This notice explains how CardFlow (the “Operator”, “we”, “us”) handles personal data for the public CardFlow website and the tenant portal at cardflow.uk. It covers the data we hold as a controller — primarily the account information of shop owners who sign up. Personal data that a tenant processes about their own customers (for example, storefront orders) is handled under the Data Processing Agreement, where the tenant is the controller and we are the processor.
1. Who we are
CardFlow is a UK-based multi-tenant SaaS platform for trading card shops. For questions about this notice or your data, contact [email protected]. You can also reach our support team at [email protected].
2. What we collect and why
- Account details (name, email, shop name, chosen subdomain) — collected at signup to create and operate your tenant. Lawful basis: contract (Art. 6(1)(b) UK GDPR).
- Billing information — subscription payments are handled by our payment processor (Stripe); we never see or store your card number. We retain invoices and transaction records to meet our accounting and tax obligations. Lawful basis: legal obligation and contract.
- Operational data (sign-in events, audit logs, support correspondence) — to secure the service, prevent abuse, and provide support. Lawful basis: legitimate interests.
- Essential cookies — a session cookie keeps you signed in to the portal. We do not use advertising or analytics cookies. See section 7.
3. How long we keep it
Account data is retained for the life of your tenant and during the deletion window after a tenant ends, then erased (see our retention process in the Terms). Financial records are kept for 6 years to meet HMRC requirements. Audit and security logs are kept for a limited period proportionate to their purpose.
4. Who we share it with
We share personal data only with the sub-processors needed to run the service — for example our payment processor (Stripe) and transactional email provider — each under a data processing agreement. We do not sell your data or share it for advertising. A current list of sub-processors is available on request and in the DPA.
5. Where it is processed
We host and process data in the UK/EEA. Where a sub-processor processes data outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Addendum).
6. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data. To exercise any of these, email [email protected]; we will respond within one calendar month. If you are unhappy with our response you may complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
7. Cookies
This site and the portal use only strictly necessary cookies — a session cookie to keep you signed in and remember your preferences. Under the Privacy and Electronic Communications Regulations 2003 (PECR), strictly necessary cookies do not require consent. We do not use analytics, advertising, or third-party tracking cookies. If that changes, we will update this notice and seek consent before setting any non-essential cookie.
8. Changes to this notice
We may update this notice; material changes increment the version shown above and, where appropriate, we will notify you.