MintLGS legal
Privacy Policy
This policy explains the information MintLGS handles for the platform and on behalf of stores, including payments, marketplaces, storefront customers, and POS hardware.
Last updated: August 17, 2026 · Version 2026-08-02
On this page
- 1. Scope and our role
- 2. Information we process
- 3. Where information comes from
- 4. How we use information
- 5. Subscriptions and payment processing
- 6. Marketplaces and seller accounts
- 7. Optional Google Calendar publishing
- 8. POS hardware and the Hardware Connector
- 9. Who receives information
- 10. Public storefront content
- 11. Cookies, browser storage, and analytics
- 12. Retention and deletion
- 13. Security
- 14. Choices and privacy requests
- 15. Children and youth events
- 16. Locations and transfers
- 17. Changes to this policy
- 18. Contact
1.Scope and our role
This policy covers MintLGS websites, account and billing areas, store dashboards, point of sale, hosted storefronts, APIs, support, emails, and the optional Hardware Connector.
MintLGS decides how to use information for platform signup, subscriptions, security, support, product administration, and our own website. When a store uses MintLGS for its shoppers, customers, staff, orders, events, buylists, or store credit, the store normally decides why that information is collected and MintLGS processes it to provide the service. Store customers should usually direct requests about store records to that store first.
2.Information we process
Depending on how MintLGS is used, we process:
- Account and business information: name, email, password hash, store identity, staff roles, permissions, custom domains, subscription and referral status, accepted legal versions, login history, IP address, and browser or device details.
- Store operations: products, TCG singles, quantities, prices, discounts, presales, suppliers, warehouses, imports, exports, pages, branding, settings, tax configuration, reports, and accounting records.
- Store customer information: name, email, phone, address, account status, merchant notes, tax-exempt status, loyalty information, store-credit balance and ledger, and purchase or return history. A store may create a record without an email and link it later after the customer proves control of the address.
- Orders and payments: line items, totals, discounts, taxes, fulfillment, shipping address, tracking, refunds, chargebacks, payment status, processor identifiers, receipt details, and limited card descriptors such as brand and last four digits.
- Events and buylists: registrations, guest contact details, custom form answers, attendance, results, prizes, card offers, condition assessments, payout preference, tracking, and staff notes.
- Support and communications: ticket content, replies, attachments, feedback, email content, delivery status, suppression information, and support diagnostics.
- Technical and security information: authentication cookies, browser storage, logs, errors, security events, rate-limit data, challenge results, device information, and operational health.
3.Where information comes from
Information comes from account owners, staff, store customers, imported files, store devices, connected payment processors and marketplaces, shipping or catalog providers, security services, and normal use of MintLGS. A store controls which optional accounts and providers it connects.
4.How we use information
We use information to provide and secure accounts; run POS, inventory, storefront, buylist, event, customer, reporting, accounting, pricing, marketplace, shipping, and hardware workflows; process subscriptions and configured payments; deliver emails; prevent fraud and abuse; support users; maintain backups; diagnose failures; comply with law and provider requirements; and improve reliability and usability.
Where a legal basis is required, processing may be necessary to perform a contract, follow a store's documented instructions, meet legal obligations, protect legitimate interests such as security and service improvement, or carry out a choice made with consent. We do not sell personal information or use store customer data for targeted advertising.
5.Subscriptions and payment processing
Stripe processes MintLGS subscription billing. Stores may also connect supported payment providers such as Stripe, Square, Clover, or PayPal for their own sales. Raw card details are entered into provider-controlled forms, terminals, or SDKs and tokenized by the provider. MintLGS still processes the order, amount, status, provider identifier, refund data, receipt data, and limited card descriptors needed to run the store and resolve payment issues.
A connected provider may independently collect identity, bank, business, transaction, device, or compliance information under its own terms and privacy policy. See Service Providers and Connected Services.
6.Marketplaces and seller accounts
When a store connects a marketplace, MintLGS may receive seller account details, credentials or tokens, listings, inventory, orders, buyer contact and shipping information, tracking, refunds, returns, cancellations, fees, payouts, webhook events, and synchronization results. We use that information only to provide the marketplace workflows authorized by the store, maintain records, protect inventory integrity, reconcile financial activity, and troubleshoot failures.
For eBay, MintLGS also receives marketplace account deletion or closure notices. We remove or redact matching eBay personal information from active marketplace records, disconnect a matching seller connection when required, and may retain non-personal transaction totals, legally required records, and keyed suppression hashes that prevent deleted information from being imported again.
