Privacy Policy

Last updated October 5, 2026

The short version

  • You can use MasterSet.io without an account. Checklists you keep while signed out stay in your browser.
  • If you sign in, we store your email address, an optional display name and your collection, so it follows you between devices.
  • We use our own analytics, plus Google Analytics and Microsoft Clarity, to understand how the site is used. You can switch them off.
  • We don’t sell your personal information, and we don’t show ads.
  • You can download or delete your data at any time from your account page.

Who we are

MasterSet.io (masterset.io) is operated by Solobuy, LLC (“we”, “us”). We decide how the personal information described here is used, which makes us its “controller” under the GDPR. For any question or request about your information, email nick@masterset.io.

What we collect

When you browse

  • Your checklist, kept in your browser. Cards you mark while signed out, your display settings and your Find Your Master Set answers are saved in your browser’s local storage. They stay on your device.
  • An anonymous collection summary. Once you’ve acknowledged our cookie notice and started a set, your browser sends us a summary: for each set you’ve started, how many cards you’ve marked owned and how many you’re watching, and your total collection value — which your browser works out itself from the same public pricing every visitor sees, and sends us only as a number. It’s tagged with the same random ID as our analytics (below), and the summary itself carries no name, email, IP address or list of which cards you have. It also tells us if you’re using MasterSet as an installed app. It tells us how many people are collecting, which sets they’re working on, and roughly what those collections are worth.
  • Our own analytics. Once you’ve acknowledged our cookie notice, we record how the site is used in our own database: the pages you view; the site, search engine or campaign that brought you (the referring site’s address, and any campaign tags in the link you arrived on); your device type, browser and operating system (worked out from your browser’s user-agent, which we don’t keep); how long pages are on screen; and what you do, such as searching, opening a set or a card, marking a card owned or unowned, watching a price, or clicking through to a marketplace. That includes which card you marked, as a record of what you did, not a copy of your checklist. These records are tagged with a random ID for your browser (the ms_vid cookie), not your name or email, and are linked to your account if you’re signed in or sign in later. They don’t run on the sign-in, account or admin pages.
  • Comparing versions. Sometimes we show different versions of a feature to different visitors, at random, to see which works better (for example, when we ask you to save your progress). A cookie remembers which version your browser sees; it holds only the version’s name. Once you’ve acknowledged our cookie notice, which version you saw, and when, is recorded in our own analytics with your browser’s random ID, and compared with what visitors did afterwards, such as creating an account. With analytics off you still see a version, but nothing about it is recorded.
  • Google Analytics and Microsoft Clarity. Once you’ve acknowledged our cookie notice, they also record the pages you visit and the features you use (for example searching, opening a card, marking a card owned, or clicking through to a marketplace), with your device type, browser, screen size, the site that referred you and an approximate location worked out from your IP address. Clarity also records clicks, scrolling and mouse movement, which it can replay as a session recording; what you type into forms is masked. Clarity is also given the random IDs our own analytics uses for your browser and for the visit (never your name or email; it scrambles the browser ID before storing it), so a visit in our records can be matched to its recording, and the name of any version you’re seeing while we compare versions. Neither runs on the sign-in, account or admin pages.
  • Search and analytics reports from Google. We copy daily totals from Google Search Console (how often our pages appeared in Google results, for which searches, and how often they were clicked) and from Google Analytics (visits per day by source, landing page and device) into our own database. These are counts across all visitors; they say nothing about any one person.
  • Behaviour reports from Microsoft Clarity. Once a day we copy Clarity’s totals for each page and device type (for example, how many visits had repeated clicks on something that didn’t respond, how far down a page people scrolled, and for how long they were active) into our own database, without the page addresses’ search terms. These are counts across all visitors; they say nothing about any one person.
  • Your IP address, which our hosting provider receives to deliver pages to you, as it would for any website.

