Privacy Policy
Controller: Cardography
Contact: contact@cardography.co.uk
Data We Collect
- Email address, username, account status, login timestamps, and magic-link/session records.
- Collection data you save, including owned/wanted cards, quantities, condition, grade, notes, imports, exports, and saved views.
- Stripe customer, checkout, subscription, and payment-status identifiers. Full card details are handled by Stripe, not Cardography.
- Aggregate first-party website analytics, including page views, search terms, referrer domains, usage events, bot counts, and daily visitor counts based on short hashes from IP and browser data. Raw IP addresses are not saved in the analytics file.
- Operational logs for emails, imports, image sync, value sync, backups, and security.
Why We Use It
We use data to provide login, membership access, billing status, collection tools, support, security, backups, legal compliance, rights-holder/takedown handling, product analytics, and service improvement. Cardography does not sell personal collection lists, wanted lists, private notes, or behavioural profiles.
Marketing
Marketing emails are only sent where you have opted in or where UK rules allow it. Service emails such as magic links, trial status, payment issues, and account notices are separate from marketing.
Processors
Stripe processes payments and billing. Brevo processes outbound Cardography email, including magic links, service notices, and opted-in collector digests. Hosting infrastructure stores the application data.
Retention and Deletion
Account and collection data is kept while your account exists. A confirmed Account-page deletion removes live account and collection records immediately; residual snapshot copies age out within 30 days. Limited billing, fraud-prevention, security, or legal records may be retained only where required. Operational logs are kept only as long as needed for security, support, and legal records. Aggregate analytics are kept for up to 120 days.
Your Rights
You can ask for access, correction, deletion, restriction, portability, or objection where UK GDPR gives those rights. Every signed-in user can export their collection as CSV. You can also complain to the ICO.