Privacy Policy
Last updated: August 15, 2026
This Privacy Policy explains how CardLinkly LLC (“CardLinkly”) collects, uses, discloses, and protects information in connection with cardlinkly.com, the CardLinkly mobile application, and related products, features, and services (collectively, the “Service”). Use of the Service constitutes acknowledgment of the practices described in this Privacy Policy.
Information we collect
The categories of information collected depend on how the Service is used and may include:
- Account information — name, email address, and password, with passwords stored securely by CardLinkly’s authentication provider and not visible to CardLinkly in plain text. If a user signs in with Google or Apple, CardLinkly receives information provided by the applicable sign-in provider, which may include name and email address. If Apple’s “Hide My Email” feature is used, Apple may provide CardLinkly with a private relay email address instead of the user’s personal email address. Google sign-in may also provide a profile picture.
- Card content — the information you put on a card: name, title, company, bio, contact details, links, location, category, and any photo or design you upload.
- Reviews — ratings and comments you leave, and your name (from your account) or the name you provide when leaving a verified review after a tap.
- Usage & analytics — when a card is opened or acted on (views, actions like Call/Email/Save-contact), and coarse, IP-derived location (city, region, country) and the page path, used to understand where interest is coming from. We do not store your precise location or full IP address for analytics.
- Orders & payments — if you order a physical card, the shipping and contact details for that order. Payments are processed by our payment processor (Stripe); we do not store your full card number.
- Church / community data — for organizations using our community tools: posts, tasks, events, groups, and staff messages you create.
- Children’s check-in data — see “Children’s privacy” below. We deliberately collect the minimum needed and never a child’s date of birth, address, or photo.
- Communications — inquiries (for example, the church contact form) and messages you send us for support.
- Cookies & local storage — used to keep you signed in and to avoid double-counting analytics within a browser session. We don’t use third-party advertising trackers.
How we use information
- To provide and operate the Service — showing your card, powering the “Find a Pro” directory, and running the community tools.
- To keep reviews honest — tying a “Verified” badge to a real tap and preventing fake or duplicate reviews.
- To show you analytics about your own card.
- To understand, in aggregate, where interest comes from so we can focus our marketing.
- To fulfill physical card orders and process payments.
- To communicate with you — confirmations, replies, and important account or service notices.
- To protect the Service against abuse, fraud, and spam.
Information that is public
Published cards, reviews, and “Find a Pro” directory listings are public and may be viewed by anyone without an account. Please do not include information on a public card unless you are comfortable making it publicly available. Draft cards are private to your account unless and until you publish them.
How we share information
CardLinkly does not sell personal information. CardLinkly discloses information only in the following limited circumstances:
- With service providers who run the Service on our behalf — our database/authentication and storage provider, hosting/CDN, email delivery, and payment processing. They may only use the data to provide their service to us.
- Publicly, for the parts of your card, reviews, and listings you choose to make public.
- For legal reasons — to comply with the law, enforce our Terms, or protect the rights and safety of people and the Service.
- In a business transfer — if CardLinkly engages in a merger, acquisition, or sale of assets, subject to this policy.
Children’s privacy
You must be at least 16 years old to create an account, and the Service is not directed to children under 16. We do not knowingly collect personal information from children under 16 for their own accounts. If you believe a child under 16 has created an account, please contact us and we will take appropriate steps to remove the account and related information. Users under 18 should use the Service only with involvement from a parent or guardian.
The kid’s check-in feature is provided as a tool for churches and is set up and managed by parents, guardians, and church staff. It is designed to minimize data collection. The feature collects only a child’s first name, a class or age band, and any allergy note the family chooses to provide. We do not collect a child’s date of birth, home address, photo, or contact information through this feature. This information is used only to support safe check-in and check-out and is controlled by the church. A parent, guardian, or church may request removal of a child’s record at any time by contacting us or the church. If you believe a child’s information has been provided without proper consent, contact us at support@cardlinkly.com and we will delete it.
Your choices and rights
- You can view and edit your profile and cards at any time in your dashboard.
- You can delete a card, which is retained for 7 days after deletion and then permanently purged, or ask us to delete your account and associated personal data.
- Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information. To exercise these, email support@cardlinkly.com.
- You can opt out of non-essential emails using the unsubscribe link or by contacting us; we may still send essential account and transaction messages.
