MINT HQ
GuidePricing
Sign in

Privacy Policy

Last updated: 11 October 2026

What changed on 11 October 2026. We now keep a 30-day history of the changes you make to your records, so you can undo them from Activity (section 2). On 8 October 2026 we said that, if you connect eBay, we also read refunds and cancellations on your eBay orders and, if you allow it, the fees eBay charged you for each sale, and we make a short code for each item to paste into eBay (section 2). On 7 October 2026 we said that Whop is our merchant of record: when you pay for a plan you buy it from Whop, which is responsible for the payment, your card and billing details, tax and receipts (section 2). We also began to explain what we read from eBay when you connect it, and what we never read (section 2), and the eBay sale posts you can turn on for your own Discord (section 4). On 6 October 2026 we added what the MINT HQ bot posts in our Discord server and the choices you have (section 3), your own Discord alerts and backups (4), MINT CCG packs and cards (5), gift links (6), the Founder's coin (7), payments through Whop, email updates, how you found us, and the full list of services we use. Our Terms of Service changed on the same days: they now cover Discord, MINT CCG, prizes and payments.

1. Who we are

MINT HQ is a profit tracking web application for UK resellers, operated as a sole trader trading as MINT HQ, United Kingdom. MINT HQ is the data controller for the personal data described in this policy.

If you have any questions about this privacy policy or how we handle your data, contact us at support@minthq.app.

2. What data we collect and why

Account data

When you create an account, we collect your email address and a hashed password (or, if you sign up with Discord, the details in the next paragraph). We use this to sign you in and give you access to your account. We also record which version of our Terms and this policy you agreed to, and when. Legal basis: contract performance.

Signing in with Discord

If you sign in with Discord, or connect Discord in Settings, Discord shares with us your Discord user ID, username, display name, avatar and the email address on your Discord account. We use these to sign you in, to show your name and avatar in MINT HQ (we only fill in a display name if you haven't set one), and on your FLEX share cards if you choose to show your Discord name there. We keep your Discord user ID linked to your account. We never see your Discord password, and we never store your Discord access token: it is used once, while you sign in, and then thrown away.

Discord asks your permission to “join servers for you”. We use that permission for one thing: to add you to the MINT HQ Discord server when you sign in or connect. While MINT HQ is in beta, we also give you the server's Beta Tester role.

You can disconnect Discord at any time in Settings → Account → Connected accounts, once your account has a password. Disconnecting removes the link between your accounts and the MINT HQ roles described in section 3 (it does not remove the Beta Tester or Founder role). Disconnecting, or deleting your MINT HQ account, does not remove you from the MINT HQ Discord server: you can leave the server yourself in Discord at any time. Legal basis: contract performance (signing you in) and consent (joining the server, which you give on Discord's own permission screen).

Reselling data

Data you enter into MINT HQ (purchases, sales, expenses, supplier refunds, platforms, stores, prices, dates, notes and product photos) is stored to provide the app's features. This data belongs to you. Legal basis: contract performance.

We also keep a history of the changes you make to your purchases, sales, expenses and supplier refunds (what each record looked like before and after, and when), so you can see your recent changes in Activity and undo them. Each change is kept for 30 days, then deleted, and it is deleted with your account. Legal basis: contract performance.

When you search the product catalogue to find a photo, the words you type are sent to KicksDB, our catalogue provider, and the photo you pick is copied into your MINT HQ storage. Nothing that identifies you is sent with the search.

Connecting eBay

If you connect eBay in Settings, you approve it on eBay's own page and eBay gives MINT HQ read-only access to your eBay sales. We read, for each order: the order and line numbers, the listing number, the item title, its variation (such as size or colour), your custom label, the quantity, the price, eBay's fees, the postage your buyer paid, the listing photo and the date. If eBay later refunds or cancels an order, we read that too (the amount, and whether it was in full) so the sale can be updated. If you allow it, we also read the fees eBay charged you for each sale from your eBay finances, including promoted listing fees, so your profit uses eBay's own figures. We use them to add your eBay sales to MINT HQ, matched to the items in your stock, and to remember which listing is which item so the next sale matches itself. We also make a short code for each of your items (such as MH-4K7Q) that you can paste into the custom label on eBay, so that item's sales match themselves. We also keep your eBay user ID and username, and a long-lived eBay access key, encrypted, so new sales can come in by themselves. eBay's order details include your buyer's name, address and username; we ignore them and never keep your buyer's name, address, email or username, and we can't list, edit or message anyone on eBay.

