// legal

Privacy Policy

Last updated: 1 August 2026

This policy explains what personal data Cardable collects, why we collect it, who we share it with, and the choices you have. It covers three different groups of people: card owners (people with a Cardable account), card viewers (people who open someone's card), and organization members whose cards are managed by an employer.

1. Data we collect from card owners

2. Data we collect about card viewers

When someone opens a card page, we record an anonymized view event: timestamp, coarse referrer, device category, and country. These events power the analytics we show the card owner. We do not build advertising profiles and we do not sell this data.

If a viewer chooses to use lead capture and submits their name, email, phone, or a note, that information is shared with the card owner (and, for organization cards, with the organization's administrators). Submission is always voluntary and clearly labelled. In that relationship the card owner or their organization is the controller of the submitted data and Cardable acts as processor on their behalf.

3. Why we process data

Under GDPR our legal bases are performance of a contract, legitimate interests, compliance with legal obligations, and consent where required. You can withdraw consent at any time without affecting prior processing.

4. Cookies and similar technologies

We use strictly necessary cookies for sign-in and security. Analytics on card pages is event-based and does not require advertising cookies or cross-site tracking. Where local law requires a consent banner, we show one before setting any non-essential cookie.

5. Sharing and subprocessors

We do not sell personal data. We share it only with service providers who process it on our instructions:

We may also disclose data where legally required, or as part of a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy. A current subprocessor list is available on request at [email protected].

6. International transfers

Data may be processed in the United States and other countries. For transfers out of the EEA, UK, or Switzerland we rely on Standard Contractual Clauses together with supplementary technical measures including encryption in transit and at rest.

7. Retention and deletion

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to lodge a complaint with a supervisory authority.

California (CCPA/CPRA): you may request disclosure of the categories of personal information collected, request deletion or correction, and opt out of "sharing" for cross-context behavioural advertising. We do not sell or share personal information in that sense, and we do not discriminate against you for exercising your rights.

To exercise any right, email [email protected]. We respond within 30 days and may need to verify your identity first. If a request concerns a card managed by an employer, we will forward it to that organization as the controller.

9. Security

We use encryption in transit and at rest, row-level access controls on stored records, hashed credentials, least-privilege internal access, and audit logging on administrative actions. No system is perfectly secure; if a breach affects your personal data we will notify you and any required regulator without undue delay.

10. Children

The Service is not directed to children under 18 and we do not knowingly collect data from anyone younger than 18. If you believe a child has created an account, contact us and we will remove it.

11. Enterprise customers

Where Cardable processes personal data on behalf of an organization, that organization is the controller and Cardable is the processor. We will sign a data processing agreement including SCCs, maintain records of processing, support data subject requests, and provide our security documentation on request.

12. Changes

We will post any update here with a revised date, and will notify account holders by email of material changes before they take effect.

13. Contact

Privacy questions: [email protected]. General support: contact page.