It’s Time!

Privacy Policy

Last updated October 5, 2026

This policy explains how the It’s Time staff application (the “Service”), reachable at itstimecards.ai and as an app for iPhone and iPad, handles information. The Service is built and operated by Omar’s Automations, LLC (“we”) for TCG Lunatic LLC, doing business as IT’S TIME! Sports Cards, TCG & eSports, of Agoura Hills, California (“the Store”). The iPhone and iPad app is published by Home County Pizza, Inc. on its Apple developer account and distributed privately to the Store’s staff: through Apple’s TestFlight while it is tested, then as a custom app through Home County Pizza, Inc.’s Apple Business Manager organization.

The Service is not open to the public. It is an internal tool for the Store’s own staff and the business partners the Store gives a login. There is no self-service sign-up, no advertising, and no analytics or tracking pixels, and personal information is not sold or shared as California law defines those terms. The only accounts are ones an administrator has created. The public can give the Service information only through the Store’s customer forms described in Section 3.

1. Information the Service handles

Account information. For each authorized user: name, username, work email address and mobile number where the account has them (used to send sign-in codes), a password stored only as a one-way hash (Argon2id for every password set through the Service), an authenticator-app secret where the user set one up, role and permissions, and sign-in activity (when, from which browser or device, and whether each attempt succeeded).

Activity records. The Service logs each page a signed-in user opens (with the network address it was requested from), each sign-in attempt, and the changes it records, such as buys, time-clock punches and edits to time records, against the individual user. When a user browses a website through the Service’s vendor portals, the address of each page opened there (the site and path, without the query string) is also kept against that user. For staff, a portal reaches only the Store’s supplier, marketplace and business-service websites (and the security-check services those sites use); for the Store’s administrators it can reach any website, and those page addresses are kept too. Problem reports staff send from the Buy desk (what they write, the name they give and their browser’s identifier) are kept in the Store’s Buy & Trade sheet in Google Drive. The Store uses these records to audit its own operations.

Business records from connected systems. The Service reads the Store’s own records from systems the Store already uses: its Buy & Trade sheet and folders in Google Drive; its sales channels and marketplaces (Shopify, eBay, Whatnot, TCGplayer, Temu and DoorDash); its shipping tool (Pirate Ship); its scheduling tool (EasyTeam); payroll reports from its payroll provider (Paylocity); and its accounting ledger. The owner can also upload the Store’s bank statements. These contain inventory, purchases, sales, orders, customer messages, shipments, staff schedules and pay, the Store’s own accounts, and the customer details the Store records when it buys cards.

Time records. Clock-in and clock-out times for staff on the time clock, whether made on the store iPad or from the app, and any edits to them.

Photographs. Staff can photograph cards and products with the device camera, or choose photos from the photo library, for a buy, an inventory item or a Repackers order or item. Those photographs are uploaded to the Service’s own server and attached to the record they were taken for; the photographs of a completed buy are also saved to the Store’s Buy & Trade photo folder in Google Drive, and photographs of cards taken into stock may be added to the Store’s Shopify product listings. To identify a card, a photograph may be sent to the services named in Sections 4 and 7. Staff can also take or pick a photo to attach to a question for the assistant (see Assistant conversations). In a vendor portal, a website’s own upload button can also let a user take a photo or a video with the camera, or pick a photo or file, to upload to that website (iOS then offers the photo library, the camera, for a photo or, where the site accepts one, a video, and Files); it goes from the device to that website, not to the Service. The app has no permission to read the device’s photo library: iOS’s own picker hands it only the photos the user picks. The app saves a picture to the device’s photo library only when the user chooses Save to Photos or Save Image.

Assistant conversations. Questions staff ask the built-in assistant, and the answers returned, are kept so the Store can audit what was asked and reported. A file or photo attached to a question is sent with that question to the language model (Section 4); the Service keeps only its file name and type, not the file.

