CardPin Privacy Policy
Last updated: 21 September 2026
This policy explains what personal data CardPin (the "Service") collects, why, how long we keep it, and what you can do about it.
Three things worth knowing first
- The cards you post are fully public. The photo, the text and the place it was taken are visible to anyone using the Service.
- We do not track your movements. Your location is captured once, at the moment you create a card, and is tied to that card. The nearby-card reminder works out on your device whether you are near a place with cards; that result is never uploaded.
- You can delete your account and everything in it at any time. See the account deletion page.
What we collect
The table below lists every category of personal data the Service collects or derives. It corresponds item by item to the specifications of each feature, and is updated whenever a category is added or removed.
| Category | What it includes | Why | How long we keep it |
|---|---|---|---|
| Account data | Email address, password hash (people who use third-party sign-in may have no password), username, email verification status, the time and version of terms you accepted, age confirmation, third-party identity links (the user identifier provided by Apple or Google) | To create and verify your identity, sign you in, and send account-related email | Until you delete your account |
| Sign-in sessions | For each sign-in: creation time, last-used time, a device summary (platform and app version), expiry time | To keep you signed in and let you review and sign out other devices | Up to 90 days; signing out or deleting your account ends and removes the session |
| Email hash after account deletion | A one-way hash of the email address (it cannot be turned back into the address) and an expiry time | To block re-registration with the same address for a short period, so suspensions cannot be evaded | 30 days after deletion; if you were suspended when you deleted the account, until the suspension ends (30 days for a permanent suspension) |
| Card photo and text | The photo taken with the in-app camera (including any filter you applied) and an optional short note | To make up the card that is shown publicly on the map | Until the card is withdrawn or deleted, or the account is deleted; removed permanently from all storage within 24 hours |
| Where and when the photo was taken | Latitude, longitude, accuracy and time at the moment of capture; the country code derived from those coordinates | To pin the card on the map, decide interaction range, and show country flags on your profile | With the card; deleted when the card is deleted |
| Interactions | View records (who, which card, first time), hearts, saves, hidden-card preferences | To count views and hearts (once per person), keep your saved list, and stop showing cards you hid | Until you undo the interaction, the card is removed, or the account is deleted. Who gave a heart is never shown to other people, and your saves are visible only to you |
| Reports | Who reported, which card, the reason category, an optional note, and the time | Content safety review | 90 days after review is complete. If you delete your account, reports are de-identified: the reason and card remain, the reporter's identity is removed |
| Moderation and suspension records | Moderator, subject, action taken, reason, notes, summary; suspension level, duration and reason; the reason a card was hidden | Governance audit and the basis for appeals | Action records for 1 year; suspension records for 1 year after they end. These cannot be deleted on request because they are audit evidence; after account deletion the subject is replaced with an identifier |
| In-app notices | The message telling you about an action taken, and its time | So anyone affected knows what happened and how to appeal | 90 days; removed when the account is deleted |
| Co-posting | Co-posting sessions and invitations (who was tagged, status, response time, who cancelled), card participants and their roles, party rosters and extension records, withdrawal requests (requester, optional reason, each person's response) | To run the confirmation flow, credit everyone on a shared card, and handle deletion that needs everyone's agreement | Participation stays with the card; cancelled sessions are cleared within 10 minutes of expiry; withdrawal requests are deleted within 30 days of concluding |
| Nearby-reminder trigger check | The coordinates at the moment of a location event (used for one query only), plus the notification log and reminder preferences held on your device | To work out whether you are near a place with cards, so we can send a "cards nearby" reminder | The coordinates are not kept. The server does not store them or write them to logs, and the device does not write them to a file. The device keeps a notification log for 7 days to avoid repeat reminders; turning reminders off, signing out or removing the app clears it |
| Language preference | The interface language you chose (Traditional Chinese / English / follow system) and the language sent with each request | To show the interface and send email in the right language | Stored with the account and deleted with it; the language sent with a request is not stored separately or used for analytics |
What we do not collect
- Your movement trail or location history
- Name, phone number, date of birth, gender, national ID or any other field not requested at registration
- Your contacts, photo library, messages or data from other apps
- Advertising identifiers. The Service carries no advertising and uses no third-party analytics or tracking
- The full list of locales on your device, or your keyboard languages
Who else handles your data
The following third parties process some data so that the Service can work. They may use it only as needed to provide that service.
| Who | For what | What they see |
|---|---|---|
| Map provider | Serving map tiles | The map area you are viewing, handled under the provider's own policy |
| Object storage provider | Storing and serving card photos | Card photos |
| Email delivery provider | Sending verification, password reset and account email | Your email address and the contents of those messages |
| Apple, Google | Third-party sign-in | Only if you choose to sign in with them: they give us a user identifier and, depending on your settings, an email address |
Apart from the above, we do not sell, rent or otherwise share your personal data. If we are legally required to disclose it, we will notify you beforehand to the extent the law allows.
International transfers
The cloud services we use may store or process data outside Taiwan. We check that providers have reasonable data protection measures in place before choosing them.
Security
- All traffic between the app and our servers is encrypted in transit.
- Passwords are stored as one-way hashes; we cannot read your original password.
- Authentication and authorisation are enforced on the server.
- Access to production data is limited to the minimum needed to operate the Service.
Your rights
- Access and correction: you can view and change your account details in the app's settings.
- Deletion: you can delete an individual card at any time, or delete your whole account. See the account deletion page.
- Withdrawing consent: you can revoke camera, location or notification permissions in your system settings at any time; the related features will then stop working.
- Questions: email [email protected].
Children
The Service is not for anyone under 13. If we learn that we have collected personal data from someone under 13, we will delete the account and its content as soon as we can. If you are a parent or guardian and believe your child is using the Service without your consent, please contact us.
Changes to this policy
We may update this policy. Significant changes will be announced in the app or by email before they take effect, and the date at the top of this page will be updated.