Your U.S. state privacy rights
Depending on state of residence, including states such as California, Texas, Virginia, or Colorado, users may have additional rights regarding personal information. These rights may include the right to access, correct, delete, or receive a portable copy of personal information and the right to opt out of certain data sales or targeted advertising. CardLinkly does not sell personal information and does not use personal information for cross-context targeted advertising. Requests to exercise privacy rights may be submitted to support@cardlinkly.com. CardLinkly will verify requests, respond within the timeframe required by applicable law, and will not discriminate against users for exercising privacy rights.
Texas privacy rights
If a user is a Texas resident and the Texas Data Privacy and Security Act (“TDPSA”) applies to CardLinkly, the user may have the right to confirm whether CardLinkly processes personal data, access personal data, correct inaccuracies, delete personal data provided by the user or obtained about the user, obtain a portable copy of personal data, and opt out of processing for targeted advertising, sale of personal data, or certain profiling that produces legal or similarly significant effects. CardLinkly does not sell personal information and does not use personal information for cross-context targeted advertising or third-party advertising trackers.
Requests to exercise Texas privacy rights may be submitted to support@cardlinkly.com and should identify the right the user seeks to exercise. A user is not required to create a new account to submit a privacy request. CardLinkly will verify the request and respond within the timeframe required by applicable law. If CardLinkly denies a request, the user may appeal by replying to CardLinkly’s decision or emailing support@cardlinkly.com with “Texas Privacy Appeal” in the subject line. If the appeal is denied, CardLinkly will provide information regarding how the user may contact the Texas Attorney General.
CardLinkly does not knowingly process sensitive personal data except as necessary to provide requested features or where permitted by law. Where the TDPSA requires consent before processing sensitive personal data, CardLinkly will request consent before such processing. If applicable law requires CardLinkly to honor a recognized universal opt-out mechanism for sale of personal data or targeted advertising, CardLinkly will honor that signal when technically feasible and legally required.
Data retention
CardLinkly retains information for as long as the applicable account is active or as otherwise needed to provide the Service. Deleted cards are retained for 7 days after deletion and then permanently purged. CardLinkly may retain certain records as required or permitted for legal, tax, security, fraud-prevention, or compliance purposes.
Security
CardLinkly uses administrative, technical, and organizational safeguards designed to protect information, including access controls, database row-level security, and encryption in transit and at rest. No method of transmission or storage is completely secure, and absolute security cannot be guaranteed. If a data breach affects personal information, CardLinkly will notify affected users and applicable authorities without unreasonable delay and as required by applicable law, including the breach-notification laws of the states where affected users reside. For Texas residents, notice will be provided without unreasonable delay and, where Texas law applies, no later than 60 days after CardLinkly determines that a reportable breach occurred, unless a permitted delay applies. If a reportable breach affects 250 or more Texas residents, CardLinkly will notify the Texas Attorney General as soon as practicable and no later than 30 days after determining that the breach occurred. The Texas Attorney General notice will include the nature and circumstances of the breach or use of sensitive personal information, the number of Texas residents affected, the number of residents notified at the time of submission, the measures taken regarding the breach, any measures CardLinkly intends to take after the notice, and information regarding whether law enforcement is engaged in investigating the breach. For Arizona residents, where Arizona law applies, CardLinkly will notify affected individuals within 45 days after determining that a reportable security system breach occurred, unless a permitted law-enforcement delay applies. Arizona notices will include the approximate date of the breach, a brief description of the personal information involved, contact information for the three largest nationwide consumer reporting agencies and the Federal Trade Commission or other applicable federal identity-theft assistance agency, and information about fraud alerts and security freezes. If an Arizona breach requires notification of more than 1,000 individuals, CardLinkly will also notify the three largest nationwide consumer reporting agencies, the Arizona Attorney General, and the Director of the Arizona Department of Homeland Security in writing, using any required form or by providing a copy of the individual notice where permitted.
Where we operate
CardLinkly is based in the United States, and CardLinkly’s service providers may process information in the United States. Users who access or use the Service from outside the United States acknowledge that their information will be processed in the United States.
Changes to this policy
CardLinkly may update this Privacy Policy from time to time. CardLinkly will update the “Last updated” date above and, where significant changes are made, provide more prominent notice as appropriate or required by law.
Contact us
Questions regarding privacy may be submitted to support@cardlinkly.com.
See also our Terms of Service.