Legal

Privacy Policy

Effective July 6, 2026 · Last updated August 1, 2026

This Privacy Policy explains what personal information Rip & Hold collects, how we use and share it, and the choices and rights you have.

1. Introduction

This Privacy Policy describes how Rip & Hold LLC(“Rip & Hold,” “we,” “us,” or “our”) handles personal information in connection with the Rip & Hold website at ripandhold.com, the Rip & Hold application at app.ripandhold.com, and related services (the “Service”). It applies to information we collect through the Service and does not apply to third-party websites or services that we do not control.

By using the Service, you agree to this Privacy Policy and our Terms & Conditions.

2. Information we collect

Account information

When you create an account, our authentication provider, Clerk, collects and processes information such as your name, email address, and login credentials (or the identifiers from any single sign-on provider you choose). We receive a limited account profile from Clerk to identify you within the Service.

Billing information

When you purchase a subscription, payments are processed by Stripe. Stripe collects your payment card and billing details directly. We do not receive or store your full payment card number; we receive limited information such as subscription status, plan, and partial card metadata needed to manage your subscription.

Checkout also collects your billing address, which Stripe stores against your customer record. It is used to determine the sales tax or VAT applicable to your purchase and to keep that calculation correct on renewals.

Sensitive information

We do not intentionally collect sensitive personal information such as Social Security numbers, government identification numbers, health information, precise geolocation, biometric information, or payment card numbers. Please do not submit sensitive personal information through the Service.

Usage and content data

We collect information about how you use the Service, such as your card holdings, watchlists, saved portfolios, investment theses, saved tools, preferences, and the cards, sets, and indexes you view or interact with. Some content you create has a visibility setting: content you mark public (for example, a public investment thesis) is shown to other users together with your account name and profile link on surfaces such as card pages and your profile page; content marked private is visible only to you. You can change a visibility setting or delete the content at any time. If you claim a profile username or write a profile bio, they are shown publicly whenever your profile is public; a master switch on your account page hides your entire profile.

Public means publicly accessible, not just visible to other members. Public profiles, public theses, and published community indexes — including the cards those indexes hold — can be read by anyone on the internet without signing in or holding an account. Public profile pages are also indexed by search engines and generate a preview image when someone shares a link to them. Content you keep private is never included in any of this.

Challenges, XP, and competitions

The Service includes research challenges, an experience-point (XP) system, and card-picking competitions. When you complete a qualifying action we add a record to an append-only ledger: the type of action, the item it applied to (a card, variant, index, or portfolio identifier), when it happened, and — for XP entries — the points awarded, the season, and a key that stops the same action being counted twice. These records hold identifiers, category labels, counts, dates, and card catalog names. They do not hold text you write. We also keep the totals derived from them: your lifetime XP, your level, your XP for the current season, your current and longest streak, and when you were last active.

Each challenge is stored with its progress count, when you completed it, and the identifiers that counted toward it. When you enter a competition we store the cards you picked, when you submitted or last edited the entry, the market prices we record for those cards when the competition locks and again when it resolves, and the return and rank we calculate from them.

Some of this is shown to other people:

  • Your collector level and title appear on your public profile and beside your name on leaderboards. Your XP total, your XP history, and your challenge progress are not shown to anyone else.
  • Once a competition locks, the standingsshow each entrant’s display name, the cards they picked, and their return. While a competition is still open, you see only your own picks.
  • Leaderboards and competition standings are shown only to signed-in accounts, and are not visible to logged-out visitors.

The level shown beside your name is calculated partly from private activity — such as adding cards to your collection or watchlist — so it can move as you use the Service even when nothing you did was public.

Public ranking

Ranking is not a separate switch. Publishing an investment thesis with performance tracking enabled, or setting an index or portfolio to public, is itself what enters that content into the ranked boards. A ranked row publishes statistics we calculate about it — returns over several time windows, performance against a benchmark, and a composite score and rank — alongside your display name. A ranked portfolio row also publishes the combined market value of the positions held in it.

Hiding your profile has limits we would rather state here than have you discover. Hiding it makes your profile page unavailable to others and removes your @username and your avatar from leaderboards and competition standings. It does not remove the name on your account: that name can still appear as the creator of a public index, the owner of a public portfolio, the author of a public thesis, and an entrant in a competition standing. To take content off these surfaces, set it to private or delete it.

