Privacy Policy
Last updated: Sep 18, 2026
Template notice: this is a starting point, not legal advice — have it reviewed for your product before you launch. This policy explains what Bitecard does with personal data — the data account holders give us when they buy a subscription and use the product. We sell personal data to nobody and we run no advertising trackers.
Who is responsible for your data
Bitecard, operated by [Company legal name], [registered address], is the data controller for account holders and for visitors to this website. You can reach us at support@bitecard.app.
What we collect when you open an account
To create and run your account we store:
- Your name, email address, phone number and the language you chose to work in.
- The organizations you set up — their name, logo, contact details — and the team members you invite to them.
- Your subscription status, plan and billing period. Card details are entered on Stripe's own pages and never reach our servers.
What is collected automatically
Our hosting provider logs the technical details every web request carries — IP address, browser and the page requested — to keep the service running and to stop abuse. We do not build profiles from them.
There are no advertising or marketing cookies anywhere on this site. Product analytics run inside the admin app, which this policy discloses, and on our marketing pages only after you accept them in the banner.
On a restaurant's public menu page we count how often the page is opened, so the restaurant can see whether guests use it. The count is anonymous: the page sets no cookie, loads no analytics script and shows no consent banner, and each view is sent to PostHog as a one-off event with no identifier, no profile and no IP address.
Inside the admin app we also record account holders' own sessions — the pages, clicks and scrolling of the person signed in — so we can see where the product is hard to use. Those recordings never run on our marketing pages, and every field typed into is masked.
What we use it for
Personal data is used only for the things the product exists to do:
- Running your account, your organizations and your team.
- Sending transactional email — sign-in links, invitations, billing notices — to you and your team.
- Signing you in, which is done with a one-time link sent to your email address.
- Taking subscription payments and telling you when a plan limit is reached.
- Answering you when you contact support.
- Rate-limiting, fraud prevention and keeping the service available.
The legal bases we rely on
Under the GDPR, our processing rests on:
- Performance of a contract — everything needed to give you the account you signed up for.
- Legitimate interests — keeping the service secure and available, and preventing abuse.
- Legal obligations — keeping the billing records tax law requires us to keep.
- Consent — for anything optional, such as analytics on our marketing pages. You can withdraw it at any time. Signed in, the analytics answer is under Settings; signed out, clearing this site's cookies puts the question back.
Who else sees it
We do not sell or rent personal data, and we share it only with the providers that make the product work. Each processes data on our instructions, under a data processing agreement:
- Stripe — subscription payments and card processing.
- Resend — delivery of transactional email.
- PostHog — product analytics, on their EU servers.
- Sentry — error monitoring, on their EU servers.
- Our hosting and database providers, which run the application and store its data.
- Authorities, where the law obliges us to disclose something.
Some of these providers operate outside the European Economic Area. Where data leaves the EEA it is transferred under the European Commission's Standard Contractual Clauses.
Cookies
The cookies this site sets and what each is for. Only the analytics one waits for your permission:
- A session cookie that keeps you signed in after you follow your sign-in link.
- A cookie remembering the language you chose, so the site opens in it next time.
- A cookie remembering which of your organizations you were last working in.
- A cookie recording whether you accepted or declined analytics on our marketing pages, and — only once you accept — the cookies PostHog sets so that one visit is counted as one visit. Decline and the first is set, the rest never are.
How long we keep it
Account data is kept for as long as your account is open. Close it and we delete your account and your organizations, apart from the billing records tax law requires us to retain.
Your rights
Wherever we are the controller of your data, the GDPR gives you the right to:
- Ask what we hold about you and get a copy of it.
- Have anything inaccurate corrected.
- Have it erased.
- Have its processing restricted, or object to it.
- Receive it in a portable, machine-readable format.
- Withdraw a consent you gave, without affecting what was done before you withdrew it.
Write to support@bitecard.app and we will respond within one month.
You may also complain to your local data protection authority.
How it is protected
Data is transmitted over encrypted connections and stored on managed infrastructure with access restricted to those who need it. Your account has no password to lose — sign-in is by one-time link. No system is perfect, and if a breach ever affects your data we will tell you and the supervisory authority as the law requires.
Children
Bitecard is a product for organizations and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may amend this policy. The date at the top always says when it last changed, and we will email account holders before any change that materially affects them takes effect.
Contact us
Questions about this policy, or about the data we hold? Write to support@bitecard.app.