Privacy Policy
Last updated: September 2026
This policy explains what CardControl does with personal data — yours, as a business using the platform, and your customers’, which you entrust to us when you create cards.
1. Who is responsible for the data
CardControl is the controller for your business account data. For your customers’ data, your business is the controller and CardControl acts as processor: we handle that data only to provide the service and on your instructions.
2. What data is collected
From the business: name, email, hashed password, company details and billing history. From your customers: a name and at least one contact (email or mobile), the programme they are enrolled in, and their stamp and redemption history. We collect no payment data from your customers and no special categories of data.
3. What it is used for
To issue and display cards, send the customer the link to their own card, notify them when a card is complete if they asked for it, produce the statistics on your dashboard, and bill your subscription. We do not sell data and we do not use it for advertising.
4. Legal basis
Performance of the contract, for everything the service needs to function; legitimate interest, for security and abuse prevention; and consent, for the messages a customer can switch on and off from their own card page.
5. Who else touches the data
Supabase, which hosts the database and authentication in the European Union; Cloudflare, which serves the application; Stripe, which processes subscription payments; and Resend, which delivers transactional email. Each handles only the minimum its role requires.
6. For how long
For as long as the account is active. When an account is closed, card and customer data is deleted within 30 days, except billing records, which law requires us to keep for ten years.
7. Your rights
Access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority. Your customers exercise these rights with you; for your own account data, write to suporte@cardcontrol.pt
8. Cookies and local storage
Only what is essential: your signed-in session and your chosen language, kept in your browser. We use no advertising, tracking or third-party cookies, which is why there is no consent banner.
9. International transfers
Data is hosted in the European Union. Where a processor handles data outside the European Economic Area, it does so under the standard contractual clauses approved by the European Commission.
10. Changes to this policy
If this policy changes materially, we will tell you by email before the change takes effect. The date at the top of the page always names the version in force.