Product analytics

We collect product analytics events describing which features are used — for example that a portfolio was saved, a card page was viewed, or an upgrade prompt was shown. These events carry identifiers, feature names, and counts, and do not contain the content you write (such as thesis text, notes, or portfolio names). We enforce that by switching off the features of our analytics tool that would otherwise capture it: there is no session recording, no automatic capture of the text you click on, no on-site surveys, and no heatmap collection. When you are signed in, events are tied to your account id, and we attach a limited profile to that id — your email address and name (received from Clerk) — so we can recognize your account in our analytics tools; when you are signed out, events are associated with a device identifier instead.

Two parts of this are worth stating precisely, because they behave differently:

  • In your browser, product analytics (PostHog) load only after you accept them using the consent control on the site. Until then no PostHog request is made and no ph_* cookie is set.
  • Aggregate traffic measurement (Vercel Analytics and Speed Insights) runs on every visit regardless of that choice. It is cookieless and measures page performance and volume, not individuals.
  • On our servers, a small number of product events (for example completing a challenge or publishing a thesis) are recorded against your account id when the action happens. These are part of operating the Service and are not covered by the browser analytics choice.

Communications

We send email through our email provider, Resend, which receives your email address and the contents of the message. Account, security, and billing email is necessary to operate the Service and is always sent. Everything else falls into one of two groups:

  • You asked for it. A portfolio export is emailed to you when you request it, and it contains your holdings.
  • Product and activity email. When an index you follow rebalances or publishes an update, a weekly digest of those updates, when someone you follow publishes a thesis or an index, and an announcement when we add a new official index. The first four follow from something you chose to follow; the new-index announcement goes to all accounts.

You can switch off all product and activity email from your notifications page, whatever the per-index settings there say. You can also turn it off for an individual index instead. Account, security, and billing email is not affected by those choices. We do not send marketing or newsletter email beyond the product and activity messages described above, and we do not sell or rent your email address.

Device and log data

Like most online services, our infrastructure providers automatically collect technical information such as your IP address, browser type, device information, pages viewed, referring pages, and timestamps, for security, diagnostics, and analytics. Separately, our own application code reads your IP address to apply rate limits — this protects the Service against automated abuse and excessive load. We use it for that check and do not build a profile from it.

Errors and security reports are handled by two providers, split by where they originate:

  • Errors on our servers go to Sentry, and reports may include limited technical request context.
  • Errors in your browser, together with page-performance measurements, go to PostHog — and only when you have accepted analytics, since they travel with the same browser analytics described above.
  • Content-security reports are the exception to that split. Your browser reports it to us whenever something on a page tries to load from a source our security policy does not allow, and we forward that report to Sentry. This happens on any visit and is not governed by the analytics choice, because it is a security control rather than analytics. We deliberately keep the report minimal: which rule was triggered, and the origin (the site name, never the full address) that was blocked. Your browser also offers a snippet of the affected code and the file it came from; because those are the fields most likely to contain page content, we discard them on receipt and never store or forward them.

3. How we use information

We use personal information to:

  • provide, operate, maintain, and improve the Service;
  • create and manage your account and authenticate you;
  • process subscriptions, payments, and renewals;
  • personalize your experience (e.g., your portfolio, watchlists, and saved tools);
  • communicate with you about your account, security, and service updates;
  • monitor, prevent, and address fraud, abuse, and security issues; and
  • comply with legal obligations and enforce our Terms.

We do not sell your personal information.

5. Cookies & tracking

We and our providers use cookies and similar technologies that are necessary to operate the Service (for example, to keep you signed in and to secure your session), and we may use a limited set of cookies to remember preferences and understand aggregate usage. Our product analytics provider, PostHog, uses browser storage to associate usage events with your account once you sign in. You can control cookies through your browser settings; disabling essential cookies may prevent parts of the Service from functioning.

Browser product analytics (PostHog) load only after you accept themusing the consent control shown on the site; until then, no PostHog cookie is set. Your choice is stored in your browser’s local storage, not in a cookie, and you can change it at any time. Cookieless aggregate measurement (Vercel Analytics and Speed Insights) runs on every visit and is not affected by that choice. For a full list of the cookies and local storage we use, see our Cookie Policy.

6. Do Not Track

Some browsers offer a “Do Not Track” signal. There is not currently a uniform industry standard for responding to these signals, so the Service does not respond to them in a separate or automated way. You can still control cookies and browser storage through your browser settings, and disabling non-essential storage may affect analytics or preferences without preventing core account functionality.

