Privacy Policy
This Privacy Policy explains what personal data we collect, why we collect it, and what rights you have under the EU General Data Protection Regulation (GDPR). We have written this to be readable, not just legally compliant.
1. Who We Are (Data Controller)
The data controller for this website and the guide purchase is the operator of this service. For data requests, contact us at hello@cardwize.eu.
2. What Data We Collect and Why
| Data | Why We Collect It | Legal Basis | Retention |
|---|---|---|---|
| Email address | To deliver your purchase confirmation and PDF download link. To send guide updates (Complete tier). | Contract performance (Art. 6(1)(b) GDPR) | 3 years from purchase, or until you unsubscribe |
| Payment data (card details, billing address) | To process your payment. We do not store card details — these are handled entirely by Stripe. | Contract performance | Not stored by us. Stripe retains per their policy. |
| Purchase record (amount, product, date, order ID) | Accounting, refund processing, and dispute resolution. | Legal obligation (Art. 6(1)(c) GDPR) | 7 years (EU accounting law requirement) |
| Session hash (one-way hash of IP address + browser type + date) | Counting unique page views per layout variant. The hash cannot be reversed. No raw IP address is stored. | Legal obligation / legitimate interest (Art. 6(1)(c)(f) GDPR) | Refreshed daily. Raw IP never stored. |
| Support correspondence | To respond to your emails and resolve issues. | Contract performance / legitimate interest | 2 years from last contact |
3. Third Parties We Share Data With
- Stripe — payment processing. Stripe is GDPR-compliant and acts as a data processor. Their privacy policy: stripe.com/privacy.
- Email delivery provider — used to send purchase confirmations and update emails. No marketing lists are sold or shared.
We do not sell your personal data. We do not use your data for advertising. We do not share your data with financial providers mentioned in the guide.
4. Cookies & Session Tracking
This website uses the following cookies and session mechanisms:
| Cookie / Mechanism | Purpose | Duration | Can you opt out? |
|---|---|---|---|
| ab_variant | Stores which page layout variant you were shown, so you see the same version on return visits and so we can measure which layouts lead to more purchases. No personal data is stored — only a variant identifier (e.g. "v1", "v2"). This is a functional analytics cookie, not an advertising cookie. | 7 days | Yes — clearing cookies removes it. The site works without it; you may be shown a different variant on your next visit. |
| Stripe cookies | Set by Stripe during the payment process. Necessary for fraud detection and payment security. We do not control these cookies. | Session / varies | No — required for payment processing to function. |
| Session hash | A one-way hash of your IP address, browser type, and the current date — used to count unique page views per variant without identifying you personally. This hash cannot be reversed to find your IP address. Stored server-side only, not in a cookie. | Refreshed daily | N/A — stored server-side only, not on your device. |
We do not use advertising cookies, tracking pixels, or third-party analytics platforms (e.g. Google Analytics) that profile you across websites. The variant tracking described above is entirely first-party and self-hosted.
If you disable cookies, the Stripe payment process may not function correctly. The page variant system will still work but you may see a different layout on each visit.
5. Your GDPR Rights
To exercise any right, email hello@cardwize.eu. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
6. Data Security
We use HTTPS encryption for all data transmission. Payment processing is handled by Stripe (PCI DSS Level 1 certified). We do not store payment card details. Access to purchase records is restricted to the data controller only.
7. International Transfers
Stripe may process payment data outside the EU under Standard Contractual Clauses (SCCs) as approved by the European Commission. We do not otherwise transfer your personal data outside the EU/EEA.
8. Changes to This Policy
We may update this policy when our practices change. Material changes will be communicated to purchasers via email. The "Last updated" date at the top of this page always reflects the current version.
9. Contact
Privacy questions: hello@cardwize.eu