Privacy Policy
Last updated: 5 September 2026 · Beta
Who is responsible
KARD is operated by Criativatek (Pedro Alves). For any privacy matter, write to [email protected].
Two different roles
KARD has two kinds of people, and we handle each one's data differently:
- People who create cards (registered users) — here we are the controller.
- People who visit a card or book a meeting — that data belongs to the card owner, who is the controller; KARD stores it on their behalf, as a processor.
Accounts created by a reseller. If your KARD account was created by a partner (an agency, a print shop, whoever sold you the card), they can sign into your account to manage your KARDs — and while inside they see everything you see, including the contacts people leave through your form. Every entry is recorded with the date and time. What they cannot do, even inside the account: change your password, change your email, delete the account, or connect your Google calendar. You can ask us at any time to disconnect them — the account and the KARDs stay yours.
What we collect from people who create cards
- Account: name, email and password (stored as a hash — never in plain text).
- Card content: text, contacts, images and links you choose to publish. A published card is, by definition, public.
- Google Calendar connection (optional, for bookings): we store the email of the connected Google account and the encrypted access tokens, and use them only to check availability and create events. You can disconnect it at any time.
- Account origin: if you arrived through a campaign link (
utm_source,utm_medium,utm_campaign) or another site, we store that origin in the session and attach it to the account on sign-up. It's only used to know which campaigns bring accounts — it doesn't depend on you accepting the landing page's analytics. - Bug reports (account holders): if you report a problem, we store the description, a screenshot of what you see before sending, the URL, the browser and the last console messages. The report becomes an issue in a private GitHub repository, without your name or email. Resolved reports are deleted, along with the images, 90 days after resolution; unresolved ones are kept.
What we collect from people who visit a card
- Contact form: whatever the visitor writes (name, email and any fields the card owner has configured), the date, and the exact consent text they accepted. We also store a hash of the IP address with a secret key (never the plain IP) for abuse prevention.
- Bookings (when the card has that block): name, email, phone, message, date and time, and the same IP hash. This data is sent to the card owner's Google Calendar to create the event — it's Google that emails the invite to the person who booked. It's kept until the owner deletes it, just like contact-form entries.
- Visit counts: numbers aggregated by day, with no individual profile of who visits.
Analytics and cookies
The homepage (kard.pt) uses Google Analytics, but only after you click «Accept» on a
notice — without that response, the script never loads. If you accept, Google sets cookies
(_ga, _ga_*, ~2 years) to measure visits. Your choice is stored on your
phone or computer (not in a cookie); you can change it at any time via the «Cookies» link in the
page footer, which reopens the notice.
Published cards and the editor panel have no analytics at all — only the technical session cookie, needed for the service to work. Sending the IP of someone who taps a card to Google would be a GDPR problem in the card owner's name, not ours.
Content from other sites (embeds)
A card can show posts from Instagram, Facebook, YouTube or TikTok. That content only loads if you tap it — before that, none of your data (including your IP address) is sent to those platforms. Once you tap it, the privacy policy of the source site applies.
Abuse reports
If you report a profile, we store the reason, the text you write, your email (if you leave one — it's optional) and an IP hash with a secret key.
Account support
To resolve a problem you report, our administration may temporarily sign in to your account. Each sign-in is logged (who signed in, on which account, when) and, while it lasts, you see a banner at the top of the screen warning you. We never see your password.
What we use the data for
- Providing the service: showing cards, delivering contacts to the owner, booking meetings, sending service emails.
- Security: preventing abuse, phishing and spam (that's what the IP hash is for).
- Improving the product: understanding which campaigns bring accounts and fixing reported problems.
- Legal obligations, where they exist.
We do not sell data. We do not show advertising on cards or in the panel.
Who processes the data for us
The data is hosted on servers within the European Union, and backups are kept on a server of our own, also within the European Union. We use these processors:
- Hosting (server within the European Union).
- Cloudflare: all site traffic passes through its network before reaching us (United States, under standard contractual clauses).
- Google: analytics on the homepage, with your consent; and Google Calendar, for people using bookings (United States, standard contractual clauses).
- GitHub: bug reports become issues in a private repository, without the reporter's name or email (United States, standard contractual clauses).
- Email provider, for service messages.
All of them are bound by data processing agreements.
For how long
- Account and cards: for as long as the account exists. Deleting the account takes
the profiles offline immediately. The address (
kard.pt/your-name) stays reserved forever and never passes to another person — that's what stops an already-printed card or QR Code from opening a stranger's profile. To permanently delete cards, images and contacts, write to us: we do it within the legal deadline. - Contacts and bookings (leads): until the card owner deletes them — any data subject can ask the owner directly, or us, to remove their data.
- Bug reports: resolved ones are deleted, along with the images, 90 days after resolution.
Your rights
Under the GDPR, you have the right to access, rectification, erasure, restriction, portability and objection. To exercise them, write to [email protected]. You also have the right to lodge a complaint with the CNPD (cnpd.pt) or, if you live in another European Union country, with that country's data protection authority.
Changes
If this policy changes, we update this page and the date at the top. Significant changes are notified by email to account holders.
