Privacy Policy

Last updated

This policy explains what Cardless Club collects, why, how long it is kept, who it is shared with, and what you can ask us to do about it. It covers cardless.club, the pages hosted on it, the dashboard, and Cardless Reviews. It applies to three kinds of people: members who hold an account, visitors to a member's page, and customers of a business that uses Cardless Reviews. It is written to meet the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, and it forms part of our Terms of Service.

1. Who is responsible

Cardless Club, operated from India, is the data fiduciary for the information described in sections 2, 4, 6, and 7. For information a member collects through their own page or review location (section 3 and parts of section 5), the member is the data fiduciary and we process it on their instructions. Our contact for anything in this policy is [email protected].

2. Members: what we collect and why

2.1 Account

When you sign up, our sign-in provider collects your name, your email address, and, if you sign in with a third-party account such as Google, the identifier and profile picture that account shares. We use this to create and secure your account, to sign you in, to send you notices about the Service, and to answer you when you write to us. Signing in sets a session cookie on your browser; see section 8.

2.2 What you put on the Service

Your handle, display name, bio, location, pronouns, avatar, cover and preview images, links, text, embeds, contact details, theme choices, custom CSS, and anything else you add to a page or a review location. This is content you publish, and we store and display it because that is the Service. Some of it is public by design: whatever is on a published page can be seen by anyone with the link.

2.3 Settings that reach a third party

On plans that allow it, you can enter a Google Analytics measurement id or a Meta Pixel id. We store the id and render the corresponding tag on your live page. We do not receive anything those tags collect; section 5 says what that means for your visitors.

2.4 Cards

When you claim a card we record the card's code, the account it belongs to, the page it points to, and the private nickname you give it. The PIN is stored only as a hash and cannot be read back by anyone, including us.

2.5 Plans and payments

Payments are taken by our payment provider, currently Razorpay, on its own pages. We never receive your full card number, CVV, UPI credentials, or bank details. We receive and keep the provider's identifiers for the order, payment, and any subscription mandate, the amount, the currency, the plan bought, the status, and the date. We keep these because we must be able to prove what you paid for and because tax law requires it.

2.6 When you write to us or join a waiting list

The contact form and the "tell me when this is ready" buttons record what you asked about, your name if you give it, an email address or a phone number, and which page you pressed the button on. We use this to answer you and to tell you when the thing you asked about is available. Asking us to stop is recorded as a status rather than a deletion, so that pressing the same button again does not quietly re-subscribe you.

2.7 Importing from another service

If you ask us to bring your links over from Linktree, we fetch the public page at the address you give us, show you what we found, and copy only what you choose into your new page. We do not sign in to the other service and we do not keep the fetched page after the import.

2.8 Reviews alerts

If you set up alerts on a review location, we keep the email address or WhatsApp number you want them sent to and a record of each alert we sent, whether it was delivered, and, if it was not, why.

3. Members: information you collect through your page

If you switch on a contact form, an email capture, or a private feedback form, the details that visitors and customers submit are collected by you. We store them on your behalf, show them to you in the dashboard, and, on plans that include it, let you export them. We do not use them for any purpose of our own, we do not send messages to the people on your lists, and we do not share them with anyone except as you direct or the law requires. You are responsible for telling those people what you do with their details, for obtaining any consent the law requires, and for honouring their requests; section 10 explains how we help with that.

4. Visitors to a page: what we record

When someone opens a page on cardless.club, or follows a link from it, we count it so that the page's owner can see how many people came and what they clicked. For each visit or click we record:

  • the date and time;
  • how the visitor arrived, from a short fixed list (a card tap, a QR scan, a social network, an email, a direct visit), and any campaign tag the page's owner put in the link;
  • a coarse device class (phone, tablet, or computer) and, from the same request, the country it came from;
  • the site that sent them, if their browser told us;
  • which card was tapped, if it was one of the owner's cards.

We do not store IP addresses and we do not store browser user-agent strings. The country is derived from the request by our hosting provider and only the country name is written down. The device class is derived from the user-agent string and only the class is kept.

Two short-lived pieces of information exist to keep the counts honest and the Service up. First, a hashed, non-reversible mark of the visit, held for 30 minutes so that a refresh counts as one visit rather than two; it is not a cookie, it is not written to the visitor's browser, and it expires on its own. Second, a request budget keyed on the connecting address, held briefly in memory to stop loops and abuse. It is never written to a database, never joined to a page's analytics, and is gone within minutes. We cannot tell a page's owner who visited, and we cannot tell ourselves either.

