Privacy policy

A clear explanation of what data we use, why, who we share it with and when we delete it. We comply with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Data controller

[COMPLETAR: tu nombre y apellidos, o la razón social] (Tax ID [COMPLETAR: NIF/DNI]), [COMPLETAR: domicilio fiscal completo]. For any privacy question: [COMPLETAR: email de contacto].

2. What data we use and why

If you create or buy a card

Purpose: to prepare, show and deliver the card you bought. Legal basis: performance of the purchase contract (Art. 6(1)(b) GDPR) and, for what the law requires us to keep (invoicing), compliance with legal obligations (Art. 6(1)(c)).

If you receive a card

We only process your data if you choose to reply: your text and/or photo are emailed to the person who gave you the card. The photo is cleaned before sending (we remove the GPS location and other hidden data phones store). Legal basis: your consent, given when you press send (Art. 6(1)(a)). We never show you the sender's email or give them yours.

People in the photos

The person creating the card guarantees they have permission from the people appearing in their photos and, if they are minors, that they are their parent or guardian or have their authorization. Photos are used only for that card, never for advertising or to train our own AI models, and they are not public: only people with the link can see them.

Technical data

We use your IP address to prevent abuse (for example, limiting how many times the AI can be used per hour) and to show prices in your currency. These counters are deleted automatically within 24 hours at most. Legal basis: our legitimate interest in protecting the service (Art. 6(1)(f)). We measure visits in aggregate and without cookies, and we never measure card addresses (more in the cookie policy).

3. Artificial intelligence

The AI makes no decisions about you: it only generates a text or an image that you review. Photos edited with AI are labeled as such in the card.

4. Who we share data with

We don't sell or transfer data to anyone. It is only processed, on our behalf and under a data processing agreement, by the providers we need for the website to work:

ProviderPurposeWhere
Cloudflare (Workers)Website hosting and cookie-free visitor analyticsGlobal network (EU / USA)
NeonDatabase (orders and card texts)USA
Cloudflare (R2)Private storage of photos and audioEU
StripeCard payments (we never see your card details)EU / USA
ResendSending emails (card link and replies)USA
UpstashAnti-abuse counters by IP address (deleted within 24 h at most)EU
Kie.aiAI: writing the message, reviewing custom photo ideas and editing the main photo if you choose a “magic touch” (uses models from providers such as OpenAI)Outside the EU
SpotifyEmbedded Christmas song playerSweden / USA

When a provider is outside the European Economic Area, the transfer is covered by the EU-U.S. Data Privacy Framework or by the Standard Contractual Clauses approved by the European Commission. We only share data with authorities when legally required.

5. How long we keep it

6. Your rights

You can ask us at any time to access, correct or delete your data (for example, to remove a card early), to object to or restrict its use, or to receive it in a portable format. Write to [COMPLETAR: email de contacto] including the card link if you have it. We reply within one month at most.

If you believe we haven't handled your data properly, you can file a complaint with the Spanish Data Protection Agency (aepd.es) or with the data protection authority of your country.

7. Minimum age

You must be 18 or older to make a purchase.

8. Security

Photos and audio are kept in private storage and only shown through temporary links. Each card has an address that's impossible to guess, and the website only works over an encrypted connection (HTTPS). If a security incident affecting you ever occurred, we would notify you and report it to the authorities as required by law.

Privacy · Wrelia