Picker Radar

Privacy Policy

Picker Radar  ·  Last updated: April 27, 2026  ·  Effective upon publication

Table of Contents

  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Bases for Processing
  5. Third-Party Subprocessors
  6. eBay Data Sources
  7. When We Share Data
  8. Data Retention
  9. Data Security
  10. Children's Privacy
  11. Cookies
  12. Your Rights — California (CCPA/CPRA)
  13. Additional State Rights
  14. International Users / GDPR Note
  15. Breach Notification
  16. Changes to This Policy
  17. Contact and DSAR Requests

1. Who We Are

In short: Picker Radar is operated by a US company. This policy explains how we handle your data.

Picker Radar (pickerradar.com) is operated by Qualuxe Goods LLC, located at 7533 S Center View Ct, Ste R, West Jordan, UT 84084, Highland, Utah, United States. For privacy-related questions, contact us at support@pickerradar.com.


2. What Data We Collect

In short: Account info, photos you upload, scan history, billing metadata, and basic usage analytics. We don't sell your data.

2.1 Account Information

2.2 Photos and Scan Data

Important disclosure — AI processing: When you scan an item, the photo or video frame you upload is transmitted to Google (via the Gemini API on Google Cloud Platform) for AI-powered item identification. Google processes this image on our behalf as a subprocessor. See Section 5 for details. We do not use your photos to train AI models beyond what is described in Google's API terms.

2.3 Billing Data

2.4 Usage and Technical Data

2.5 Optional Location Data


3. How We Use Your Data

In short: To deliver the Service, improve it, handle billing, and communicate with you about your account.
PurposeData Used
Deliver item identification and eBay comp resultsUploaded photos, transmitted to Google Gemini API
Provide Pick/Leave recommendations and profit estimatesAI inference output + eBay comp data
Store scan history and per-store statsScan records, store associations, pick decisions
Manage subscriptions and enforce scan quotasSubscription tier, scan count
Process paymentsBilling metadata via Stripe
Send transactional emails (e.g., OTP, billing receipts)Email address, via Clerk
Respond to support requestsAccount info, scan logs as relevant
Monitor service health and debug errorsLog data, error context
Comply with legal obligationsAs required by applicable law

We do not sell your personal data. We do not use your data for advertising or share it with advertising networks.


In short: We process data because you agreed to our Terms (contract), because we have a legitimate interest in operating the service, and because the law sometimes requires it.

5. Third-Party Subprocessors

In short: These are the vendors that handle your data on our behalf. Each is bound by data-processing agreements.
VendorPurposeData InvolvedPrivacy / Security Reference
Vercel, Inc. Frontend hosting, API routes, Blob storage for uploaded images All data transmitted to the app; uploaded photos stored in Vercel Blob vercel.com/legal/privacy-policy
Railway Corp. Background worker hosting; PostgreSQL database All application database records (accounts, scan history, subscriptions) railway.com/legal/privacy
Clerk, Inc. User authentication, session management, transactional email (OTP) Email address, name, auth tokens clerk.com/legal/privacy
Stripe, Inc. Payment processing and subscription billing Payment card data (processed directly by Stripe; we receive only billing metadata) stripe.com/privacy
Google LLC (Gemini API / GCP) AI vision inference — item identification from uploaded photos Photos you upload during scans are transmitted to the Gemini API for processing cloud.google.com/terms/data-processing-terms
Google LLC (Places API) Store location lookup when you use the store-detection feature GPS coordinates (optional, session-only) policies.google.com/privacy
ScrapingBee SAS Retrieval of eBay sold-comp data via proxied web requests No personal data; requests contain only item search queries scrapingbee.com/privacy-policy
Google LLC (BigQuery / GCP Billing) Internal billing cost analytics (GCP billing export). Not user-facing data. Aggregate API usage cost data only — no personal user data exported cloud.google.com/terms/data-processing-terms

We may update this subprocessor list as the Service evolves. Material additions will be reflected in an updated Privacy Policy with notice per Section 15.


