1. Overview
Cardora ("we," "us," or "our") operates the Cardora digital greeting card platform (the "Service") available at https://cardora.com. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights regarding that information.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Name and email address (when registering with email and password)
- Card and board content you create (titles, messages, uploaded images, GIFs)
- Recipient names and email addresses you enter for card delivery
- Messages and communications you send us (e.g., via the contact form)
2.2 Information Collected via Google Sign-In (OAuth 2.0)
When you choose to sign in with Google, we request access only to your basic profile information via Google's OAuth 2.0 service. Specifically, we receive:
- Your Google account email address
- Your display name
- Your Google profile photo URL (used only as an avatar within the Service)
- A unique Google account identifier (used solely to authenticate your session)
Important: We do not request access to your Gmail inbox, Google Drive, contacts, calendar, or any other Google service beyond the basic profile scope. We do not store your Google password. We do not use your Google data for advertising. We do not share your Google profile information with any third party.
2.3 Information Collected via Facebook & LinkedIn Sign-In
If you choose to sign in with Facebook or LinkedIn, we similarly receive only your basic public profile — name, email address, and profile photo — under the same restrictions described above.
2.4 Automatically Collected Information
- Browser type and version, operating system, and device type
- IP address and approximate geographic region (country/city level)
- Pages visited, time spent on pages, and navigation paths within the Service
- Referring URLs and search terms used to reach the Service
- Session cookies necessary to keep you logged in
3. How We Use Your Information
We use the information we collect solely to:
- Provide the Service — create and manage your account, store your cards and boards, and deliver them to recipients
- Authenticate you — verify your identity when you sign in, including via Google, Facebook, or LinkedIn OAuth
- Send transactional emails — delivery notifications, card invites, and account-related communications (e.g., password reset)
- Improve the Service — analyse aggregate, anonymised usage patterns to fix bugs and improve features
- Respond to support requests — address questions or issues you submit via the contact form
- Comply with legal obligations — retain records as required by applicable law
We do not use your personal data for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
4. Data Sharing and Disclosure
We do not sell, rent, trade, or otherwise share your personal information with third parties for their own marketing or commercial purposes — ever.
We share data only in the following limited circumstances:
- Service providers acting on our behalf: We use Supabase (database and authentication infrastructure) and Resend (transactional email delivery). These sub-processors receive only the minimum data necessary to perform their function and are contractually prohibited from using it for any other purpose.
- Card recipients: When you send a card or board, the recipient's name and any message you compose are shared with that recipient — this is the core function of the Service and is done at your explicit direction.
- Legal requirements: We may disclose personal data if required to do so by law, court order, or government authority, or to protect the rights, property, or safety of Cardora, our users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, who will be bound by this Privacy Policy.
5. Data Storage and Security
Your data is stored on Supabase's infrastructure, hosted on Amazon Web Services (AWS) servers in the United States. We implement the following security measures:
- All data is transmitted over HTTPS (TLS 1.2+) — never in plain text
- Passwords are hashed using bcrypt and are never stored in recoverable form
- OAuth tokens are managed by Supabase Auth and are never stored in our application layer
- Database access is restricted by row-level security (RLS) policies — each user can only access their own data
- API keys and secrets are stored as environment variables and never exposed in client-side code
- We conduct periodic security reviews and keep all dependencies up to date
While we take security seriously, no method of transmission or storage is 100% secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorised access to your account.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service.
- Account data (name, email, profile photo): retained until you delete your account
- Cards and boards: retained until you delete them or delete your account
- Transactional email logs: retained for up to 90 days for delivery confirmation purposes
- Server logs (IP addresses, access logs): retained for up to 30 days for security and debugging purposes, then automatically purged
Upon account deletion, we will remove or anonymise your personal data within 30 days, except where we are required to retain it for legal compliance.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request that we correct inaccurate or incomplete data
- Deletion — request that we delete your personal data ("right to be forgotten")
- Portability — request your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data in certain circumstances
- Objection — object to processing based on legitimate interests
- Withdraw consent — revoke OAuth access at any time via Google's security settings
To exercise any of these rights, please contact us at privacy@cardora.com. We will respond within 30 days. EU/EEA residents may also lodge a complaint with their local data protection authority.
9. Children's Privacy
The Service is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we discover we have inadvertently collected data from a child, we will delete it immediately. If you believe we have collected information from a child, please contact us at privacy@cardora.com.
10. International Data Transfers
Cardora is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States. We rely on standard contractual clauses and other appropriate safeguards for cross-border transfers in compliance with applicable data protection laws, including the GDPR.
11. Third-Party Links
The Service may contain links to external websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies. This Privacy Policy applies solely to information collected by Cardora.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page and, for material changes, notify you via email or a prominent notice within the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Questions about your privacy?
We're happy to explain anything in plain language.
Contact Us at privacy@cardora.com