Legal

Privacy Policy

Last updated: 1 May 2026 · Applies to cardwize.eu

This Privacy Policy explains what personal data we collect, why we collect it, and what rights you have under the EU General Data Protection Regulation (GDPR). We have written this to be readable, not just legally compliant.

1. Who We Are (Data Controller)

The data controller for this website and the guide purchase is the operator of this service. For data requests, contact us at hello@cardwize.eu.

2. What Data We Collect and Why

DataWhy We Collect ItLegal BasisRetention
Email address To deliver your purchase confirmation and PDF download link. To send guide updates (Complete tier). Contract performance (Art. 6(1)(b) GDPR) 3 years from purchase, or until you unsubscribe
Payment data (card details, billing address) To process your payment. We do not store card details — these are handled entirely by Stripe. Contract performance Not stored by us. Stripe retains per their policy.
Purchase record (amount, product, date, order ID) Accounting, refund processing, and dispute resolution. Legal obligation (Art. 6(1)(c) GDPR) 7 years (EU accounting law requirement)
Session hash (one-way hash of IP address + browser type + date) Counting unique page views per layout variant. The hash cannot be reversed. No raw IP address is stored. Legal obligation / legitimate interest (Art. 6(1)(c)(f) GDPR) Refreshed daily. Raw IP never stored.
Support correspondence To respond to your emails and resolve issues. Contract performance / legitimate interest 2 years from last contact

3. Third Parties We Share Data With

We do not sell your personal data. We do not use your data for advertising. We do not share your data with financial providers mentioned in the guide.

4. Cookies & Session Tracking

This website uses the following cookies and session mechanisms:

Cookie / MechanismPurposeDurationCan you opt out?
ab_variant Stores which page layout variant you were shown, so you see the same version on return visits and so we can measure which layouts lead to more purchases. No personal data is stored — only a variant identifier (e.g. "v1", "v2"). This is a functional analytics cookie, not an advertising cookie. 7 days Yes — clearing cookies removes it. The site works without it; you may be shown a different variant on your next visit.
Stripe cookies Set by Stripe during the payment process. Necessary for fraud detection and payment security. We do not control these cookies. Session / varies No — required for payment processing to function.
Session hash A one-way hash of your IP address, browser type, and the current date — used to count unique page views per variant without identifying you personally. This hash cannot be reversed to find your IP address. Stored server-side only, not in a cookie. Refreshed daily N/A — stored server-side only, not on your device.

We do not use advertising cookies, tracking pixels, or third-party analytics platforms (e.g. Google Analytics) that profile you across websites. The variant tracking described above is entirely first-party and self-hosted.

If you disable cookies, the Stripe payment process may not function correctly. The page variant system will still work but you may see a different layout on each visit.

5. Your GDPR Rights

Right of Access
Request a copy of all personal data we hold about you.
Right to Erasure
Request deletion of your data. Note: some data must be retained for legal/accounting reasons.
Right to Rectification
Request correction of inaccurate personal data we hold.
Right to Portability
Receive your data in a machine-readable format to transfer elsewhere.
Right to Object
Object to processing based on legitimate interest (e.g. analytics).
Right to Withdraw Consent
Unsubscribe from update emails at any time via the link in any email.

To exercise any right, email hello@cardwize.eu. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

6. Data Security

We use HTTPS encryption for all data transmission. Payment processing is handled by Stripe (PCI DSS Level 1 certified). We do not store payment card details. Access to purchase records is restricted to the data controller only.

7. International Transfers

Stripe may process payment data outside the EU under Standard Contractual Clauses (SCCs) as approved by the European Commission. We do not otherwise transfer your personal data outside the EU/EEA.

8. Changes to This Policy

We may update this policy when our practices change. Material changes will be communicated to purchasers via email. The "Last updated" date at the top of this page always reflects the current version.

9. Contact

Privacy questions: hello@cardwize.eu