5a. eBay Data Sources

In short: We pull recently-sold eBay item prices on demand to help you make informed reselling decisions. We don't store, redistribute, aggregate, or train on eBay data, and every comp links back to the source eBay listing.

eBay Data: Picker Radar uses eBay's Marketplace Insights API (and where the API isn't yet provisioned, eBay's public sold-listing search) to display recently-sold item prices that help users make informed reselling decisions. We fetch sold-listing summaries — title, price, item thumbnail, and a link to the source listing — on demand for each user query and display them in the user's active scan session. We do not store eBay data beyond what the user reviewed in that scan, do not redistribute it, do not aggregate it into a separate dataset, and do not use it to train models. All sold-listing displays link back to the source eBay item page as the primary call to action.


6. When We Share Data

In short: We don't sell data. We share it only with subprocessors listed above, or when required by law.

We do not sell, rent, or trade your personal data to third parties. We share data only:


7. Data Retention

In short: We keep your data as long as your account is active, plus a short grace period. You can request deletion at any time.
Data TypeRetention Period
Account profile (name, email)Until account deletion + 30-day grace period
Scan records and item dataUntil account deletion + 30-day grace period
Uploaded photos (Vercel Blob)Until account deletion + 30-day grace period
Pick/Leave decisions and store statsUntil account deletion + 30-day grace period
Billing records (subscription history)7 years (financial record-keeping requirement)
Server logs (IP, request metadata)90 days, then automatically purged
Error logs30 days

After account deletion, data is permanently deleted from our systems within 30 days, except billing records retained for legal compliance. Note that subprocessors may have their own retention schedules.


8. Data Security

In short: We apply industry-standard practices. No system is 100% secure, but we take reasonable precautions.

We apply industry-standard security practices to protect your data, including:

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at support@pickerradar.com.


9. Children's Privacy

In short: Picker Radar is not for users under 13. We don't knowingly collect data from children.

The Service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If we learn that we have collected data from a child under 13 without parental consent, we will delete it promptly. If you believe a child under 13 has provided us with personal data, contact us at support@pickerradar.com.


10. Cookies

In short: We use essential cookies for authentication and security. No advertising cookies. See our full Cookie Policy.

We use cookies and similar technologies as described in our Cookie Policy. We use strictly necessary cookies for authentication (Clerk), payment flow (Stripe), and CSRF protection. We do not use advertising or tracking cookies. Clerk and Stripe set their own cookies subject to their respective privacy policies.


11. Your Rights — California Residents (CCPA / CPRA)

In short: California residents have the right to know, delete, correct, and opt out. We don't sell or share your data for advertising.

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

To exercise these rights, submit a Data Subject Access Request (DSAR) to support@pickerradar.com with the subject line "CCPA Request" and your account email address. We will respond within 45 days (extendable by an additional 45 days with notice). We may need to verify your identity before processing the request.


12. Additional State Rights

In short: Residents of Virginia, Colorado, and Utah have similar privacy rights. Contact us to exercise them.

Residents of the following states have rights under their respective state privacy laws. To exercise these rights, follow the DSAR process in Section 11.

We do not sell personal data or use it for targeted advertising under any of these statutes. Response time for DSAR requests from these states is 45 days.


13. International Users / GDPR Note

In short: Picker Radar is US-focused. Your data is processed in the United States.

Picker Radar is operated in the United States and is primarily directed at US users. We do not actively market to users in the European Economic Area or the United Kingdom. All data processing occurs on servers located in the United States or with US-based subprocessors. If you are located outside the US and choose to use the Service, you understand that your data will be transferred to and processed in the United States, which may have different data protection rules than your country.

If we later expand to serve EU/UK users, we will update this section to address GDPR transfer mechanisms and appoint a representative as required.


14. Breach Notification

In short: If we have a breach that affects your data, we'll tell you and applicable regulators as required by law.

In the event of a data breach that affects your personal data, we will notify you and any required regulatory authorities in accordance with applicable law (including California Civil Code §1798.82 and other applicable state breach-notification statutes). We will notify affected users without undue delay and within any legally required time frame, describing the nature of the breach, the types of data affected, steps you can take to protect yourself, and what we are doing to address the incident.


15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email to your account address and by posting an updated version with a new "Last updated" date. Your continued use of the Service after the effective date of the updated policy constitutes acceptance. If you do not agree, please contact us to close your account and we will delete your data per Section 7.


16. Contact and DSAR Requests

To exercise your privacy rights, ask questions, or submit a Data Subject Access Request:

We will acknowledge your request within 5 business days and complete it within 45 days (extendable by 45 days with notice).