Privacy Policy
This policy explains what Mintward collects, why, who else touches it, and what you can do about it. It's written to be read — but it's not legal advice, and it'll change as the product does. When it changes in a way that matters, we'll tell you first (see Changes to this policy). This policy sits alongside our Terms of Service and our Cookie Policy; the effective date is the “last updated” date above.
1. What we collect
We try to collect only what running the service actually requires:
- Account details — your email, your name, and (for dealers) your business name and sales-tax rate.
- Your inventory data — the coin photos you upload and the details you record about each coin (grade, price, notes, and so on).
- Customer records you create — if you record customers for sales and receipts, that information is data you entered about other people; you're responsible for having a basis to hold it, and we process it on your behalf.
- Payment method — subscription billing runs through Square. Square handles your card details; we don't see or store full card numbers.
- Security and login data — a hashed version of the IP address and the user-agent seen at login, used only for throttling brute-force attempts; multi-factor codes and session state when MFA is on.
- Cookies — a small set of strictly-necessary and functional cookies. The full list is in our Cookie Policy.
2. How we use it
We use what we collect to:
- Run the service — store and display your inventory, grade your coins with AI, generate receipts and reports.
- Bill you — process subscription payments and grade packs through Square.
- Keep your account secure — multi-factor authentication, IP-based login throttling, and abuse investigation.
- Send transactional email — sign-in codes, receipts, and account notices, delivered through Azure Communication Services. These aren't marketing; they're the emails the service needs to send to work.
We do not build advertising profiles, and we don't do behavioral ad targeting.
3. Who processes your data
A handful of vendors process data on our behalf so we don't have to reinvent hosting, payments, and email. Each is bound by its own agreement and privacy terms:
- Microsoft Azure — hosting and infrastructure, plus Azure OpenAI Service for AI grading. Under Microsoft's Azure OpenAI privacy commitments, your inputs and the AI's outputs stay inside our Azure tenant and are not used to train Microsoft's models.
- Azure Blob Storage — where your coin photos live, encrypted at rest.
- Azure Communication Services — transactional email delivery.
- Square — payment processing, subject to Square's privacy terms.
- Cloudflare — DNS and edge networking for the domain.
To be explicit: we do not sell your personal data, we do not share it with advertisers, and we do not use it to train AI models.
4. Cookies and tracking
We use a small set of cookies — strictly-necessary ones that keep you signed in, and a functional one that remembers a trusted device for MFA. We currently run no third-party analytics tracking cookies; if we turn analytics on, we plan to use a cookieless, privacy-first tool. The complete cookie list, with durations and categories, is in our Cookie Policy.
5. Data retention
Your data lives until you delete it. Deleting your account from the Danger zone on your Profile is a hard, immediate delete: it cascades through your inventory, customers, sales, notes, photos, grading history, pack credits, pending invitations, error logs, and import jobs, and it cancels any active subscription with Square first. The one exception is a narrow legal-hold carve-out — we may retain specific records where the law requires it (a fraud investigation, tax records, or a subpoena), and only for as long as that obligation lasts.
6. Your rights
We give every user the same rights, regardless of where they live — we treat the GDPR's bar as the universal one rather than drawing lines by geography. You can:
- Access and export your data — the “Export my data” button on your Profile downloads a JSON bundle of your inventory, customers, sales, and grading history.
- Correct anything inaccurate — most of it you can edit directly in the app; for the rest, email us.
- Delete your account and everything in it, any time, from the same Profile page.
- Object to or restrict processing, or ask us a question about how your data is handled.
To exercise any of these beyond the in-app tools, email support@mintward.app.
7. Data security
Traffic to Mintward is encrypted in transit with TLS, and data at rest is encrypted with Azure-managed AES. Passwords are hashed with bcrypt — we never store them in the clear. Multi-factor authentication is available on every account, login attempts are throttled per IP to blunt brute-force attacks, and a web application firewall sits at the Azure edge. No system is perfectly secure, but these are the controls we run.
8. Children
Mintward is for adults running a coin business or collection. You must be 18 or older to use it (this mirrors section 2 of our Terms of Service). It is not intended for, or directed at, minors, and we don't knowingly collect data from them.
9. International users
Mintward's data resides in the United States (Azure West US 2). If you're in the EU or UK, applicable GDPR requirements still apply to how we handle your data, and you can reach us at the address below to make a data-subject request.
10. Changes to this policy
We may update this policy as Mintward evolves. For material changes we'll give you at least 14 days' notice — by email and by a banner in the app — before the change takes effect (this mirrors section 9 of our Terms of Service).
11. Contact
Any privacy question, or any data-subject request, goes to support@mintward.app. We read it.