Privacy Policy

Last updated: April 2026

1. Data Controller

Card Calendar Ltd (company number placeholder) is the data controller responsible for your personal data. Our registered address is placeholder. You can contact us at [email protected].

2. What Data We Collect

We collect and process the following categories of personal data:

  • Account information: name, email address, and optional phone number.
  • Contact data: names, birthdays, and addresses of people you add or import (read-only) from Google or Apple contacts.
  • Addresses: postal addresses for card delivery purposes.
  • Handwriting data: style embeddings derived from handwriting samples you provide. Original images are not retained after processing.
  • Payment information: processed securely by Stripe. We do not store card numbers or full payment details.
  • Card preferences: occasion types, design preferences, and message history.
  • Usage data: how you interact with our service, including pages visited and features used.

3. Legal Basis for Processing

We process your personal data under the following legal bases as defined in the UK GDPR:

  • Consent: for importing contacts from Google or Apple and for optional analytics cookies. You may withdraw consent at any time.
  • Legitimate interest: for service delivery, personalisation of card recommendations, and fraud prevention.
  • Contract: for processing your subscription, managing your account, and fulfilling card orders.

4. How We Use Your Data

  • Personalise card selection and recommendations.
  • Generate and manage occasions (birthdays, anniversaries, and other events).
  • Process card orders, printing, and postal delivery.
  • Send notifications about upcoming occasions, order status, and service updates.
  • Improve our service through aggregated, anonymised analytics.

5. Contact Data

When you import contacts from Google or Apple, we access your contact list in read-only mode. We store names, birthdays, and addresses solely for the purpose of generating card occasions. You can delete any imported contact at any time from your account. We do not share your contact data with third parties for marketing or any other purpose beyond card fulfilment.

6. Handwriting Data

When you provide handwriting samples, we generate style embeddings that capture the characteristics of your handwriting. These embeddings are stored to reproduce your handwriting style on cards. The original images you upload are processed in real-time and are not retained after the embedding has been generated.

7. Payment Processing

All payment processing is handled by Stripe. We do not store your credit or debit card numbers. We retain only a Stripe customer identifier and subscription identifier to manage your account. Please refer to Stripe's Privacy Policy for details on how they handle your payment data.

8. Third-Party Processors

We use the following third-party processors to deliver our service:

  • Stripe — payment processing.
  • Prodigi — card printing and fulfilment.
  • Twilio — SMS and WhatsApp notifications.
  • AWS SES — transactional email delivery.
  • Supabase — database hosting and authentication.

Each processor is bound by data processing agreements and processes data only on our instructions.

9. Data Retention

We retain your account data for as long as your account is active. If you delete your account, all personal data will be permanently removed within 30 days. Anonymised, aggregated data may be retained indefinitely for analytics purposes.

10. Your Rights

Under the UK GDPR, you have the following rights:

  • Right of access: request a copy of your personal data via our data export feature.
  • Right to rectification: update or correct your data through your account settings.
  • Right to erasure: delete your account and all associated data at any time.
  • Right to data portability: export your data in a machine-readable format.
  • Right to object: object to processing based on legitimate interest.
  • Right to withdraw consent: withdraw consent for contact imports or analytics at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

11. Cookies

We use essential cookies only for authentication session management. These are strictly necessary for the service to function and do not require consent. We may also use optional analytics cookies to understand how our service is used. Analytics cookies are only set with your explicit consent, which you can manage via our cookie consent banner.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by email or through a notice on our website. We encourage you to review this page periodically.

13. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us at [email protected].

Card Calendar