CARDBUSTER

Privacy Policy

Effective Date: 31 March 2026

Last Updated: 28 August 2026

Dual-Jurisdiction Compliance

Malaysia & Singapore

Malaysia Entity KAD BUSTER COLLECTIONS SDN. BHD.
Reg. No. 202401010064 (1555914-M)
Level 27, Centrepoint North Tower, Mid Valley City, Kuala Lumpur, 59200
Singapore Entity KAD BUSTER PTE. LTD.
UEN 202537731G
68 Circular Road, #02-01, Singapore 049422

1. Introduction and Scope

CardBuster ("we," "us," or "our") is committed to protecting your privacy and ensuring transparency in how we collect, use, and process your personal data. This Privacy Policy explains our data handling practices for users accessing our Trading Card Game (TCG) marketplace platform at https://cardbuster.com.

This policy is designed to comply with the data protection laws of both Malaysia and Singapore, where CardBuster operates through two distinct legal entities. The Privacy Policy applies to all users, customers, sellers, and visitors of our platform, regardless of jurisdiction.

2. Definitions

Personal Data: Information relating to an identified or identifiable individual.

Data Controller: The entity determining the purposes and means of processing personal data. CardBuster operates as a data controller for all data collected through our platform.

Data Subject: Any individual to whom personal data relates.

Processing: Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, and deletion.

Third-Party Service Provider: External organizations that process personal data on CardBuster's behalf, including payment gateways, shipping carriers, and analytics providers.

3. Data Controller Information

3.1 Malaysia Entity

Business Name: KAD BUSTER COLLECTIONS SDN. BHD.

Registration No.: 202401010064 (1555914-M)

Business Address: Level 27, Centrepoint North Tower, Mid Valley City, Kuala Lumpur, 59200, Malaysia

Jurisdiction: Malaysia Personal Data Protection Act 2010 (PDPA 2010)

3.2 Singapore Entity

Business Name: KAD BUSTER PTE. LTD.

UEN: 202537731G

Registered Office: 68 Circular Road, #02-01, Singapore 049422

Jurisdiction: Singapore Personal Data Protection Act 2012 (PDPA 2012)

3.3 Platform

Website: https://cardbuster.com
Brand: CardBuster

4. What Personal Data We Collect

We collect personal data in the following categories:

4.1 Account Registration Information

4.2 Card Recognition and Scanning Data

CardBuster uses advanced AI-powered card recognition technology to analyze trading card images. This process involves:

4.3 Listing and Product Information

4.4 Transaction and Payment Data

4.5 Shipping and Delivery Data

4.6 Messaging and Communication Data

4.7 Collection Album Usage Data

4.8 Device and Technical Data

4.9 Location Data

5. How We Collect Personal Data

5.1 Direct Collection

We collect personal data directly from you when you:

5.2 Automatic Collection

We automatically collect certain data through:

5.3 Third-Party Sources

We may receive personal data from third-party service providers, including:

5.4 Social Login and Facebook Data

CardBuster offers Facebook Login as an optional way to sign in, create an account, or link an existing CardBuster account. When you choose Facebook Login, we may receive your Facebook user ID, name, profile picture, and email address, depending on the permissions you grant and the information available in your Facebook account.

We use this information only to authenticate you, create or link your CardBuster account, protect account security, and provide account support. CardBuster does not post content to Facebook on your behalf and does not sell personal data received through Facebook Login.

You may remove CardBuster from the Apps and Websites section of your Facebook settings. To request deletion of your CardBuster account and associated Facebook Login data, follow our User Data Deletion instructions.

6. Purposes for Processing Personal Data

CardBuster processes personal data for the following legitimate purposes:

6.1 Platform Operations

6.2 AI and Card Recognition Services

6.3 User Communication

6.4 Analytics and Improvement

6.5 Security and Compliance

6.6 Legal Obligations

6.7 Marketing (Consent-Based)

7. Legal Basis for Processing

CardBuster processes personal data based on the following legal grounds:

7.1 Consent

We obtain your explicit consent for processing personal data not otherwise justified by contractual necessity or legal obligation. You may withdraw consent at any time by contacting us (see Section 16).

7.2 Contractual Necessity

Processing is necessary to perform our contract with you, including account creation, payment processing, order fulfillment, and dispute resolution.

7.3 Legitimate Interests

We process personal data to pursue legitimate business interests, including fraud prevention, cybersecurity, analytics, and service improvement, provided this does not override your fundamental rights and freedoms.

7.4 Legal Obligation

Processing is required to comply with applicable laws, regulatory requirements, and government requests in Malaysia and Singapore.

8. Cookies and Tracking Technologies

8.1 What Are Cookies?

Cookies are small text files stored on your device that help us recognize you, remember your preferences, and improve your experience on CardBuster.

8.2 Types of Cookies We Use

8.3 Controlling Cookies

You can control cookie preferences through your browser settings. However, disabling essential cookies may impair platform functionality. We will seek your consent before deploying non-essential cookies in compliance with PDPA 2010 and PDPA 2012 requirements.

8.4 Third-Party Tracking

Our analytics partners and service providers may use cookies and tracking technologies. For details on their practices, please review their privacy policies.

9. Third-Party Service Providers and Data Sharing

CardBuster shares personal data with selected third-party service providers to deliver platform services. These organizations are contractually obligated to process data only as necessary and in accordance with this Privacy Policy.

9.1 Payment Processing

9.2 Card Recognition and AI Services

9.3 Shipping and Logistics

9.4 Messaging and Communication

9.5 Market Data and Analytics

9.6 Cloud Hosting and Infrastructure

9.7 No Unauthorized Sales

CardBuster does not sell personal data to third parties for their independent marketing or commercial purposes. We only share data as necessary to deliver platform services or comply with legal obligations.

