Privacy Policy
Plain answers about your data.
Personal data we collect
- Account: your name, and either your WhatsApp mobile number (WhatsApp sign-in) or your email and profile picture (Google Sign-In), plus your country. Used to save your invites, let you log back in, and show prices in your currency.
- Content you add: event details, names, photos, messages, links and audio you put on your pages, and the card images you upload. Stored so your pages work.
- Guest replies (RSVP): when a host switches RSVP on, guests give their name, attendance, and optionally a WhatsApp number, dietary notes and answers to the host’s questions. These are collected for the host and shown only to that host.
- Payments: Razorpay processes payments. We keep the order id, amount, plan and status. We never see or store card numbers or UPI credentials.
- Usage: standard analytics (pages visited, device type, country) via Google Analytics, and a few first-party events (for example that a publish window was opened), to understand what to improve. Team browsers are excluded.
- A browser id: we keep a random identifier in your browser’s local storage. It carries no name and nothing about your device, and it exists so a free design or a verified WhatsApp number is still yours when you come back, and so we can tell one visitor from another when counting how a page performs. Clearing your browser’s site data removes it and a new one is made. If you sign in, we link it to your account so what you made while signed out is not lost.
- Connected apps: if you connect CardToPage to an AI assistant (ChatGPT, Claude), that app can see and edit your own invitations after you press Allow on our consent screen. We store the access token it holds; you can revoke it any time by disconnecting the app or asking us.
Why we use it (purposes)
- To build, host and serve your invitation pages and collect replies for you.
- To sign you in, keep your account secure and take payment for what you buy.
- To read details off an uploaded card automatically, using an AI vision model, only when you upload a card and only to pre-fill your own form.
- To understand which pages and features people use, so we can improve the product.
How long we keep it (retention)
- Your account: until you ask us to delete it. Deletion removes your invitations, replies, uploads and connected-app tokens within 30 days.
- Full websites: stay live for 37 days after the last event date (a week for late guests, then 30 more days kept in case of a refund or payment dispute), then are deleted. You can delete one yourself at any time.
- Free Starter websites: live for 30 days from first publication, then deleted.
- Unpublished drafts: deleted 7 days after their event date. Drafts started over WhatsApp that were never opened are removed after 30 days.
- Guest replies, wishes and photos guests add: deleted together with the page they belong to.
- Payment records: as long as tax and accounting law requires.
- Activity timeline (the steps you took on the site, used for support): 90 days.
- First-party usage events tied to a browser id: 18 months, then deleted. Aggregate counts (how many people opened a page) contain no id and stay.
- Google Analytics: event data is retained for 14 months.
- Connected-app tokens: access tokens expire after 30 days and refresh tokens after 180, or immediately when you disconnect.
- Backups: daily database backups are kept for 14 days, then overwritten.
What we do NOT do
- We don’t sell your data. Ever.
- We don’t read or mine your guest lists or messages for advertising.
- We don’t send marketing email without your consent.
Sharing & visibility
A published page is visible to anyone who has its link - that’s the point of the product. Share links carefully. Unpublishing or deleting an invite removes public access.
Who receives your data (recipients)
- Cloudflare: hosting protection, CDN and media storage.
- Google: Sign-In, Analytics, and Gemini (the vision model that reads an uploaded card; the image is processed and not used to train Google’s models under the API terms).
- Razorpay: payments.
- MSG91 (Meta WhatsApp Business API): WhatsApp sign-in codes, notifications you opt into, and the WhatsApp card upload bot.
- The AI assistant you connect (OpenAI for ChatGPT, Anthropic for Claude): receives the invitation data you ask it to work on, under that provider’s own privacy terms.
Each processor sees only what its function needs. Data is stored in India and in the processors’ regions.
Cookies and similar technologies
Essential cookies and browser storage support sign-in, security, abuse prevention and remembering your choices. Optional analytics uses Google Analytics cookies and CardToPage browser and session identifiers to measure visits and how pages and features are used.
Every visitor sees a short cookie notice once. In the European Union, the European Economic Area and the United Kingdom, optional analytics stays off until you tick it. Everywhere else, including India, it is on by default; choose Manage cookies in the notice, or Cookie Settings at any time, to turn it off. Turning it off does not prevent you from creating invitations or using your account.
To apply the right rule, we look up your country from your IP address using the IP Geolocation by DB-IP database, which runs on our own server. The same country sets the currency and prices you see. Your IP address is not sent to DB-IP.
Use to accept, reject or change your analytics preference at any time. Rejecting stops further optional analytics and removes analytics identifiers stored by this website; it does not delete data already received. Contact us below for a data deletion request.
Your controls and rights
You can edit or delete any invite from your dashboard, export or delete guest replies, disconnect a connected app, or ask us to delete your entire account and data via Contact. We answer access, correction and deletion requests at [email protected] within 30 days. Guests can ask a host to remove their reply, or write to us.