Visitors leave no account with us and receive no cookies from us. Third-party content embedded on a page is a separate matter; see section 5.

5. Visitors to a page: third parties the owner chose

A page owner can embed content from other services (YouTube, Vimeo, Loom, Spotify, Apple Music, SoundCloud, Calendly, Google Forms). When a page containing such an embed loads, the visitor's browser connects to that service directly, and that service may set cookies and collect information under its own privacy policy. We do not control that collection and do not receive it.

On plans that include it, a page owner can also add their own Google Analytics or Meta Pixel tag to their page. Those tags send information about the visit to Google or Meta on the owner's behalf, under the owner's account with that provider, and the owner is responsible for any notice or consent that requires. We do not receive that information and the tag never renders in the editor preview.

6. Customers of a business using Cardless Reviews

When a customer taps or scans a review point, the page they see is served by us for the business. It uses no JavaScript, sets no cookies, and makes no third-party request. We record:

  • the rating chosen, which review point it came from, and the date and time, so the business can see how each printed point is doing;
  • whether the customer went on to Google, opened the feedback form, or left, as counts and not as identities;
  • if the customer writes private feedback, the message and, only if they choose to fill them in, their name, email address, phone number, and whether they asked to be contacted. Feedback can be sent without giving any of these, and nothing on the form requires identity.

Private feedback is a message to the business and belongs to it. It is kept for six months and then deleted automatically, whatever plan the business is on; the form says so before the customer types. The counts and ratings are kept as numbers after the words are gone. Where the business has switched on alerts, a low rating with a message is forwarded to the business by email or WhatsApp, which means it passes through the providers named in section 9.

The summaries a business sees of what its feedback is about are computed on our own servers from the words in the messages. No customer's message is sent to any outside service, including any artificial-intelligence service, to produce them.

The same collection rules as section 4 apply to the review page: no IP address and no user-agent string is stored, and a short-lived budget on the connecting address protects the page from abuse.

7. Google account data

A business that has been enabled for it may connect the Google Business Profile of its own listing so that the dashboard can count the reviews that were actually published. This is what that connection does and does not do:

  • It uses Google sign-in with the Google Business Profile permission, and it reads the listing's published reviews and their ratings. It reads nothing else from the Google account.
  • It is read-only. We never post, reply to, edit, or delete reviews, posts, or any other content on Google.
  • The token that keeps the connection alive is encrypted before it is stored and is used only to refresh that one listing's reviews.
  • Reviews read from Google are shown to the business that connected them and used to compute the counts in its own dashboard. They are not used for advertising, not sold, not shared with any other business, and not used to train any model.
  • The business can disconnect at any time from its dashboard, or by removing Cardless Club from its Google account permissions. When it does, we stop reading and delete the stored token.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

8. Cookies and similar technologies

We set cookies only to sign members in and keep them signed in. These are set by our sign-in provider, are strictly necessary for the dashboard to work, and are not used to track you across other sites. Public pages and review pages set no cookies of ours. We run no advertising cookies, no cross-site trackers, and no cookie of our own on any page a visitor sees. When you pay, our payment provider's checkout sets its own cookies on its own pages, under its own policy. Because we use only strictly necessary cookies, we do not show a cookie banner.

9. Who we share information with

We do not sell personal information, and we do not share it with anyone for their own marketing. We share it only with the providers we need to run the Service, each of which is bound to process it only for us, and with authorities where the law requires. Today those providers are:

  • Clerk: sign-in and account management (name, email, sign-in identifiers, session cookies).
  • Cloudflare: hosting for our API, the database in which everything in this policy is stored, image storage, caching, network protection, and the country lookup in section 4.
  • Vercel: hosting for the website and dashboard.
  • Razorpay: payments and subscription mandates.
  • Resend: sending email, including Reviews alerts, from our own domain.
  • Meta (WhatsApp Cloud API): sending Reviews alerts to a WhatsApp number the business has asked for.
  • Google: only where a business has connected its Google Business Profile (section 7), or a member has added a Google Analytics tag to their own page (section 5).
  • Sentry: error monitoring. When something breaks, the report can include the address of the page, the browser, and the request that failed, so that we can fix it. Reports are kept briefly and are not joined to page analytics.
  • Shopify: cards are sold through a separate store. What you give that store when you order is covered by its own privacy policy, not by this one.

