CX
CollectorsExchange
πŸ”
← Hub Browse Sell My Orders FAQ Terms Support
Sign In
+ List Item U
← Back to Collectors Exchange

Privacy Policy

Collectors Exchange β€” operated by Cardonomics Lounge  Β·  Last updated: March 2026

This policy explains how we collect, use, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using Collectors Exchange ("the Platform"), you consent to the practices described below.

1. Who We Are

Collectors Exchange is an online marketplace for trading cards and collectibles, operated by Cardonomics Lounge ("we", "us", "our"). We are based in Victoria, Australia. This Platform is available at exchange.collector-edge.com and related domains.

2. What Personal Information We Collect

We collect personal information that is reasonably necessary for operating the Platform and facilitating transactions between buyers and sellers. The categories of information we collect include:

Category Examples Purpose
Identity Display name, email address, Discord username Account creation, authentication, communication
Delivery Delivery address (street, city, state, postcode) Shared with sellers to fulfil completed transactions
Business details Business name, ABN, GST registration, business & return addresses Seller compliance, invoicing, returns
Payment BSB/account number, PayPal email, Wise tag, PayID, crypto wallet address Facilitating payment between buyer and seller
Transaction Listings, bids, orders, order messages, disputes, ratings Operating the marketplace, dispute resolution, reputation system
Technical IP address, browser type, session tokens (cookies) Authentication, security, platform operation
Membership Whop membership status, membership tier Single sign-on, feature access

We do not collect sensitive information (as defined in the Privacy Act) such as racial or ethnic origin, political opinions, religious beliefs, health information, or sexual orientation.

3. How We Collect Your Information

  • Directly from you β€” when you register, complete your profile, create listings, place bids, send order messages, or contact support.
  • From Whop β€” if you are a Cardonomics Lounge member, we receive your email address and Discord username via single sign-on (SSO) to automatically create or link your account.
  • Automatically β€” we collect technical data (IP address, session cookies) through your use of the Platform for authentication and security purposes.

We do not collect personal information by covert or deceptive means.

4. How We Use Your Information

We use your personal information for the following purposes:

  • Creating and managing your account
  • Authenticating your identity (via magic link email or Whop SSO)
  • Operating the marketplace β€” listing items, processing bids, matching buyers and sellers
  • Sharing delivery addresses with sellers to fulfil completed orders
  • Displaying your payment details to buyers for completed transactions
  • Resolving disputes between buyers and sellers
  • Operating the reputation and ratings system
  • Sending transactional emails (magic links, order updates, dispute notifications)
  • Enforcing our Terms of Use
  • Preventing fraud and maintaining platform security

We will not use your personal information for direct marketing unless you have given explicit consent, and you may opt out at any time.

5. Who We Share Your Information With

We disclose personal information only as necessary to operate the Platform:

  • Other users (transaction counterparts) β€” your display name is visible publicly. When a transaction is completed, your delivery address is shared with the seller, and the seller's payment details are shared with the buyer. Your email address, real name, and other personal details are never shared with other users.
  • Service providers β€” we use the following third-party services to operate the Platform:
    • Cloudflare (United States) β€” hosting, content delivery, database (D1), security
    • Resend (United States) β€” transactional email delivery
    • Whop (United States) β€” membership verification and SSO
  • Law enforcement or regulators β€” if required or authorised by Australian law, a court order, or to cooperate with an investigation.

We do not sell, rent, or trade your personal information to third parties for their own purposes.

6. Overseas Disclosure

Some of the third-party services we use to operate the Platform are based in the United States. By using the Platform, you acknowledge that your personal information may be processed and stored in the United States by Cloudflare, Resend, and Whop in accordance with their respective privacy policies.

We take reasonable steps to ensure these service providers handle your information in a manner consistent with the Australian Privacy Principles.

7. Cookies and Session Data

We use the following cookies strictly for authentication and session management:

  • cx_session β€” a secure, HTTP-only session cookie that identifies you as a logged-in user on Collectors Exchange.
  • cl_session β€” a secure, HTTP-only JWT cookie set when you authenticate via the Collector Edge hub (Whop SSO).

We do not use advertising cookies, tracking pixels, analytics tools, or any form of behavioural tracking. Our cookies are functional only and are essential for the Platform to operate.

8. Data Security

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:

  • All connections to the Platform are encrypted via HTTPS/TLS
  • Session cookies are HTTP-only, Secure, and SameSite-protected
  • Authentication uses time-limited magic links β€” we do not store passwords
  • Database access is restricted to authorised application functions only
  • Payment details are locked after initial profile completion to prevent tampering
  • Admin access is role-restricted

No system is completely secure. While we take reasonable precautions, we cannot guarantee the absolute security of your information transmitted to or stored on the Platform.

9. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services to you. Specifically:

  • Account data β€” retained while your account is active. You may request deletion at any time (see Section 10).
  • Transaction records β€” retained for a minimum of 5 years to comply with Australian tax record-keeping requirements and to support dispute resolution.
  • Magic link tokens β€” automatically expire and are deleted after use or expiry.
  • Session tokens β€” expire after 30 days of inactivity.

When personal information is no longer required, we will take reasonable steps to destroy or de-identify it.

10. Your Rights β€” Access and Correction

Under the Australian Privacy Principles, you have the right to:

  • Access β€” request a copy of the personal information we hold about you.
  • Correction β€” request that we correct any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
  • Deletion β€” request deletion of your account and associated personal information, subject to our legal obligations to retain certain records (e.g., transaction data for tax purposes).

To exercise any of these rights, contact us via the Support page or email us at the address in Section 13. We will respond to access and correction requests within 30 days.

We will not charge you for making a request or for providing access to your personal information, unless the request is manifestly unfounded or excessive.

11. Children

The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a user is under 18, we will take steps to delete their account and associated information.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or by a prominent notice on the Platform. The "Last updated" date at the top of this page indicates when the policy was last revised.

Your continued use of the Platform after any changes constitutes acceptance of the updated policy.

13. Contact Us and Complaints

If you have any questions about this Privacy Policy, wish to exercise your rights under Section 10, or wish to make a complaint about how we have handled your personal information, please contact us:

  • Support page: exchange.collector-edge.com/support
  • Community: Cardonomics Lounge Discord

We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.

Β© 2026 Collectors Exchange Β· Cardonomics Lounge Terms of Use Privacy Policy Support FAQ Browse Listings