Privacy Policy
CardCadence is an independent sole proprietorship (“CardCadence,” “we,” “us”) based in California. Privacy questions and requests may be sent to [email protected].
This policy explains what personal data CardCadence collects, how we use it, and your choices. It covers two distinct groups: our customers (the businesses who use CardCadence) and mail recipients (the people your postcards are sent to).
1. Data we collect from customers
- Account data — name, business name, email, and login credentials.
- Billing data — wallet funding and payment details, processed by our payment provider; we do not store full card numbers.
- Content — the designs, copy, and recipient lists you upload.
- Usage data — how you interact with the app, for support and product improvement.
2. Recipient data you provide
To mail your postcards, you upload recipient names and addresses. CardCadence processes this data on your behalf solely to print, mail, and track the cards you send. We do not sell recipient data or use it for our own marketing. You are the controller of that data and are responsible for having the right to use it.
3. How we use data
- To provide the service — designing, printing, mailing, and tracking your postcards.
- To process wallet funding and apply per-piece charges.
- To provide scan and response analytics back to you.
- To support you and improve the product.
- To meet legal and security obligations.
4. Tracking on the website
Our public website uses privacy-conscious analytics. We do not build personal profiles, we mask form inputs in session recordings, we honor “Do Not Track,” and we do not store visitor IP addresses for analytics. Postcard QR-code scans are tracked so customers can measure their own campaigns; the resulting scan data is provided to the customer who sent the card.
5. Sharing & sub-processors
We share data only with the service providers needed to run CardCadence — for example, print and mailing partners, our payment processor, hosting, and analytics — and only as needed to deliver the service. We don’t sell personal data.
One detail worth stating plainly: our print-and-mail account is operated on shared infrastructure, and the administrators of that account can see the mailings created through it — including recipient addresses and card artwork. They use it to run the service, not for their own purposes, and it does not change what we do with your data. We mention it because “only the providers needed to run the service” is easy to read as a shorter list than it is.
6. Data retention
We retain account and campaign data while your account is active and as needed for legal, accounting, and dispute-resolution purposes. You may request deletion of your account data by contacting us.
7. Security
We use industry-standard safeguards to protect personal data. No method of transmission or storage is perfectly secure, but we work to protect your information and that of your recipients.
8. Your choices
You can access or update your account information in the app, and request export or deletion of your data by emailing us. If you are a mail recipient and wish to be removed from a sender’s list, contact the business that mailed you; we will assist that business in honoring removal requests.
9. California residents
CardCadence is based in California. Whether or not we currently meet the revenue and volume thresholds that trigger the California Consumer Privacy Act as amended by the CPRA, we extend its core rights to California residents as a matter of policy:
- Know — what personal information we have collected about you, where it came from, why we collected it, and who we shared it with.
- Access — a copy of that information in a portable form.
- Correct — inaccurate personal information we hold.
- Delete — your personal information, except where we’re required to keep it for legal, tax, fraud-prevention, or dispute-resolution reasons.
- Limit use of sensitive information — we do not collect sensitive personal information as the CPRA defines it, so there is nothing to limit.
- No retaliation — we will not deny you service, change your price, or degrade the product because you exercised any of these rights.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA — not your account data, and not the recipient data you upload. We do not disclose personal information for cross-context behavioral advertising. Because there is no sale or sharing, there is no “Do Not Sell or Share My Personal Information” process to run; if that ever changes, this policy changes first.
To exercise any of these rights, email [email protected]. We’ll verify your request against the account it concerns and respond within 45 days, extending once if a request is complex — we’ll tell you if that happens. An authorized agent may submit a request on your behalf with written permission we can verify.
If you are a mail recipient rather than a customer, we process your name and address on behalf of the business that mailed you. Send removal and access requests to that business; write to us at the address above and we will route the request and help them honor it.
Under California Civil Code § 1798.83 (the “Shine the Light” law), California residents may request details of personal information disclosed to third parties for their direct-marketing purposes. We make no such disclosures.
10. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new date.
11. Contact
Questions about privacy? Email [email protected], or [email protected] for anything else.