Skip to content
Cardline

Legal

Privacy policy

Last updated 12 February 2026

Who we are

Cardline provides digital business cards for teams. This policy covers the marketing site (gocardline.com), the product, and the public card pages we host under /c/.

What we collect on this website

Page views, referrer, approximate country, and device type — aggregated, and derived from a hashed request signature that is discarded daily. We do not set analytics cookies, do not build a profile across visits, and cannot single you out of the aggregate. That is why you did not see a consent banner: there is nothing here that requires one.

If you submit the contact or partner form, we receive the fields you typed plus a timestamp, and we keep the message for as long as needed to answer it and to keep a record of the conversation.

What we collect in the product

  • Account data — name, work email, and organization, used to authenticate you and to bill the organization.
  • Card content — whatever your organization chooses to publish on a card. Public cards are, by design, publicly readable.
  • Usage events — card views, saves, and QR scans, shown to admins as counts. These are not linked to identified recipients.

Controller and processor

For account data we are the controller. For the card content your organization uploads and the contacts it collects, your organization is the controller and Cardline is the processor acting on its instructions. Our Data Processing Addendum sets out those obligations and forms part of the contract.

Legal bases

Contract performance for running the service and billing; legitimate interests for aggregate analytics, security, and abuse prevention; consent where we ask for it explicitly, such as product emails you opt into; and legal obligation for tax and accounting records.

Retention

  • Aggregate analytics: 25 months, with the daily request signature discarded within 24 hours.
  • Form submissions: 24 months from the last reply.
  • Account and card data: for the life of the subscription, then 30 days before deletion.
  • Invoices and tax records: as long as tax law requires, typically seven years.

Sharing

We use a small set of subprocessors — hosting, transactional email, and payment processing — each under a data-processing agreement. We do not sell personal data, and we do not share it with advertising networks.

International transfers

Where a subprocessor operates outside your region, transfers rely on Standard Contractual Clauses or an equivalent approved mechanism. EU-hosted data residency is available on the Business plan.

Your rights

Depending on where you live, you can request access, correction, deletion, portability, restriction, or objection, and you can withdraw consent where we relied on it. Admins can self-serve export and deletion from the admin. Otherwise email us and we will respond within 30 days. If you are in the EU or UK you may also complain to your local supervisory authority.

Security

Encryption in transit and at rest, role-based access, audited admin actions, and least-privilege internal access. Our security page describes the controls in more detail.

Changes

If we change this policy in a way that materially affects you, we will email account admins and update the date above before the change takes effect.

Questions a lawyer needs answered?

Email legal@gocardline.com and you will get a person, not a ticket number.