When you create an account

  • Your email address, and a display name if you give one.
  • When you joined, when you last signed in, when you confirmed your email address, and which part of the site you signed up from.
  • Your collection: cards you mark owned, missing or wanted, the target prices on your watchlist, and any quantities, conditions, purchase prices or notes you add.
  • Find Your Master Set results you choose to save.
  • Whether you use MasterSet as an installed app: when we first saw you use it that way, and the last day you opened it. Recorded only once you’ve acknowledged our cookie notice.
  • For each sign-in link and each signed-in device: your browser’s user-agent string and a salted, one-way hash of your IP address, used for security and rate limiting. We don’t store the IP address itself.
  • Your email preferences, and a log of the emails we’ve sent you: which email, when, whether it was delivered, and whether a link in it was followed.
  • A record of account activity: when you request a sign-in link, sign in or out, and when your saved collection changes (which card was added or removed, and the first card you marked in each set). This comes from what you save to your account, so it’s kept whether or not analytics are on in your browser.
  • If analytics are on in a browser you sign in on, the analytics that browser recorded before (see above) are linked to your account, so your history from before you signed up stays with you.

When you contact us

  • Through the community form: your name, email address and message, the page you sent it from, anything else you choose to add (such as a name to credit publicly or a website), your browser’s user-agent and a hashed IP address.
  • If you email us, the conversation.

When you click through to a marketplace

  • We record that a link was clicked (which card, where on the page, and when). If analytics are on in your browser, our own analytics also record the click with your browser’s random ID, and your account if you’re signed in. Nothing that identifies you is sent to the marketplace. Once you arrive, the marketplace and its affiliate network (the eBay Partner Network, or Impact for TCGplayer) may set their own cookies, and their privacy policies apply. See our Affiliate Disclosure.
  • Each eBay link carries a reference made up at random for that one click. When a purchase follows, the eBay Partner Network reports it to us with that reference: the item, what it sold for, and what we earned. eBay never tells us who bought it. If analytics were on in your browser when you clicked, we connect the purchase to that click’s analytics record, so we can learn which pages lead to purchases.
  • Photos in the eBay listings on card pages load directly from eBay’s servers, which receive your IP address as a result.

How we use it, and why we’re allowed to

If you’re in the European Economic Area, the UK or Switzerland, the law requires a legal basis for each use. Ours are:

  • Running your account: signing you in, and saving and syncing your collection across devices. Necessary to provide the service you asked for (contract).
  • Keeping the service secure: rate limiting, preventing abuse and fixing email delivery problems. Our legitimate interest in a safe, working service.
  • Price alerts for target prices you set. Contract.
  • Product updates and the weekly digest. Our legitimate interest in telling you about the service you use. You can opt out at any time, and we always honour it.
  • Understanding how the site is used: our own analytics, Google Analytics, Microsoft Clarity, the anonymous collection summary and whether you use the installed app. Your consent, which you give by acknowledging our cookie notice and can withdraw below.
  • The record of account activity (sign-ins, and changes to your saved collection). Our legitimate interest in understanding how the service is used, limited to what you’ve already saved with us.
  • Replying to messages and acting on corrections. Our legitimate interest in answering you and keeping the data accurate.
  • Meeting legal obligations, when the law requires it.

We don’t use your information for advertising, and we don’t make automated decisions about you that have legal or similarly significant effects.

Emails we send

  • Sign-in links and account emails are always sent. They’re how you get in. Each sign-in email also has a six-digit code you can type instead of using the link; it works once, for the same 15 minutes.
  • Product updates are on by default when you create an account, and come no more than monthly. A weekly collection digest is also on by default: on Sundays, a summary of your collection’s value, what you added and the sets you’re closest to finishing, sent only in a week when something changed. It comes by email, and as a notification on devices where you’ve turned those on. Price alerts are on by default too: when a card on your watchlist falls to the target price you set, checked after each nightly price update, at most one message a night. To do that we keep, for each card you watch, its target, the price at the last check, and when we last alerted you.
  • Turn any of them off from your notification settings, where you also choose, for each kind, whether it comes by email, as a notification on your devices, or both. The unsubscribe link at the bottom of each email stops that kind of email, or all of them if you prefer.
  • Our email provider tells us whether each email was delivered, bounced or reported as spam. If an address bounces for good, or someone reports our email as spam, we stop sending it optional email: we turn those emails off for the account, and keep the address on a do-not-send list as a one-way code (a hash), not the address itself. Sign-in links still arrive.
  • Links in our optional emails pass through masterset.io first, so we can count which emails people click. If you’ve accepted analytics on this browser, the visit is linked to that email in our own analytics.

