Legal
Privacy Policy
Last updated: August 4, 2026
This policy is issued by BabelOn Incorporated d/b/a Cardbop, the company that operates Cardbop and the controller of the information described below. It forms part of our Terms of Service.
What we collect
Card content. The photos you upload and the text you add — names, teams, dates, stats, and the message on the back. This is the product, so we store it to render, print, and ship your card, and to show it again if you return to a saved design.
Order and shipping details. When you buy, Stripe collects your email, billing address, and a US shipping address on our behalf, and we store the resulting order record (order number, amount, currency, what was ordered, promo code used, and where to send it).
Payment details. Handled entirely by Stripe. Card numbers never reach Cardbop's servers.
Account details. If you create an account, we store your email address and authentication data through Supabase. Passwords are handled by Supabase and are not visible to us.
Usage data. Pages viewed, approximate location derived from IP, device and browser type, and a small number of events — clicking a call-to-action, uploading photos, saving a draft, reaching preview, publishing a pack, starting checkout, and completing a purchase. See Analytics and cookies.
Messages you send us. If you contact us, we keep your message, name, and email address so we can reply.
Newsletter subscription. If you sign up, we store your email address, where you signed up from, and whether you have since unsubscribed.
Your rights confirmation. When you confirm that you own or have permission to use the photos in an order, we store that confirmation — the exact wording and the time — alongside the order. See Your photos.
IP address, briefly. We read your IP address to rate-limit forms and block bots, and to decide which country you are in for the analytics rule below. We do not store IP addresses in our database — they are held in memory for a few minutes and discarded. Our hosting and security providers keep their own short-lived logs.
Categories, sources, and purposes
Set out formally, for California and other state privacy laws, here is every category of personal information we have collected in the past 12 months, where it comes from, and why we hold it.
| Category | Examples | Source | Why we hold it |
|---|---|---|---|
| Identifiers | Email address, name on an order, account ID, shipping address | You, and Stripe at checkout | Fulfil orders, run your account, support |
| Card content | Photos you upload and the text on the card | You | Render, print, and ship your card |
| Commercial information | Orders placed, amounts, what was ordered, promo codes used | You and Stripe | Fulfilment, accounting, tax, support, fraud prevention |
| Financial information | Payment method details — held by Stripe, not by us | You, via Stripe | Take payment and handle refunds |
| Internet and device activity | Pages viewed, device and browser type, referring page, builder events | Automatic | Measure and improve the site and the card builder |
| Approximate location | Country or region inferred from IP address | Automatic | Analytics, and deciding whether to load analytics at all |
| Communications | Messages you send us and newsletter subscription status | You | Reply to you, and send email you asked for |
Each category is disclosed to the service providers listed in Who we share it withfor the purpose shown. We do not collect Social Security numbers, driver's licence numbers, precise geolocation, health information, or account credentials for other services.
Sensitive personal information. A photograph can reveal things a privacy law treats as sensitive — for example race or religion. We do not use photographs to infer any characteristic about you, and we do not use sensitive personal information for any purpose beyond printing the card you asked for. We therefore do not use or disclose it for purposes that would trigger the right to limit its use under California law.
How we use it
To design, print, and deliver your order; to show you your saved cards; to process payment and handle refunds or reprints; to send order and shipping email about a purchase you made; to send newsletter email if you asked for it; to answer your questions; to detect abuse and prevent fraud; to keep a record of the photo-rights confirmation you gave; to meet accounting, tax, and legal obligations; and to understand which parts of the site are useful so we can improve them.
We do not use your photos or card content to train machine-learning models, we do not sell them, and we do not use them in marketing without asking you first.
We do not use your information to make decisions about you that produce legal or similarly significant effects without human involvement.
Why we are allowed to use it
If you are in a place whose law requires us to identify a legal basis — the UK and the EEA, for example — we rely on the following:
- Performance of a contract — to make and deliver the cards you ordered, and to run your account.
- Legitimate interests — to secure the site, prevent fraud and abuse, understand how the product is used, and keep a record of the rights confirmation you gave. We balance these against your interests.
- Consent — for newsletter email, and for anything else we specifically ask you to agree to. You can withdraw consent at any time.
- Legal obligation — to keep tax and accounting records and respond to lawful requests.
Who we share it with
We share personal information only with service providers who process it on our instructions to help us run Cardbop:
- Stripe — payment processing, billing and shipping collection, tax calculation.
- Supabase — database, file storage for photos and card art, and account authentication.
- Vercel — website hosting and delivery.
- Google Analytics — website usage measurement (not loaded for EEA, UK, and Switzerland visitors).
- Cloudflare — Turnstile bot and abuse protection on our forms.
- Our printing partner — receives the card artwork needed to produce your order, and nothing that identifies you: not your name, your email address, or your shipping address.
