Privacy notice

What we hold, and why.

This notice explains what personal data Cardr processes, the lawful basis for each purpose, how long we keep it, and the rights you have. It is written to satisfy Articles 13 and 14 of the UK GDPR.

Who is responsible for your data

The data controller is [[LEGAL ENTITY NAME]], registered in England and Wales, company number [[COMPANY NUMBER]], registered office [[REGISTERED ADDRESS]]. We trade as Cardr.

For anything in this notice, including a request to exercise your rights, contact [[PRIVACY EMAIL]].

We are registered with the Information Commissioner's Office under registration number [[ICO REGISTRATION NUMBER]].

If you have a Cardr

You give us this data when you create and use a card. Every field except your private email is published on your card by your own choice.

WhatWhyLawful basis
Name, job title, company, contact links, optional bio and photo To build and serve your Wallet pass and your public profile page Performance of a contract
Your private email address To send the sign-in link that proves the card is yours, and service notices Performance of a contract
Your card's web address (slug) It is the public address of your card Performance of a contract
Scan records: time, browser user-agent string, referring page To show you how often your card is opened Legitimate interests, in providing a feature you asked for
Wallet device registrations: a device identifier and an Apple push token So an edit to your card reaches copies already saved on other people's phones Performance of a contract
Subscription records and Stripe customer reference To run billing and give you the plan you paid for Performance of a contract, and legal obligation for tax records

We never sell personal data, we do not run advertising, and we do not use your data to train any machine-learning model.

If you shared your details with someone's Cardr

Read this if you filled in a form on someone's Cardr page. Your details are not only emailed to that person. They are also stored in their Cardr account so the record survives a bounced or spam-filtered email. That storage is described below, and you can ask us to delete it at any time.

When you send your details from someone's card, the cardholder is the controller of the contact record that results, and we process it on their behalf. We also hold it as a controller for the limited purposes of running and securing the service.

WhatWhyLawful basis
The name, email, phone number and message you typed To pass them to the cardholder you chose to share them with, and to store them in that cardholder's contact list Legitimate interests, in completing the exchange you initiated
A one-way hash of your IP address, salted with a key that changes daily To stop the same source flooding a card with fake submissions. The raw IP address is never written to our database Legitimate interests, in preventing abuse
Your browser user-agent string Same anti-abuse purpose Legitimate interests, in preventing abuse

We also process the raw IP address of every request momentarily, in memory, to apply rate limits. It is not written to disk and is discarded when the rate-limit window passes.

AI-drafted follow-ups

On a paid plan, a cardholder can ask Cardr to draft a follow-up message to a contact. When they do, we send the contact's name, job details, any note the cardholder wrote, and the message that contact sent, to Google's Gemini API so it can write the draft. We send no other data, and the draft is returned to the cardholder to edit and send themselves.

Google processes this as our processor under its API terms. Google states that data submitted through the paid Gemini API is not used to train its models. If a cardholder would rather no contact data leave our servers, they should not use the drafting feature; every other part of Cardr works without it.

How long we keep things

DataKept for
Your card and its contentUntil you delete it, or ask us to
Sign-in linksThey expire shortly after issue and are then deleted
Contact records from exchangesUntil the cardholder deletes them, or the card is deleted. A card holds at most 5,000; beyond that the oldest are dropped
Scan recordsUntil the card is deleted
Billing recordsSix years after the end of the tax year they relate to, as UK tax law requires
Wallet device registrationsUntil the pass is removed from the device, or the card is deleted

Deleting a card deletes everything attached to it, including its contact records, scan history and device registrations. Deletion is permanent and we cannot undo it.

Who else processes your data

ProcessorWhat forWhere
ResendSends sign-in links, exchange alerts and service emailUnited States
StripeTakes subscription payments. We never see or store your card numberUnited States and Ireland
Google (Gemini API)Drafts follow-up messages, on a paid plan onlyUnited States
AppleDelivers pass updates to Wallet through the Apple Push Notification serviceUnited States
[[HOSTING PROVIDER]]Runs the servers and stores the database[[HOSTING REGION]]

Transfers outside the UK

Some of the processors above are in the United States. Where a transfer is not covered by the UK's adequacy regulations for the UK-US Data Bridge, it is made under the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for a copy of the safeguards that apply to a specific transfer.

Your rights

Under the UK GDPR you have the right to:

Write to [[PRIVACY EMAIL]] and we will respond within one month. There is no charge.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113. We would rather you came to us first so we can put it right.

Cookies

Cardr sets one cookie: cardr_edit, a signed session token that proves you own the card you are editing. It is strictly necessary for the service to work, which is why it needs no consent banner.

There is no analytics cookie, no advertising cookie, and no third-party cookie. We do not use Google Analytics, Meta Pixel, or any similar tracker.

Security

Data is served over HTTPS only. Sign-in links are stored as hashes, not as the link itself, and expire after a short window. Sensitive endpoints are rate limited. Passwords do not exist here, because Cardr has no passwords to leak.

No system is perfect. If you believe you have found a vulnerability, email [[SECURITY EMAIL]] and we will work with you on it. We will not pursue anyone who reports a genuine issue in good faith.

Children

Cardr is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.

Changes to this notice

If we change how we use personal data in a way that materially affects you, we will email active cardholders before the change takes effect, and update the date below.

Last updated: 4 August 2026. Previous version: 26 April 2026.