KARD ← kard.pt

Privacy Policy

Last updated: 5 September 2026 · Beta

Who is responsible

KARD is operated by Criativatek (Pedro Alves). For any privacy matter, write to [email protected].

Two different roles

KARD has two kinds of people, and we handle each one's data differently:

Accounts created by a reseller. If your KARD account was created by a partner (an agency, a print shop, whoever sold you the card), they can sign into your account to manage your KARDs — and while inside they see everything you see, including the contacts people leave through your form. Every entry is recorded with the date and time. What they cannot do, even inside the account: change your password, change your email, delete the account, or connect your Google calendar. You can ask us at any time to disconnect them — the account and the KARDs stay yours.

What we collect from people who create cards

What we collect from people who visit a card

Analytics and cookies

The homepage (kard.pt) uses Google Analytics, but only after you click «Accept» on a notice — without that response, the script never loads. If you accept, Google sets cookies (_ga, _ga_*, ~2 years) to measure visits. Your choice is stored on your phone or computer (not in a cookie); you can change it at any time via the «Cookies» link in the page footer, which reopens the notice.

Published cards and the editor panel have no analytics at all — only the technical session cookie, needed for the service to work. Sending the IP of someone who taps a card to Google would be a GDPR problem in the card owner's name, not ours.

Content from other sites (embeds)

A card can show posts from Instagram, Facebook, YouTube or TikTok. That content only loads if you tap it — before that, none of your data (including your IP address) is sent to those platforms. Once you tap it, the privacy policy of the source site applies.

Abuse reports

If you report a profile, we store the reason, the text you write, your email (if you leave one — it's optional) and an IP hash with a secret key.

Account support

To resolve a problem you report, our administration may temporarily sign in to your account. Each sign-in is logged (who signed in, on which account, when) and, while it lasts, you see a banner at the top of the screen warning you. We never see your password.

What we use the data for

We do not sell data. We do not show advertising on cards or in the panel.

Who processes the data for us

The data is hosted on servers within the European Union, and backups are kept on a server of our own, also within the European Union. We use these processors:

All of them are bound by data processing agreements.

For how long

Your rights

Under the GDPR, you have the right to access, rectification, erasure, restriction, portability and objection. To exercise them, write to [email protected]. You also have the right to lodge a complaint with the CNPD (cnpd.pt) or, if you live in another European Union country, with that country's data protection authority.

Changes

If this policy changes, we update this page and the date at the top. Significant changes are notified by email to account holders.