Notifications on your devices

  • Notifications are off until you turn them on for a device from your notification settings, and your browser asks you to allow them. Each browser or installed app is turned on separately. You need an account. Which kinds of notification you get is your choice there too, the same for all your devices.
  • For each device you turn on, we keep the address your browser gave us for delivering notifications and its encryption keys, what kind of device and browser it is (for example “Chrome on Mac”), and when it was turned on and last used.
  • Notifications are delivered by your browser’s own push service: Google for Chrome and most Android browsers, Apple for Safari and iPhone, Mozilla for Firefox, Microsoft for Edge on Windows. The content is encrypted so that only your device can read it. A notification can appear on your lock screen, depending on your device’s settings.
  • Turn them off in your notification settings, or in your device’s or browser’s settings. Signing out on a device turns them off there. Devices you haven’t used for 180 days are turned off, and turned-off devices are deleted 90 days later.

Cookies and browser storage

The first time you visit, we show a notice that the site uses cookies and analytics. Choosing “I understand”, or clicking anywhere else on the site, dismisses it and turns analytics on. Nothing in the analytics list below runs before then.

In the UK, the EEA and Switzerland the notice works differently. A click elsewhere on the page doesn’t count there. The notice offers “Accept” and “Decline”, analytics stays off until you press “Accept”, and so does the version cookie below. If you’re somewhere we can’t tell, we use this stricter version too. If you agreed earlier by clicking elsewhere, we ask you again.

The essential items are needed for the site to work and are always used. Outside the UK and the EEA the version items are used from your first visit while we compare versions of a feature, but nothing about them is sent to us until analytics is on.

Checking your analytics setting…

Turning analytics off takes effect straight away and on every later visit in this browser. Cookies they already set expire on their own, or you can clear them in your browser settings.

Essential

ms_session
Cookie
Keeps you signed in. Only set when you sign in.
180 days after your last visit
mastersetio_view
Cookie
Whether set values and checklists include cameos, trophy cards and promos. Only set when you change that choice.
1 year
mastersetio:<set>:ownership, mastersetio:<set>:rules, mastersetio:collection:unseen
Local storage
Your checklist progress and each set’s display settings, on this device.
Until you clear it
mastersetio:cardView, mastersetio:finder:v1, mastersetio:auth:*, mastersetio:trackingNotice:v1
Local storage
Remembers your view preference, your Find Your Master Set progress, which prompts you’ve already seen, and your answer to our cookie notice.
Until you clear it
Offline cache
Cache storage
Copies of the app’s files, pages and card images, so the site loads faster and works offline.
Replaced as the site updates

Comparing versions (from your first visit)

ms_exp
Cookie
Which version of a feature this browser sees while we compare two or more versions, for example “after 5 cards” or “on the first card” for the save-your-progress prompt. It holds only the version names, never an ID, and isn’t set for signed-in visitors.
13 months, or until the comparison ends
mastersetio:exp:<name>
Local storage
The version this browser joined and when, so it keeps seeing the same one. Sent to us only once analytics is on (see below).
Until you clear it

Analytics (only after you acknowledge the notice)

ms_vid, ms_sid
Cookie · MasterSet analytics
Random IDs for this browser (ms_vid) and for the current visit (ms_sid), so our own analytics can tell visits apart and see how the site is used over time.
ms_vid: 13 months after your last visit · ms_sid: 30 minutes
_ga, _ga_*
Cookie · Google Analytics
Tells visits apart so we can count visitors and see which pages and features get used.
Up to 2 years
_clck, _clsk, MUID
Cookie · Microsoft Clarity
Links the pages of a visit together for Clarity’s heatmaps and session recordings.
From 1 day (_clsk) to 1 year
mastersetio:visitorId, mastersetio:summary:lastSent
Local storage
The same random ID as ms_vid, used by the anonymous collection summary described above, and when that summary was last sent.
Until you clear it or switch analytics off
mastersetio:analytics:debug
Local storage
Only set if you open a page with ?analytics_debug=1: shows our analytics events in your browser’s console.
Until you clear it, or open a page with ?analytics_debug=0
mastersetio:analytics:internal
Local storage
Only in the site owner’s own browsers: keeps Microsoft Clarity from loading there.
Until you clear it
mastersetio:app:lastReported
Local storage
When this browser last told us you opened MasterSet as an installed app, so it tells us at most once a day.
Until you clear it

Who we share it with

These service providers handle personal information on our behalf, only to provide their service to us:

  • Fly.io: Hosts the website
  • Neon: Hosts our database (on Amazon Web Services)
  • Resend: Delivers our emails, and tells us whether each one was delivered
  • Google (Google Analytics): Website analytics
  • Microsoft (Clarity): Website analytics, heatmaps and session recordings

We don’t sell or rent personal information, and we don’t share it for targeted advertising. We would disclose it only if the law required us to, to protect someone’s rights or safety, or to a buyer if MasterSet.io were ever sold (in which case we’d tell you first).

