Privacy Policy
Last updated: January 2025
1. Information We Collect
Cardity collects: location data (GPS coordinates, used only while the app is active or running in the background with your permission); financial data (transaction history via Plaid's secure, bank-grade API — we never see or store your bank login credentials); and account information (email address, card preferences, and in-app settings).
2. How We Use Your Data
Your location is used solely to identify nearby merchants and deliver card recommendations. We do not sell, rent, or share your location history with advertisers. Financial data is used exclusively to personalize recommendations and calculate your savings. We use Plaid — a regulated, SOC 2 compliant financial infrastructure company — to securely access your transaction data with your explicit consent.
3. Data Storage & Security
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. We use Supabase, a SOC 2 compliant database platform, to store your account information. Transaction data is retained for 12 months. You may request complete deletion of your data at any time by emailing privacy@Cardity.app.
4. Third-Party Services
We use Plaid for bank connectivity, Google Places API for merchant identification, and Expo/React Native for our mobile infrastructure. Each operates under their own privacy policies. We do not use your data for advertising, and we do not sell data to brokers under any circumstances.
5. Your Rights
You have the right to access, correct, export, or delete your personal data at any time. You may revoke bank access through your Cardity account settings without deleting your account. Contact privacy@Cardity.app to exercise any rights.
6. Children's Privacy
Cardity is not directed to children under 13. We do not knowingly collect personal information from children under 13.
7. Contact
privacy@Cardity.app