Privacy policy
Updated 29 July 2026
privacy@getcardbridge.com
Data held in Sydney (ap-southeast-2)
Who we are
CardBridge is a trading name of CardBridge, 40 South Gateway, Avondale Heights VIC 3034, Australia. We hold account data in our own right, and we handle contacts our customers collect through their profiles on those customers' behalf. Reach us at privacy@getcardbridge.com or +61 450 735 748.
We handle personal information in line with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. We operate to the APP standard whether or not the small-business exemption applies to us at any given time, because customers handing us their contacts deserve it either way.
What we collect
| Data | Why | Basis |
|---|---|---|
| Name and email address | Create your account and send your sign-in link — we store no password | Contract |
| Profile content you publish | Display your contact page — public by design | Contract |
| Shipping address | Print and post your card | Contract |
| Billing details | Take payment — held by Stripe, not by us | Contract |
| Tap, view and save counts | Show you aggregate activity | Legitimate interest |
| Contacts submitted through your form | Pass them to you | Processed on your behalf |
| Support messages | Answer you and keep a record | Legitimate interest |
| Subscription status | Send, and stop sending, product news | Consent |
What we do not do
- We do not sell, rent or trade personal data.
- No advertising trackers or third-party ad pixels, on this site or on contact pages.
- We do not market to contacts collected through customers' profiles.
Cookies
This marketing site sets no cookies. The application uses one first-party session cookie to keep you signed in, and Plausible for page counts, which does not profile individuals or set cross-site identifiers.
One third-party request is worth naming: the typefaces on this site are served by Google Fonts, so loading a page discloses your IP address to Google. No cookie is set by it. If that matters to you, tell us at privacy@getcardbridge.com — self-hosting the fonts removes the request entirely and is on our list.
Who we share with
Only the suppliers needed to run the service, each under a data processing agreement: Vercel for hosting, Amazon SES for email, Stripe for payments, our print partners for card printing, and Plausible for analytics. We disclose data to authorities only where the law requires it.
Where data lives, and for how long
Primary storage is in Sydney (ap-southeast-2), so Australian customer data stays onshore by default. Account data is kept while your account is open and for 90 days after closure, then deleted. Billing records are kept 7 years to meet ATO record-keeping requirements. Suppressed email addresses are kept indefinitely, because that is the only way to keep honouring an unsubscribe.
Disclosure overseas
Some of the suppliers above are located outside Australia, which means your information may be disclosed overseas — principally to the United States (Stripe for payments, and Vercel for edge delivery). Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, through the data processing terms in each supplier contract. You can ask us at privacy@getcardbridge.com which countries your data may reach.
Your rights
Under the Australian Privacy Principles you can ask for access to the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, take it elsewhere in a portable format, or withdraw marketing consent at any time. Write to privacy@getcardbridge.com and we respond within 30 days. Contacts collected through a customer's profile should raise requests with that customer; if they reach us, we forward them and help.
If you are unhappy with how we handled a privacy request, you can complain to us first, and then to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. We would rather you gave us the chance to fix it, but we will not stand in your way.
Data breaches
We follow the Notifiable Data Breaches scheme. If a breach involving personal information is likely to result in serious harm, we notify the affected people and the OAIC as soon as practicable, and always within 30 days of becoming aware of it.
Security
Traffic is encrypted in transit, sign-in uses single-use emailed links rather than stored passwords, and access to production data is limited to staff who need it and logged. If a breach affects you we will tell you and the relevant regulator within the time the law allows.
Children
CardBridge is for working adults. We do not knowingly collect data from anyone under 16.
Changes
If we change this policy in a way that matters, account holders get an email before it takes effect. The date above always reflects the current version.