You can disconnect eBay at any time in Settings → Account → Connected accounts: we delete the access key and the eBay sales still waiting to be matched. Sales already added stay in MINT HQ as your records. If eBay tells us your eBay account was deleted, we delete everything we hold from it. Legal basis: contract performance (a feature you switched on).

Usage analytics

With your consent, we collect usage data such as pages visited, features used and session length through PostHog (EU region). Events are linked to your MINT HQ account ID only: they never include your email address, your name, your business or Discord name, item names, anything you type, or money amounts. Nothing is collected until you accept analytics cookies. Legal basis: consent. You can withdraw consent at any time through the cookie settings.

How you found us

When you create an account we record, once, how you arrived: a partner or campaign link (its code), a friend's gift link, our Discord server, a blog post you came from, or none of these. We use it to see which links bring people to MINT HQ. It is only ever reported to us as totals. Legal basis: legitimate interests (understanding how MINT HQ grows).

Email updates

If you sign up on our blog to hear when new packs drop, we store your email address, where you signed up, the wording you agreed to and when, and whether you confirmed. We only email you after you click the confirmation link we send, and every email has a one-click unsubscribe. If you unsubscribe, we keep your address marked as unsubscribed so we don't email you again; ask us at support@minthq.app and we'll delete it entirely. Legal basis: consent.

Waitlist data

If you join the waitlist, we store your email address to tell you when access opens. Legal basis: legitimate interests. You can ask us to remove you at any time by emailing support@minthq.app.

Payment data

Whop (whop.com) is our merchant of record: when you pay for MINT HQ Pro or a Founding membership, you buy it from Whop on its checkout, and Whop is responsible, separately from us, for taking the payment, your card and billing details, tax and receipts. We never see or store your card details. Whop tells us about your membership: its ID, the plan, its status, when the current period ends, your link to manage it on Whop, and the email address on it. We use this to switch your plan on or off. We also keep a record of the payment notices Whop sends us, with personal details removed. Legal basis: contract performance and legal obligation (keeping business records). Whop's own privacy policy applies to the data Whop holds.

Security and abuse prevention

To stop abuse, we limit how often some actions can be repeated, using your IP address or account ID as a short-lived counter (through Upstash). For gift links and the Founder's coin we also keep a one-way hash of your IP address (described in sections 6 and 7); we never store the IP address itself for these. Legal basis: legitimate interests (keeping MINT HQ fair and secure).

3. Your activity in the MINT HQ Discord server

The MINT HQ bot posts in our Discord server. This section explains what it can post about you and the choices you have. MINT CCG features (packs, cards and the posts about them) are being switched on gradually, so some of these may not apply to your account yet.

What the bot posts

  • #pulls: big MINT CCG pulls (the card, its rarity and, for named posts, its number, and the kind of pack it came from), finished sets, and Vault packs you find. When the very rare Grail card is pulled, the bot says how many have been pulled so far.
  • #success: a win, your month, your year or a record, but only when you tap “Post to #success” and confirm after seeing the exact image. These can show an item's name, photo and size, the platform and date it sold, and counts such as how many sales you made.
  • Hall of Masters: a list of everyone who has completed the whole First Drop set, numbered in the order they finished, and a banner with the first three.
  • Pull of the week: each Sunday the bot pins the week's best pull that was posted under the name of someone who shows on leaderboards.
  • #founders: when you earn a Founder's coin (section 7), the bot posts that a Founder's coin was struck, with its number. It names you only if you have turned on Show me on leaderboards; otherwise the post doesn't say who.

Your choices

  • Posting your pulls under your name. You choose this when you first join the server and can change it any time in Settings → Account → Connected accounts (“Post my pulls to #pulls”: Off, Epic+ or Rare+). When it's on, posts mention your Discord account. When it's off (the default), a new Epic or Legendary card and a Vault pack you find are still posted, but anonymously: as “a MINT CCG collector”, with no Discord ID, no mention and no card number. Rare cards and finished sets are never posted anonymously; they're only posted under your name, if you've chosen that or tap “Post to #pulls”.
  • Show me on leaderboards. Off by default. When it's on, the Hall of Masters, its banner and Pull of the week can show your Discord name. When it's off you appear as “a private collector” and keep your place and number.
  • Your MINT HQ roles. While “Show my MINT HQ roles in the server” is on (the default), we give you roles that match your MINT HQ tier coin, your Collector level, the Hall of Masters and First Edition cards. Turning it off removes them. The Beta Tester and Founder roles are separate and stay.
  • We record what you chose and when you answered, and every post the bot makes (its type, what it was about, when, and whether it named you), so a card is only ever posted once and the daily limit of five posts works.