Location when clocking in from a phone. Staff on the time clock may clock in or out from their own phone instead of the store iPad, only in the app, and only from a phone whose sign-in is linked to it (see Device information). When they tap Clock in or Clock out, and only then, the app asks iOS for the phone’s current location (with permission, “While Using the App”), together with iOS’s own report of whether that location was simulated by software or came from an external accessory. The app itself puts the location, those two reports, the action and a one-time code from the Service into a punch, signs it with the phone’s device key, and sends it to the Service over a connection that accepts only the certificate authorities that issue the Service’s website certificates; the web pages shown in the app never receive the location. The Service accepts the punch only if it is signed by that phone’s key, iOS did not report the location as simulated or from an accessory, and the location is recent, precise enough, and within 100 meters of the Store. These checks cannot catch a phone whose operating system has been modified to report a false location. For each attempt the Service keeps the distance, the location’s accuracy, how old the location was, the result and the reason for it, and the identifier string the app or browser sent (its user agent); it does not keep the coordinates. The Service judges at most twelve signed tries a minute from a user. Other refused attempts, such as requests the phone did not validly sign or tries past that limit, are kept one by one, with log lines saying why, up to twelve a minute per user; any more in that minute are only counted, on the last of them. The app never reads location in the background, and no web page shown in the app can read it: the app’s own pages, its document viewer and its vendor portals (which show the supplier’s website and, for administrators, can reach other websites) are all denied location, and links from the app’s own pages and documents to other websites open in Safari, outside the app. While Apple reviews the app, a test account used for that review may clock in from anywhere; its punches are kept apart and are not time records.

Voice questions. Staff can hold the microphone button in the assistant to ask a question by voice. For a voice question the microphone is on only while the button is held. Speech is turned into text on the device where the device supports it, and otherwise by Apple’s speech recognition service. The app keeps no audio and sends none to the Service; the text appears in the question box and is sent only when the user sends it, like a typed question. The only other use of the microphone is a video, with its sound, that a user chooses to record with a website’s own upload button in a vendor portal (see Photographs); it goes to that website. No web page shown in the app can turn on the camera or microphone by itself.

Device information for the app. The app keeps a random installation identifier on the device. On devices that support it, the app also creates a key in the device’s secure hardware using Apple’s App Attest service; Apple certifies that the key belongs to a genuine copy of the app on a genuine device, and the Service links each sign-in made in the app to that key. While device protection is switched on (the Store’s setting, on by default), protected actions from a linked sign-in, such as finalizing a Buy desk record and vendor portal sessions, must be signed with the key, so a copied session cannot perform them from another device; clocking in or out from the phone always needs the key’s signature, and is closed while device protection is switched off. A linked sign-in is never moved to another device’s key, and an App Attest key is linked to an installation only when Apple’s certificate covers that installation’s identifier. For the Store’s administrators who open vendor portals on a phone, the app also makes a second key in the device’s secure hardware, which signs each portal they open there; we approve each such key after reading a six-digit code shown on that phone, and the Service keeps its public half, the installation identifier, the device’s model, and when the key was registered, approved and last used. The keys identify the installation only; neither carries an advertising identifier or biometric data. If notifications are turned on, Apple’s push token for the device is kept and used only to deliver work notifications, such as shift reminders, to it; the app’s version and the device’s model and iOS version are kept with it. Notifications stop when the user turns them off or signs out, when the device’s key is revoked, and when an administrator signs that device out, resets the password or turns the account off. If a user signs out from the app’s lock screen while the device is offline, the app stops taking notifications on that device at once, for whoever signs in next too, and keeps trying to tell the Service (for a few minutes, then each time the app is opened or brought back) until the Service has heard; only then can that device take notifications again. To diagnose faults, the Service also keeps, against the user, why a device check or a signed request was refused (a technical description of what the device sent, never the signature itself; for clocking in from a phone, within the per-minute limit described above) and why a device could not be verified.

Face ID and Touch ID. A user can choose to require Face ID, Touch ID or the device passcode to open the app on their device, and turning that off, or making the app lock less often, asks for them too. That check is handled entirely by iOS. The app never receives biometric data; it only learns whether the unlock succeeded. The setting is stored on that device only.

2. How information is used

  • to run the Store’s inventory, buying, and sales operations;
  • to keep staff time records, and to send work notifications, such as shift reminders, to a device on which the user has turned notifications on;
  • to authenticate users and protect accounts;
  • to keep an audit record of who did what, and when; and
  • to diagnose faults.

Information is not used for advertising or profiling, and is not sold or shared as those terms are defined under California law.

