Privacy Policy
Last updated: January 2026
Overview
CardSignal ("we", "our", "us") respects your privacy. This policy explains what data we collect, how we use it, and your rights regarding your information.
1. Information We Collect
Account Information
- Email address — Required for account creation and notifications.
- Name — From your Google account if you use Google Sign-In.
- Profile picture — From your Google account (optional display).
Usage Data
- Searches you perform within the dashboard.
- Cards you set alerts for.
- Pages you visit and features you use.
- Device information (browser type, operating system).
Payment Information
Payment processing is handled entirely by Stripe. We do not store, process, or have access to your credit card numbers. We only receive confirmation of successful payments and subscription status from Stripe.
2. How We Use Your Information
- To provide the Service — Display market data, send price alerts, manage your account.
- To improve the Service — Understand usage patterns and optimize features.
- To communicate with you — Send transactional emails (alerts, receipts, account updates).
- To process payments — Manage subscriptions and billing through Stripe.
3. Information Sharing
We do NOT sell your personal information. We share data only in these cases:
- Stripe — For payment processing.
- Google — If you use Google Sign-In (OAuth authentication only).
- Legal requirements — If required by law or to protect our rights.
4. Data Security
We implement industry-standard security measures to protect your data:
- HTTPS encryption for all data in transit.
- Encrypted database storage.
- OAuth-based authentication (no password storage).
- Regular security audits and updates.
5. Cookies and Tracking
We use essential cookies to maintain your login session. We do not use third-party advertising cookies or cross-site tracking.
We may use privacy-respecting analytics (such as Plausible or similar) to understand aggregate usage patterns. These tools do not track individual users across sites.
6. Your Rights
You have the right to:
- Access — Request a copy of the data we have about you.
- Correct — Update inaccurate information in your account.
- Delete — Request deletion of your account and associated data.
- Export — Download your data in a portable format.
- Opt out — Unsubscribe from non-essential emails.
To exercise these rights, contact us at privacy@cardsignal.app.
7. Data Retention
We retain your account data as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are legally required to retain it (e.g., billing records for tax purposes).
8. Third-Party Data
The market data displayed in CardSignal is aggregated from public Facebook group posts. This data includes usernames and post content that are publicly visible. We do not collect private information from Facebook users beyond what is publicly posted.
9. Children's Privacy
CardSignal is not intended for users under 18 years of age. We do not knowingly collect information from children. If you believe we have collected data from a minor, contact us immediately.
10. International Users
CardSignal is operated from the United States. By using the Service, you consent to the transfer of your data to the US and processing under US law. We comply with applicable data protection regulations including GDPR for EU users.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions or requests, contact us at:
Email: privacy@cardsignal.app