Never in a post

Bot posts never include money amounts, profit, prices or ROI, your email address, or your real name. A post that names you does so with a Discord mention, which nobody gets pinged by.

Legal basis and changing your mind

Legal basis: consent for posts under your name, for #success posts and for being named on leaderboards; legitimate interests for anonymous posts, the Founder's coin post, your roles and running the server. You can change any of these choices at any time in Settings → Account → Connected accounts. A change applies to future posts. Posts already made stay in the server unless you ask us to delete them at support@minthq.app. We can also stop the bot posting about you if you ask.

Discord is an independent controller for what happens on Discord, including the messages and roles you can see there. Discord's own privacy policy applies.

4. Discord alerts and backups (your webhooks)

If you add your own Discord webhook in Settings, we send your alerts to the channel you chose: for example return deadlines, refunds to chase, subscriptions renewing, presale releases, your monthly target and a weekly summary. These can include item names, photos, store names and money amounts, so anyone who can see that channel can see them.

If you've connected eBay and turn on “eBay sales” in Settings → Alerts, we also post each new eBay sale to that channel: the item's name, colour and size, what it sold for, your profit and ROI when it's matched to your stock, and a photo (the listing's photo from eBay, or your own photo of the item). It never includes anything about your buyer. It's off unless you turn it on, and you can turn it off at any time.

If you turn on automatic backups, we send a full copy of your MINT HQ data to the separate backup webhook you chose, on the schedule you picked. We keep a short log of each backup (when it ran and whether it worked). Your webhook addresses are stored with your account and used only to send these messages.

You can remove either webhook at any time in Settings; we stop sending at once. Legal basis: contract performance (a feature you switched on).

5. MINT CCG: packs and cards

When you earn and open packs, we record which packs you received and why (for example a daily pack, a level-up or a gift), when you opened them, which cards you pulled with their numbers and editions, the dust you earned and spent, the cards you crafted, and the sets you completed. We use this to run MINT CCG, to number cards and set completions fairly, and to stop abuse such as using more than one account. Legal basis: contract performance (running the features you use) and legitimate interests (preventing abuse).

Prizes are switched off during the beta: packs hold cards only. We don't run partner packs yet, and we share no data with any partner. Before either starts, we'll update this policy to say exactly what is collected and shared.

6. Gift links

Each account can have one personal gift link to send a friend a free pack. If your account uses Discord, your Discord name appears on your gift link's page and its preview image, and on the pack your friend receives (otherwise it says “a friend”). Anyone you share the link with can see it.

When someone creates an account through a gift link, we record who sent it, who claimed it, when, the pack it gave, whether the friend has made their first sale (which earns the sender a pack), and a one-way hash of the IP address it was claimed from. We use the hash to spot one link being claimed over and over from the same place: the friend still gets their pack, but the sender's reward for those claims waits for a review. As a sender you only ever see counts, such as how many gifts were opened this month and how many friends have made a sale, never who they are. Legal basis: legitimate interests (running the gift feature fairly and preventing abuse).

7. The Founder's coin

To award the Founder's coin we count your progress through the Founder's trial: the setup steps you've completed, how many items and sales you've logged, how many days you've been active, and whether Discord is connected. We count these; we never look at money amounts for it.

Each coin can only be earned once per person, so when one is struck we keep your Discord user ID, a normalised form of your email address and a one-way hash of your IP address with it. We also keep a one-way hash of the IP address you sign in from (when you sign in with Discord or an email link) and of the one you check the trial from. If another account that has earned a coin shares an IP hash with yours, your coin waits for a manual review before it is struck. When a coin is struck we may post it in #founders (section 3), give you the Founder role and a pack, and send you one reminder email about the Founding membership offer before it closes.

If a coin is cancelled for abuse, or the account that held one is deleted, we keep the Discord ID and normalised email address on a list so the coin can't be earned again with them. Legal basis: legitimate interests (making sure each numbered coin goes to one real person).

