CardPrime is operated by CardPrime Korlátolt Felelősségű Társaság ("CardPrime", "we", "us"), the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).
Contact: info@cardprime.io
| Data | When | Purpose |
|---|---|---|
| Email address | Account registration (Cognito) | Login, account identification |
| Display name | Account registration (optional) | Personalizing your profile |
| Password | Account registration | Authentication (stored only as a salted hash by AWS Cognito — CardPrime never sees or stores your plaintext password) |
| Card records you add | Every time you add a card (photo + manual details) | Building your collection |
| Approximate location (coarse, rounded to ~1.1 km) | Only at the moment you save a card you've added | Fraud detection — flagging implausible location patterns (e.g. the same card added in two distant cities minutes apart) |
| Login timestamps | Every sign-in | Security monitoring |
We do not collect precise/continuous location, contacts, photos outside the card-entry flow, or any advertising identifiers. We do not use analytics or crash-reporting SDKs (no Firebase, Sentry, Amplitude, Mixpanel, or similar).
Performance of a contract — account creation, authentication, and collection management are necessary to provide the service you request.
Legitimate interest — approximate location capture when you add a card, and the resulting fraud/geo-velocity checks, protect the integrity of the card catalog and other users, and are limited to the minimum precision needed for that purpose.
Your data is processed only by our infrastructure provider, Amazon Web Services (AWS), in the following services: Cognito (authentication), DynamoDB (database), S3 (card images), Lambda/API Gateway (application logic). We do not sell, rent, or share your data with advertisers, data brokers, or any other third party.
All data is stored and processed in AWS's eu-north-1 (Stockholm, Sweden) region, within the European Union. We do not transfer your personal data outside the EU/EEA.
We retain your data for as long as your account remains active. If you request deletion, your account and all associated data are erased automatically — not through a manual, delayed process.
Under GDPR, you have the right to:
For any other request, or if you cannot access the app, email info@cardprime.io.
When you add a card, we run an automated check comparing the location and timing against the card's history (the "geo-velocity check"). This may generate an in-app notification if the pattern looks physically implausible. This check only produces an alert — it does not automatically suspend, restrict, or take any legal or similarly significant action against your account.
CardPrime is not directed at children under 16. We do not knowingly collect data from children under this age.
If we materially change what data we collect or how we use it, we will update this policy and notify you in the app.
CardPrime Korlátolt Felelősségű Társaság
Email: info@cardprime.io