Card Event

Privacy Policy

Last updated 7 September 2026

What we collect

If you create a card: your email address, and a name and avatar if you sign in with Google. Your payment details go to Stripe, not to us; we keep only a customer reference and a record of what was paid.

If you contribute to a card: the name you type, the message or media you upload, and optionally your email address if you provide one. You do not need an account, and we do not create one for you.

If you open a delivered card: nothing that identifies you.

Why we collect it

To run the card: to show your message to the recipient, to let the organizer moderate it, to take payment, and to email the organizer when their card is ready. We do not sell anything and we do not use your content to train models.

Who else sees it

A contribution is visible to the card's organizer and, once delivered, to anyone the organizer sends the link to. Behind the scenes we use Supabase (database and sign-in), Amazon S3 and CloudFront (storing and serving uploads), Stripe (payments), Resend (email) and PostHog (anonymous product analytics). Each sees only what it needs.

How long we keep it

Delivered cards are kept so the recipient can reopen them. Unpaid cards and everything uploaded to them are deleted 90 days after their reveal date, or after creation when none was set.

Your rights

You can ask for a copy of your data or its deletion at any time. If you contributed to someone else's card and want your message removed, ask the organizer, or contact us and we will remove it.

Cookies

We set a cookie to keep you signed in and one to remember your language. Contributors get a token stored in their own browser so they can add a second message without retyping their name. No advertising cookies.

Contact

Questions about any of this: privacy@cardevent.app