For parents · COPPA direct noticeNotice version 2026-08-01

Children’s privacy notice

KidCard is built for children under 13, so the Children’s Online Privacy Protection Act applies to everything here. This page is the direct notice we give you before we collect anything from your child.

KC-48201
H
HockeyHank
UP FOR TRADES
TRADESHockey · Baseball
WANTSHockey rookies

“I am always looking for a great hockey card.”

★ 7.4 avg128 cards
🛡️ Nickname, avatar, cards. Nothing else.
⚠️

Draft — HAVE COUNSEL REVIEW. This notice is written to be launch-grade and tracks the amended COPPA Rule (16 CFR Part 312), but it has not yet been reviewed by an attorney. Do not remove this marker until it has.

Who we are: MyKidCard LLC, Pittsburgh, Pennsylvania. Questions, requests, and deletions: privacy@mykidcard.com.

The complete list

What we collect from a child

This is the complete list. There is nothing else. Tap a highlighted spot on the profile, or let it tour.

KidCardKid view
Up for tradesHockeyBaseball
My vault128 cards
Real namenot collected
Locationnot collected
Photo of childnot collected
01
Nickname
2 to 20 characters, chosen by you and your child. Please do not use their real name.
02
Avatar
One of six preset characters. Not a photo.
03
Birth year
The year only, so we can apply the right protections.
04
Cards your child adds
A title, a category, an optional description and wish note, and a photo of the trading card itself. Card photos are stored privately, are shown to other families only after you approve the card, and are deleted with the card or the profile. We never ask for, and you should never upload, a photo with a person in it.
Never

What we never collect from a child

  • ✕Full name, date of birth, home address, email address, or phone number
  • ✕A photograph or video of your child, or their voice
  • ✕Location of any kind, including approximate location from an IP address
  • ✕Contacts, friend lists imported from anywhere, or school information
  • ✕Persistent identifiers used to build an advertising profile
Parent verificationStripeIdentity

How we verify you are the parent

Before your child’s profile exists, you complete a government-ID check with a matching selfie, handled by Stripe Identity. We receive the yes-or-no outcome and a timestamp. We then ask Stripe to redact the ID images and the selfie. We do not store your ID, your selfie, or any biometric template.

0
ID images or selfies stored by us
2
things we keep: outcome and timestamp

If you cannot complete the ID check, email support@mykidcard.com. We offer an alternative knowledge-based verification method.

  1. 1
    You create a parent account
    Email and password, or sign in with Google.
  2. 2
    Government ID
    Driver’s license, passport or national ID, scanned with your phone. Stripe checks the security features and expiry.
  3. 3
    Live selfie
    A short liveness check, matched to the photo on the ID.
  4. 4
    We receive yes / no + timestamp
    Nothing else crosses to us. Stripe redacts the images at our request.
  5. 5
    Now, and only now, a kid profile can exist
    Every permission below is yours to grant. Every connection meets another verified parent on the other side.
Permissions

What each permission means

You turn each one on. You can turn each one off.

Creating a kid profile
Required
Without it there is no account.
Sharing a QR code
Optional
Lets your child’s profile be found by another family scanning the code in person. Both parents must still approve.
Listing cards
Optional
Lets your child add cards for you to review.
Trading
Optional
Lets your child propose a swap with a connected friend. Both parents approve the swap, and the swap itself happens in person.
Selling
Optional
Lets a card carry an asking price. Any money moves between parents, never between children.
Who else sees your child’s information

How connecting with a friend works

Another family sees your child’s nickname, avatar, and approved cards only after both parents have approved a connection. Nobody else. Click a step or let it play.

  1. 1
    Your child shows their KidCardKid
    The QR on the printed card or in the app. Sharing it is a permission you turn on.
  2. 2
    A friend scans itFriend
    Their phone opens a connection request. Nothing about your child is shown yet.
  3. 3
    Your approvalParent
    You see the friend’s nickname and the category of where they met. You approve or decline.
  4. 4
    The other parent’s approvalParent
    Their parent gets the same request about your child.
  5. 5
    ConnectedBoth
    Each family now sees the other child’s nickname, avatar and approved cards. Nobody else.
HHockeyHank
IN PERSON ONLY
CCardQueen
Connections start in person, never by search.
Service providers

Who does work for us

These service providers act on our instructions and may not use your child’s information for their own purposes. We do not run third-party advertising or analytics on any page your child uses. Our marketing pages use analytics; the signed-in app does not.

ProviderPurposeReceives about your child
Supabase
Database, authentication, file storage.Nickname, avatar, birth year, card records and card photos.
SStripe
Verifies you are the parent, and handles payments.Nothing about your child.
▲Vercel
Hosting.Nothing stored. Serves the pages.
Google (Gemini)
Identifies and grades a trading card your child scans.The photo of the trading card. We reject any photo containing a person’s face, and we do not store the photo.
GGroq
Estimates a card’s value.The card’s details (name, year, condition). Nothing about your child.
PPrintful
Prints and ships cards.Your name and address, and your child’s nickname and avatar as printed on the card.
KCOur customer-relationship system
Keeps the parent’s customer record. You are the customer record; your child is not.When two families connect, exactly four things about a child: their nickname, the category of where they met (from a fixed list — never a school or place name), which side asked first, and the nickname of the other child.
In transit
HTTPS only
Every page and request is encrypted, with HSTS so browsers never fall back to plain HTTP.
At rest
Encrypted storage
The database and card photos are encrypted at rest. Card photos sit in a private bucket.
Access
Family-only reads
A family sees only its own data and what a connected family has approved. No public listing of children.
Kids
No email, no social login
Kids sign in with a username and password you make, or by scanning your code. Nothing to phish.
Your rights as a parent

You can see it, stop it, or erase it

Email privacy@mykidcard.com and we will act within 30 days. Deletion is immediate on request.

Review
Review everything we hold about your child.
Delete
Delete your child’s profile and everything attached to it.
Withdraw
Withdraw any permission at any time. Withdrawing the first one stops all further collection and removes the profile.
Refuse
Refuse to let us collect more without deleting what already exists.
If this notice changes materially

We version this notice. If we change it in a way that matters, your existing permissions stop counting and we ask you again before collecting anything further. You will see the request the next time you sign in.