Last updated: April 29, 2026 Effective: as of the publication date
1. Who is responsible for your data
DIGITAL SOLUTION CORE, S.A. ("Cardreen", "we") is the controller of personal data we collect through cardreen.com and the related platform.
- Tax ID: Aviso de Operación N° 155728089-2-2022 DV20
- Address: Calle U, Casa B8, Urbanización Chanis, Corregimiento de Parque Lefevre, Distrito de Panamá, Provincia de Panamá, República de Panamá
- Privacy email: privacidad@cardreen.com
This policy explains what data we collect, why, with whom we share it, and what rights you have.
2. Two kinds of "you"
Cardreen has two user types and we treat them differently:
2.1 You as a Cardreen user
You created an account to build and share digital cards. This policy applies to your personal data and your contractual relationship with us.
2.2 You as a captured lead on a Cardreen card
You scanned a QR or visited a mini-landing and submitted your data via the contact form. In that case:
- The controller of your data is the Cardreen user who invited you to leave your contact, not Cardreen.
- Cardreen acts as processor and only handles your data following that user's instructions.
- To exercise rights over your data, contact the user who collected it. If you can't reach them or need help, email us at privacidad@cardreen.com.
3. What data we collect
3.1 Cardreen-user data
When you create an account and use the service, we collect:
| Category | Data | Source | |---|---|---| | Identification | Name, email, optional phone | You at sign-up | | Account | Password (bcrypt-hashed, 12 rounds), plan, registration date | Generated by the system | | Card profile | Photo/avatar, logo, professional info, social links, configured CTAs | You when building your card | | Payment | Last 4 digits of card, payment method, billing history | Processor (Mercado Pago / Stripe) | | Technical usage | IP, browser, login date/time, platform events | Generated when using Cardreen | | Communications | Support tickets, survey responses | You when contacting us |
We do not store full credit-card data. That's handled by the payment processor.
3.2 Captured-lead data (collected BY the user, THROUGH Cardreen)
When someone leaves their data on a public mini-landing, we collect on the user's behalf:
- Name, email, phone, company, message (the form fields the user configures).
- Visitor IP, date/time and user-agent (audit and anti-fraud).
- Scan source (physical QR, shared link, etc.) when available.
This data belongs to the Cardreen user, not to Cardreen. We process it only to:
- Display it to the user in their mini CRM.
- Let them export to CSV.
- Send the user an email notification when a new lead is captured.
3.3 Cookies and similar technologies
See the Cookie Policy (/legal/cookies) for full detail.
4. Why we use the data
| Purpose | Data | Lawful basis (GDPR) | |---|---|---| | Create and run your account | Identification, account, profile | Contract (art. 6.1.b GDPR) | | Charge your plan | Payment data | Contract (art. 6.1.b GDPR) | | Display your public mini-landing | Card profile | Contract (art. 6.1.b GDPR) | | Handle support requests | Communications | Contract (art. 6.1.b GDPR) | | Improve the service (anonymous aggregate analytics) | Technical usage | Legitimate interest (art. 6.1.f GDPR) | | Comply with legal duties (invoicing, court orders) | As needed | Legal obligation (art. 6.1.c GDPR) | | Send Cardreen marketing communications | Email | Consent (art. 6.1.a GDPR) — opt-out anytime | | Process leads captured by the user | Leads | The user is controller; Cardreen is processor (art. 28 GDPR) |
We do not make automated decisions with legal effects about you. We do no profiling for advertising.
5. With whom we share the data
Cardreen does not sell or rent personal data to third parties. We share only with the following processors, under signed data-processing agreements:
| Category | Provider | Purpose | Location | |---|---|---|---| | Hosting | Hostinger | Host the platform and database | EU / US (plan-dependent) | | Payment processor | Mercado Pago | LATAM payments | LATAM | | Payment processor | Stripe (Phase 2) | International payments | US | | Transactional email | Titan / Hostinger | Operational emails (password reset, notifications) | EU / US |
We do not use Google Analytics, Facebook Pixel, or ad trackers in the MVP. If we ever add them, we'll notify you and they will only activate with your explicit consent via the cookie banner.