- Shipping carriers — receive the delivery address and recipient name needed to get the parcel to you.
- Our email automation provider — receives the details needed to send order, account, contact, and newsletter email (including your email address and the relevant order or message).
These providers are contractually limited to using the information for the services they provide to us. We may also disclose information where the law requires it, to respond to lawful requests, to enforce our Terms, or to protect the rights, safety, or property of Cardbop, our customers, or others.
Business transfers. If BabelOn Incorporated is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this policy, and we will notify you of any material change.
We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioral advertising — as those terms are defined by the California Consumer Privacy Act and comparable state laws. We have not done so in the past 12 months, and we do not sell or share the personal information of anyone under 16.
We do not run advertising pixels or ad-network tags on this site. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” process to complete — but if you send us a Global Privacy Control signal or a Do Not Track header, we treat it as a request to opt out anyway and will not enable any future sale or sharing for your browser.
Analytics and cookies
We measure usage in two separate ways, and they behave differently. This distinction matters, so we spell it out rather than calling it all “analytics.”
1. Google Analytics 4 (third party, uses cookies). This tells us which pages people find and which ones lead to someone making a card. It sets cookies and processes information such as your IP address, device, and the pages you view, and Google may use that data under its own policies. We do not load Google Analytics for visitors in the European Economic Area, the United Kingdom, or Switzerland. No Google Analytics cookies are set for those visitors, which is why you will not see a cookie banner there.
2. Our own product analytics (first party, no cookies). When you use the card builder, we record a few events on our own servers — photos uploaded, draft saved, preview reached, pack published — together with counts like how many cards are in the order, and your account ID if you are signed in. This is how we find out where people get stuck. It sets no cookies and involves no third party.
To be clear about the difference: the EEA, UK, and Switzerland exclusion described above applies to Google Analytics. Our own first-party product analytics run for everyone, including visitors in those regions. We rely on legitimate interests for it, we do not use it to build advertising profiles or track you across other websites, and you can object at any time using the contact details below.
Strictly necessary cookies.A small number of cookies make the site work: keeping you signed in, remembering your cart and card drafts, and recording whether analytics should load. These are not used to track you across other websites. Drafts and photos in progress are also stored in your browser's local storage on your own device.
You can block cookies in your browser, and you can opt out of Google Analytics with Google's browser opt-out add-on. Blocking cookies may stop drafts and sign-in from working.
Email you get from us
Order and account email — confirmations, shipping updates, and replies to your questions — is transactional. We send it because you bought something or contacted us, and you cannot unsubscribe from it while an order is in progress.
Newsletter and marketing email is only sent if you asked for it, and you can stop it at any time. To unsubscribe, reply to any marketing email asking to be removed, or email contact@cardbop.comwith “Unsubscribe” in the subject. Every marketing email we send tells you how to opt out and includes our postal address.
We act on opt-out requests within ten business days at the latest, and usually much sooner. We keep a suppression record showing that you unsubscribed — that record exists only so we do not add you back by mistake, and it is never used to email you.
Your photos
Photos you upload are stored so your card can be rendered, printed, and re-opened later. The “isolate the subject” background-removal tool runs entirely on your own device — that photo is not uploaded anywhere for processing, and the model files come from our own servers rather than a third-party CDN.
You must own or have permission to use every photo you upload — including permission from anyone shown in it, and from a parent or guardian when that person is a child. Before you can check out, you confirm this with a checkbox, and we record that confirmation with your order. The full obligation is set out in Section 6 of the Terms of Service. We do not verify ownership of imagery and rely on your confirmation.
Your photos are shared with our printing partner so your card can be produced — the artwork only, with nothing attached that identifies you. They are not shared with anyone else, not sold, and not used to train AI models.
If you believe someone has uploaded a photo of you, or of your child, without permission, contact us at contact@cardbop.com and we'll remove it. Copyright owners can send a notice under the process in Section 19 of the Terms.
Face and biometric data
Because our product involves photographs of people, we want to be unambiguous about this.
We do not perform facial recognition, and we do not collect, capture, store, or use biometric identifiers or biometric information — no faceprints, no face geometry, no fingerprints, no voice prints. We do not use photographs to identify anyone, to match a person across images, or to infer demographic characteristics.
The background-removal tool uses a general image-segmentation model that separates a foreground subject from its background. It does not detect or recognize faces, it does not produce a biometric template, it runs entirely on your own device, and nothing from it is sent to us or to any third party. We do not sell, lease, trade, or otherwise profit from biometric data, because we do not have any.
How long we keep it
We keep personal information only as long as we actually need it. Rather than quote a fixed number of years we could not honor consistently, here are the criteria we use for each kind of information:
- Order records — kept for as long as tax, accounting, and record-keeping law requires us to keep them, and for any period in which a claim relating to the order could still be brought.
