Privacy Policy

1. Who we are (Controller)

The controller of your personal data in connection with the service cardcanfly.com is Katarzyna Liaszkewicz, correspondence address: [email protected], email: [email protected] (the “Controller”, “we”, “us”). We operate from Poland and process data in accordance with GDPR/RODO.

We have not appointed a Data Protection Officer. For any privacy questions please contact us at the email above.

2. What data we process

  • Account & order data: email, first and last name, delivery/return address, order details.
  • Personalisation content: images, text and other materials you upload to generate your personalised card (including e-card).
  • Recipient data for e-cards: email address of the recipient that you provide so we can send an e-card on your behalf.
  • Communication data: messages sent to us (email/support), your preferences.
  • Technical data: strictly necessary cookies and similar technologies (see Section 7), device/browser information, IP, server and authentication logs, and security signals/tokens from anti-abuse tools such as reCAPTCHA.

Payment cards: we do not store your full card details. Card processing is performed by Stripe.

Special categories: we do not request special categories of personal data (Art. 9 GDPR). Please do not upload content revealing sensitive data (e.g., health, religion). If you choose to include such data (e.g., in photos), you confirm you have a proper legal basis (e.g., explicit consent of data subjects). We process such data, if present, only to fulfil your order and delete it according to the retention periods.

3. Purposes and legal bases

  • Create and fulfil your orders (including personalised printing and e-card delivery) — Art. 6(1)(b) GDPR (contract).
  • Handle complaints and legal/accounting obligations — Art. 6(1)(c) GDPR (legal obligation).
  • Security and service maintenance (incl. strictly necessary cookies, logs, fraud prevention) — Art. 6(1)(f) GDPR (legitimate interests).
  • Direct marketing (e.g., newsletters, promo codes) — Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time.

E-card recipients’ data: for one-time delivery of e-cards to recipients whose email you provide, we rely on legitimate interests (Art. 6(1)(f) GDPR): delivering the card on your request. Recipients may object to processing or request deletion by contacting us at [email protected]. We do not use recipient data for marketing and keep it only as long as needed to deliver the e-card and handle delivery issues.

4. Children

Our service is intended for users 16+. If you are under 16, you may use the service only with verifiable consent of a parent/guardian.

5. Data recipients

We share data only when necessary and under appropriate safeguards:

  • Payment processing: Stripe — independent controller for payment data. We receive only limited payment status information.
  • Postal and courier services: to deliver physical cards (name, address, contact).
  • Hosting and IT providers: to operate and secure our website and storage.
  • Email and messaging providers: to send order updates and e-cards.
  • Security and authentication providers: Google reCAPTCHA and Google Identity Services, used for bot protection, fraud prevention, and Google sign-in. These providers may process technical data such as IP address, browser/device information, and interaction or security signals under their own privacy policies.
  • Third-party embeds (on user action): e.g., Spotify iframe player. We load such embeds only after you actively choose to use the feature (e.g., click “Play”). These providers may set their own cookies — see Section 7.
  • Public authorities when required by law.

6. International transfers

Some providers (e.g., Stripe, Google/reCAPTCHA, Google Identity Services, email/CDN) may transfer data outside the EEA. In such cases we rely on GDPR-compliant safeguards such as Standard Contractual Clauses (SCCs) and additional measures, where required.

7. Cookies (essential + optional analytics)

We always use strictly necessary cookies required to provide the Service (e.g., session/authentication, security, load balancing, Google sign-in and CSRF protection, reCAPTCHA security checks, remembering essential preferences such as language). In addition, we may use optional Google Analytics cookies to understand traffic and improve the Service, but only when you provide consent where required by law.

For signed-in users, the authentication refresh token is stored in a strictly necessary, server-set HttpOnly cookie. The short-lived access token is held only in browser memory while the application is open and is not stored in local storage or cookies. To synchronize logout between open tabs, we store a logout-event timestamp in local browser storage; it contains no authentication token.

Where required by applicable law, we display a cookie banner that lets you accept or reject analytics cookies. Essential cookies remain active because they are necessary for core functionality. You can also manage or delete cookies via your browser settings.

Third-party embeds (e.g., Spotify) are loaded only after your explicit interaction (e.g., clicking “Play”). When activated, the provider may set its own cookies solely to deliver that embedded functionality, under its own privacy policy. See our Cookie Policy for details about essential and optional analytics cookies.

8. Server & authentication logs

For security, we log access and authentication events (timestamps, IP, user agent, success/failure, lockouts) to detect abuse, protect accounts from brute-force attacks and investigate incidents.

Authentication logs are retained for a maximum of 90 days and are not shared with third parties except when required by law or for security investigations.

9. Data retention

  • Account & order data: for the duration of your account and then for legal limitation periods (e.g., accounting/tax).
  • Personalisation media (uploads): e-cards — up to 30 days after sending; physical cards — up to 90 days after delivery; or earlier on your request where feasible.
  • Marketing data (consent): until you withdraw consent.
  • Technical logs: as per Section 8.

Please note that technical backups may retain deleted data for a limited period with restricted access, after which backup copies are overwritten.

10. Your rights

You have the right to access, rectify, erase, restrict, object (where processing is based on legitimate interests), and to data portability (for data processed under consent/contract).

You can withdraw consent at any time (e.g., for marketing) without affecting the lawfulness of processing before withdrawal. To exercise your rights, contact us at [email protected]. We may need to verify your identity.

You also have the right to lodge a complaint with the Polish supervisory authority: President of the Personal Data Protection Office (Prezes UODO).

11. How we secure your data

We use industry-standard measures such as encryption in transit, access controls, backups, rate-limiting and regular updates to protect your data.

12. Third-party links and embeds

Our site may include links, embeds, or third-party security/authentication tools (e.g., Spotify, Google sign-in, reCAPTCHA). Their processing is governed by their own privacy policies. We do not control third-party processing.

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced on the site and/or via email. The effective date is shown at the top. Your continued use after changes means you have read the updated Policy.

14. Contact

Last updated: 25/05/2026