International transfers: some providers are outside the EEA / LATAM. In those cases we use:
- Standard Contractual Clauses (SCC) approved by the European Commission for EU transfers.
- Equivalent guarantees under LFPDPPP (Mexico) and Ley 1581 (Colombia).
6. How long we keep your data
| Data type | Retention | |---|---| | Active account | While your account is active | | Cancelled account | 30 days after cancellation, then deleted | | Billing data | 5 years (tax law) | | Closed support tickets | 2 years | | Captured leads | Whatever the Cardreen user (controller) decides. If they delete their account, leads are deleted within 30 days | | Technical logs (IP, events) | 90 days | | Backups | 30-day rotation |
7. Your rights
Depending on your country, you have the following rights over your personal data:
7.1 Universal rights (GDPR / LFPDPPP / Ley 1581 / CCPA)
- Access: know what data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure / Deletion: ask us to delete your data ("right to be forgotten" in GDPR).
- Object: object to certain processing (especially marketing).
- Portability: receive your data in a structured, reusable format (CSV/JSON).
- Restriction: ask us to pause use of your data while a dispute is resolved.
- Withdraw consent you've given us, anytime.
7.2 Additional rights by jurisdiction
- Mexico (LFPDPPP): the above are called ARCO rights (Access, Rectification, Cancellation, Opposition).
- GDPR (EU/EEA): right to lodge a complaint with your supervisory authority (AEPD in Spain, CNIL in France, etc.).
- Colombia (Ley 1581): right to file a complaint with the Superintendencia de Industria y Comercio (SIC).
- California (CCPA/CPRA): right to know, delete, correct, not be discriminated against for exercising rights, and "do not sell my personal information" (which in Cardreen is already the default — we don't sell data).
7.3 How to exercise your rights
Email privacidad@cardreen.com from the address associated with your account, indicating:
- Which right you want to exercise.
- If needed, a copy of valid ID (to verify it's you).
Response time: up to 20 business days (LFPDPPP/Ley 1581) or 30 calendar days (GDPR/CCPA), extendable for complex requests.
Cost: free. We may only charge for manifestly excessive or repetitive requests, as allowed by applicable law.
8. Security
We apply reasonable measures to protect your data:
- Encryption in transit: all connections use HTTPS (TLS 1.2+).
- Encryption at rest: the database is encrypted at the provider level.
- Passwords: hashed with bcrypt (12 rounds).
- Authentication: JWT with 15-minute access tokens and 30-day refresh tokens with rotation.
- CSRF tokens, security headers (helmet, CSP), rate limiting and prepared statements on all SQL.
- HMAC-signed webhooks.
- Encrypted backups, 30-day rotation.
- Restricted, audit-logged internal access.
No system is 100% secure. If we detect a breach affecting your data, we will notify you within 72 hours (GDPR) and the relevant authority.
9. Children's data
Cardreen is not directed to people under 18 (or the legal age of majority in your country). If we learn a minor created an account, we will delete it. If you believe a minor in your care has given us data, email privacidad@cardreen.com.
10. Changes to this policy
If we make material changes, we'll notify you by email with 30 days notice. Minor changes take effect upon publication. The "Last updated" date always reflects the current version.
11. Contact
- Privacy email: privacidad@cardreen.com
- Address: Calle U, Casa B8, Urbanización Chanis, Corregimiento de Parque Lefevre, Distrito de Panamá, Provincia de Panamá, República de Panamá
- Controller: DIGITAL SOLUTION CORE, S.A., tax ID Aviso de Operación N° 155728089-2-2022 DV20
If our response doesn't satisfy you, you may file a complaint with:
- Mexico: INAI (Instituto Nacional de Transparencia).
- Colombia: Superintendencia de Industria y Comercio (SIC).
- EU/EEA: your national data-protection authority.
- California: California Office of the Attorney General.
Cardreen — Menos papel, más oportunidades. / Less paper, more opportunities.