Card prices and listings come from third-party data sources. We ask them about cards, never about you.

Your country

To show you your own eBay site (eBay UK for a visitor in the United Kingdom, for example) and to ask for consent the way your country’s rules require, we work out which country you’re in from the address your device connects from. The lookup runs on our own server against a database that ships with the site, so the address isn’t sent to anyone for it. We don’t store the address for this or keep the country. It’s used while your page loads. IP geolocation by DB-IP.

International transfers

We’re based in the United States, and our providers store data there. If you’re in the EEA, the UK or Switzerland, your information is transferred to the US under the safeguards our providers offer: the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where they’re certified, or the European Commission’s Standard Contractual Clauses.

How long we keep it

  • Your account, collection, preferences and saved Finder results: until you delete your account.
  • Signed-in sessions: until you sign out, or 180 days without a visit.
  • Sign-in links: they expire after 15 minutes (7 days for links in our emails) and are deleted a day after that.
  • The log of emails we’ve sent: while your account exists. Entries not linked to an account, including yours after you delete it, are deleted after 90 days. Our email provider’s delivery reports that match no email are deleted after 90 days too.
  • The do-not-send list: kept, as one-way codes rather than addresses, so a bounced or opted-out address isn’t emailed again.
  • Anonymous collection summaries: deleted after a year without an update.
  • Messages you send us: as long as we need them to act on what you told us. Ask, and we’ll delete them sooner.
  • Our own analytics and the record of account activity: deleted after 25 months, and a browser’s random ID after 25 months without a visit, together with the record of which versions it was shown. When you delete your account, these records are unlinked from it.
  • eBay Partner Network purchase reports: kept as our financial records. They hold nothing that identifies you, and their connection to you goes when the analytics record of the click does.
  • Google Analytics and Microsoft Clarity: Google Analytics keeps event data for at most 14 months, and Microsoft Clarity keeps session recordings for about 30 days.

Your rights and choices

Whoever you are

  • Download your data with “Download my data” on your account page.
  • Correct it: change your display name on your account page, or email us about anything else.
  • Delete it with “Delete account” on your account page. Your account, collection, sessions and preferences are removed immediately, and analytics records are unlinked from you.
  • Choose your emails on your account page or with any unsubscribe link.
  • Switch analytics off above.

In the EEA, the UK and Switzerland

You also have the right to access, correct or erase your information, to restrict or object to how we use it (including objecting to marketing emails at any time), to receive it in a portable format, and to withdraw consent. You can also complain to your local data protection authority. We respond to requests within one month.

In US states with privacy laws

Depending on where you live (for example California, Colorado, Connecticut or Virginia), you may have the right to know what we collect, to get a copy, and to have it corrected or deleted. We don’t sell personal information or share it for targeted advertising, so there is nothing to opt out of. We won’t treat you differently for using any of these rights.

To make a request that the account page doesn’t cover, email nick@masterset.io from the address on your account, or we may ask you to confirm you control it. Someone acting on your behalf can contact us too; we’ll confirm the request with you.

Children

MasterSet.io is for a general audience and isn’t directed at children under 13. You must be 13 or older to create an account, or older if the law where you live requires it. If you believe a child under 13 has given us personal information, email us and we’ll delete it.

Security

The site is served only over HTTPS. Sign-in links and session tokens are stored only as one-way hashes, so a copy of our database can’t be used to sign in as you, and IP addresses are stored only as salted hashes. No system is perfectly secure; if a breach affects your information, we’ll tell you as the law requires.

Changes to this policy

When this policy changes, we’ll update the date at the top. If a change is significant, we’ll email account holders before it takes effect.

Contact

Solobuy, LLC
nick@masterset.io