1. Who we are
Cardliv is operated from the Netherlands. For any privacy-related question you can reach us at privacy@cardliv.com. We act as the data controller for the personal information described in this policy.
2. Personal information we collect
We only collect data that we need to provide the service:
- Account information — name, email address, password (hashed), preferred language, country and timezone.
- Payment information — handled entirely by Stripe. We never see or store your card number, CVC or bank details; we only receive a customer ID and subscription status.
- Card & collection data — the cards, folders, storage units, sales, shows, breaks and notes you create in Cardliv.
- AI scan uploads — the photos you submit for AI recognition, plus the derived crops, metadata and estimated values.
- Usage & device data — IP address, browser, operating system and pages viewed, collected only if you accept analytics cookies.
- Support communications — the messages you send us and our responses.
3. Payment information (Stripe)
Subscriptions and one-time payments are processed by Stripe Payments Europe, Ltd. Stripe is PCI-DSS Level 1 certified. Card details are entered on Stripe-hosted forms and never touch our servers.
4. AI scan uploads and images
Photos you upload for AI recognition are stored in your private account storage and processed by our AI providers to identify the card, extract metadata and estimate market value. Images are not used to train third-party AI models. You can delete any image at any time; deletions are permanent after 30 days in the Trash Bin.
5. Cookies
We use a small number of cookies to keep you signed in, remember your preferences and (with your consent) measure anonymous usage with Google Analytics 4. Full details are in our Cookie Policy.
6. Google Analytics 4
When you accept analytics cookies, Cardliv loads Google Analytics 4 with IP anonymisation, no advertising features and Google Consent Mode v2. GA4 helps us understand which features are used so we can improve the product. You can withdraw consent at any time.
7. Legal basis for processing
- Contract — to provide the Cardliv service you sign up for.
- Legitimate interests — to secure the platform, prevent fraud and improve the product.
- Consent — for analytics cookies and optional marketing emails.
- Legal obligation — to keep invoices and tax records.
8. How we store and protect your data
Data is stored in encrypted databases inside the EU on infrastructure provided by Supabase (hosted on AWS eu-west). All connections use TLS 1.2+. Passwords are hashed with bcrypt. Access to production data is restricted to a small number of Cardliv staff, protected by two-factor authentication and logged.
9. Third-party services
We rely on a short list of processors, each bound by a data-processing agreement:
- Supabase — database, authentication and file storage (EU).
- Stripe — payments, invoices and subscription management (EU/US).
- Google Analytics 4 — anonymous usage analytics (with your consent).
- OpenAI & other AI providers — card recognition and metadata extraction on your uploaded images.
- Cloudflare — content delivery, DDoS protection and edge compute.
- Postmark / Resend — transactional email (sign-up, password reset, receipts).
10. International data transfers
Some of our processors (Stripe, Google, OpenAI, Cloudflare) may process data outside the EEA. When this happens the transfer is protected by the European Commission's Standard Contractual Clauses and, where available, the EU-US Data Privacy Framework.
11. Data retention
- Account data — kept for as long as your account is active. Deleted within 30 days after you close your account.
- Card, collection and image data — kept while your account is active. Items in the Trash Bin are permanently deleted after 30 days.
- Invoices and tax records — kept for 7 years to comply with Dutch tax law.
- Analytics events — anonymised and retained for up to 14 months in Google Analytics.
- Support emails — kept for up to 2 years.
12. Your rights under the GDPR
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data (“right to be forgotten”).
- Restrict or object to certain processing.
- Export your data in a portable format.
- Withdraw consent for analytics or marketing at any time.
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise any of these rights, email privacy@cardliv.com. We respond within 30 days.
13. Children's privacy
Cardliv is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, please contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by email or a notice inside the app at least 14 days before they take effect. The “Last updated” date at the top of the page always reflects the current version.
15. Contact
Questions? Email privacy@cardliv.com or write to Cardliv, Amsterdam, The Netherlands.