7. How we share information

We do not sell your personal information. We share it only with service providers that help us operate the Service, and only as needed for them to perform their functions:

  • Clerk — authentication and account management;
  • Stripe — payment processing and subscription billing;
  • Neon — managed database hosting for your application data;
  • Vercel — application hosting, content delivery, and cookieless traffic and performance analytics;
  • PostHog — product analytics (feature-usage events tied to your account id, with your email and name attached to that id; never the content you write), and, when you have accepted analytics, browser errors and page-performance measurements;
  • Sentry — error monitoring and diagnostics for server and edge errors, and the browser security reports described above;
  • Resend — sending account, transactional, and opt-in email;
  • GitHub — hosting our source code and running the scheduled jobs that refresh market data and send the weekly digest, which access the production database;
  • Cloudflare — bot and abuse protection on our sign-in and sign-up pages, used by Clerk as part of authentication.

We aggregate card catalog and market data from third-party data providers (TCGdex and ScryDex) into the Service; we do not send your personal information to them.

We may also disclose information (a) to comply with law, legal process, or lawful requests; (b) to protect the rights, property, or safety of Rip & Hold, our users, or others; or (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy.

8. Data retention

We retain personal information for as long as your account is active and, after your account is closed, for up to 30 days or as long as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Some records held by our providers (for example, billing records at Stripe) are retained on their own schedules to meet financial and legal requirements.

You can delete individual items (holdings, watchlist entries, theses, portfolios, and custom indexes) at any time from within the Service. To close your account, use the request button on your account page, which opens an email to us; see “Your privacy rights” below.

Cancel any active subscription first. Account deletion is deliberately blocked while a subscription can still renew, so that closing an account never leaves a charge behind. Cancel through the billing portal, then send the deletion request.

When your account is deleted, an automated process erases your personal data from our database. That goes further than deleting content item by item: it also removes the derived copies that would otherwise remain, such as your entries in leaderboard history and the revision history of indexes you created. A small number of shared records are kept with your identifier removed — for example the edit history of an index other people follow, which would otherwise become unreadable for them — and internal logs that never contained a user identifier in the first place are unaffected.

Deletion applies to our own database. Copies held by our providers follow their own schedules: Stripe retains billing records as the financial system of record for as long as tax and accounting law requires, and records at Clerk, PostHog, and Sentryare removed according to those services’ retention settings rather than immediately. If you need data removed from a specific provider, contact us and we will action it.

9. Data security

We use reasonable technical and organizational measures designed to protect personal information, and we rely on providers (Clerk, Stripe, Neon, Vercel) that maintain their own security programs. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us at contact@ripandhold.com. We will respond consistent with applicable law and may need to verify your identity first.

11. EEA / UK rights (GDPR)

If you are in the EEA or the UK, you have the right to: access your personal data; request rectification or erasure; restrict or object to processing; data portability; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority. Where we transfer data outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

12. U.S. state privacy rights

Depending on your state of residence, including California, Colorado, Connecticut, Virginia, Utah, and other states with consumer privacy laws, you may have the right to know or access the personal information we collect, request correction or deletion, obtain a portable copy, opt out of certain processing, and be free from discrimination for exercising your rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California privacy law. We do not knowingly collect, sell, or share the personal information of consumers under 16.

To exercise your rights, contact us at contact@ripandhold.com. We may need to verify your identity and may ask for information reasonably necessary to process the request. You may use an authorized agent to submit a request on your behalf where applicable law allows.

13. Children's privacy (COPPA)

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Service or provide any information about yourself. If you believe a child under 13 has provided us with personal information, contact us at contact@ripandhold.com and we will take steps to delete it. Users between 13 and the age of majority should use the Service only with the involvement of a parent or guardian, and may not purchase a subscription.

14. International data transfers

We are based in the United States, and our providers may process and store information in the United States and other countries. By using the Service, you understand that your information may be transferred to and processed in countries whose data-protection laws may differ from those of your country. Where required, we use appropriate safeguards for such transfers.

15. Third-party links & services

The Service may reference or link to third-party websites and services (such as marketplaces, grading companies, or data providers). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.

16. Communications & email preferences

Account and transactional messages (such as sign-in security, billing receipts, and important service notices) are necessary to operate the Service and cannot be turned off while your account is active. A portfolio export is sent only when you ask for it.

Product and activity email — index rebalances and updates, the weekly digest, theses and indexes published by people you follow, and new-index announcements — is optional. A single switch on your notifications page turns off all of it, and each followed index also has its own setting. See Section 2 for what each message contains. Turning product and activity email off does not affect account, security, or billing email.

All email is delivered through our provider, Resend. We do not sell or rent your email address, and we do not send marketing or newsletter email beyond the product and activity messages described above.

17. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.

18. Contact us

If you have questions or requests regarding this Privacy Policy or your personal information, contact us at contact@ripandhold.com.

Rip & Hold LLC · ripandhold.com

See also our Terms & Conditions and Privacy Policy. Rip & Hold provides research and market data only and is not financial advice.