Privacy Policy
Last updated: September 2026
1. Introduction
NIL CARD ("we," "us," "our") respects your privacy. This Policy explains how we collect, use, disclose, store, and protect your personal information when you use our platform, services, APIs, and AI features. By accessing NIL CARD, you agree to the practices described in this Policy. If you do not agree, do not use the service.
This policy applies to all users — athletes, fans, coaches, and administrators — and to all data processed through our web application, mobile interfaces, payment integrations, AI engines, analytics pipeline, and external integrations.
2. Information We Collect
2.1 Account & Profile Data
When you register or update your profile, we collect: email address, full name, username, sport, school, position, bio, avatar/cover URLs, and account status (free / pro / suspended). We also collect authentication-related data (session cookies, JWT tokens, OAuth provider IDs from third-party identity providers) managed by our authentication service.
2.2 Usage & Analytics
We collect page views, link clicks, feature usage, time-on-page, referral sources, and event logs through product analytics (opt-out available via cookie consent). Analytics data is used for feature improvement and debugging; individual user data is not sold or shared with non-service providers.
2.3 Payment & Financial Data
All payments and payouts are processed by our third-party payment processor. We never store full card numbers, CVV, or bank routing details. We store transaction metadata (amount, fee split, status, processor account ID) to maintain balances, generate revenue reports, and support dispute resolution.
2.4 Content You Upload
Photos, videos, text posts, social links, deal/value listings, and bio content you upload remain your property. We process this content to display it, generate AI-enhanced versions (bio builder, content engine), and moderate it for policy compliance.
2.5 AI / LLM Inputs & Outputs
When you use AI features (bio builder, content engine, knowledge assistant), we send your prompt text and relevant context (profile data, past content, preferences) to our AI inference provider. We do not train third-party models on your data without your explicit consent. AI outputs (generated bios, posts, suggestions) are stored in your account unless you delete them.
3. How We Use Your Information
- Service delivery: account management, profile display, tip processing, and subscription billing.
- AI features: generating, editing, and suggesting content based on your inputs.
- Analytics: aggregate usage reports, performance monitoring, and feature improvement.
- Security: fraud detection, abuse monitoring, rate-limiting, and incident response.
- Communications: transactional emails (Resend), notifications, and, with consent, marketing messages.
- Legal compliance: tax reporting, regulatory obligations, and enforcing our Terms.
4. Legal Bases for Processing (GDPR / UK GDPR / CCPA)
Where applicable (EU/UK users), we rely on: (a) contract performance — providing the platform; (b) legitimate interests — security, analytics, and service improvement; (c) consent — marketing communications, optional analytics, and AI features requiring context beyond basic profile data; (d) legal obligation — tax and regulatory reporting.
For CCPA (California) users, we do not sell personal information. We disclose categories of data (identifiers, profile/content data, usage data, financial data, inference data from AI outputs) to service providers necessary to operate the platform.
5. Data Sharing & Subprocessors
We do not sell personal data. We share data only with the following categories of service providers under strict data-processing agreements:
- Cloud database & authentication: secure storage of account, profile, and content data, with row-level access controls.
- Payment processor: handling subscriptions, tips, payouts, and required tax reporting.
- AI inference provider: generating bio and content suggestions from your inputs.
- Email delivery service: sending transactional and (with consent) marketing emails.
- Product analytics: aggregate usage reporting (opt-out via cookie consent).
- Error monitoring: detecting and reporting crashes and bugs.
- Application hosting: running the website, APIs, and background jobs.
Some providers may process data outside the EU/UK. Where required, we rely on Standard Contractual Clauses (SCCs) and adequate safeguards.
6. Cookies & Tracking
We use essential cookies (authentication, session), analytics cookies (opt-out available), and preference cookies (theme, consent). You can manage cookie preferences via the cookie banner or browser settings. Essential cookies are required for the service to function.
7. Data Retention
We retain profile and content data for the duration of your account and for a reasonable period after deletion to comply with legal obligations, resolve disputes, and enforce agreements. Analytics data is retained for 24 months or until you opt out. Payment records are retained for tax and regulatory requirements (typically 7 years in applicable jurisdictions). AI inputs/outputs tied to your account are deleted upon account deletion unless you explicitly request retention.
8. Your Rights (Access, Correction, Deletion, Portability)
You may export your data, correct inaccurate information, or delete your account at any time from Settings → Account. For GDPR/CCPA requests (access, deletion, portability, opt-out of sales or automated decision-making), email hey@nilcard.app with the subject line "Privacy Request — [Your Email]". We will respond within 30 days (72 hours for access/deletion under some laws).
If you are under 13, do not create an account. If you provide a false age and we discover it, we will delete your account. We do not knowingly collect data from children.
9. Security
We use HTTPS everywhere, encrypt data at rest and in transit, enforce strict database access controls, rely on our payment processor's PCI-compliant environment for financial transactions, and maintain role-based access controls for internal systems. We do not guarantee zero risk, but we invest in regular security reviews and incident response.
10. Data Breaches
If a breach occurs that affects your personal data, we will notify you without undue delay (and where required, within 72 hours to regulators, or as required by state law). We will provide information about the nature of the breach, the categories of data affected, measures taken, and steps you can take.
11. International Transfers
Data may be processed in the United States and other jurisdictions by our third-party service providers. For users in the EU/UK, we rely on Standard Contractual Clauses (SCCs) with our providers and, where applicable, data-protection addenda.
12. AI / Automated Decision-Making
We use AI to generate content suggestions and analytics. These outputs do not make legal or financial decisions about you (e.g., they do not determine pricing, access, or account status). You can opt out of AI content suggestions in Settings where available.
13. Changes to This Policy
We may update this Policy when our services, legal requirements, or practices change. Material changes will be notified via email or in-app notification. Continued use after changes constitutes acceptance.
14. Contact
For privacy questions, data requests, or to report a concern: hey@nilcard.app. For data-protection officer / EU representative matters, use the same address with "DPO" in the subject line.
