LVLING

Version privacy-uk-alpha-v6 · 17 August 2026

Privacy Notice — UK Closed Alpha

This notice covers the invited UK closed alpha. It explains the account, collection, pricing, test-transaction and fulfilment data LVLING stores, including the pseudonymous close-friends preview and the encrypted-address capability that remains closed to real collector addresses.

1. Account and product data

When you sign in with Google we store your Google account identifier, your email address, and the display name and avatar Google provides. Using the product stores what you put into it: the cards you mark as owned or wanted, graded-card details you enter, decks, discovery decisions, preferences, contribution and Verification Quest proposals, and push-notification subscriptions. We also keep your invitation, entitlement, accepted document-version history and each acceptance time, daily portfolio snapshots, recognition events where enabled, and the minimum operator audit needed to run, investigate and secure the alpha.

A close-friends preview link does not use Google or a password. If you choose to enter through one, we create a random internal account identifier and collector name, set the account to the UK sandbox, and store the invitation campaign, accepted document-version history and acceptance times. We do not ask for or infer your email. The one-use link key is removed from the browser address before consent is sent; only its SHA-256 digest is stored, so the database cannot reconstruct the link.

After a completed Trade or Purchase, you can optionally leave one structured private product response: how the journey felt, which part shaped that answer, and whether you would use the journey again. It contains no free text and is not a review of the other collector.

Older beta records may include a WhatsApp, Instagram or Discord handle supplied before the off-platform exchange path was retired. Current Trade and Purchase journeys do not collect, require or reveal those handles.

Product usage signals.To see where the alpha works and where it gets stuck, LVLING records first-party product telemetry — product usage signals — inside its own database: which product screens you open (recorded as a screen template such as “set grid”, never the full address or any search text), that a sitting started, when a card sheet is opened and which of its tabs you switch to, your Discovery decisions and card views, ownership changes you make, taps on next-step buttons, empty screens you reach, price states shown as uncertain, the short in-product prompts you are shown and the one-tap answer you give, and client-side error digests. Each event carries your account identifier, a random session key that lives only in that browser tab, the event name, a closed-vocabulary detail and a time. It carries no free text, no query string, no IP address, no device fingerprint and no location. These signals are used only to improve the product and are never sold, shared with advertisers, or used to change a price, a transaction, Trade Standing or Collector Rank.

2. Test transaction and fulfilment data

The current Trade and Purchase sandbox stores test-only listings, orders, trade legs, itemised amounts, temporary-authorisation facts, synthetic provider references, shipment and tracking events, structured cases, refunds, returns, notifications, custody and reconciliation evidence. It also stores your private test Trade Standing tier, limit, evidence events, accepted-proposal snapshots, active exposure and appeals. Other members do not see it, Collector Rank does not set it, and test Standing never creates a live transaction limit. These records simulate the intended journey; they are not proof that real money, a label or a card moved.

3. Postal addresses

Real-address collection is not enabled in the current sandbox. If it is enabled after the remaining security, legal and operational gates pass, LVLING can store an encrypted ship-to and ship-from snapshot, its country and routing jurisdiction, address role, verification result, document versions, creation and retirement state, and a payload-free access or command audit. Street, locality and postcode material stays inside the encrypted payload.

Address material is available only to the bounded server fulfilment operation that needs it. Ordinary product reads, notifications, logs, support cases and account exports do not reveal ciphertext, integrity keys or another member’s route. Opening a support case never grants a support operator access to address material.

Unbound address material can be erased with the account. An address tied to an active transaction cannot be purged while that route or another participant’s rights depend on it. After obligations end, ciphertext is purged or the minimum pseudonymous transaction evidence is retained only under the approved legal retention policy. The exact production retention schedule, key custody and privacy operating process must be approved before any real address is requested.

4. What we deliberately do not hold

No card numbers or security codes: payment credentials would be held by the approved payment provider, not LVLING, and the platform does not hold a member balance. No private messages, because there is no messaging. No advertising trackers, device fingerprints or IP-address profiles. No seller photographs are retained as catalogue images or test evidence. The marketing site’s visit counter (GoatCounter) is cookieless.

5. Why we hold it

We use account and product records to provide the service you joined; collection, discovery and contribution records to deliver and improve those features; and security, consent, test-transaction and audit records to prevent abuse, diagnose failures and preserve an accurate history. Before live transactions, any additional identity, fraud, payment, carrier or relationship signals require a documented lawful basis and privacy review.

Product usage signals are used to understand which parts of the alpha are used, where members stop, and which prompts help; they are read in aggregate by the LVLING team and are kept for the duration of the alpha and its evaluation.

Optional post-transaction feedback is used only to improve the Trade and Purchase journeys. It does not change a transaction, price, Trade Standing or Collector Rank, and it is not treated as NPS, willingness-to-pay or proof of commercial conversion.

If you ask for help, we store a case ID, structured issue category, account or exact Trade/Purchase reference, priority, status, response template and an append-only customer/operator timeline. The first-alpha case form accepts no free text or uploads. A support case cannot expose another member’s transaction, change transaction state or give a support operator access to payment credentials or addresses.

Your profile is private by default. Making it public is an explicit toggle, and it does not publish your email, address, payment facts, private transaction evidence or legacy contact handle.

6. Cookies

We use a session cookie that keeps you signed in and short-lived security cookies while Google sign-in or an invitation is completing. A close-friends preview uses the same strictly necessary HttpOnly session cookie after its one-use fragment is consumed; the raw fragment is not put into that cookie. A device-local preference remembers your collecting focus. No consent banner is shown because there is no advertising or optional tracking cookie.

7. Where it goes

Data lives in our database (hosted on Railway/Neon in Europe) and is not sold or shared with advertisers. Market references come from configured data sources subject to source and publication gates; your member identity, collection and behavior are not sent to them. Google processes the sign-in you choose.

The current transaction sandbox makes no Stripe, carrier or label-provider call. If live providers are later approved, the payment provider would receive the payment and identity fields needed for its role, and the exact carrier would receive only the route/contact fields needed for the selected service. The revised live notice will name those roles and retention rules before that sharing begins.

8. Your rights and how to use them

You can ask for a copy of your data, correction, or deletion at any time through Account → Help & Support. Choose the privacy, deletion, complaint or legal category to receive an attributable case ID inside LVLING. The ordinary product data is deleted and your profile is scrubbed. We retain the minimum stable Google identifier needed to stop the erased account being silently recreated, the invitation/consent record needed to preserve the founding allocation or one-use preview record, and a minimal pseudonymous deletion audit. For a close-friends preview, the retained re-registration tombstone is the random internal preview identifier rather than a Google identifier. If an account ever has trade or payment history, deletion is paused for a reviewed legal retention decision rather than automated. Where no transaction-retention obligation applies, we remove the member link from an immutable feedback response and retain only a de-linked, pseudonymous structured product-improvement record. Its exact transaction reference and timestamp remain to preserve the record's integrity, so we do not claim that retained feedback is anonymous. You can also complain to the ICO (ico.org.uk) if you think we have handled your data badly.

9. Who we are

LVLING is operated by Taskm8 Ltd (company number 16527524), the data controller for this service. Account → Help & Support is the attributable in-product contact route during the private alpha. This notice is versioned; material changes are announced, never silently substituted.

See also the Platform Terms.