Cardography

Privacy Policy

Controller: Cardography
Contact: contact@cardography.co.uk

Collection-data promise: private by default, export whenever needed, your collection remains yours, and personal collection data is not sold. Read the plain-English promise.

Data We Collect

Why We Use It

We use data to provide login, membership access, billing status, collection tools, support, security, backups, legal compliance, rights-holder/takedown handling, product analytics, and service improvement. Cardography does not sell personal collection lists, wanted lists, private notes, or behavioural profiles.

Marketing

Marketing emails are only sent where you have opted in or where UK rules allow it. Service emails such as magic links, trial status, payment issues, and account notices are separate from marketing.

Processors

Stripe processes payments and billing. Brevo processes outbound Cardography email, including magic links, service notices, and opted-in collector digests. Hosting infrastructure stores the application data.

Retention and Deletion

Account and collection data is kept while your account exists. A confirmed Account-page deletion removes live account and collection records immediately; residual snapshot copies age out within 30 days. Limited billing, fraud-prevention, security, or legal records may be retained only where required. Operational logs are kept only as long as needed for security, support, and legal records. Aggregate analytics are kept for up to 120 days.

Your Rights

You can ask for access, correction, deletion, restriction, portability, or objection where UK GDPR gives those rights. Every signed-in user can export their collection as CSV. You can also complain to the ICO.