Privacy Policy
Last updated: August 1, 2026 — Version 1.2
1. Data Controller
Lindox OrbIT (“we”, “us”) operates CardMan at https://cardman.dk. For data-related inquiries, contact hello@cardman.dk.
2. What Data We Collect
- Account data — name (optional), email address, hashed password, language preference.
- Subscription & payment-method data — service names, billing cycles, amounts, currencies, card last-4 digits, expiry dates, wallet types, invoice emails, start dates, and renewal dates. For investment-type subscriptions, we also store expected interest rates and initial investment values. We never store full card numbers.
- Subscription categories — each subscription may be classified as a subscription, investment, saving, or reimbursed entry. This categorisation is used for spending analysis and investment forecasting.
- Usage data — activity history (add/edit/delete events), login timestamps, preferred theme, currency, language, and view mode.
- Technical data — IP address, browser user-agent string (stored in consent records, session records, and login history).
- Email interaction data — when you click a link in an email we send (e.g. renewal reminders, card expiry alerts, trial expiry notices), we record which link was clicked and the email type. We do not track email opens or use tracking pixels.
- Consent records — we log which policy versions you have accepted, along with timestamps, to fulfil GDPR record-keeping requirements.
3. Why We Process Your Data
| Purpose | Legal Basis (GDPR Art. 6) |
| Provide the service (dashboard, reminders, spending analysis, investment forecasting) | Performance of contract |
| Account security (hashed passwords, rate limiting, login history) | Legitimate interest |
| Send transactional emails (verification, password reset, renewal & trial expiry reminders) | Performance of contract |
| Measure email link engagement to improve notification quality | Legitimate interest |
| Record consent and track policy version acceptance | Legal obligation (GDPR Art. 7) |
| Data export (CSV) for portability | Performance of contract / GDPR Art. 20 |
4. Data Retention & Account Deletion
Your data is retained for as long as your account is active. You can permanently delete your account at any time from Settings → Danger Zone → Delete Account. The process requires email confirmation for your security: we send a verification link, and deletion is finalised only after you confirm on the linked page. Upon deletion, all personal data (subscriptions, payment methods, activity history, preferences, and session tokens) is permanently removed via cascading foreign keys. A final confirmation email is sent to acknowledge the deletion. Consent logs are retained for 3 years with your user ID removed, to fulfil legal record-keeping obligations. Login history (timestamps, IP addresses, and user-agent strings) is automatically purged after 2 years.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties. Data is processed solely on our own servers. Transactional emails are sent via Google SMTP (Gmail/Workspace); no message content is stored by us beyond delivery.
6. Your Rights (GDPR)
As a data subject you have the right to:
- Access — request a copy of all data we hold about you.
- Rectification — correct inaccurate personal data.
- Erasure (“right to be forgotten”) — delete your account and all associated data directly from the Settings page, or by contacting us.
- Data portability — receive your data in a structured, machine-readable format.
- Object / Restrict processing — limit how we use your data.
- Withdraw consent — at any time, without affecting prior lawful processing.
To exercise any right, email hello@cardman.dk. We respond ASAP!
7. Security
We use industry-standard measures including:
- Encryption at rest — all personal and financial data (names, service names, payment-method details, card last-4 digits, expiry dates, billing amounts, currencies, billing cycles, renewal dates, start dates, interest rates, initial investment values, notes, and activity history) is encrypted with AES-256-GCM using per-user encryption keys. Only system identifiers, subscription type classifications, and non-personal preferences remain unencrypted.
- Key management — each user’s encryption key is derived from their password and also protected by a server recovery key, so data remains secure even if the database is compromised. Password resets recover data via the server key without re-encryption.
- Password hashing — bcrypt (industry-standard one-way hashing).
- Transport security — HTTPS-only cookies with httponly and samesite flags.
- Application security — CSRF tokens, rate limiting, prepared SQL statements, and strict input validation.
8. Data Portability
You can export all your subscription data at any time as a CSV file from the dashboard. The export includes service names, amounts, currencies, billing cycles, renewal dates, start dates, subscription types, interest rates, and notes. You may also print or save a PDF of your dashboard view.
9. Consent Versioning
This policy is versioned. When we make material changes, you will be asked to review and accept the updated policy upon your next login. Your acceptance of each policy version is logged with a timestamp for audit purposes. You may decline by logging out; however, continued use of the service requires acceptance of the current policy.
10. Changes
We may update this policy. Material changes will require re-acceptance at login (see Section 9). The version number and date are displayed at the top of this page.