What we hold, and why.
This notice explains what personal data Cardr processes, the lawful basis for each purpose, how long we keep it, and the rights you have. It is written to satisfy Articles 13 and 14 of the UK GDPR.
Who is responsible for your data
The data controller is [[LEGAL ENTITY NAME]], registered in England and Wales, company number [[COMPANY NUMBER]], registered office [[REGISTERED ADDRESS]]. We trade as Cardr.
For anything in this notice, including a request to exercise your rights, contact [[PRIVACY EMAIL]].
We are registered with the Information Commissioner's Office under registration number [[ICO REGISTRATION NUMBER]].
If you have a Cardr
You give us this data when you create and use a card. Every field except your private email is published on your card by your own choice.
| What | Why | Lawful basis |
|---|---|---|
| Name, job title, company, contact links, optional bio and photo | To build and serve your Wallet pass and your public profile page | Performance of a contract |
| Your private email address | To send the sign-in link that proves the card is yours, and service notices | Performance of a contract |
| Your card's web address (slug) | It is the public address of your card | Performance of a contract |
| Scan records: time, browser user-agent string, referring page | To show you how often your card is opened | Legitimate interests, in providing a feature you asked for |
| Wallet device registrations: a device identifier and an Apple push token | So an edit to your card reaches copies already saved on other people's phones | Performance of a contract |
| Subscription records and Stripe customer reference | To run billing and give you the plan you paid for | Performance of a contract, and legal obligation for tax records |
We never sell personal data, we do not run advertising, and we do not use your data to train any machine-learning model.
If you shared your details with someone's Cardr
Read this if you filled in a form on someone's Cardr page. Your details are not only emailed to that person. They are also stored in their Cardr account so the record survives a bounced or spam-filtered email. That storage is described below, and you can ask us to delete it at any time.
When you send your details from someone's card, the cardholder is the controller of the contact record that results, and we process it on their behalf. We also hold it as a controller for the limited purposes of running and securing the service.
| What | Why | Lawful basis |
|---|---|---|
| The name, email, phone number and message you typed | To pass them to the cardholder you chose to share them with, and to store them in that cardholder's contact list | Legitimate interests, in completing the exchange you initiated |
| A one-way hash of your IP address, salted with a key that changes daily | To stop the same source flooding a card with fake submissions. The raw IP address is never written to our database | Legitimate interests, in preventing abuse |
| Your browser user-agent string | Same anti-abuse purpose | Legitimate interests, in preventing abuse |
We also process the raw IP address of every request momentarily, in memory, to apply rate limits. It is not written to disk and is discarded when the rate-limit window passes.
AI-drafted follow-ups
On a paid plan, a cardholder can ask Cardr to draft a follow-up message to a contact. When they do, we send the contact's name, job details, any note the cardholder wrote, and the message that contact sent, to Google's Gemini API so it can write the draft. We send no other data, and the draft is returned to the cardholder to edit and send themselves.
Google processes this as our processor under its API terms. Google states that data submitted through the paid Gemini API is not used to train its models. If a cardholder would rather no contact data leave our servers, they should not use the drafting feature; every other part of Cardr works without it.
How long we keep things
| Data | Kept for |
|---|---|
| Your card and its content | Until you delete it, or ask us to |
| Sign-in links | They expire shortly after issue and are then deleted |
| Contact records from exchanges | Until the cardholder deletes them, or the card is deleted. A card holds at most 5,000; beyond that the oldest are dropped |
| Scan records | Until the card is deleted |
| Billing records | Six years after the end of the tax year they relate to, as UK tax law requires |
| Wallet device registrations | Until the pass is removed from the device, or the card is deleted |
Deleting a card deletes everything attached to it, including its contact records, scan history and device registrations. Deletion is permanent and we cannot undo it.
Who else processes your data
| Processor | What for | Where |
|---|---|---|
| Resend | Sends sign-in links, exchange alerts and service email | United States |
| Stripe | Takes subscription payments. We never see or store your card number | United States and Ireland |
| Google (Gemini API) | Drafts follow-up messages, on a paid plan only | United States |
| Apple | Delivers pass updates to Wallet through the Apple Push Notification service | United States |
| [[HOSTING PROVIDER]] | Runs the servers and stores the database | [[HOSTING REGION]] |
Transfers outside the UK
Some of the processors above are in the United States. Where a transfer is not covered by the UK's adequacy regulations for the UK-US Data Bridge, it is made under the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for a copy of the safeguards that apply to a specific transfer.
Your rights
Under the UK GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Rectify anything inaccurate.
- Erase your data, where we have no overriding reason to keep it.
- Restrict or object to processing we carry out on the basis of legitimate interests. If you object, we stop unless we can show compelling grounds that override your interests.
- Portability: receive the data you gave us in a structured, machine-readable format.
- Withdraw consent at any time, where we relied on consent.
Write to [[PRIVACY EMAIL]] and we will respond within one month. There is no charge.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113. We would rather you came to us first so we can put it right.
Cookies
Cardr sets one cookie: cardr_edit, a signed session token that proves you own the card you are editing. It is strictly necessary for the service to work, which is why it needs no consent banner.
There is no analytics cookie, no advertising cookie, and no third-party cookie. We do not use Google Analytics, Meta Pixel, or any similar tracker.
Security
Data is served over HTTPS only. Sign-in links are stored as hashes, not as the link itself, and expire after a short window. Sensitive endpoints are rate limited. Passwords do not exist here, because Cardr has no passwords to leak.
No system is perfect. If you believe you have found a vulnerability, email [[SECURITY EMAIL]] and we will work with you on it. We will not pursue anyone who reports a genuine issue in good faith.
Children
Cardr is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
Changes to this notice
If we change how we use personal data in a way that materially affects you, we will email active cardholders before the change takes effect, and update the date below.