CardBridge Get a card
Privacy

Privacy policy

Updated 29 July 2026
privacy@getcardbridge.com
Data held in Sydney (ap-southeast-2)

Who we are

CardBridge is a trading name of CardBridge, 40 South Gateway, Avondale Heights VIC 3034, Australia. We hold account data in our own right, and we handle contacts our customers collect through their profiles on those customers' behalf. Reach us at privacy@getcardbridge.com or +61 450 735 748.

We handle personal information in line with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. We operate to the APP standard whether or not the small-business exemption applies to us at any given time, because customers handing us their contacts deserve it either way.

What we collect

DataWhyBasis
Name and email addressCreate your account and send your sign-in link — we store no passwordContract
Profile content you publishDisplay your contact page — public by designContract
Shipping addressPrint and post your cardContract
Billing detailsTake payment — held by Stripe, not by usContract
Tap, view and save countsShow you aggregate activityLegitimate interest
Contacts submitted through your formPass them to youProcessed on your behalf
Support messagesAnswer you and keep a recordLegitimate interest
Subscription statusSend, and stop sending, product newsConsent

What we do not do

  • We do not sell, rent or trade personal data.
  • No advertising trackers or third-party ad pixels, on this site or on contact pages.
  • We do not market to contacts collected through customers' profiles.

Cookies

This marketing site sets no cookies. The application uses one first-party session cookie to keep you signed in, and Plausible for page counts, which does not profile individuals or set cross-site identifiers.

One third-party request is worth naming: the typefaces on this site are served by Google Fonts, so loading a page discloses your IP address to Google. No cookie is set by it. If that matters to you, tell us at privacy@getcardbridge.com — self-hosting the fonts removes the request entirely and is on our list.

Who we share with

Only the suppliers needed to run the service, each under a data processing agreement: Vercel for hosting, Amazon SES for email, Stripe for payments, our print partners for card printing, and Plausible for analytics. We disclose data to authorities only where the law requires it.

Where data lives, and for how long

Primary storage is in Sydney (ap-southeast-2), so Australian customer data stays onshore by default. Account data is kept while your account is open and for 90 days after closure, then deleted. Billing records are kept 7 years to meet ATO record-keeping requirements. Suppressed email addresses are kept indefinitely, because that is the only way to keep honouring an unsubscribe.

Disclosure overseas

Some of the suppliers above are located outside Australia, which means your information may be disclosed overseas — principally to the United States (Stripe for payments, and Vercel for edge delivery). Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, through the data processing terms in each supplier contract. You can ask us at privacy@getcardbridge.com which countries your data may reach.

Your rights

Under the Australian Privacy Principles you can ask for access to the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, take it elsewhere in a portable format, or withdraw marketing consent at any time. Write to privacy@getcardbridge.com and we respond within 30 days. Contacts collected through a customer's profile should raise requests with that customer; if they reach us, we forward them and help.

If you are unhappy with how we handled a privacy request, you can complain to us first, and then to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. We would rather you gave us the chance to fix it, but we will not stand in your way.

Data breaches

We follow the Notifiable Data Breaches scheme. If a breach involving personal information is likely to result in serious harm, we notify the affected people and the OAIC as soon as practicable, and always within 30 days of becoming aware of it.

Security

Traffic is encrypted in transit, sign-in uses single-use emailed links rather than stored passwords, and access to production data is limited to staff who need it and logged. If a breach affects you we will tell you and the relevant regulator within the time the law allows.

Children

CardBridge is for working adults. We do not knowingly collect data from anyone under 16.

Changes

If we change this policy in a way that matters, account holders get an email before it takes effect. The date above always reflects the current version.