10. Data Localisation (No Cross-Border Transfer)

10.1 Data Localisation by Jurisdiction

CardBuster stores and processes your personal data within your own country of residence. The personal data of users in Malaysia is collected, stored, and processed in Malaysia by KAD BUSTER COLLECTIONS SDN. BHD., and the personal data of users in Singapore is collected, stored, and processed in Singapore by KAD BUSTER PTE. LTD. We do not transfer your personal data between Malaysia and Singapore, nor between our Malaysian and Singapore entities. Each entity independently maintains data protection standards compliant with the Personal Data Protection Act 2010 (Malaysia) or the Personal Data Protection Act 2012 (Singapore), as applicable to your jurisdiction.

10.2 No Cross-Border Transfer

We do not transfer your personal data to any country outside your country of residence. Where we engage technical service providers to operate the Platform, we require by contract that any processing of your personal data takes place within your own jurisdiction and is protected to a standard no lower than the applicable PDPA. We will not introduce any cross-border transfer of your personal data without first updating this Policy and, where required by law, obtaining your consent.

10.3 Adequate Safeguards

11. Data Retention

CardBuster retains personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations.

11.1 Retention Approach

11.2 Secure Deletion

Upon expiration of retention periods, personal data is securely deleted or anonymized. We do not retain personal data longer than necessary unless required by law.

12. Data Security

12.1 Security Measures

CardBuster implements industry-standard technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, and destruction:

12.2 Data Breach Notification

In the event of a personal data breach, CardBuster will notify affected individuals and relevant regulators (PDPC in Singapore, Commissioner in Malaysia) without undue delay, as required by applicable data protection laws.

12.3 Limitation of Liability

While we implement reasonable security measures, no method of transmission over the internet or electronic storage is completely secure. CardBuster cannot guarantee absolute data security but commits to maintaining security standards consistent with applicable laws.

13. Your Rights

Depending on your jurisdiction (Malaysia or Singapore), you have the following rights concerning your personal data:

13.1 Universal Rights (Malaysia & Singapore)

Right to Access

You may request a copy of the personal data we hold about you and request information on how it is being processed.

Right to Rectification

You may request that we correct, update, or complete inaccurate personal data.

Right to Erasure ("Right to Be Forgotten")

While neither the Malaysia PDPA nor the Singapore PDPA currently provides a statutory right to data deletion equivalent to the GDPR’s “right to be forgotten,” CardBuster voluntarily commits to deleting or anonymising your personal data within a reasonable period of your request, except where retention is required by law, tax obligations, or ongoing dispute resolution.

Right to Withdraw Consent

You may withdraw consent for processing at any time. Withdrawal does not affect the lawfulness of prior processing.

Right to Lodge a Complaint

You have the right to lodge a complaint with the relevant data protection regulator.

13.2 Malaysia-Specific Rights (PDPA 2010)

13.3 Singapore-Specific Rights (PDPA 2012)

13.4 Exercising Your Rights

To exercise any of these rights, please contact us at the details provided in Section 16. We will respond to your request within statutory timeframes (typically 14-30 days depending on jurisdiction and request complexity). We may require identity verification before processing your request.

13.5 Right to Opt-Out of Marketing

You may opt out of marketing communications by clicking the "Unsubscribe" link in any promotional email or by contacting us directly.

14. Children's Privacy

CardBuster is not intended for children under 18 years of age. We do not knowingly collect personal data from children below this age. If we become aware that a child under 18 has provided personal data, we will take steps to delete such information and terminate the child's account. Parents or guardians who believe their child has provided personal data should contact us immediately.

15. Updates to This Policy

CardBuster may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. Continued use of CardBuster following notification of changes constitutes your acceptance of the updated Privacy Policy.

16. How to Contact Us

If you have questions, concerns, or wish to exercise your data rights, please contact CardBuster at:

Malaysia Operations

KAD BUSTER COLLECTIONS SDN. BHD.

Level 27, Centrepoint North Tower

Mid Valley City, Kuala Lumpur, 59200

Malaysia

Registration No.: 202401010064 (1555914-M)

Singapore Operations

KAD BUSTER PTE. LTD.

68 Circular Road, #02-01

Singapore 049422

UEN: 202537731G

General Inquiries

Website: https://cardbuster.com
Email: contact@cardbuster.com

17. Jurisdiction-Specific Provisions

17.1 Malaysia — Personal Data Protection Act 2010 (PDPA 2010)

Data Protection Principles

CardBuster complies with the seven data protection principles under PDPA 2010:

Malaysian Data Protection Commissioner

For complaints regarding PDPA 2010 compliance, contact:

Personal Data Protection Commissioner
Malaysian Communications and Multimedia Commission (MCMC)
63000 Cyberjaya
Selangor, Malaysia
Website: https://www.pdp.gov.my

17.2 Singapore — Personal Data Protection Act 2012 (PDPA 2012)

PDPA 2012 Compliance

CardBuster complies with the Singapore PDPA 2012 requirements, including:

Data Breach Notification

CardBuster notifies the Personal Data Protection Commission (PDPC) and affected individuals of data breaches without undue delay as required by PDPA 2012.

Singapore Personal Data Protection Commission (PDPC)

For complaints regarding PDPA 2012 compliance, contact:

Personal Data Protection Commission
Singapore
Website: https://www.pdpc.gov.sg

END OF PRIVACY POLICY

Related Policies

Terms of Service · User Data Deletion

General inquiries: contact@cardbuster.com