription identifiers, and promo code attribution
  • Inventory and operations: TCGplayer product identifiers, card names, quantities, conditions, prices, physical storage locations, import filenames, pull-sheet history, audit and repricing data, and related fulfillment records
  • Support: ticket subject, category, status, and message content when you contact us through in-app support. Where email notifications are enabled, your email address, ticket subject, and message contents are delivered through Resend to our support inbox
  • Technical data: essential authentication and app-state storage, browser preferences, and optional cookieless PostHog audience measurement as described below

TCGzaar does not connect to TCGplayer's API. Inventory and order data comes from CSV files you upload. You are responsible for complying with TCGplayer's own terms and policies. BEAUZAAR is not affiliated with or endorsed by TCGplayer.

Large imports may be stored temporarily in Supabase Storage. If you are on the free tier and do not sign in for an extended period (typically 60 days), we may archive your inventory data to cold storage and clear active database records. Archived data may be restored automatically when you return.

Tagzaar and future products

Tagzaar and other BEAUZAAR products listed on this site may not yet be available. When we launch them, we will describe product-specific data practices in updates to this policy.

Payment information

Paid TCGzaar subscriptions are processed by Stripe. We do not store your full payment card number. Stripe collects and processes payment details according to Stripe's Privacy Policy. We receive billing metadata such as subscription status and the last four digits of your card where Stripe provides it.

Service providers

We use trusted providers to operate our services, including:

  • Supabase — authentication, database, file storage, and related infrastructure
  • Stripe — subscription billing and customer portal
  • Google — OAuth sign-in
  • Vercel — website hosting
  • PostHog — product and web analytics on https://thebeauzaar.com and TCGzaar. PostHog uses pseudonymous browser/device identifiers on this brand site and temporary cookieless audience identifiers on TCGzaar; we do not send account email addresses, uploaded file contents, or inventory data to PostHog
  • Resend — delivery of bulk-inquiry emails and TCGzaar support notifications

These providers process data on our behalf under their own privacy policies and contractual obligations.

Cookies and analytics

On https://thebeauzaar.com, we use PostHog (US Cloud) for product and web analytics. Browser events are sent through a first-party /ingest proxy to PostHog. This includes frontend autocapture, heatmaps, and Web Vitals. Session recording and automatic client exception capture are turned off. We do not call posthog.identify, and we do not send email addresses to PostHog, so PostHog does not receive your real-world identity from this site. PostHog may still assign a pseudonymous distinct ID for your browser or device, and cookies or similar browser storage may retain that ID so a returning browser can be recognized across visits. This is not advertising or retargeting.

Separately from our custom event properties, PostHog automatically receives technical metadata with analytics events. That can include your IP address; IP-derived approximate location (which may include country, region, city, and approximate coordinates); browser, browser version, language, operating system, and device type; the current page URL and referring URL; screen and viewport dimensions; timestamps; and pseudonymous device, session, window, and pageview identifiers. We use this metadata for traffic attribution, device and browser reporting, geographic summaries, site usage, and performance measurement.

Custom waitlist analytics events include only the product you signed up for and, on failure, a generic closed reason code. Custom outbound-link event properties include only stable identifiers such as channel, shop, platform, or product — they omit destination URLs and display labels. That does not change PostHog's automatic page metadata, which may still include the current page and referring URLs described above. Waitlist emails remain in Supabase and are not sent to PostHog.

Vercel hosts https://thebeauzaar.com. We do not use Vercel Analytics or Vercel Speed Insights on this site.

Where enabled, TCGzaar uses PostHog (US Cloud) for optional cookieless audience measurement. It records page categories, landing-page scroll milestones and foreground time, public-link clicks, sign-in attempts and outcomes, onboarding, observed inventory-import completion, pull creation, and checkout starts. Sanitized error categories and release identifiers help diagnose failures. Campaign labels describe advertising sources; raw ad click identifiers are excluded.

TCGzaar does not send account IDs to PostHog or create identified person profiles. PostHog does not retain an analytics identifier in cookies or local/session storage in this mode. Autocapture, heatmaps, and session recording remain disabled. The event filter excludes names, emails, CSV contents and filenames, card names, inventory quantities and values, physical locations, support-message content, authentication tokens, raw exceptions, and URL query strings and fragments. TCGzaar no longer loads the Vercel Analytics or Speed Insights browser integrations.

Cookieless does not mean that no personal-data processing occurs. Network requests still reach PostHog; request information, including IP address and browser information, can be used to derive temporary audience identifiers. We disable location enrichment in TCGzaar events. Audience estimates are not verified customer counts. Browser measurements may be absent when analytics is blocked or a job finishes after the browser closes.

TCGzaar uses essential browser storage for authentication and temporary app state. Its privacy page and public footer offer a browser-level analytics opt-out, remembered in browser storage. Global Privacy Control and Do Not Track signals disable optional TCGzaar analytics. This choice applies to that browser, does not delete previously collected data, and does not change other devices or essential account processing. It does not enable session recording. Manage this choice at TCGzaar privacy settings. If we add tracking tools or enable recordings, we will update this policy before doing so. These TCGzaar-specific settings do not change the brand site analytics described above.

Your choices and deletion

You can manage TCGzaar billing through the Stripe Customer Portal in Settings. For account deletion, waitlist removal, or other data requests, email contact.beauzaar@gmail.com. Launch emails include instructions to opt out of future BEAUZAAR marketing messages.

Security

We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children

Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this policy from time to time. The "Last updated" date above will change when we do. Publishing this notice does not itself provide consent to new processing. We will provide additional notice or obtain consent where required before applying a material change to how we use personal information.

Contact

Questions about this policy or your data: contact.beauzaar@gmail.com

See also our terms of service.