3. Information from the Store’s customers

The public can give the Service information in two ways. Customers who sell cards to the Store may fill in its sell form at /buy (the sell page on the Store’s own website leads there, and the Service still accepts submissions sent from the Store’s earlier online sell forms). It collects the name and contact details the customer enters, the cards they list and any photographs of those cards they add, and keeps them in the Store’s buy records (the Service’s own records and the Store’s Buy & Trade sheet and photo folder in Google Drive) so the sale can be completed at the counter; to identify a card, a photograph may be sent to the services named in Sections 4 and 7. And after an order in the Store’s online shop (Shopify), the order’s thank-you page may ask how the customer heard about the Store; the answer is kept with the order number. Those records are the Store’s business records and are handled under this policy.

4. Artificial intelligence

To answer a question, the assistant sends the question, any file attached to it, and the records needed to answer it to Anthropic’s API, which operates the underlying language model; the Store’s daily briefing is written the same way. To identify the card in a photograph, the Service may send the photograph to Google’s Gemini API and to the card identification services named in Section 7. We do not train any model on the Store’s data.

5. Retention

Inventory, purchase, and sales records, photographs, time records, assistant conversations and activity records are the Store’s business records and are kept for as long as the Store needs them. Account records are kept for the life of the account plus the audit period. An administrator can turn off a user’s account on request, which ends its sign-ins and stops its notifications; the records it made are kept as business records.

6. How information is protected

  • The Service runs on a dedicated server, behind Cloudflare’s network, which carries all public traffic to it.
  • All traffic between users’ devices and the Service is encrypted with TLS.
  • Passwords are stored only as one-way hashes (Argon2id for every password set through the Service), never in readable form. While two-step sign-in is switched on (the Store’s setting), an account with an authenticator app set up, or with an email address or mobile number on file that the Service is set up to send codes to, must also enter a one-time code to sign in. Other accounts, such as vendor and test accounts, sign in with a password only.
  • Sign-in attempts, page visits and recorded changes are logged against the individual user, including failed sign-in attempts.

No system is perfectly secure, and we do not claim otherwise. We will notify the Store promptly on becoming aware of a breach affecting its data, as required by law.

7. Service providers and connected services

  • Anthropic: operates the language model behind the assistant and the daily briefing.
  • Google: hosts the Store’s Drive sheets and its buy photographs, and (Gemini API) identifies cards in photographs.
  • CardSight AI, eBay, Card Dealer Pro, PriceCharting and SportsCardsPro: receive card photographs to identify the card and look up its price.
  • Price and catalog sources (such as PSA, Card Ladder, Waxstat, Cardmarket and TCGplayer): receive card names, numbers or certification numbers to look up prices, never personal information.
  • Shopify, eBay, Whatnot, TCGplayer, Temu and DoorDash: the Store’s sales channels and systems of record (Shopify also receives photographs of cards listed for sale); Pirate Ship, its shipping tool; EasyTeam, its scheduling tool; Paylocity, its payroll provider, from which the Service receives payroll reports.
  • Supplier, marketplace and business-service websites the Store has accounts with, opened through the Service’s vendor portals (and, for administrators, any other website opened there): those sites see what is done there under the Store’s account, including any photo, video or file uploaded to them.
  • Titan (email) and Textbelt (text messages): deliver sign-in codes and work email or text messages.
  • Apple: distributes the app, delivers push notifications to it when they are turned on, certifies the app’s device key (App Attest), and turns a voice question into text when the device cannot do that on its own.
  • Cloudflare: the network in front of the Service.

We do not disclose information to anyone else except where required by law, and we will tell the Store if that occurs unless legally prohibited.

8. California privacy rights

Users are California residents and the Store is a California business. Personal information handled here is largely employment- and business-related. Subject to the exemptions that apply to such information, California residents may request to know what personal information is held about them, to have it corrected or deleted, and not to be retaliated against for asking. Requests should be directed to the Store, or to us at the address below.

9. Children

The Service is a workplace tool and is not directed to children. We do not knowingly collect information from anyone under 16 through it.

10. Changes to this policy

We may update this policy. The date at the top reflects the current version, and material changes will be communicated to the Store’s administrator.

11. Contact

Omar’s Automations, LLC: [email protected]