We may also disclose information where we believe in good faith that doing so is required by law or a valid legal order, is needed to protect the rights, safety, or property of a person, of the public, or of Cardless Club, or is needed to investigate fraud or abuse of the Service. If Cardless Club is sold, merges, or transfers its business, your information may transfer to the successor, who will be bound by this policy; we will tell you before that happens.

10. Where information is stored, and for how long

Our providers operate globally, and information in this policy may be stored or processed on their infrastructure outside India. Each provider is contractually bound to protect it, and we transfer only to countries not restricted by the Government of India under the Digital Personal Data Protection Act, 2023.

How long we keep things:

  • Account and page content: for as long as your account exists. Deleting a page deletes its content, images, leads, and analytics; deleting your account (section 11) deletes everything else.
  • Page analytics: 30 days on the free plan, 365 days on Club+, and for the life of the page on Pro. Older rows are deleted nightly against the plan you last paid for, so a lapse never deletes the history you paid to keep.
  • Review counts and ratings: for the life of the review location, as daily totals.
  • Private feedback: 180 days from the day it was written, then deleted automatically on every plan.
  • Leads and email sign-ups: until the page owner deletes the page, deletes the entry, or asks us to remove it, or until you ask us under section 11.
  • Payment records: for as long as Indian tax and accounting law requires after the transaction, currently eight years.
  • Contact and waiting-list entries: until we have answered you and the thing you asked about has shipped, or until you ask us to stop, in which case we keep only the fact that you asked us to stop.
  • Alert delivery records: for the life of the review location they belong to, so that a disputed delivery can be traced.
  • Operator audit records: for as long as we run the Service. They record which member of our staff did what to which account, and an audit trail that can be trimmed is not one.
  • Error reports and infrastructure logs: for the short period our providers keep them, typically under 90 days.

We may keep information longer where the law requires it, where it is needed to resolve a dispute or enforce our terms, or where a court or authority has asked us to preserve it.

11. Your rights and how to use them

Whether you are a member, a visitor, or a customer of a business, you can ask us:

  • what personal information we hold about you, and for a copy;
  • to correct or complete it;
  • to delete it, including closing your account and everything in it;
  • to withdraw a consent you gave, from that point on, without losing anything you are entitled to;
  • to nominate a person who can exercise these rights for you if you cannot;
  • to stop sending you messages you did not need to receive, at any time.

Write to [email protected] from the address on your account, or with enough detail for us to find your information and to confirm it is you. We answer within 30 days. Members can unpublish or delete a page themselves from the dashboard; closing the account itself is done by writing to us, and we complete it within 30 days of confirming the request, apart from the payment records section 10 requires us to keep.

If your information was collected by a member through their page or review location, you can write to them directly or to us. Where it reaches us, we remove what you ask us to from our systems, tell the member we have done so, and pass your request to them for anything they have exported.

If you are not satisfied with our answer, you can escalate through our grievance channel (section 14) and, after that, to the Data Protection Board of India.

12. Children

The Service is not directed at children. A person under 18 may not open an account except through a parent or legal guardian who has agreed to our terms and consented on their behalf. We do not knowingly collect personal information from a child, do not track children or show them targeted advertising, and will delete any such information we learn we hold. If you believe a child has given us information, write to [email protected].

13. Security

We protect information with measures appropriate to what it is: all traffic is encrypted in transit; card PINs are stored only as hashes; the token behind a Google connection is encrypted at rest; access to member data by our own staff is limited to what a task needs and every operator action is recorded in an audit log that cannot be edited; anything that decides who may see or change data denies access when it cannot be sure, and public endpoints carry abuse limits. No system is perfectly secure, and if a breach affects your personal information we will notify you and the authorities as the law requires and tell you what we know and what you can do.

14. Grievance officer and complaints

To raise a grievance about how your information has been handled, write to [email protected] with the subject "Grievance" and tell us what happened and what you would like us to do. We acknowledge every grievance within 24 hours and resolve it, or explain why we cannot, within 15 days. This channel serves as our grievance mechanism under the Information Technology Act, 2000, the rules under it, and the Digital Personal Data Protection Act, 2023.

15. Changes to this policy

When we change this policy we update the date at the top of this page. If a change materially affects how your information is used or shared, we tell members by email or in the dashboard before it takes effect, and, where the law requires it, ask again for your consent. Older versions are available on request.

16. Contact

Questions about this policy go to [email protected], or through the contact page.