Last updated: October 2, 2026
This Privacy Policy explains how SlabStake, the business that operates the SlabStake platform and the websites at slabstake.ca and slabstake.com (the “Service”), collects, uses, discloses, retains and protects your personal information. SlabStake lets members turn a cryptocurrency deposit into a US dollar cash balance and use that balance to acquire fractional shares of PSA-graded trading cards held in custody.
We are based in Quebec, Canada. We handle personal information under Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, and under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). Where we knowingly serve members elsewhere, the laws of their own jurisdiction may also apply to them, and we comply with those that apply to us.
By creating an account or using the Service, you acknowledge that you have read this Policy. If you do not agree with it, do not use the Service.
The person in charge of the protection of personal information at SlabStake is our Privacy Officer, the founder of SlabStake. You can reach the Privacy Officer at [email protected]. If you have an account, in-app support reaches the same people and keeps your request in one thread.
We collect what we need to run the Service, to confirm who you are where the law requires it, to hold and move funds for you, and to keep the marketplace honest. Specifically:
0x1a2b…3c4d) and, if you choose one, a public username. Other members see one of these in place of your name.Because we hold funds and shares on your behalf, we confirm that each member is a real, unique adult before trading and withdrawals open. The check is run by a specialist identity-verification provider through a flow hosted on its own systems. You photograph a government-issued identification document and take a selfie. The provider reads the document and confirms that the selfie shows a live person. It then compares the face in the selfie with the photograph on the document, which is a biometric process. The provider also screens the verified name against sanctions and politically-exposed-person lists, and it reads signals about the connection you used, such as a VPN or a data-centre address. You are asked to agree to this processing on the verification page before the check starts.
The document data and the images are processed by the provider in the European Union, under its own privacy terms. We do not receive the document or the images, and we do not store them. What reaches us is the outcome, a session reference, any screening flags, the verified name and date of birth, and the country that issued the document. We keep the outcome and the session reference. From the verified name and date of birth we compute a one-way fingerprint, kept so that the same person cannot verify two accounts, and we compare them with the name and date of birth you gave at signup. The verified name and date of birth are not themselves kept, and neither is the address on the document. We keep the issuing country, and compare it with the country of residence you gave at signup, because the Service is open only to residents of the countries it serves.
The same check is used for one other purpose. If you lose your second factor and have no backup code or other passkey to fall back on, you can recover two-factor authentication by confirming your identity again, and you are asked to agree to that check before it starts. We use its result only to decide whether the person asking is the person the account belongs to: the verified name and date of birth are compared with the fingerprint described above, or with the name and date of birth you gave at signup if you were never verified. That check screens nobody against sanctions lists. We keep when a recovery was started, how far it went, why it ended and the network address the request came from, and none of the identity details.
We also keep a record of each verification session: when it was opened, its status at the provider, the result of each step and the provider’s warning codes. That record holds no name, no date of birth, no document number and no image. Verification is carried out by the provider alone. Our staff never ask you to type your legal name or your address, and they decide a verification only when a screen has flagged it for a person to examine.
We do not collect bank account or payment-card numbers, and we never hold the private keys to a cryptocurrency wallet. Cryptocurrency payments are processed by our third-party processor (see Section 6).
We use personal information for the following purposes:
The legal bases for these uses are your consent, the necessity of the processing to perform our contract with you, our legitimate business interests balanced against your rights, and compliance with legal obligations.
We do not sell your personal information. We disclose it only in the following circumstances:
We rely on the following categories of provider. Each processes only the data its function needs, and we share personal information with it only as necessary:
Cards are sourced and valued with external services: a marketplace listing API and a market-price data feed. The grading company’s public certificate registry is consulted as well. A query to any of these carries information about the card, such as a listing identifier or a certificate number. Your personal information is not sent.
Some of these providers process information outside Quebec: the identity-verification provider in the European Union, and the email and error-monitoring providers in the United States. Information held there may be subject to the laws of that place, including lawful access by its courts and authorities. We take contractual and technical measures intended to give it protection comparable to the protection it has here.
We keep personal information for as long as the purposes in this Policy require, or for as long as the law requires, whichever is longer. Because we hold and move funds, some records outlive your account:
When information is no longer needed and no legal obligation requires us to keep it, we delete or anonymize it.
We use technical and organizational safeguards designed to protect your information: encryption of traffic in transit; one-way hashing of passwords; two-factor authentication, which is required before a deposit address is issued; session invalidation on a password change or an account suspension; append-only ledgers, so that a balance cannot be altered silently; an audit log of privileged actions; rate limiting and abuse detection; and a rule that your real name and your credentials are never exposed to other members or to staff. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your password confidential.
If a confidentiality incident involving your personal information presents a risk of serious injury, we will notify you and the relevant authorities as applicable law requires, and we record every such incident whether or not it is reportable.
We set two cookies. A secure, http-only session cookie keeps you signed in and is essential to the Service. A preference cookie remembers whether you chose the light or the dark theme and lasts a year. While a sign-in or a passkey setup is under way, one more cookie holds that step for at most ten minutes and then expires. The portfolio page also keeps one preference, whether your balances are hidden, in your browser’s own storage. We set no advertising cookie and no cross-site tracking cookie. Cookies can be blocked or deleted in your browser settings, though the Service does not work without the session cookie.
Our product analytics (Section 3d) uses no cookie at all: usage events are recorded on our own servers through the session you already have, no third-party analytics script runs in your browser, and we do not fingerprint your device. This is why the Service shows no cookie consent banner: nothing about it is optional.
Subject to applicable law and to our legal obligations to retain certain records, you have the right to:
Closing your account works as follows. You request deletion from Settings. The request is refused while you hold a balance or shares, or have an open pledge, an open order, a pending withdrawal or a live listing, since those have to be settled first. Once accepted, you have 30 days to change your mind and sign back in. After that, your profile is anonymized: your name, email address, phone number, date of birth, country and username are removed, and the records listed in Section 7 are kept for the period stated there.
To exercise any of these rights, contact the Privacy Officer at the address in Section 2. We may need to verify your identity before acting on a request, and we respond within the time applicable law allows, which in Quebec is 30 days.
The Service is intended only for individuals who are at least 18 years of age. Signup asks for your date of birth and refuses anyone under 18. Identity verification then reads the date of birth on your government document and declines a document that shows an age under 18. If we learn that we have collected personal information from a minor, we delete it.
Some decisions about your account are made by automated processing alone. When you verify your identity, the outcome is decided by rules applied to the provider’s result, without a person reviewing it. A document that shows an age under 18 is declined, and so is a document whose name or date of birth does not match your account. A clean result opens trading and withdrawals. A result that carries a sanctions or politically-exposed-person warning, or a warning about the connection used, is not decided automatically. It is held for review by our staff, and for legal reasons we may not be able to tell you why. Other automated rules apply rate limits and enforce the one-account fingerprint.
When an automated decision is made about you, we tell you at the time we tell you the decision. You may then ask us for the personal information the decision was based on and for the reasons behind it, and ask for that information to be corrected. You may also ask that a member of our staff review the decision. Use in-app support or write to the Privacy Officer.
If you have a concern about how we handle your personal information, contact the Privacy Officer first so that we can try to resolve it. You also have the right to complain to:
We may update this Policy from time to time. When we make a material change, we update the “Last updated” date and notify you by email or through the Service. Your continued use of the Service after a change takes effect means you accept the updated Policy.
Questions about this Policy or about your personal information go to the Privacy Officer at [email protected], or through in-app support if you have an account.
This Privacy Policy is provided for general information and does not constitute legal advice. Nothing on SlabStake is investment advice. See also our Terms of Service.