8. Who we share your data with

We use a small number of services to run MINT HQ. Each acts as a processor on our behalf, except where we say otherwise:

  • Supabase: database, file storage and sign-in. Your account data and reselling data are stored here. Supabase is SOC 2 Type II certified. Data is stored in the UK (London).
  • Vercel: hosts the MINT HQ web app and processes request data (such as IP addresses and browser headers) to serve it. Data may be processed in the US under appropriate safeguards.
  • Whop: our merchant of record, for payments and memberships (section 2). Whop's own privacy policy applies to the data it collects at checkout.
  • Discord: sign-in, the MINT HQ server, the bot's posts and roles, and any webhooks you add (sections 2 to 4). Discord is an independent controller, not our processor: its own privacy policy governs the data it holds about you.
  • eBay: if you connect eBay (section 2), eBay shares your sales with us. eBay is an independent controller, not our processor: its own privacy policy governs the data it holds about you.
  • Resend: sends our emails, such as email update confirmations, beta invitations and the Founding offer reminder.
  • PostHog: usage analytics, EU region, only with your consent.
  • Sentry: error monitoring, EU region. When something breaks we receive technical details and your account ID, never your email or name.
  • Upstash: short-lived rate-limit counters keyed by IP address or account ID.
  • KicksDB: the product catalogue. Receives the words you search for, nothing that identifies you.

We do not sell your data. We do not share your data with advertisers. We do not use your reselling data to train AI models or for any purpose other than providing MINT HQ to you.

9. How long we keep your data

We keep your account and reselling data, your packs and cards, and your choices for as long as your account is open. If you delete your account, it is deleted straight away and gone from our systems within 30 days, with these exceptions:

  • Records of payments and memberships from Whop are kept, unlinked from your account, because we must keep business and tax records.
  • If you held, or were refused, a Founder's coin, your Discord ID and normalised email address stay on the list described in section 7.
  • Posts the bot already made in our Discord server stay there unless you ask us to delete them, and anything you sent to your own webhooks stays in your channels.
  • Analytics data can't be used to identify you once your account is gone and may be kept longer.

Deleting your account also cancels any MINT HQ Pro membership you pay for on Whop. Waitlist and email update addresses are kept until you ask us to remove them or unsubscribe, or the list is no longer used.

10. Your rights

Under UK GDPR you have the following rights regarding your personal data:

  • Right of access: you can request a copy of the personal data we hold about you.
  • Right to rectification: you can ask us to correct inaccurate data.
  • Right to erasure: you can ask us to delete your data. You can also delete your account yourself in Settings, which removes your data as described in section 9.
  • Right to data portability: you can export your data as CSV from each data page, or everything at once as a ZIP or JSON file in Settings → Data. You can also ask us for a full export at support@minthq.app.
  • Right to object: you can object to processing based on legitimate interests, including anonymous posts about your pulls.
  • Right to withdraw consent: where we rely on consent (analytics, email updates, posts under your name, leaderboards), you can withdraw it at any time in the cookie settings, the unsubscribe link or Settings → Account → Connected accounts.

To exercise any of these rights, email support@minthq.app. We will respond within 30 days.

11. Cookies

MINT HQ uses cookies for two purposes:

  • Essential cookies: needed for the app to work. These are your sign-in session, the site access cookie, a session cookie that remembers the loading screen has played, and, if you arrive through a gift link or a blog link, a cookie that remembers it for up to 30 days so it counts when you create your account. These can't be switched off.
  • Analytics cookies: used by PostHog. They are only set after you accept analytics in the cookie banner. You can decline or withdraw consent at any time.

We also save some display choices (such as interface size, sound and motion) in your browser's local storage on your device. We do not use advertising cookies or tracking cookies.

12. Data security

We take reasonable technical and organisational measures to protect your data. These include:

  • All data in transit is encrypted via HTTPS/TLS
  • Database access is protected by row-level security (RLS): your data is only accessible to your own account
  • Authentication is handled by Supabase with industry-standard password hashing
  • Administrative access to the database requires multi-factor authentication

No system is completely secure. If you believe your account has been compromised, contact us immediately at support@minthq.app.

13. Children

MINT HQ is for adults: you must be 18 or over to use it (see our Terms). We do not knowingly collect data from children. If you believe a child has created an account, contact us at support@minthq.app and we will delete the account.

14. Changes to this policy

We may update this privacy policy from time to time. When we do, we update the “last updated” date at the top of this page and explain what changed. For significant changes we will tell you by email or with a notice on your dashboard.

15. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator.

ICO website: ico.org.uk
ICO helpline: 0303 123 1113

We would appreciate the opportunity to address your concerns directly before you contact the ICO. Please email support@minthq.app first.

Back to MINT HQ