- Card designs and photos — kept while your account or draft is active, so you can reorder or reprint, and deleted when you delete the design or ask us to close your account.
- Rights confirmations — kept with the order for as long as the order record, since their purpose is to evidence what you agreed to if a claim is made later.
- Account details — kept until you ask us to close the account.
- Contact messages — kept while we handle your question and for a reasonable period afterwards for support history.
- Newsletter records — kept until you unsubscribe, plus a suppression record afterwards so we do not re-add you.
- Product analytics events — kept in aggregate for trend analysis; Google Analytics data is retained on Google's standard schedule.
- Rate-limiting data — held in memory for minutes, never written to our database.
If you ask us to delete your account, we remove your designs and photos and keep only the order records we are required to retain. Backups are overwritten on a rolling schedule.
Your choices and rights
Wherever you live, you can ask us to:
- Access the personal information we hold about you, or get a portable copy;
- Correct anything inaccurate;
- Delete your information, subject to records we must keep;
- Object to or restrict certain processing, including our first-party product analytics;
- Withdraw consent you previously gave, such as for newsletter email;
- Disable a share link or remove a specific photo or card.
To make a request, email contact@cardbop.com or use the contact page. We will respond within the time your law allows — 45 days under California law, extendable once where permitted. We may need to verify your identity first, usually by confirming control of the email address on the account, and we will not charge you or treat you differently for exercising these rights.
Authorized agents. You may use an authorized agent to make a request. We will ask for proof of their authority and may still ask you to verify your own identity directly.
State privacy rights
California. Under the CCPA as amended by the CPRA, you have the rights to know, access, delete, correct, and obtain a portable copy of your personal information; to opt out of sale or sharing (we do neither); to limit the use of sensitive personal information (we do not use it in ways that trigger this); and not to be discriminated against for exercising any of them. The categories we collect and our purposes are in Categories, sources, and purposes. California's “Shine the Light” law also lets you request details of any disclosure to third parties for their direct marketing — we make none.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws give you broadly similar rights to access, correct, delete, and obtain a copy of your information, and to opt out of targeted advertising, sale, and profiling with significant effects — none of which we do. If we deny your request, you may appeal by replying to our decision or emailing contact@cardbop.comwith the subject “Privacy Appeal.” We will respond within 45 days with our decision and the reasons for it, and will tell you how to contact your state attorney general if you remain dissatisfied.
Washington. The My Health My Data Act concerns consumer health data. We do not collect, use, share, or sell consumer health data, and we do not operate a geofence around any health facility.
Nevada. We do not sell covered information as defined by Nevada law.
Children
Cardbop is intended for adults. You must be at least 18 to hold an account or place an order, and we do not knowingly collect personal information directly from children under 13. If you believe a child has given us information, contact us and we will delete it.
Cards of children are different, and very common.A parent making a card of their kid, or a coach making a team pack, means we end up processing photographs and details of children — supplied by an adult. When you upload a photo of a child you are confirming that you are that child's parent or legal guardian, or that you have their parent or guardian's permission. See Section 6 of the Terms. We use that information only to make the card, we do not build profiles of children, we do not use their images for marketing, and we do not sell them.
A parent or guardian can contact us at contact@cardbop.com at any time to see what we hold about their child, have it deleted, or have a share link disabled.
Security
We use reputable providers, encrypted connections (HTTPS), access controls, row-level security on our database, and bot and rate-limiting protection on our forms. Payment card data never touches our servers.
No method of storage or transmission is completely secure, so we cannot guarantee absolute security. You help by using a strong, unique password and keeping it to yourself. If we become aware of a breach affecting your personal information, we will notify you and the relevant regulators as required by law.
Where your information is handled
We are based in the United States and your information is processed here, including by the service providers listed above. United States law may not offer the same protections as the law where you live.
We ship only to United States addresses, so we do not offer goods or services to people in the EEA or UK. If you visit from there and we do handle your information — because you browsed the site or created an account — we rely on the legal bases above, and where a transfer mechanism is required we use the appropriate safeguards our providers offer, such as Standard Contractual Clauses. You have the right to complain to your local supervisory authority.
Changes to this policy
If we make meaningful changes we will update the date at the top of this page and, where the change is material, give additional notice such as an email or an in-product notice before it takes effect. Continuing to use Cardbop after a change means you accept the updated policy.
Contact us
Questions about privacy, or want to exercise a right? Email contact@cardbop.com or use the contact page.
The company responsible for your information is:
BabelOn Incorporated d/b/a Cardbop
8250 15th Ave NE
Seattle, WA 98115
contact@cardbop.com