Privacy Policy
Last updated: 1 August 2026
This policy explains what personal data Cardable collects, why we collect it, who we share it with, and the choices you have. It covers three different groups of people: card owners (people with a Cardable account), card viewers (people who open someone's card), and organization members whose cards are managed by an employer.
1. Data we collect from card owners
- Account data: email address, password hash or federated identity, plan and billing status.
- Card content you publish: name, photo, job title, company, phone numbers, email addresses, physical address, social profiles, custom links, video intros, and any other field you fill in.
- Usage and device data: pages viewed in the app, browser and device type, approximate location derived from IP, and diagnostic logs.
- Payment data: handled by our payment processor. We store the last four digits, card brand, expiry, and billing country — never full card numbers.
2. Data we collect about card viewers
When someone opens a card page, we record an anonymized view event: timestamp, coarse referrer, device category, and country. These events power the analytics we show the card owner. We do not build advertising profiles and we do not sell this data.
If a viewer chooses to use lead capture and submits their name, email, phone, or a note, that information is shared with the card owner (and, for organization cards, with the organization's administrators). Submission is always voluntary and clearly labelled. In that relationship the card owner or their organization is the controller of the submitted data and Cardable acts as processor on their behalf.
3. Why we process data
- To create, host, and serve your card page, QR code, wallet pass, and vCard file.
- To authenticate you and keep accounts secure (legitimate interest).
- To provide analytics, lead capture, and team features you have enabled.
- To take payment and prevent fraud (contract and legal obligation).
- To send service emails. Marketing emails are sent only with consent where consent is required, and every one has an unsubscribe link.
Under GDPR our legal bases are performance of a contract, legitimate interests, compliance with legal obligations, and consent where required. You can withdraw consent at any time without affecting prior processing.
4. Cookies and similar technologies
We use strictly necessary cookies for sign-in and security. Analytics on card pages is event-based and does not require advertising cookies or cross-site tracking. Where local law requires a consent banner, we show one before setting any non-essential cookie.
5. Sharing and subprocessors
We do not sell personal data. We share it only with service providers who process it on our instructions:
- Cloud hosting, database, and file storage for the application and card assets.
- Payment processing for subscriptions and physical product orders.
- Transactional email delivery.
- Error monitoring and product analytics.
- CRM destinations you explicitly connect, such as HubSpot or Salesforce.
We may also disclose data where legally required, or as part of a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy. A current subprocessor list is available on request at [email protected].
6. International transfers
Data may be processed in the United States and other countries. For transfers out of the EEA, UK, or Switzerland we rely on Standard Contractual Clauses together with supplementary technical measures including encryption in transit and at rest.
7. Retention and deletion
- Account and card data: kept while your account is active.
- After account deletion: card pages stop resolving immediately, and the underlying records are deleted within 30 days except where we must keep them longer for legal or accounting reasons.
- Analytics events: retained in aggregate for up to 24 months.
- Captured leads: retained until the card owner deletes them or closes the account.
- Billing records: retained for the period required by tax law, typically 7 years.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to lodge a complaint with a supervisory authority.
California (CCPA/CPRA): you may request disclosure of the categories of personal information collected, request deletion or correction, and opt out of "sharing" for cross-context behavioural advertising. We do not sell or share personal information in that sense, and we do not discriminate against you for exercising your rights.
To exercise any right, email [email protected]. We respond within 30 days and may need to verify your identity first. If a request concerns a card managed by an employer, we will forward it to that organization as the controller.
9. Security
We use encryption in transit and at rest, row-level access controls on stored records, hashed credentials, least-privilege internal access, and audit logging on administrative actions. No system is perfectly secure; if a breach affects your personal data we will notify you and any required regulator without undue delay.
10. Children
The Service is not directed to children under 18 and we do not knowingly collect data from anyone younger than 18. If you believe a child has created an account, contact us and we will remove it.
11. Enterprise customers
Where Cardable processes personal data on behalf of an organization, that organization is the controller and Cardable is the processor. We will sign a data processing agreement including SCCs, maintain records of processing, support data subject requests, and provide our security documentation on request.
12. Changes
We will post any update here with a revised date, and will notify account holders by email of material changes before they take effect.
13. Contact
Privacy questions: [email protected]. General support: contact page.