7.Optional Google Calendar publishing
When a store chooses to connect Google Calendar, MintLGS receives the connected Google account email, an OAuth authorization, the identifier and name of the secondary calendar MintLGS creates, and synchronization status. MintLGS publishes the store's public event name, public description, date and time, location, event status, and storefront event link to that calendar.
MintLGS requests access only to calendars and events created by the MintLGS application. It does not request access to the account's other calendars. Private staff notes, payment details, custom registration answers, attendee lists, and customer contact details are not sent to Google by this feature.
OAuth credentials are encrypted at rest. Disconnecting Google Calendar revokes the authorization and stops future publishing; the store can separately choose whether to remove the MintLGS-created calendar. MintLGS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
8.POS hardware and the Hardware Connector
Browser hardware features may store a checkout station's selected device and connection settings on that computer. The optional desktop Connector processes a station identifier, protected pairing credential, operating-system and release information, printer and drawer identifiers, selected configuration, receipt content needed for a print job, job results, limited diagnostics, and update state.
Read the Hardware Connector Privacy Notice before installing or pairing the Connector.
10.Public storefront content
Published storefront pages, product information, store policies, branding, testimonials, event details, social links, and uploaded public images are available to storefront visitors. Public content may remain temporarily in browser, search-engine, or content-delivery caches after a store changes or removes it. Do not upload confidential information to a public content field.
12.Retention and deletion
We keep information for as long as needed to provide the service and for security, reconciliation, dispute, fraud-prevention, tax, accounting, provider, backup, and legal purposes. Retention differs by record:
- temporary buylist drafts expire after their stated window;
- detailed completed import rows are routinely removed after 30 days and expired import recovery payloads are cleared;
- email delivery and marketplace sync logs are routinely removed after 90 days;
- completed marketplace webhook payloads are normally retained for 30 days and failed payloads for 90 days;
- completed Google Calendar publishing jobs are normally retained for 30 days and terminal failures for 90 days;
- ordinary owner-requested export files expire after the download window, while a scheduled offboarding export may remain available through the offboarding window;
- production backups are retained under a limited lifecycle, currently up to 90 days, before automatic removal.
Disconnecting a provider removes or revokes current credentials and stops new synchronization, but does not erase historical orders, payments, refunds, accounting, or audit records. Deactivating a store customer is not the same as erasing that customer's transaction and store-credit history.
When a tenant is formally offboarded, MintLGS prepares an export, provides a deletion window, shuts down connected marketplaces, and purges tenant-controlled operational data after the approved process completes. Limited offboarding, billing/referral, security, and inactive tenant records may remain. Deleted active data can remain in backups until the backup lifecycle expires, and third-party providers apply their own retention duties.
13.Security
MintLGS uses safeguards appropriate to the service, including production HTTPS, secure HTTP-only authentication cookies, password hashing, hashed temporary tokens, role and tenant access controls, rate limits, audit logging, protected provider credentials, private export downloads, backups, monitoring, and incident response procedures. No system is completely secure. Store owners must protect credentials, use individual staff accounts, review permissions, keep devices updated, and promptly remove access that is no longer needed.
14.Choices and privacy requests
Account owners can update many account and store details, disconnect providers, manage staff, and request a store data export from the account area. You may ask for access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable. We verify requests and may retain information when law, security, billing, fraud prevention, disputes, or another permitted purpose requires it.
If your request concerns a particular store's customer account, order, event, buylist, or store credit, contact that store first. MintLGS will assist the store with verified requests when required. For MintLGS account or platform data, email privacy@mintlgs.com.
We will not discriminate against a person for exercising an applicable privacy right.
15.Children and youth events
MintLGS business accounts are not intended for anyone under 18, and the MintLGS service is not directed to children under 13. Stores may run youth events or serve families. Each store is responsible for deciding what information it lawfully collects, obtaining parental permission when required, limiting custom event questions, and deleting information when it is no longer needed. A parent or guardian should contact the store about a child's store record and may also contact MintLGS if help is needed.
16.Locations and transfers
MintLGS and its providers may process information in the United States and other countries where they operate. Those locations may have different data-protection laws. Where required, we use contractual or other approved safeguards for cross-border processing.
17.Changes to this policy
We update this policy when the product, providers, or legal requirements change. We will post the new version and update date. For material changes, we will provide reasonable notice through the account, email, or another appropriate method and request renewed acceptance when the nature of the change requires it.
18.Contact
Privacy questions and requests: privacy@mintlgs.com. Product support should be submitted through the MintLGS support system after signing in.