Cardify

Privacy Policy

Останнє оновлення: 23 травня 2025 р.

1. General

This Privacy Policy describes how Cardify (cardify.pp.ua, "Service", "we") collects, uses and protects personal data of users ("you", "user"). By using the Service, you agree to this Policy.

We comply with the Law of Ukraine "On Personal Data Protection" and the EU General Data Protection Regulation (GDPR) where applicable.

2. Data We Collect

Account data: name, email address, encrypted password (bcrypt). If you sign in via Google — name and email from your Google profile.

Usage data: number of generated cards, generation type and quality, registration date, country determined by IP address.

Uploaded images: product photos you upload for generation. They are transmitted to fal.ai and OpenAI for processing.

Payment data: we do not store bank card details. Payments are processed by WayForPay — an independent payment service with its own privacy policy.

Analytics: we use PostHog for anonymous usage analytics. IP addresses are not stored in analytics.

Technical data: IP address (for rate limiting and country geolocation), session cookies for authentication.

3. How We Use Data

Collected data is used exclusively to:

  • provide Service functionality (card generation, history storage);
  • authenticate and secure accounts;
  • send transactional emails (email verification, operation notifications);
  • prevent abuse and apply rate limiting;
  • improve the Service based on anonymized statistics.

We do not sell, transfer or disclose your personal data to third parties for commercial purposes.

4. Third Parties

We use the following services to operate:

  • OpenAI — image generation (GPT Image 2). Your photos are transmitted per OpenAI's Privacy Policy.
  • fal.ai — cloud storage and image processing. Details in fal.ai's Policy.
  • WayForPay — payment processing. We never see your card details.
  • Neon — cloud database (PostgreSQL). Data stored on servers in the USA.
  • Sequenzy — transactional email delivery.
  • PostHog — usage analytics (EU Cloud, anonymized).
  • Google OAuth — optional sign-in via Google account.

5. Images and Generations

Product photos you upload are temporarily processed on fal.ai servers for generation. Generation results (links to generated images) are stored in your history until account deletion or manual clearing.

We do not use your images to train AI models.

6. Your Rights

You have the right to:

  • receive a copy of your personal data;
  • correct inaccurate data;
  • delete your account and all associated data;
  • withdraw consent to data processing.

To exercise these rights, contact cardisupp@gmail.com. We will respond within 30 days.

7. Cookies

The Service uses only functional cookies to maintain authentication sessions. We do not use advertising or tracking cookies.

8. Security

Passwords are stored encrypted (bcrypt, 12 rounds). Data transmission is secured with HTTPS/TLS. Database access is restricted and protected. However, no method of transmission over the Internet is completely secure — we cannot guarantee absolute security.

9. Age

The Service is intended for users aged 16 and older. If you become aware that a child under 16 has provided us with personal data, please contact us for deletion.

10. Changes

We may update this Policy. We will notify you of material changes on the website or by email. Continued use of the Service after changes constitutes acceptance of the new version.

11. Contact

For privacy inquiries: cardisupp@gmail.com