Legal
Privacy policy
Last updated 12 February 2026
Who we are
Cardline provides digital business cards for teams. This policy covers the marketing site (gocardline.com), the product, and the public card pages we host under /c/.
What we collect on this website
Page views, referrer, approximate country, and device type — aggregated, and derived from a hashed request signature that is discarded daily. We do not set analytics cookies, do not build a profile across visits, and cannot single you out of the aggregate. That is why you did not see a consent banner: there is nothing here that requires one.
If you submit the contact or partner form, we receive the fields you typed plus a timestamp, and we keep the message for as long as needed to answer it and to keep a record of the conversation.
What we collect in the product
- Account data — name, work email, and organization, used to authenticate you and to bill the organization.
- Card content — whatever your organization chooses to publish on a card. Public cards are, by design, publicly readable.
- Usage events — card views, saves, and QR scans, shown to admins as counts. These are not linked to identified recipients.
Controller and processor
For account data we are the controller. For the card content your organization uploads and the contacts it collects, your organization is the controller and Cardline is the processor acting on its instructions. Our Data Processing Addendum sets out those obligations and forms part of the contract.
Legal bases
Contract performance for running the service and billing; legitimate interests for aggregate analytics, security, and abuse prevention; consent where we ask for it explicitly, such as product emails you opt into; and legal obligation for tax and accounting records.
Retention
- Aggregate analytics: 25 months, with the daily request signature discarded within 24 hours.
- Form submissions: 24 months from the last reply.
- Account and card data: for the life of the subscription, then 30 days before deletion.
- Invoices and tax records: as long as tax law requires, typically seven years.
Sharing
We use a small set of subprocessors — hosting, transactional email, and payment processing — each under a data-processing agreement. We do not sell personal data, and we do not share it with advertising networks.
International transfers
Where a subprocessor operates outside your region, transfers rely on Standard Contractual Clauses or an equivalent approved mechanism. EU-hosted data residency is available on the Business plan.
Your rights
Depending on where you live, you can request access, correction, deletion, portability, restriction, or objection, and you can withdraw consent where we relied on it. Admins can self-serve export and deletion from the admin. Otherwise email us and we will respond within 30 days. If you are in the EU or UK you may also complain to your local supervisory authority.
Security
Encryption in transit and at rest, role-based access, audited admin actions, and least-privilege internal access. Our security page describes the controls in more detail.
Changes
If we change this policy in a way that materially affects you, we will email account admins and update the date above before the change takes effect.
Questions a lawyer needs answered?
Email legal@gocardline.com and you will get a person, not a ticket number.