Privacy Policy

Last updated: 19 July 2026

1. Introduction

This Privacy Policy explains how Cardition Ltd collects, uses, stores, protects, retains and, where relevant, shares personal data when you use Cardit. Cardit includes the mobile app, the webapp, card creation tools, saved cards, scanned cards, saved web cards, folders, collections, sharing tools and related support services.

Cardit lets people and businesses create, save, organise, access and share digital cards. Some cards may include contact details, images, text, websites, physical addresses, social links, ratings, comments, messages, loyalty or reward information, menus, posts, QR codes, NFC sharing, Sonic QR sharing or a BCN.

2. Who we are

Cardit is operated by Cardition Ltd. In this policy, "we", "us" and "our" mean Cardition Ltd.

Cardition Ltd is registered in England and Wales under company number 09711058. Our registered office is 15 Castellain Road, London W9 1EY, United Kingdom.

For privacy questions or to exercise your rights, contact us at support@cardition.com.

3. Scope of this policy

This policy applies when you:

  • create an account or sign in to Cardit;
  • use the Cardit mobile app or webapp;
  • create, edit, save, scan, organise, access, manage or share cards and related content;
  • use folders, collections, follow collections, group collections, scanned cards or saved web cards;
  • send or receive messages, comments, ratings, posts, notifications, menu orders, loyalty points or rewards through Cardit;
  • contact us for support, account help, privacy requests or service communications.

4. Personal data we may collect

Depending on how you use Cardit, we may collect and process the following categories of personal data.

Account and authentication information: your name, email address, login credentials or authentication-related information, profile information you choose to provide, and account identifiers.

Card and profile content: information and content you create, upload, save, scan, organise, access, manage or share through Cardit, including names, job titles, business details, contact details, addresses, images, websites, social media links, notes, ratings, comments, menus, posts, loyalty or reward data, and metadata connected to cards or folders.

Messages and communications: messages, chat content, support requests, account deletion requests and other communications you send to us or to other users through Cardit features.

Technical, usage and diagnostic information: device type, operating system, browser type, app version, IP address, log data, diagnostic information, crash data, performance data and interaction data needed to operate, secure, troubleshoot and improve Cardit.

Third-party or imported content: information you choose to save from the web, scan from cards, import, or receive from another user. You are responsible for ensuring that you have the right to upload, store or share information about other people.

5. How we use personal data

We use personal data to:

  • provide, operate and maintain Cardit;
  • create and manage user accounts;
  • authenticate users and secure access to the app and webapp;
  • enable users to create, save, scan, organise, access, manage and share cards and related content;
  • support folders, collections, follow collections, group collections, scanned cards and saved web cards;
  • deliver messages, notifications, comments, ratings, posts, menu, loyalty and reward features where used;
  • improve functionality, performance, usability and reliability;
  • monitor, troubleshoot and protect Cardit against misuse, fraud, security issues or technical issues;
  • communicate with users about account, support, service, legal or security matters;
  • process privacy, access, correction, portability and deletion requests;
  • comply with legal and regulatory obligations and enforce our terms.

6. Legal bases for processing

Depending on the context, we process personal data on one or more of the following legal bases:

  • Performance of a contract: where processing is necessary to provide Cardit and its features to you.
  • Legitimate interests: where processing is necessary for operating, securing, improving and administering Cardit, provided those interests are not overridden by your rights and interests.
  • Legal obligation: where processing is necessary to comply with applicable law.
  • Consent: where consent is required under applicable law, such as for certain optional permissions, communications or cookies.

7. Sharing of personal data

We do not sell personal data. We do not share personal data with third parties for their own advertising purposes.

Sharing initiated by you. Cardit allows you to share cards, contact details, posts, links or other content with other users or third parties. When you choose to share information, the recipient may be able to view, store, copy or further share it. You are responsible for ensuring that the information you share is lawful and authorised.

Service providers. We may use third-party service providers who help us operate, host, secure, authenticate, analyse, maintain or support Cardit. These providers may process personal data on our behalf only where needed to provide their services and subject to appropriate contractual and security safeguards.

Legal and protection purposes. We may disclose personal data where necessary to comply with legal obligations, respond to lawful requests, protect our rights, protect users or third parties, or detect, prevent or investigate fraud, security or technical issues.

8. Third-party services and platform providers

Cardit may rely on or interact with third-party infrastructure, hosting, authentication, analytics, crash reporting, email, notification, storage, payment, maps, media, app-store and connectivity providers. Their systems may affect service availability, performance or data handling.

If you use Google sign-in, Apple platform services, Firebase services, app-store downloads, external links or saved web content, those providers may process data under their own privacy policies.

9. Cookies and similar technologies

The webapp uses cookies and similar technologies where needed for authentication, session management, security, status, preferences and service operation. Optional analytics or similar technologies may be used to understand and improve performance and reliability.

You can usually control cookies through your browser settings. Blocking all cookies may prevent sign-in or limit parts of the webapp from working correctly.

10. Data storage and security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, destruction, misuse, alteration or disclosure. Data is encrypted in transit where supported by the service.

However, no digital platform, storage system, server, network or transmission method can be guaranteed to be completely secure. You should keep independent copies of information that is important to you.

11. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law.

Retention may depend on the duration of your account, how you use Cardit, operational and security needs, legal, regulatory, tax or accounting requirements, dispute resolution, fraud prevention and enforcement needs.

When personal data is no longer required, we may delete, anonymise or otherwise securely dispose of it, subject to applicable law and technical constraints.

12. Account deletion and data deletion

You may request deletion of your Cardit account and associated personal data, subject to legal retention obligations and legitimate operational requirements.

The fastest option for signed-in users is to open the Cardit app, go to Profile, then Account, and choose Delete Account and Data. If you cannot access the app, you can request deletion by email from the email address linked to your account.

Read the account and data deletion instructions.

Deletion of your account may not remove copies of information that you already shared with other users or third parties, where those copies are outside your account or must be retained by law.

13. International transfers

Where personal data is transferred outside the United Kingdom, the European Economic Area or another relevant jurisdiction, we will take appropriate steps to protect those transfers using safeguards required under applicable data protection law.

14. Your rights

Subject to applicable law, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to certain types of processing;
  • request portability of personal data;
  • withdraw consent where processing is based on consent;
  • complain to a data protection supervisory authority.

These rights may be subject to legal, technical and operational limitations. To exercise your rights, contact support@cardition.com.

15. Children's data

Cardit is not intended for use by children unless expressly stated otherwise. We do not knowingly collect personal data from children in breach of applicable law.

16. Changes to this policy

We may update this Privacy Policy from time to time. Where changes are material, we may notify users through the app, webapp, by email, or by other appropriate means.

17. Contact

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at support@cardition.com.

Cardition Ltd, 15 Castellain Road, London W9 1EY, United Kingdom.

Cardition Add Cardition To Home Screen