Privacy Policy

Last updated: July 24, 2026

1. Who we are

CardPrime is operated by CardPrime Korlátolt Felelősségű Társaság ("CardPrime", "we", "us"), the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).

Contact: info@cardprime.io

2. What data we collect

DataWhenPurpose
Email addressAccount registration (Cognito)Login, account identification
Display nameAccount registration (optional)Personalizing your profile
PasswordAccount registrationAuthentication (stored only as a salted hash by AWS Cognito — CardPrime never sees or stores your plaintext password)
Card records you addEvery time you add a card (photo + manual details)Building your collection
Approximate location (coarse, rounded to ~1.1 km)Only at the moment you save a card you've addedFraud detection — flagging implausible location patterns (e.g. the same card added in two distant cities minutes apart)
Login timestampsEvery sign-inSecurity monitoring

We do not collect precise/continuous location, contacts, photos outside the card-entry flow, or any advertising identifiers. We do not use analytics or crash-reporting SDKs (no Firebase, Sentry, Amplitude, Mixpanel, or similar).

3. Legal basis for processing

Performance of a contract — account creation, authentication, and collection management are necessary to provide the service you request.

Legitimate interest — approximate location capture when you add a card, and the resulting fraud/geo-velocity checks, protect the integrity of the card catalog and other users, and are limited to the minimum precision needed for that purpose.

4. Who we share data with

Your data is processed only by our infrastructure provider, Amazon Web Services (AWS), in the following services: Cognito (authentication), DynamoDB (database), S3 (card images), Lambda/API Gateway (application logic). We do not sell, rent, or share your data with advertisers, data brokers, or any other third party.

5. International data transfers

All data is stored and processed in AWS's eu-north-1 (Stockholm, Sweden) region, within the European Union. We do not transfer your personal data outside the EU/EEA.

6. How long we keep your data

We retain your data for as long as your account remains active. If you request deletion, your account and all associated data are erased automatically — not through a manual, delayed process.

7. Your rights

Under GDPR, you have the right to:

To delete your account: open Settings → Delete Account in the app. This immediately and automatically removes your profile, your collection, uploaded card images, card-add history, transfer requests, notifications, and login logs from our systems, and deletes your Cognito login credentials. This action is irreversible.

For any other request, or if you cannot access the app, email info@cardprime.io.

8. Automated processing

When you add a card, we run an automated check comparing the location and timing against the card's history (the "geo-velocity check"). This may generate an in-app notification if the pattern looks physically implausible. This check only produces an alert — it does not automatically suspend, restrict, or take any legal or similarly significant action against your account.

9. Children's privacy

CardPrime is not directed at children under 16. We do not knowingly collect data from children under this age.

10. Changes to this policy

If we materially change what data we collect or how we use it, we will update this policy and notify you in the app.

11. Contact

CardPrime Korlátolt Felelősségű Társaság
Email: info@cardprime.io